Privacy Notice Regarding the Processing of Personal Data Pursuant to Regulation (EU) 2016/679 (GDPR)

ILSA S.p.A. (hereinafter “Company”), with its registered office at Via Roveggia, 31 – 37136 Verona (VR) - Italy, acting as the Data Controller, provides this privacy notice to explain how we collect, process, and protect your personal data.

1. DATA CONTROLLER

The Data Controller is ILSA S.p.A., with its registered office in Verona (VR). For any questions or requests regarding your personal data, you may contact the Data Controller by email at [email protected] or by phone at +39 0444 452020.

2. TYPES OF DATA PROCESSED

Data Provided by the User

When you use our website, contact us, or purchase our goods or services, you provide us with data that allows us to identify you. Such data may include, but is not limited to: first name, last name, phone number, address, email address, job, and other relevant information. We also collect technical data, such as unique device identifiers and information about the device you are using.

Data Collected During the Communication

We collect personal data when you interact with us through our website, email, phone, or other means. This includes contact information, communication details (date, time, origin), and information about your interaction with our services.

Account creation

If you wish to access specific services, you can create an account by providing information such as your name, email address, company name, business contact information, and phone numbers. Some information, such as login credentials, is collected automatically.

Newspoint Subscription and Other Communications

If you subscribe to our newspoint or other communications, we may ask you to provide your name, email address, company name, and business contact information.

Automatically Collected Data

When you browse our website, we collect technical data such as your IP address, browser type, operating system, and browsing information (URLs visited, duration of visits). This data is collected with the cookies to analyze website usage.

Data collected during visits to our facilities or events

When you visit our facilities or attend events, we collect data through our security systems.

Data received from other sources

We may receive data from other sources, such as other companies within our Group or third parties (for example, business partners, technical service providers, analytics providers, etc.).

Special categories of data

In certain circumstances, we may collect data that falls within the special categories of personal data, as defined by the GDPR.

3. PURPOSE OF THE PROCESSING

The data collected is processed for the following purposes:

Delivery of the requested services

• Purpose: Providing the User with the requested services, managing the personal account, processing orders and payments, and sending confirmations and operational notifications.
• Type of processing: Collection, recording, use, storage, updating, and deletion of identification, contact, and payment data.
• Legal basis: Article 6, paragraph 1, point b) of the GDPR – Implementation of a contract or pre-contractual measures taken at the request of the data subject.

Improving Products and Services

• Purpose: ongoing analysis and improvement of the services offered, and adaptation to customers’ technical needs.
• Type of processing: behavioral analysis, non-automated technical profiling, statistical processing in aggregated or anonymized form.
• Legal basis: Article 6(1)(f) of the GDPR – legitimate interest of the Data Controller in improving its products and services.

Account Creation and Management

• Purpose: Management of user profiles within company systems, user experience customization, and account-related communications.
• Type of processing: Recording, storing, accessing, modifying, and deleting identification and login data.
• Legal basis: Article 6, paragraph 1, point b) of the GDPR – Implementation of a contract (use of the website and related services); Article 6, paragraph 1, point a) of the GDPR – Explicit consent of the data subject.

Contacts and Institutional Communications

• Purpose: Contacting the user regarding the services offered, contract updates, requests for information, and assistance.
• Type of processing: Sending and receiving communications via email, telephone, and digital channels; handling requests through customer service.
• Legal basis: Article 6, paragraph 1, point a) of the GDPR – Explicit consent of the data subject; Article 6, paragraph 1, point b) of the GDPR – Implementation of a contract; Article 6, paragraph 1, point c) of the GDPR – Compliance with legal obligations.

Direct Marketing

• Purpose: Sending communications regarding products, services, and initiatives of the Data Controller or Group companies.
• Type of processing: Sending emails and text messages containing technical and/or informational content; managing marketing preferences; using contact information.
• Legal basis: Article 6, para. 1, subpar. a) of the GDPR – Explicit consent of the data subject; Article 6, para. 1, subpar. f) of the GDPR – Legitimate interest of the Data Controller in promoting similar products and services, in the case of soft-spam sent to existing customers.

Advertising and Targeting

• Purpose: Providing personalized advertising, measuring the effectiveness of advertising campaigns, and conducting remarketing and behavioral targeting activities.
• Type of processing: Collection and analysis of browsing data and online behavior, profiling, interaction with external advertising platforms (e.g., social media).
• Legal basis: Article 6, paragraph 1, point a) of the GDPR – Consent of the data subject (required for the use of cookies and profiling technologies).

Interaction with Social Networks and External Platforms

• Purpose: Enabling content sharing and interaction on social media platforms or other external services.
• Type of processing: Data transfer to third-party platforms, receipt of interaction data, integration via widgets and plugins.
• Legal basis: Article 6, paragraph 1, point a) of the GDPR – Consent of the data subject (in the case of non-technical cookies or widgets); Article 6, paragraph 1, point f) of the GDPR – Legitimate interest of the Data Controller in promoting its brand online (in the absence of profiling).

