Privacy Policy on the Processing of Personal Data
effective from May 9, 2024
(version 1/2024)
Introduction
This privacy policy is provided in compliance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 ("GDPR") and the Privacy Code (Leg. Decree June 30, 2003, No. 196, and subsequent amendments). The document has also been drafted based on the Privacy Authority’s Guidelines (especially the Anti-Spam Guidelines issued by the Privacy Authority on July 4, 2013).
Data Controller: Maind Capital S.r.l. (Tax Code 12187760967), with registered office in Milan, via della Posta No. 8. Email: info@maindcapital.com, Certified Email: maindcapital.pec.it
The portal to which this privacy policy refers: https://maindcapital.com ("Portal").
The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you can send any request for information directly to the Data Controller.
General Information
This document describes how the Data Controller processes your personal data provided on the Portal.
Below are the main processing activities of your personal data. In particular, the legal basis of the processing is explained, whether the provision is mandatory, and the consequences of not providing personal data. To best describe your rights, where necessary, we have specified whether and when a particular personal data processing is not performed.
Registration on the Portal
The information and data requested during registration will be used to allow you to access the reserved area of the Portal and to use the online services offered by the Data Controller to registered users. The legal basis of the processing is the necessity of the Data Controller to take pre-contractual measures at the request of the data subject. Providing data is optional. However, your refusal to provide the data will make it impossible to register on the Portal.
Purchases on the Portal
Your personal data will be processed to allow you to make purchases on the Portal. In case of ordering online services, to allow the conclusion of the purchase contract and the proper execution of related operations (and, if necessary, in accordance with sector legislation, to fulfill tax obligations). This personal data processing also includes the possibility of sending communications (e.g., tracking and order information) via automated tools such as SMS and/or WhatsApp. The legal basis of the processing is the obligation of the Data Controller to execute the contract with the data subject or to comply with legal obligations. Regardless of the above (and therefore of your consent), the Data Controller may process your data for "soft-spam" purposes, governed by Article 130 of the Privacy Code. This means that, limited to the email you provided in the context of a purchase through the Portal, the Data Controller will process the email to allow the direct offer of similar products/services, provided you do not object to such processing in the ways provided in this privacy policy. The legal basis of the processing is the legitimate interest of the Data Controller to send this type of communication. This legitimate interest can be considered equivalent to the interest of the data subject in receiving "soft-spam" communications. The Data Controller may send emails to remind you to complete a purchase. The legal basis of this processing is the legitimate interest of the Data Controller to send this type of communication. The Data Controller may also process your personal data to send updates via email and/or phone (depending on the options available from time to time on the Portal) about the status of orders. The legal basis of this processing is the legitimate interest of the Data Controller to send this type of communication. This interest is equal to your interest in receiving such updates. Providing personal data for this purpose is optional. If personal data is not provided, the Data Controller will not be able to send such communications.
Responding to Your Requests
Your data will be processed to respond to your requests for information. Providing data is optional, but your refusal will make it impossible for the Data Controller to respond to your queries. The legal basis of the processing is the legitimate interest of the Data Controller to respond to user requests. This legitimate interest is equivalent to the user's interest in receiving responses to communications sent to the Data Controller.
Generic Marketing
With your consent, the Data Controller may process personal data you have provided for the purpose of sending you advertising material and/or newsletters related to its own or third-party products. The legal basis of this processing is your consent. Providing personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will result in the inability for you to receive advertising material related to the Data Controller's and/or third-party products/services, as well as the inability for the Data Controller to conduct market research, including direct inquiries to assess user satisfaction, and to send you newsletters. These communications will be sent to the email you provided on the Portal.
Profiling
With your consent, the Data Controller may process your personal data for profiling purposes, that is, for the analysis of your consumer choices by revealing the type and frequency of purchases made by you to send you advertising material and/or newsletters related to its own or third-party products of specific interest to you. The legal basis of this processing is your consent. Providing data for this purpose is purely optional. Failure to consent to the processing of your personal data for profiling purposes will make it impossible for the Data Controller to create your commercial profile by revealing your purchase choices and habits and to send you advertising material related to the Data Controller's and/or third-party products of specific interest to you. These communications will be sent to the email you provided on the Portal.
Geolocation
The Portal does not implement tools for geolocating the user's IP address.
Curriculum Vitae
It is not possible to send resumes via the Portal. Therefore, your data will not be processed for these purposes.
Appointment Booking
The Portal does not have active third-party appointment booking systems with the Data Controller. Therefore, your data will not be processed for this purpose. However, you can always contact the Data Controller using the contact details provided at the beginning.
Photos and Videos
The Data Controller does not request the publication of photos and/or videos depicting you. Therefore, your data will not be processed for these purposes.
Disclosure of Personal Data
In the course of its normal activities, the Data Controller may disclose your personal data to certain categories of entities. In Article 2, you can find the list of entities to whom the Data Controller discloses your personal data. To facilitate the protection of your rights, Article 2 may specify in some cases when your data is not disclosed to third parties.
The "disclosure" of personal data to third parties is different from the "transfer" (regulated in the preceding point). In fact, in the disclosure, the third party to whom the data is transmitted can only use it for the specific purposes described in the relationship with the Data Controller. In the transfer, however, the third party becomes the independent Data Controller of the personal data. Moreover, your consent is always required to transfer your personal data to third parties.
