Privacy
PRIVACY POLICY
Pursuant to Articles 13 and 14 of EU Regulation 2016/679 (“GDPR”), the following information is provided to allow the data subject to understand the identity of the data controller, as well as the purposes and methods of processing. The objective is to ensure maximum transparency regarding the processing of personal data in relation to the services provided by Cariplo Factory, existing contracts, and the publication or reproduction of such data.
The data controller is Cariplo Factory S.r.l. Società Benefit (“Cariplo Factory”), with registered office at Via Daniele Manin 23 – 20121 Milan, Tax Code/VAT No. 09440060961.
The Data Protection Officer (DPO) appointed to supervise personal data processing and protect individuals’ fundamental rights is Alice Pisapia, with office at Via Domenichino 16, 20149 Milan, email: privacy@cariplofactory.it
Data may be processed by subjects designated as external data processors, operating under the direct authority of the Data Controller (employees and/or collaborators).
OBJECT AND PURPOSE OF PROCESSING
The data provided and processed by Cariplo Factory include common, personal, and special categories of data. Processing is carried out in compliance with the principles of fairness, lawfulness, and transparency, protecting confidentiality and the rights of data subjects. Providing the requested data is mandatory under applicable laws and regulations; failure to provide them may prevent access to the requested service.
| Data processed | Purpose | Categories of personal data | Legal basis |
| 1. Data provided directly by the data subject (e.g., identification and personal details, contact information, and data entered in registration and/or enrollment and/or participation forms). | Managing requests, registration, and participation in projects, initiatives, and activities promoted by Cariplo Factory. | Common data; any special categories of data if included in the uploaded content.
|
Consent – (Art. 6(1)(a) GDPR);
Contract performance or pre-contractual measures – (Art. 6(1)(b) GDPR).
|
| 2. Content voluntarily uploaded by users as part of Cariplo Factory’s activities. | Use and management of content for participation in programs, initiatives, and activities. | Common data; any special categories of data if included in the uploaded content.
|
Consent – (Art. 6(1)(a) GDPR);
Contract performance or pre-contractual measures – (Art. 6(1)(b) GDPR).
|
| 3. Images, videos, and voice recordings of event participants.
|
Use, reproduction, and publication for organizational and promotional purposes. | Common data; any special categories of data if included in the uploaded content.
|
Consent – (Art. 6(1)(a) GDPR);
Contract performance or pre-contractual measures – (Art. 6(1)(b) GDPR).
|
| 4. Browsing data and redirection to social platforms (e.g.: Facebook, LinkedIn, Instagram, YouTube).
|
Allow navigation on the Cariplo Factory website; analyze traffic; optimize and improve the site; resolve operational issues; monitor and prevent cyberattacks and fraud. | Common data. | Consent – (Art. 6(1)(a) GDPR);
Legitimate interest – (Art. 6(1)(f) GDPR).
|
| 5. Data collected through the use of the services offered by Cariplo Factory, interactions with digital content, including browsing data and service‑usage data, expressed preferences, history of interactions with content and communications, data relating to information requests, as well as information inferred from statistical and behavioral analyses (as detailed in the Cookie Policy – Cookies – Cariplo Factory)
|
Communication and marketing: analyzing the data subject’s service‑usage habits, interests, and preferences in order to understand how the services offered by Cariplo Factory are used, optimize and improve them, and personalize the user experience by providing content, services, and communications that are better aligned with the data subject’s needs. | Common data. | Consent – (Art. 6(1)(a) GDPR). |
| 6. Data provided by sending a CV
|
Receiving, reviewing, and evaluating applications; managing the selection process; organizing interviews and assessments; contacting candidates; verifying professional requirements. | Common data; any special categories of data if included in the uploaded content.
|
Consent – (Art. 6(1)(a) GDPR);
Contract performance or pre-contractual measures – Art. 6(1)(b) GDPR.
|
If the data subject provides personal data relating to third parties, Cariplo Factory requires that the data subject possess an appropriate legal basis for the disclosure of such information and ensure that the third parties concerned have given their consent to the processing of their personal data. In all cases, Cariplo Factory asks the data subject to inform those third parties that their personal data has been provided to us, and to inform them of the purposes and methods of the processing, as well as of their rights, by providing them with a copy of this Privacy Policy.
