Skip to content

Privacy Policy

Privacy policy
Information document pursuant to and for the effects of Art. 13 of Regulation (EU) 2016/679 (GDPR)

WHY THIS INFORMATION?
Pursuant to Regulation (EU) 2016/679 (hereinafter “GDPR”), this page describes the procedures for processing personal data. This privacy notice is provided pursuant to Art. 13 of the GDPR. This notice is not to be considered valid for other third-party websites that may be consulted via links present on this website, for which no responsibility is assumed.

Processable Personal Data

  • Personal Data: any information relating to an identified or identifiable natural person («data subject»); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (C26, C27, C30 GDPR).
  • Contractor/User Data.
  • Browsing Data: the computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes IP addresses or domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment.
  • Data Provided Voluntarily: the optional, explicit, and voluntary sending of messages to the contact addresses indicated on this site and/or the completion of data collection forms entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included.

Information regarding the processing of personal data carried out through Social Media platforms
Regarding the processing of personal data carried out by the operators of the Social Media platforms used by the Data Controller, please refer to the information provided by them through their respective privacy policies. The Data Controller processes the personal data provided by users through dedicated Social Media platform pages to manage interactions with users (comments, public posts, etc.) and in compliance with current regulations.

Specific Notices
Specific notices may be presented on the pages of the Site in relation to particular services or processing of data provided.

COOKIES AND OTHER TRACKING SYSTEMS. WHAT ARE THEY? WHAT ARE THEY FOR?
For Cookies and other tracking systems, please see the cookie policy in the website footer and at the following link.

1. WHO IS THE DATA CONTROLLER? HOW TO CONTACT THEM?
The Data Controller is EFIM–ENTE FIERE ITALIANE MACCHINE SPA, with registered office in viale Fulvio Testi 128, 20092 – Cinisello Balsamo (MI), Italy, in the person of its pro-tempore legal representative. The contact details of the Data Controller are as follows: e-mail: privacy@ucimu.it Tel. +39 02/262551.

HAS A DATA PROTECTION OFFICER BEEN APPOINTED? WHAT ARE THEIR CONTACT DETAILS?
The Controller has appointed its Data Protection Officer (DPO/RPD) pursuant to Articles 37, 38, and 39 of the GDPR. The DPO can be contacted at the Controller’s office indicated above and via email by writing to: rdpefim@ucimu.it.

2. PURPOSE OF PROCESSING, LEGAL BASIS, DATA RETENTION PERIOD, NATURE OF DATA PROVISION

PURPOSE OF PROCESSINGLEGAL BASISDATA RETENTION PERIODNATURE OF DATA PROVISION
Browsing this website. Data necessary for the use of web services are also processed for the purpose of: • obtaining statistical information on the use of services (most visited pages, number of visitors per hour or day, geographical areas of origin, etc.); • checking the correct functioning of the offered services. Data will be used to ascertain responsibility in case of hypothetical cybercrimes against the site.Processing is necessary for the legitimate interests pursued by the data controller or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, taking into account reasonable expectations of the data subject and activities strictly necessary for website operation and browsing itself. (Art. 6, par. 1 point f and C47 of the GDPR)Browsing data will be retained for the duration of the browsing session. In any case, they do not persist for more than seven days (except for any need to ascertain crimes by judicial authorities).The provision of data is necessary for browsing the website.
Use of cookies and equivalent technologies. See the cookie policy in the website footer.For non-technical cookies and equivalent technologies, processing is based on consent to the processing of personal data (Art. 6 par. 1 point a and C42, C43 of the GDPR). Consent is given through the banner and cookie policy of the site.See the cookie policy in the website footer.See the cookie policy in the website footer.

