PRIVACY POLICY

Information on the processing of personal data pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR)

1. Data Controller

The Data Controller is ISA S.p.A., with its registered office at Via Madonna di Campagna, 123 – 06083 Bastia Umbra (PG), Italy.
Email: info@isaitaly.com
Privacy email:
ISA S.p.A. has appointed a Data Protection Officer (DPO), who can be contacted at the following email address: DPO@isaitaly.com
This privacy notice applies to the following websites:
www.isaitaly.com
www.spazioisa.com
www.tasselli.it
www.hizone.it

This information does not apply to other websites, pages or online services accessible via hyperlinks that may be published on these websites but which refer to resources outside the company’s domain.

2. Principles and approach to data processing

ISA S.p.A. processes personal data in accordance with the principles of lawfulness, fairness, transparency and data minimisation, adopting appropriate technical and organisational measures to ensure a high level of security.

3. Types of data processed

Whilst browsing and interacting with the websites, the following data may be processed:
personal and contact details (first name, surname, email, telephone number)
company details (company name, role, sector)
browsing data (IP address, logs, technical data)
data provided voluntarily via:
contact forms
website registration
newsletter subscription
job applications in the ‘Careers’ section
interaction with chatbots
Please do not include sensitive personal data (e.g. health, political views) in forms or CVs, unless strictly necessary.

4. Purposes of processing and legal bases

The personal data collected will be processed lawfully, fairly and transparently, ensuring that it is accurate and adequate, relevant and limited to what is necessary in relation to the purposes pursued, which, in this case, consist of:
1. managing privacy whilst browsing the website through technical cookies (browsing data)
2. data provided by the data subject for the provision of the Website’s Services or for marketing purposes;

1. Browsing data
The IT systems and software procedures used to operate the Website acquire, during their normal operation, certain Personal Data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the Website, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment. This data is used solely for the purpose of obtaining anonymous statistical information on the use of the Website and to check that it is functioning correctly (see the section on cookies below), to identify anomalies and/or misuse, and is deleted immediately after processing. The data may be used by the competent authorities to establish liability in the event of hypothetical cybercrimes committed against the website.

2. Data provided voluntarily by the data subject
Apart from what is specified regarding browsing data, the user is free to provide the personal data requested in any enquiry forms on the website (e.g. to subscribe to newsletters, register, submit a CV, book appointments, request a quote, etc.). Failure to provide such data may make it impossible to provide the service. In such cases, only the information necessary for the requested service will be requested (please refer to the specific privacy notices for details).

In particular, personal data is processed for the following purposes:
a) Handling contact enquiries
Legal basis: pre-contractual measures (Article 6(1)(b) of the GDPR)
b) Account registration and management
Legal basis: performance of a contract (Article 6(1)(b) of the GDPR)
c) Sending newsletters
Legal basis: consent (Article 6(1)(a) of the GDPR)
d) B2B direct marketing
Legal basis: legitimate interests (Article 6(1)(f) of the GDPR)
Data collected for marketing purposes may also be disclosed to selected business partners, appointed as data processors in accordance with Article 28 of the GDPR, who act on behalf of the Data Controller
e) Management of job applications (“Work with us”)
Legal basis: pre-contractual measures (Article 6(1)(b) of the GDPR)
f) Customer satisfaction
Legal basis: legitimate interest (Article 6(1)(f) of the GDPR)
g) Use of chatbots
Purpose: automated assistance and service improvement
Legal basis: legitimate interest and/or consent
The chatbot may use automated systems and artificial intelligence technologies to provide responses and support. The data processed is limited to what is necessary for the interaction.
h) Legal obligations
Legal basis: legal obligation (Article 6(1)(c) of the GDPR)
i) Improving the user experience
Legal basis: as set out in the Cookie Policy

5. Methods of processing

Processing is carried out using IT and manual tools, in accordance with procedures strictly related to the stated purposes and in compliance with the security measures required by law.

6. Provision of data

The provision of data is:
necessary for contractual and pre-contractual purposes
optional for marketing purposes
Failure to provide the necessary data may prevent the provision of the requested services.

7. Recipients of the data

The data may be disclosed to:
employees of the Data Controller who are duly authorised and trained in accordance with the provisions of the Regulation;
suppliers of the Data Controller, duly appointed as Data Processors;
parties whose access to the data is permitted by law, regulations or EU legislation.
IT, hosting, CRM and marketing platform providers
companies providing technology services (including chatbot tools)
competent authorities
Data collected for marketing purposes may also be disclosed to selected business partners, appointed as data processors pursuant to Article 28 of the GDPR, who act on behalf of the Data Controller. These parties process the data exclusively for purposes consistent with those indicated above, in compliance with current legislation and on the basis of specific contractual agreements governing the methods, security measures and retention periods, which are limited to what is necessary in relation to the purposes pursued.

8. Transfers outside the EU

In the context of the Company’s contractual relationships, Data may be transferred outside the European Economic Area (EEA), including by entering such data into databases managed by third-party companies acting on behalf of the Company.
Such transfers take place in accordance with the safeguards provided for by the GDPR, including:
Standard Contractual Clauses (SCCs)
European Commission adequacy decisions
The management of databases and the processing of Data are restricted to the purposes for which they were collected and are carried out in full compliance with the applicable legislation on the protection of personal data.
Whenever data is transferred outside the EEA, the Company will take all appropriate and necessary contractual measures to ensure an adequate level of data protection.

9. Data retention

Data is retained for:
contact form: 12 months
account: for the duration of the relationship plus 24 months
newsletter: until unsubscribed and for a maximum of 24 months
job applications: 12 months
chatbot: 12 months (or anonymisation)
Contractual data: 10 years
Technical data: as per the Cookie Policy

10. Rights of the data subject

The data subject is entitled to the following rights:
1. the right of access, i.e. the right to obtain confirmation from the Company as to whether or not Data is being processed and, if so, to access it;
2. the right to rectification and erasure, i.e. the right to have inaccurate data rectified and/or incomplete data completed, or to have the data erased on legitimate grounds;
3. the right to restriction of processing, i.e. the right to request the suspension of processing where there are legitimate grounds;
4. the right to data portability, i.e. the right to receive the Data in a structured, commonly used and machine-readable format, as well as the right to transmit the Data to another data controller;
5. the right to object, i.e. the right to object to the processing of Data where there are legitimate grounds, including the processing of Data for marketing and profiling purposes, where applicable;
6. the right to lodge a complaint with the relevant data protection authority in the event of unlawful processing of the Data.

11. Exercising your rights

The data subject may exercise the rights listed above by writing to ISA S.p.A., Via Madonna di Campagna, 123, 06083 Bastia Umbra (PG), or by sending an email to the DPO at the following email address: DPO@isaitaly.com

12. Amendments

This privacy notice may be updated from time to time. Any changes will be published on the websites.
Date of update: 12 April 2026

13. Cookies

For detailed information on the use of cookies, please refer to the dedicated Cookie Policy.