Notwithstanding the above, it is understood that the Data Controller may still use your personal data to comply with the obligations provided by the applicable laws.
Complete Privacy Policy
Art. 1: Processing Methods
1.1 The processing of your personal data will mainly be carried out with the aid of electronic or automated means, in accordance with the methods and with the tools suitable to ensure the security and confidentiality of personal data.
1.2 The acquired information and the processing methods will be relevant and not excessive concerning the type of services rendered. Your data will also be managed and protected in secure and appropriate IT environments.
1.3 Through the Portal, no "special categories of data" are processed. Special categories of data are those that can reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership in parties, trade unions, associations or organizations of a religious, philosophical, political or trade union nature, health status, and sexual life.
1.4 Through the Portal, no judicial data is processed.
Art. 2: Disclosure of Personal Data
The Data Controller may disclose your personal data to certain categories of entities. Below are the entities to whom the Data Controller reserves the right to disclose your data:
- The Data Controller may disclose your personal data to all entities (including Public Authorities) who have access to personal data by virtue of regulatory or administrative measures.
- Your personal data may also be disclosed to all public and/or private entities, natural and/or legal persons (legal, administrative, and tax consultancy firms, Judicial Offices, Chambers of Commerce, Chambers and Labor Offices, etc.), if the disclosure is necessary or functional to the proper fulfillment of legal obligations.
- The Data Controller employs employees and/or collaborators in any capacity. For the proper functioning of the Portal, the Data Controller may disclose your personal data to these employees and/or collaborators.
- In its ordinary activities of managing the Portal, the Data Controller uses companies, consultants, or professionals tasked with the installation, maintenance, updating, and, in general, the management of the hardware and software of the Data Controller or used by it for the provision of its services. Therefore, only for these purposes, your data may also be processed by these entities.
- The Data Controller does not use external companies to provide customer care services.
The Data Controller reserves the right to modify the above list based on its ordinary operations. Therefore, you are invited to regularly access this privacy policy to check which entities the Data Controller discloses your personal data to.
Art. 3: Retention of Personal Data
3.1 This article describes the length of time the Data Controller reserves the right to retain your personal data.
- Your personal data will be retained only for the time necessary to ensure the proper provision of the services offered through the Portal.
- For the purpose of executing the sales contract, the data will be retained for 10 years from the date of receipt of the purchase order. This is to allow the Data Controller to exercise its right of defense and to demonstrate that it has properly executed the contract.
- As provided by Article 2220 of the Civil Code, invoices, as well as all accounting records in general, are retained for a minimum of ten years from the date of registration, so they can be presented in the event of an audit.
- For marketing purposes, personal data will be retained until the eventual withdrawal of consent. Should consent not be withdrawn earlier, data will be retained for 24 months from the date of provision. After the withdrawal of consent or the 24-month period, personal data will be deleted and no longer used for marketing purposes.
- For "profiled" marketing purposes, should consent not be withdrawn earlier, data will be retained for 12 months from the date of provision. After the withdrawal of consent or the 12-month period, personal data will be deleted and no longer used for this purpose.
3.2 Notwithstanding the provisions of Article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as amended from time to time.
Art. 4: Transfer of Personal Data
4.1 The Data Controller is based in a country that ensures an adequate level of security from a regulatory point of view. If the transfer of your personal data occurs in a non-EU country where the European Commission has expressed an adequacy decision, the transfer is considered safe from a regulatory point of view. This Article 4.1 indicates from time to time the countries to which your personal data may eventually be transferred and where the European Commission has expressed an adequacy decision.
- Therefore, you are invited to regularly access this article to verify if the transfer of your personal data occurs in a country with these characteristics.
4.2 Notwithstanding the provisions of Article 4.1, your data may also be transferred to non-EU countries for which the European Commission has not expressed an adequacy decision. You are therefore invited to regularly review this Article 4.2 to determine which of these countries your data may be transferred to.
4.3 In this article, the Data Controller indicates the countries to which it specifically directs its activity. This circumstance may imply the application of the relevant national legislation, in addition to that governing the relationship with the user as indicated in the Introduction.
- Upon the user's request, the Data Controller will apply the more favorable regulation provided by the user's national legislation to the processing of personal data.
Art. 5: Rights of the Data Subject
The Data Controller informs you that you have the right to:
- request from the Data Controller access to your personal data and their rectification or deletion or restriction of processing concerning you or to object to their processing, as well as the right to data portability
- withdraw consent at any time without affecting the lawfulness of the processing based on consent before its withdrawal
- lodge a complaint with a supervisory authority (in Italy, the Data Protection Authority at the link https://www.garanteprivacy.it/home).
The above rights can be exercised by making a request to the contacts indicated in the Introduction without any formalities.
Art. 6: Changes and Miscellaneous
The Data Controller reserves the right to make changes to this privacy policy at any time, giving appropriate publicity to the Portal users and always guaranteeing adequate and similar protection of personal data. To view any changes, you are invited to regularly consult this privacy policy. In the case of substantial changes to this privacy policy, the Data Controller may also notify you via email.