Statistics and Technical Analysis

• Purpose: Gathering anonymous information on website usage, monitoring its proper operation, and generating statistical reports.
• Type of processing: Collection and anonymization of browsing data, aggregated analysis, and automatic deletion of data after processing.
• Legal basis: Article 6, paragraph 1, point f) of the GDPR—the Data Controller’s legitimate interest in optimizing the website; Article 6, paragraph 1, point a) of the GDPR—consent (if the processing is not anonymized or involves profiling).

Technical Management of the Website

• Purpose: Troubleshooting technical issues, managing and optimizing the website’s structure, and managing tags.
• Type of processing: Monitoring system logs, managing technical cookies, and analyzing malfunctions.
• Legal basis: Article 6, paragraph 1, point f) of the GDPR – The Data Controller’s legitimate interest in ensuring the secure and efficient operation of the website.

Safety and Prevention

• Purpose: Ensuring the website’s cybersecurity and protection against spam, malware, and unauthorized access.
• Type of processing: Analysis of traffic and IP data, automatic and manual filtering, and tracking of suspicious attempts.
• Legal basis: Article 6, paragraph 1, point c) of the GDPR – Compliance with legal obligations (e.g., data security); Article 6, paragraph 1, point f) of the GDPR – Legitimate interest of the Data Controller in protecting its systems.

Managing Contacts and Sending Messages

• Purpose: Managing contact lists for informational and commercial communications, NewsPoint, and automated notifications.
• Type of processing: Organizing data in databases, sending communications via automated systems.
• Legal basis: Article 6, paragraph 1, point a) of the GDPR – Consent of the data subject.

Interaction with data collection platforms and third parties

• Purpose: Working with external partners for statistical purposes or to integrate services.
• Type of processing: Sharing and receiving data with external platforms following notification.
• Legal basis: Article 6, paragraph 1, point a) of the GDPR – Consent; Article 6, paragraph 1, point f) of the GDPR – Legitimate interest, with regard to statistical or internal operational purposes.

Complaint management and customer support

• Purpose: Analyzing and responding to complaints received; improving customer service.
• Type of processing: Storage, review, and analysis of requests received and responses provided.
• Legal basis: Article 6, paragraph 1, point b) of the GDPR – Implementation of a contract; Article 6, paragraph 1, point f) of the GDPR – Legitimate interest in ensuring service quality.

Human resources selection processes

• Purpose: Assessing applications for open job positions and managing the selection process.
• Type of processing: Reviewing resumes, contacting candidates, verifying data, and complying with legal obligations under labor law.
• Legal basis: Article 6, paragraph 1, point b) of the GDPR – Precontractual measures at the candidate’s request; Article 6, paragraph 1, point c) of the GDPR – Legal obligation under labor law.

Legal Compliance and Protection of Rights

• Purpose: Responding to requests from authorities; protecting the rights of the Data Controller or third parties in judicial or extrajudicial proceedings.
• Type of processing: Storage, disclosure to authorized third parties, production of documents.
• Legal basis: Article 6, paragraph 1, point c) of the GDPR – Compliance with legal obligations; Article 6, paragraph 1, point f) of the GDPR – Legitimate interest in protecting the rights of the Data Controller.

4. DATA SHARING

Your personal data may be shared with other companies belonging to the Group for the purposes indicated, as well as with expressly identified third parties. In addition, your data may be disclosed to third parties in the following cases:

• when it is necessary to use external service providers to facilitate or expand the functionality of our services;
• at your explicit request;
• in compliance with court orders or legal or regulatory obligations;
• in the event of a sale, transfer, or reorganization, in whole or in part, of our business;
• to ensure compliance with our contracts or, in the event of disputes, to exercise our right of defense;
• to protect the safety of our users, customers, or third parties;
• to protect the rights and assets of the company, as well as those of our customers and third parties. “Third parties” refers to external entities that provide services to our organization or act as our representatives. These include, but are not limited to: subcontractors (including their agents), professional consultants, IT and database service providers, backup and disaster recovery specialists, email service providers, as well as other parties tasked with supporting or improving our products and services. Our suppliers and service providers are required to comply with our standards regarding personal data protection and information security.

5. DIRECT MARKETING AND PROFILING

Direct Marketing Purposes

We, as well as the other companies belonging to the Group, may use the data you provide for the following purposes:

• direct marketing, by sending you updates, technical documentation, in-depth reports, research findings and field trial results, product usage guidelines, and generally anything related to agronomic knowledge—in both print and digital formats—that we believe may be interesting to you;
• product offers and to send you informational materials and promotions, in both print and digital formats, that we believe may be interesting to you. Messages will only be sent after we have received your consent. In any case, we offer you the option to unsubscribe from any communication we send. These activities may also include conducting market research and surveys to gauge your satisfaction or to perform statistical analyses, including using anonymous and/or aggregated data.

