Sinergia Group

Privacy Policy

Information on personal data processing under Articles 12 and 13 of Regulation (EU) 2016/679.

Last updated:

1. Data controller

The data controller is Sinergia Group S.p.A., with registered office at Via Meravigli 16, 20123 Milan (MI), Italy, tax code and VAT no. 11605230967.

Contacts: email info@groupsinergia.it; certified email sinergia.group@pec.it; landline +39 06 56 55 8432; toll-free number 800 146 612.

2. Data processed

During browsing, IT systems and the hosting provider may process technical data required to deliver and protect the website, including IP address, request date and time, requested resource, browser, operating system, and diagnostic and security information.

When users contact the Company by certified email, telephone, or another available channel, the Company processes data voluntarily supplied, such as name, contact details, organisation, enquiry content, and any additional information included in the communication.

The contact form collects the user's full name, email address, optional company or organisation, reason for the enquiry, message, and confirmation that this notice has been read. Data is sent to the website server, delivered to the configured corporate mailboxes, and used to send an automatic confirmation to the address provided. The website does not retain enquiries in a separate database.

3. Purposes and legal bases

Data collected for contact enquiries is not used for marketing or newsletters without a separate legal basis and a dedicated notice.

  • Website delivery, stability, and security: the Controller's legitimate interest in providing and protecting its institutional website.
  • Responding to information, technical, or project enquiries: steps taken at the data subject's request before entering into a contract and, where applicable, legitimate interest in managing corporate communications.
  • Prevention of spam, abuse, and automated submissions: the Controller's legitimate interest in protecting the form and its systems.
  • Compliance with legal obligations and responses to competent authorities: legal obligation.
  • Establishment, exercise, or defence of legal claims: legitimate interest.

4. Processing methods

Personal data is processed using technical and organisational procedures appropriate to the nature of the data and the stated purposes, in accordance with the principles of lawfulness, fairness, transparency, minimisation, and storage limitation.

The Company does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

5. Recipients and providers

Data may be processed by authorised personnel and contractors, technical providers appointed or qualified according to their actual role, and public authorities where required by law.

NESS S.p.A. Società Benefit, a Group company, may receive enquiries submitted through the form and process their content through authorised personnel solely to support their handling and respond to the individual.

The website is hosted through Vercel Inc., which may process technical data and logs required to deliver, secure, and diagnose the service.

Plus Five Five, Inc. (Resend) processes addresses, message content, and metadata required to deliver the enquiry to the corporate mailbox and send the automatic confirmation; Cloudflare, Inc. processes through Turnstile technical signals such as IP address, TLS fingerprint, user agent, sitekey, and origin solely to distinguish legitimate users from automated submissions and protect the form. The Controller does not sell personal data.

6. International transfers

Vercel, Resend, and Cloudflare are providers based or operating infrastructure outside the European Economic Area. Any international transfers are carried out using the instruments provided by Chapter V of the GDPR, including, where applicable, adequacy decisions, the Data Privacy Framework, and Standard Contractual Clauses approved by the European Commission.

7. Retention

Technical logs and security signals are retained by providers for the period necessary to deliver, protect, and diagnose the service, according to their respective configurations and retention policies.

Contact enquiries and related communications are retained in the recipient corporate mailboxes for up to 12 months after the enquiry is closed. They may be retained longer where a contractual relationship arises, where required by law, or where necessary to protect a right. Resend retains data and technical metadata for the time required to provide its service and comply with its obligations.

8. Provision of data

Technical browsing data is processed automatically. Providing data in communications is optional, but failure to provide information required to handle an enquiry may prevent the Company from responding.

9. Data subject rights

Where provided by the GDPR, individuals may request access, rectification, erasure, restriction, portability, and object to processing. They may also lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority.

  • Requests may be sent to the Controller by certified email or through the other contact details set out in section 1.
  • Exercising rights is free of charge, except for manifestly unfounded or excessive requests as provided by law.

10. Updates

This notice may be updated following legal, organisational, or technical changes. The current version is identified by the date shown at the beginning of the page.

Loading the Sinergia Group website