The purpose of this document is to inform the natural person (hereinafter referred to as the “Data Subject”) about the processing of their personal data (hereinafter referred to as “Personal Data”) collected by the data controller, Aldea S.r.l., with registered office at Via Anton Cechov 20, 00142 Rome, CF/VAT No. 06563021002, email address info@aldea.it, (hereinafter referred to as the “Controller”), through the website www.aldea.it (hereinafter referred to as the “Application”).
Modifications and updates will be binding as soon as they are published on the Application. If the Data Subject does not accept the changes made to the Privacy Policy, they must cease using this Application and may request the Controller to delete their Personal Data.
1. Categories of Processed Personal Data
The Controller processes the following types of Personal Data voluntarily provided by the Data Subject:
Contact Data: name, surname, address, email, phone number, images, authentication credentials, any additional information sent by the Data Subject, etc.
Fiscal and Payment Data: tax code, VAT number, credit card details, bank account details, etc.
The Controller also processes the following types of Personal Data collected automatically:
Technical Data: Personal Data produced by devices, applications, tools, and protocols used, such as device information, IP addresses, browser type, Internet Service Provider (ISP) type. These Personal Data may leave traces that, especially when combined with unique identifiers and other information received from servers, can be used to create profiles of natural persons.
Browsing and Usage Data of the Application: such as visited pages, number of clicks, actions taken, session duration, etc.
Failure by the Data Subject to provide Personal Data for which there is a legal or contractual obligation or when they constitute a necessary requirement for concluding a contract with the Controller will make it impossible for the Controller to establish or continue the relationship with the Data Subject.
The Data Subject who communicates third-party Personal Data to the Controller is directly and exclusively responsible for their origin, collection, processing, communication, or dissemination.
2. Cookies and Similar Technologies
The Application uses cookies, web beacons, unique identifiers, and other similar technologies to collect the Data Subject’s Personal Data regarding visited pages, clicked links, and other actions performed while using the Application. These are stored and transmitted during the next visit by the Data Subject. The complete Cookie Policy is available at the appropriate link.
3. Legal Basis and Purposes of Processing
Personal Data processing is necessary:
For the performance of the contract with the Data Subject, specifically:
Fulfilling any obligation arising from the pre-contractual or contractual relationship with the Data Subject.
Registration and authentication of the Data Subject: allowing the Data Subject to register on the Application, access it, and be identified, including through external platforms.
Support and contact with the Data Subject: responding to requests from the Data Subject.
Payment management: managing payments via credit card, bank transfer, or other methods.
For legal obligations, specifically:
Compliance with any obligations set forth by applicable regulations, laws, and rules, particularly in tax and fiscal matters.
Based on the Controller’s legitimate interest, for:
Email marketing of the Controller’s products and/or services: to directly sell the Controller’s products or services using the email provided by the Data Subject in the context of selling a product or service similar to the one sold.
Management, optimization, and monitoring of technical infrastructure: identifying and resolving technical issues, improving Application performance, managing, and organizing information in an IT system (e.g., servers, databases, etc.).
Security and fraud prevention: ensuring the security of the Controller’s assets, infrastructure, and networks.
Anonymous statistical analysis: performing statistical analysis on aggregated and anonymous data to analyze Data Subject behavior, improve products and/or services provided by the Controller, and better meet the Data Subject’s expectations.
Based on the Data Subject’s consent, for:
Marketing of the Controller’s products and/or services: sending commercial and/or promotional information or materials, conducting direct sales of the Controller’s products and/or services, or performing market research through automated and traditional methods.
The Data Subject’s Personal Data may also be used by the Controller to protect itself in legal proceedings before the competent courts.
4. Processing Methods and Recipients of Personal Data
Personal Data processing is carried out using paper and IT tools with organizational methods and logic strictly related to the indicated purposes and by adopting appropriate security measures.
Personal Data is processed exclusively by:
Persons authorized by the Controller who have committed to confidentiality or have an appropriate legal confidentiality obligation.
Entities operating independently as separate data controllers or entities designated as processors by the Controller to carry out all necessary processing activities to achieve the purposes stated in this notice (e.g., business partners, consultants, IT companies, service providers, hosting providers).
Entities or bodies to whom Personal Data must be communicated by law or by order of authorities.
The listed entities must use appropriate guarantees to protect Personal Data and can access only those necessary to perform their assigned tasks. Personal Data will not be indiscriminately disseminated.
5. Location
Personal Data will not be transferred outside the European Economic Area (EEA).
6. Personal Data Retention Period
Personal Data will be retained for the period necessary to fulfill the purposes for which they were collected, specifically:
For contract execution purposes, retained for the duration of the contractual relationship and, after termination, for the ordinary statute of limitations of 10 years. In case of judicial disputes, for the entire duration until all appeal actions are exhausted.
For legitimate interest purposes, retained until the interest is fulfilled.
For compliance with legal obligations, authority orders, and legal defense, retained per the timeframes established by these obligations and regulations, and in any case, until the statute of limitations set by applicable laws expires.
For purposes based on the Data Subject’s consent, retained until consent is revoked.
At the end of the retention period, all Personal Data will be deleted or stored in a form that does not allow identification of the Data Subject.
7. Data Subject’s Rights
Data Subjects may exercise specific rights concerning their Personal Data processed by the Controller. Specifically, the Data Subject has the right to:
Be informed about the processing of their Personal Data.
Withdraw consent at any time.
Restrict the processing of their Personal Data.
Object to the processing of their Personal Data.
Access their Personal Data.
Verify and request rectification of their Personal Data.
Obtain restriction of their Personal Data processing.
Obtain the deletion of their Personal Data.
Transfer their Personal Data to another controller.
Lodge a complaint with the supervisory authority and/or take legal action.
To exercise their rights, Data Subjects can send a request to info@aldea.it. Requests will be handled by the Controller promptly and processed as soon as possible, in any case within 30 days.
Last update: 10/03/2025
Follow our linkedin page to read updates and case studies.