PRIVACY NOTICE REGARDING THE PROCESSING OF PERSONAL DATA ON THE WEBSITE
(pursuant to Article 13 of EU Regulation 2016/679, GDPR)

Pursuant to Regulation (EU) 2016/679 (hereinafter the “Regulation”), this page describes how the personal data of users who visit the Mind-Mercatis Srl website, accessible online at
via the following URL: https://mindmercatis.com/, is processed.


This information does not apply to other websites, pages, or online services accessible via hyperlinks that may be published on this site but that refer to resources outside the registry’s domain.

As a result of visiting the website, data relating to identified or identifiable individuals may be processed. Information regarding the use of cookies and other tracking tools is available in the Cookie Policy, which can be viewed on the website.

1. DATA CONTROLLER.

Mind-Mercartis srl, with headquarters at Viale Sarca 336/F, Building 16 – 20126 Milan (MI), VAT number 04475010965, contact email: co*****@**********is.com Certified Email (PEC) mi**********@*******il.it, as the Data Controller, hereby informs you that the personal data you have provided will be used to ensure the execution and successful fulfillment of the signed contract, for the following purposes and in the following manner 

2. CONTACT INFORMATION FOR THE DATA PROTECTION OFFICER (DPO).

The Data Controller has appointed the “Data Protection Officer” required by the Regulation.

For any questions regarding the processing of data subjects’ personal data and/or to exercise the rights provided for in the Regulation itself, as listed in Article 10 of this privacy notice, you may contact the DPO at the following email address: dp*@**********is.com

3. CATEGORIES OF DATA PROCESSED.

Personal data refers to information concerning an identified or identifiable natural person, such as the name, address, and other personally identifiable details relating to the individual requesting a service. 

In order to enhance your experience when using the services provided by the Website and related services, the Data Controller will collect and process certain personal data about you. The processing of this data is intended to ensure the effective provision of the requested service and is carried out in compliance with applicable data protection laws. 

The types of data processed may include:

  • Personal Data, any information relating to an identified or identifiable natural person, even indirectly, by reference to any other information, including a personal identification number; 
  • Identifying Information, personal data that allows for the direct identification of the data subject (e.g., first name, last name, email address)
  • Browsing Data: The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of the computers and devices used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response provided by the server (successful, error, etc.), and other parameters related to the user’s operating system and computing environment.
  • Data Provided by the User: The optional, explicit, and voluntary sending of messages to the contact addresses of Mind-Mercatis Srl, as well as the completion and submission of any forms found on the Mind-Mercatis Srl websites, entails the collection of the sender’s contact information—which is necessary to respond—as well as all personal data included in the communications.

4. PURPOSE OF THE PROCESSING AND LEGAL BASIS

Personal data will be processed, with your consent where necessary, for the following purposes, where applicable:

  1. Purposes related to the technical operation and security of the Website: to enable normal navigation and use of the Website, to detect and prevent any fraudulent or abusive activities, and to ensure the security of the Data Controller’s IT systems. The legal basis for the processing is Article 6(1)(f) of the Regulation, namely the Data Controller’s legitimate interest in the proper functioning and security of the Website. 
  2. direct marketing purposes; to this end, we may send newsletters, advertising materials, and/or commercial communications regarding our services and products, related offers, discounts, and any other promotional and loyalty initiatives; The legal basis for the processing is Article 6(1)(a) of the Regulation, as it is based on your consent, which may be revoked at any time without affecting the lawfulness of the processing carried out prior to the revocation, in accordance with the provisions of Article 7 of the Regulation.
  3. indirect marketing purposes, through the sending via email of advertising material and commercial communications regarding products and services similar to those you have purchased, pursuant to Article 130, paragraph 4 of the Code, unless you expressly opt out of receiving such communications, the legal basis for the processing is Article 6(1)(f) of the Regulation, namely the legitimate interest of the Data Controller. 
  4. To respond to a request or questionnaire you have submitted via email or through forms on the Website, the legal basis for the processing is Article 6, paragraph 1, subparagraph (b) of the Regulation, as the processing is necessary for the provision of the requested services. 
  5. For the purpose of determining liability in connection with criminal offenses committed against the Data Controller, in order to prevent any form of fraud, the legal basis for the processing is Article 6(1)(f) of the Regulation, namely the Data Controller’s legitimate interest. 
  6. To bring legal action to enforce a right or to exercise the right of defense in legal proceedings (Abuse/Fraud), the legal basis for the processing is Article 6(1)(f) of the Regulation, namely the Data Controller’s legitimate interest in meeting its defense needs.
  7. To comply with any obligations under applicable laws, regulations, or EU legislation, or to respond to requests from authorities, the legal basis for the processing is Article 6, paragraph 1, subparagraph (c) of the Regulation.

