Privacy policy
Information notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. Last updated: 22 September 2026.
1. Data controller
The data controller is F. & B. S.r.l., with registered office at Via Singen 26/I/5, 00071 Pomezia (RM), Italy, and administrative headquarters and plant at Strada delle Campore 12, 05100 Terni (TR), Italy, VAT no. IT01418601009, tax code 05590910583.
Privacy contacts: email info@febsoluzionimeccaniche.it, certified email febsrltr@pec.it, telephone +39 0744 800179.
The Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 of the GDPR do not apply.
2. What data we process
Browsing data. The IT systems and software procedures that operate this website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP addresses, time of the request, page requested, outcome of the request, browser and operating system. This data is used only to obtain anonymous statistical information on the use of the site and to check that it works correctly and securely.
Data provided voluntarily. By filling in the contact form or writing to the email addresses published on the site, the user provides us with the data needed to reply: name and surname, company, email address, telephone number, content of the message and any attachments (drawings, photos, samples). Sending an email also involves the acquisition of the sender’s address and any other data included in the message.
Cookies and similar technologies. The site uses technical cookies and, only with consent, third-party services (Google Maps map). Full details are in the Cookie Policy, where you can also change your preferences at any time.
3. Purposes and legal bases of processing
- Responding to requests for information, on-site work or quotations sent via the form, email or telephone, and managing the resulting pre-contractual and contractual relationships. Legal basis: performance of pre-contractual measures taken at the data subject’s request and performance of the contract (Art. 6(1)(b) GDPR).
- Ensuring the security of the site, preventing abuse, fraud and unauthorised access, including by logging access and applying protection filters. Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
- Complying with legal obligations, in particular accounting and tax obligations and responding to requests from the authorities. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Displaying third-party content (Google map) involving the use of non-technical cookies. Legal basis: consent of the data subject (Art. 6(1)(a) GDPR), given through the banner and revocable at any time.
The data is not used for marketing, profiling or sending unsolicited commercial communications. Any information about products and services will be sent only with the specific consent of the data subject.
4. Nature of the provision of data
Providing the data marked as mandatory in the contact form is necessary in order to reply to the request; failure to provide it makes it impossible to follow up the request. Providing the other data is optional.
5. Processing methods and retention periods
The data is processed with IT and paper tools by authorised and trained staff, with security measures suitable to prevent loss, unlawful or improper use and unauthorised access. The site is protected by an encrypted connection (HTTPS), an application firewall and periodic backups.
- Requests received via the form or email are kept for the time needed to reply and manage the relationship, and in any case no longer than 24 months from the last contact, unless a contractual relationship arises: in that case the data is kept for the duration of the relationship and, afterwards, for the periods required by law for accounting and tax documentation (10 years).
- Browsing data and security logs are kept for a limited period, not exceeding 12 months, unless needed to investigate computer crimes.
- Preferences expressed through the cookie banner are kept for the periods indicated in the Cookie Policy.
6. Recipients of the data
The data may be accessed by the Controller’s staff authorised to process it and by external parties carrying out activities on behalf of the Controller, appointed as processors under Art. 28 GDPR, in particular:
- Hostinger International Ltd. (Cyprus): website hosting service, with servers located in the European Union, and content delivery network (CDN).
- Brevo SAS (France): service for sending notification emails of requests received through the contact form.
- Defiant Inc. (USA): provider of the site protection system (Wordfence), which processes the IP addresses of blocked requests for security purposes.
- Google Ireland Ltd. (Ireland): Google Maps service, activated only with the user’s consent.
- Consultants and professionals (accountant, legal and IT consultants) and banks, as necessary for the management of contractual relationships.
The data may also be disclosed to public and judicial authorities in the cases provided for by law. The data is not disseminated.
7. Transfer of data outside the European Union
The data is stored on servers located in the European Union. Some of the providers listed in point 6 (Defiant Inc. and, for the Google Maps service, the Google group) are based or have servers in the United States: in these cases the transfer takes place on the basis of the European Commission’s adequacy decision on the EU-US Data Privacy Framework and/or the standard contractual clauses approved by the European Commission, with the further safeguards provided for in Articles 44 et seq. of the GDPR.
8. Rights of the data subject
At any time the data subject may exercise, towards the Controller, the rights provided for in Articles 15-22 of the GDPR: obtain confirmation of the existence of data concerning them and access to it; obtain its rectification, erasure or restriction of processing; object to processing; receive the data in a structured, commonly used format (portability); withdraw consent given, without affecting the lawfulness of processing carried out before withdrawal.
Requests should be sent to info@febsoluzionimeccaniche.it or to febsrltr@pec.it, or by post to the registered office. The Controller replies within one month of the request, extendable by two months in cases of particular complexity.
Data subjects who believe that the processing violates the GDPR have the right to lodge a complaint with the supervisory authority, in Italy the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it), or to take legal action.
9. Automated decision-making and minors
The Controller does not carry out processing based on automated decision-making, including profiling. The site and the services offered are aimed at businesses and professionals and are not intended for minors under 18; the Controller does not knowingly collect data from minors.
10. Changes to this notice
The Controller reserves the right to update this notice following changes in legislation or in the services used. The updated version, with the date of the last revision, is always available at this address.
