Privacy Policy
Notice regarding the processing of personal data in accordance with Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
The Data Controller for the processing of personal data is:
Med Marine Srl
Via Carpinetana Sud, 144 – 00034 Colleferro (RM) – Italy
VAT No.: 02027771006
Tel: +39 06 97 23 893
Email: info@medmarine.it
Website: www.medmarine.it
The Data Controller undertakes to process personal data in compliance with Regulation (EU) 2016/679 (“GDPR”) and applicable national legislation.
2. Types of Data Processed
2.1 Data voluntarily provided by the user
Through the contact forms available on the website, the user may voluntarily provide:
- first and last name;
- email address;
- phone number;
- company/organization (if provided);
- message content and any other information entered in free-text fields;
- any documents or files attached.
2.2 Browsing Data
The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. Such data include, by way of example:
- IP addresses;
- type of browser used;
- pages visited and time of the request;
- numeric codes indicating the status of the server response;
- other parameters relating to the user’s operating system and IT environment.
This data is used solely to obtain anonymous statistical information on the use of the website and to monitor its correct functioning.
2.3 Cookies and Similar Technologies
The website uses technical cookies and, subject to prior consent, its own and/or third-party analytics and profiling cookies. For further details, please refer to the Cookie Policy.
3. Purposes of Processing
The user’s personal data is processed for the following purposes:
- Managing contact requests submitted through the forms on the website and responding to the user’s inquiries;
- Managing pre-contractual and contractual relationships (quotes, commercial proposals, support on projects and services);
- Compliance with legal obligations of an administrative, tax, and accounting nature;
- Website security and prevention of fraudulent or abusive activities;
- Anonymous statistical analysis of website usage to improve content and functionality;
- Direct marketing (only where applicable and subject to prior consent): sending informational and/or promotional communications relating to the services offered by Med Marine.
4. Legal Basis for Processing
The processing of personal data is based on the following legal grounds:
- Art. 6.1.b GDPR – performance of pre-contractual and contractual measures at the data subject’s request (responding to contacts, offers, quotations);
- Art. 6.1.c GDPR – compliance with legal obligations (for example in the areas of taxation, accounting, workplace safety);
- Art. 6.1.f GDPR – the Data Controller’s legitimate interest in ensuring the security of the website and improving the services offered;
- Art. 6.1.a GDPR – the data subject’s consent for specific purposes (e.g., profiling cookies, marketing communications where applicable).
5. Methods of Processing
Processing is carried out using IT tools and, in limited cases, also in paper form, according to procedures strictly related to the purposes indicated and in compliance with the appropriate security measures provided for by Art. 32 GDPR, aimed at ensuring the confidentiality, integrity, and availability of data.
The data is not subject to automated decision-making processes that produce legal effects for the data subject, nor to profiling that has not been expressly authorized.
6. Data Retention Period
Personal data is stored for the time strictly necessary to achieve the purposes for which it was collected, and in particular:
- Contact requests: up to 24 months from the last meaningful contact, unless further retention is required in connection with ongoing contractual relationships;
- Administrative and accounting data: for the period required by applicable law (generally 10 years);
- Browsing data: generally up to 24 months, unless it is necessary to ascertain cybercrimes;
- Cookies: as indicated in the Cookie Policy.
Once the above periods have elapsed, the data will be deleted, anonymized, or otherwise rendered no longer attributable to the user’s identity.
7. Recipients of Personal Data
Personal data may be disclosed to:
- the Data Controller’s staff and collaborators, duly authorized and instructed;
- IT and hosting service providers, website technical maintenance providers, email service providers;
- external consultants (e.g., tax, legal, and labor consultants), to the extent necessary to perform their respective assignments;
- public bodies or competent authorities, in the cases provided for by law.
Personal data is not disclosed to the public nor sold to third parties for independent marketing purposes.
8. Transfer of Data to Third Countries
Some services used by the website (for example, statistical analysis services, CDNs, video or social platforms) may involve the transfer of personal data to countries outside the European Economic Area (EEA).
In such cases, the Data Controller ensures that any transfer is carried out in compliance with Articles 44 et seq. of the GDPR, for example through:
- adequacy decisions issued by the European Commission;
- Standard Contractual Clauses (SCCs);
- other appropriate safeguards.
9. Data Subject’s Rights
The user, as a data subject, may exercise at any time the rights set out in Articles 15–22 of the GDPR, including:
- Right of access to personal data;
- Right to rectification of inaccurate or incomplete data;
- Right to erasure (“right to be forgotten”), where applicable;
- Right to restriction of processing;
- Right to data portability, where applicable;
- Right to object to processing based on legitimate interest;
- Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise these rights, you may contact the Data Controller at info@medmarine.it.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
10. Minors’ Data
The website and the services offered by the Data Controller are not intended for minors under the age of 14. Should data relating to minors be inadvertently collected, the Data Controller will delete it without delay, upon request or as soon as it becomes aware of it.
11. Updates to this Notice
The Data Controller reserves the right to amend or update this Privacy Policy at any time. Any changes will be published on this page. Users are therefore encouraged to review this section periodically.
Last updated: November 2025.