5. PROCESSING METHODS AND SECURITY MEASURES

Data processing is carried out in accordance with the principles of fairness, lawfulness, transparency, and the protection of the data subject’s privacy and rights, using computerized procedures or other electronic means, or manually and on paper, by internal or external personnel who have been specifically assigned and authorized for this purpose and who are bound by confidentiality obligations. 

The data is processed and stored using tools designed to ensure its security, integrity, and confidentiality through the implementation of appropriate security measures, as required by law.

6. Whether Providing Data Is Mandatory or Optional and the Consequences Thereof

The nature of the provision of personal data and the consequences of a refusal vary depending on the purpose of the processing, as specified below:

    • Purpose 1 (technical operation and security of the Website): The collection of browsing data occurs automatically upon connecting to the Website and is necessary for the normal use of the Website; therefore, it is not subject to the data subject’s choice.
    • Purposes 2 and 3 (direct and indirect marketing): Providing your data is optional. Any refusal or withdrawal of consent will not affect your use of the Site or the requested services, but will simply prevent you from receiving promotional communications.
    • Purpose 4 (response to requests or questionnaires): Providing data is optional, but failure to do so will make it impossible for the Data Controller to respond to the request received.
    • Purposes 5 and 6 (determination of liability/fraud, protection of a right in court): The provision of data is not subject to the data subject’s choice, as it is necessary for the Data Controller to pursue its legitimate interest.
    • Purpose 7 (compliance with legal obligations): The provision of data is mandatory. Any refusal will make it impossible for the Data Controller to comply with the regulatory obligations to which it is subject.

7. RECIPIENTS OF THE DATA.

Your personal data may be shared with:

  • persons authorized by the Data Controller to process personal data, pursuant to Article 29 of the Regulation;
  • third parties who, in providing services, typically act as data processors, pursuant to Article 28 of the Regulation;
  • individuals, entities, or authorities to whom it is mandatory or necessary to disclose your personal data, pursuant to legal provisions, orders from authorities, or to protect or defend the rights of the Data Controller;

The complete list of recipients of the data subjects’ personal data is kept at the Data Controller’s headquarters and may be accessed by sending a written request to the Data Controller at the contact information provided in this Privacy Notice.

8. TRANSFER OF DATA TO THIRD COUNTRIES.

Personal data is not transferred to countries outside the European Union; however, some service providers or subcontractors may process personal data outside the EU/EEA. In such cases, the Data Controller ensures that the safeguards provided for in Articles 44–49 of the Regulation are used to legitimize the transfer: namely, the consent of the data subject, a decision by the EU Commission certifying that the country outside the EU/EEA to which your personal data is transferred provides an adequate level of protection, or the use of standard contractual clauses approved by the EU Commission.

The Data Controller, should it be necessary to transfer data for backup purposes, shall have the right to transfer personal data outside the EU. In the latter case, the Data Controller hereby guarantees that the transfer of data outside the EU will take place in accordance with legal provisions, ensuring that the necessary agreements and standard contractual clauses are in place beforehand.

