Privacy Policy
1. Data Controller
The Data Controller of the personal data collected through the website csr-italia.org is Luciano Frascà, domiciled in Bologna, Via M. Calari 23, Italy, who can be contacted at contatti@csr-italia.org.
2. Types of data collected
Through the website, the following personal data may be collected and processed:
identification and contact data voluntarily provided by the user, such as name, email address, subject and message content;
any additional personal data voluntarily included by the user in contact forms or email communications;
technical browsing data, such as IP address, browser information, device used, date and time of the request, technical logs and other data necessary for the operation and security of the website;
data related to access to password-protected content, where applicable;
data related to the website’s technical preferences, including any language preferences.
3. Purposes of Processing
Personal data are processed for the following purposes:
to manage contact requests submitted through the website;
to manage confidential contact requests;
to assess and manage any requests for credentials or access to protected content;
to respond to communications sent by the user;
to ensure the proper technical functioning and security of the website;
to comply with legal, regulatory or rights-protection obligations of the Data Controller.
4. Legal Basis for Processing
The processing of personal data is based, depending on the circumstances, on the following legal grounds:
the performance of pre-contractual measures taken at the request of the data subject;
the legitimate interest of the Data Controller in the orderly management of requests received, in protecting the website and in safeguarding its rights;
compliance with legal obligations, where applicable.
5. Methods of Processing
Personal data are processed using manual, IT and telematic tools, according to methods strictly related to the purposes indicated above and by adopting appropriate security measures to prevent unauthorized access, disclosure, alteration or destruction of data.
6. Contact Forms and Confidential Requests
The website allows users to submit contact requests, confidential contact requests and requests relating to access to protected content.
The data entered in the forms are used exclusively to manage the request received, provide a response and, where necessary, assess the possible release of credentials for access to restricted content.
The optional, explicit and voluntary sending of messages to the contact addresses indicated on the website entails the acquisition of the sender’s contact details and of all personal data included in the communication.
7. Data Recipients and Third-Party Providers
Personal data may be processed, within the limits of the purposes stated above, by third parties providing technical or organizational services on behalf of the Data Controller.
In particular, the website uses Brevo for the sending and management of email communications generated by the website, including those relating to contact forms.
Data may also be processed by providers of hosting, technical maintenance, security, email management and website infrastructure services, including Register.it, within the limits strictly necessary for the provision of such services.
An updated list of any data processors may be requested from the Data Controller using the contact details indicated above.
8. Data Transfers
Should certain technical providers of the website process personal data outside the European Economic Area, such processing shall take place in compliance with the applicable legislation and by adopting the appropriate safeguards provided for by Regulation (EU) 2016/679.
9. Data Retention Period
Personal data collected through the website are retained for the time strictly necessary to achieve the purposes for which they were collected.
In particular, data submitted through contact forms or direct email communications may be retained for the time necessary to manage the request and, subsequently, for a period not exceeding 12 months, except where further retention is necessary to protect the rights of the Data Controller or to comply with legal obligations.
Technical and security-related data may be retained for the period necessary to ensure the proper functioning of the website, the prevention of abuse and the protection of the infrastructure.
10. Cookies and Technical Data
Il sito, realizzato su piattaforma WordPress, utilizza cookie e strumenti tecnici necessari al funzionamento del sito stesso, alla gestione delle preferenze tecniche e linguistiche, alla sicurezza e, ove applicabile, all’accesso a contenuti protetti da password.
Tali strumenti non sono utilizzati, allo stato, per finalità di profilazione commerciale.
Per maggiori informazioni sui cookie utilizzati dal sito, l’utente può consultare la relativa Cookie Policy.
11. Data Subject Rights
Data subjects may exercise, where provided for by applicable law, the following rights:
to obtain confirmation as to whether or not personal data concerning them are being processed;
to access their personal data;
to request rectification or updating of their personal data;
to request erasure of their personal data, where permitted;
to obtain restriction of processing;
to object to processing, where applicable;
to request data portability, where provided for by law;
to lodge a complaint with the Italian Data Protection Authority.
12. How to Exercise Rights
To exercise their rights or request further information on the processing of personal data, users may contact the Data Controller at the following email address: [contatti@csr-italia.org](mailto:contatti@csr-italia.org).
13. Changes to This Notice
The Data Controller reserves the right to modify or update this Privacy Policy at any time, including in consideration of legal, organizational or technical changes affecting the website.
Users are invited to consult this page periodically in order to review the most up-to-date version of this notice.