Furthermore, where the data subjects are minors, it is necessary for parents or other individuals exercising parental responsibility to sign an additional specific authorization regarding the use and reproduction/publication of photos and/or videos that include the minors’ images or voices.
PLACE OF PROCESSING
Processing is carried out at Cariplo Factory’s operational headquarters located within the BASE building, in the former Ansaldo area, at Via Bergognone 34, 20144 Milan. However, it should be noted that data processing and storage may also take place at Cariplo Factory’s registered office, located at Via Daniele Manin 23, 20121 Milan.
METHODS OF PROCESSING
Processing is carried out using automated, manual, and electronic tools, including paper‑based and digital storage media.
Personal data may also be processed, on an occasional basis, through the use of AI tools, in compliance with applicable legislation.
Personal data will be stored both in paper archives and in the company’s electronic database for the purposes indicated, in accordance with the security measures set out in Article 32 of the GDPR and handled by specifically authorized personnel in compliance with Article 29 GDPR.
In accordance with the principles of lawfulness, purpose limitation, and data minimization under Article 5 GDPR, and subject to the data subject’s free and explicit consent, personal data will be retained only for the period strictly necessary to achieve the purposes for which they were collected and processed.
It should be noted that the data subject’s personal data may be transferred outside the European Economic Area (EEA), in particular to the United States of America, where certain service providers, such as Mailchimp, are located.
In any case, any transfer of data outside the EEA is carried out in compliance with Chapter V of the GDPR and with all other measures required by applicable data protection legislation.
COMMUNICATION AND DISCLOSURE
We inform you that the data collected will never be disseminated and will not be communicated to third parties without the explicit consent of the data subject, except for those communications that are necessary and may involve the transfer of data to entities acting as external processors under the direct authority of the Data Controller, including employees, collaborators, consultants, or other authorized parties.
Furthermore, through the Cariplo Factory website, it may be possible to access third‑party websites or links to external sites to which this Privacy Policy does not apply. Users are therefore referred to the respective privacy policies of such third parties, which operate with full autonomy in the processing of personal data and adopt their own methods, purposes, and legal bases. The data subject is encouraged to review such policies before continuing navigation.
DATA SUBJECT RIGHTS
At any time, the data subject may exercise the rights provided for in Articles 15 to 22 of the GDPR, including the right to:
- Request confirmation as to whether personal data concerning them are being processed;
- Obtain information regarding the purposes of the processing, the categories of personal data involved, the recipients or categories of recipients to whom the personal data have been or will be disclosed, and, where possible, the envisaged retention period (right of access);
- Obtain the rectification or erasure of personal data (right to rectification);
- Obtain the restriction of processing;
- Receive their personal data from the data controller in a structured, commonly used, and machine‑readable format, and transmit those data to another controller without hindrance (right to data portability), as well as obtain notification from the controller in cases of rectification or erasure of personal data or restriction of processing;
- Object to the processing at any time (right to object);
- Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (right to withdraw consent);
- Request the erasure of their personal data, insofar as compatible with the controller’s legal obligations (right to be forgotten);
- Lodge a complaint with a supervisory authority.
The data subject may submit a complaint to the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), located at Via di Monte Citorio 121, Rome, following the procedures and instructions available on the Authority’s website www.garanteprivacy.it
Please note that the exercise of the rights referred to above, such as the right to erasure or objection, is subject to the limitations imposed by applicable legislation (DPCM 22 February 2016, Articles 56 and 57, and DPCM 24 October 2014, Article 7) concerning data retention obligations.
The data subject may exercise their rights by submitting a written request to Cariplo Factory S.r.l. Società Benefit, either by post at Via Daniele Manin 23, 20121 Milan, or by email at privacy@cariplofactory.it or via certified email (PEC) at cariplofactory@legamail.it
USER TRACKING
The website collects certain user data to provide its services. For details, refer to the Cookies – Cariplo Factory.