9. DATA RETENTION PERIOD

Your data is retained, in accordance with the principles of data minimization and storage limitation set forth in Article 5.1, subparagraphs (c) and (e) of the Regulation, in the Data Controller’s information systems for the time strictly necessary to achieve the purposes for which it was collected, in accordance with the following criteria:

  • Browsing data (Purpose 1): retained for up to 6 months from the date of collection, unless the judicial authorities need to investigate criminal offenses, in which case the retention period may be extended until the conclusion of the proceedings.
  • Data processed for direct marketing purposes (Purpose 2): retained until consent is withdrawn and, in any case, for a maximum period of 24 months from the date of collection or the data subject’s last interaction, after which consent must be obtained again.
  • Data processed for indirect marketing purposes (Purpose 3): retained for a maximum period of 24 months from the purchase of the product/service or from the last relevant contact, unless the data subject objects earlier.
  • Data processed to respond to requests or questionnaires (Purpose 4): retained for as long as necessary to manage and process the request and, thereafter, for a maximum of 12 months from the date the request is closed, for the purposes of providing feedback and any follow-up.
  • Data processed for the purposes of determining liability or detecting fraud (Purpose 5) and for the exercise or defense of a right in court (Purpose 6): retained for the time necessary to manage the specific incident and, in any case, no longer than the ordinary statute of limitations provided for by Italian law (Art. 2946 et seq. of the Italian Civil Code, generally 10 years, reduced to 5 years for non-contractual liability pursuant to Art. 2947 of the Italian Civil Code).
  • Data processed to comply with legal obligations (purpose 7): retained for the period specified by the applicable sector-specific regulations (e.g., 10 years for accounting and tax records pursuant to Article 2220 of the Italian Civil Code and Article 22 of Presidential Decree No. 600/1973).

Once the time limits indicated above have expired, personal data will be erased, destroyed, or anonymized permanently and irreversibly, in accordance with the technical erasure and backup procedures adopted by the Data Controller.

10. AUTOMATED DECISION-MAKING PROCESSES.

The data collected for the aforementioned purposes are not subject to automated decision-making (including profiling).

11. RIGHTS OF DATA SUBJECTS

With regard to personal data, every data subject may exercise the rights provided for in Chapter III of the EU GDPR 2016/679:

  • Access to Data (Art. 15): The data subject has the right to obtain from the data controller confirmation as to whether or not personal data concerning him or her are being processed and, if so, to obtain access to the personal data in a commonly used electronic format, as well as certain information regarding the processing (e.g., purposes, categories of data processed, recipients to whom the data are disclosed, transfers outside the EU, profiling activities, etc.);
  • Rectification of Data (Art. 16): The data subject has the right to obtain the rectification of inaccurate personal data concerning him or her without undue delay and/or the completion of incomplete personal data, including by providing a supplementary statement;
  • Erasure of data or “right to be forgotten” (Art. 17): The data subject has the right to obtain from the data controller the erasure of personal data concerning him or her without undue delay, and the data controller is obligated to erase the personal data without undue delay;
  • Restriction of processing (Art. 18): The data subject has the right to obtain from the data controller the restriction of processing; 
  • Data portability (Art. 20): The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a data controller, in a structured, commonly used, and machine-readable format, and has the right to transmit those data to another data controller without hindrance from the data controller to whom the data were provided;
  • Objection to Processing (Art. 21): The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her pursuant to Article 6(1)(e) or (f), including profiling based on those provisions.
  • Complaint to the Supervisory Authority (Art. 77): The data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State where he or she habitually resides, works, or where the alleged infringement occurred, if he or she believes that the processing of personal data concerning him or her violates the Regulation (in Italy, the Italian Data Protection Authority).

Pursuant to Article 12 of EU Regulation 2016/679, the Data Controller reminds the data subject that the information provided pursuant to Articles 13 and 14, as well as any communications and actions taken pursuant to Articles 15 through 22 and Article 34, are free of charge. 

However, if the requests are found to be manifestly unfounded or excessive—in particular because they are repetitive—the Data Controller may:

  1. charge a reasonable fee, taking into account the administrative costs incurred in providing the information or communication or taking the requested action; or 
  2. refuse to grant your request.

12. DATA CONTROLLER AND DATA PROTECTION OFFICER

The above rights may be exercised by writing to the Data Controller: Mind-Mercartis srl, with registered office at Viale Sarca 336/F, Building 16 – 20126 Milan (MI), VAT number 04475010965, contact email: co*****@**********is.com or to the Data Protection Officer at the email address dp*@**********is.com 

 

Last updated: June 19, 2026