In addition to browsing, personal data will be processed for:

PURPOSE OF PROCESSINGLEGAL BASISDATA RETENTION PERIODNATURE OF DATA PROVISION
A) CONTACTS/REQUEST FOR INFORMATION, sending contact requests, information regarding trade fair activities, or similar sector events.Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (C44). Art. 6 par. 1 point b) of the GDPR.Maximum 12 months.The provision of data is necessary. Failure to provide the necessary data will make it impossible to be contacted and receive the requested information.
B) MANAGEMENT OF YOUR REQUESTS and requests of other data subjects, pursuant to Articles 15 et seq. of the GDPR (rights of the data subject).Processing is necessary for compliance with a legal obligation to which the controller is subject (C45). Art. 6 par. 1 point c) of the GDPR.5 years from the closure of the request, except in case of disputes.The provision of personal data is mandatory, as it is essential to comply with legal obligations.
C) PREVENTION AND MANAGEMENT OF DISPUTES AND OTHER LEGAL ISSUES AND FOR DEFENSE IN CASE OF LITIGATION.Processing is necessary for the legitimate interests pursued by the controller or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject requiring personal data protection (C47-C50). Art. 6 par. 1 point f) GDPR.10 years, unless objected to and except for the time necessary for legal defense.The provision of data is necessary. Failure to provide it will prevent the achievement of the Controller’s legitimate interest indicated in the purposes of this point. Refusal must be balanced with the Controller’s legitimate interest indicated in the purposes of this point.

3. TO WHOM WILL PERSONAL DATA BE COMMUNICATED? RECIPIENTS OF DATA
Personal data will be communicated to entities that will process the data as independent Data Controllers or Data Processors (Art. 28 GDPR) and processed by natural persons (Art. 29 GDPR) acting under the authority of the Controller and Processors based on specific instructions provided regarding the purposes and methods of processing. Data will be communicated to recipients belonging to the following categories:

  • entities providing services for the management of the information system used by the Data Controller and telecommunication networks;
  • freelancers collaborating with the Data Controller;
  • entities dedicated to maintenance and/or updating activities of this website;
  • competent authorities for compliance with legal obligations and/or provisions of public bodies, upon request.

The list of appointed Processors is available by contacting the Data Controller at the contact details provided above.
The list of Data Processors pursuant to Art. 28 is available by writing to privacy@ucimu.it or to the other contact details indicated above.

4. WILL DATA BE TRANSFERRED TO NON-EEA COUNTRIES?
Personal data provided will not be transferred outside the European Economic Area (EEA).

5. IS THERE AN AUTOMATED PROCESS?
Personal data will be subjected to traditional manual, electronic, and automated processing. It is specified that fully automated decision-making processes are not carried out.

6. WHAT ARE YOUR RIGHTS? HOW CAN YOU EXERCISE THEM?
Data subjects may assert their rights as expressed in Articles 15 et seq. of the GDPR, by contacting the DPO/RPD at the email address: rdpefim@ucimu.it or by addressing the Data Controller at the email address: privacy@ucimu.it or writing to the contacts indicated above.

The Controller guarantees data subjects the possibility to request, at any time, access to their personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18). The data controller shall communicate (Art. 19) any rectification, erasure, or restriction of processing carried out to each recipient to whom the personal data have been disclosed. The data controller shall inform the data subject about those recipients if the data subject requests it.

The controller guarantees the right to data portability (Art. 20) and, in case of requests pursuant to Art. 20, will provide data subjects with data in a structured, commonly used, and machine-readable format.

Data subjects are granted the right to object (Art. 21), at any time, to data processing based on legitimate interest, by writing to the contacts above with the subject “objection”. In case of exercising the right to object to processing based on legitimate interest, the controller grants data subjects the possibility to obtain, upon request, information about the balancing test performed.

Data subjects have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

If data subjects believe that the processing of personal data carried out by the Controller occurs in violation of the provisions of Regulation (EU) 2016/679, they are free to lodge a complaint with a national Supervisory Authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement (Italian Data Protection Authority https://www.garanteprivacy.it/), or to take appropriate judicial action.

7. CHANGES TO THE PRIVACY POLICY
The controller may change, modify, add, or remove any part of this Privacy Policy. In order to facilitate the verification of any changes, the policy will contain an indication of the update date of the policy itself.

Update date: June 1, 2026