Purpose of Profiling

The Company may use the data indicated above, any clicks and/or opens you make on emails received, visits to the e-commerce website if you are registered in the Reserved Area, statistical analyses conducted to identify customer segments, and any purchases made to analyze specific behaviors and/or consumer habits in order to improve the services offered and tailor commercial offers based on the interests you have shown. Your data may also be used to conduct market research and statistical surveys, including using anonymous and/or aggregated data.

Consent and Right to Object

Processing is based on your explicit and freely given consent, as defined in Article 6, paragraph 1, point (a) of the GDPR, and any refusal on your part will not affect your ability to purchase our products and/or receive the related services. In any case, in every communication, you will always be given the option to unsubscribe easily and immediately.

Exercising the Right to Object

You have the right to opt out of receiving marketing communications at any time by sending an email to [email protected] or by using the unsubscribe option included in every communication.

6. COOKIES

We automatically collect certain data through the use of cookies. Cookies are text files containing small amounts of information that a website sends to the user’s browser, which may then be stored on the device. These files allow us to recognize the device without directly identifying the user. Some pages on our website use cookies to improve your browsing experience on future visits. You can configure your browser to notify you when a cookie is sent, so you can decide whether to accept it. You can also disable cookies entirely through your browser settings, but doing so may affect the proper functionality of certain areas of the website. For a complete list of the cookies we use and their purposes, please see our Cookie Policy.

7. DATA DISCLOSURE

By providing your personal data, you consent to its processing by ILSA S.p.A. for the purposes set forth in this Privacy Policy, in accordance with applicable regulations, in particular the GDPR. Providing your data is optional, but it may be necessary to supply you with certain services, such as accessing your account or sending direct marketing communications, provided you have given your consent. If you refuse to submit the requested data, certain services may not be available, or we may be unable to fulfill our obligations. Your data will be processed exclusively for the specified purposes and will not be used for other purposes without your prior consent, when required by law.

8. LINKS TO THIRD-PARTY WEBSITES AND SOCIAL MEDIA

Any links to external websites and social media platforms on our website are provided solely for informational purposes. These websites are not under our control; therefore, this Privacy Policy does not apply to their use. If you access these sites via the links we provide, their respective operators may collect and process your personal data in accordance with their own privacy policies, which may differ from this policy. We therefore encourage you to review their privacy policies before providing any personal data.

9. DATA RETENTION

Your personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, in accordance with our legitimate interests and applicable legal obligations. Data will be retained for the entire duration of your account. After your account is closed, your data will be retained only for as long as necessary to comply with regulatory, tax, or accounting obligations, or to protect our rights in the event of a dispute. If you exercise your right to object to processing for direct marketing purposes, we will retain only a copy of your contact information to add you to an opt-out list, ensuring that you will not receive any further promotional communications.

Retention Period and Legal Obligations

Unless otherwise specified, personal data is processed and retained for as long as necessary to fulfill the purpose for which it was collected, and may be retained for a longer period to comply with legal obligations or based on the User’s consent. If the processing is based on consent, the data may be retained until such consent is withdrawn. In addition, data may be retained for a longer period to comply with legal obligations or pursuant to an order from competent authorities. We will not delete personal data if it is necessary for the establishment, exercise, or defense of a legal claim in court or during an investigation. In such cases, the data will be retained until the conclusion of the proceedings.

Data Erasure

At the end of the retention period, personal data will be deleted. Therefore, once that period expires, the rights of access, erasure, rectification, and data portability can no longer be exercised.

10. RIGHTS OF THE DATA SUBJECT

Pursuant to Regulation (EU) 2016/679, as a data subject, you have the right to exercise specific rights regarding your personal data processed by the Data Controller. These rights may be exercised within the limits and under the conditions set forth in Articles 15 through 22 of the GDPR. We reserve the right to verify the identity of the requester and to request any additional information necessary to process the request. Your rights are as follows:

• Right of Access (Article 15 GDPR) You have the right to obtain confirmation as to whether or not personal data concerning you is being processed and, if so, to access such data, receive a copy of it, and obtain information about its use. To exercise this right, you may write to us at: [email protected];
• Right to Rectification, Erasure, and Restriction of Processing (Articles 16, 17, and 18 of the GDPR) You have the right to request the rectification of inaccurate data, the completion of incomplete data, the erasure of personal data (the so-called “right to be forgotten”), or the restriction of processing when the conditions set forth by law are met. It is your responsibility to ensure that the personal data you provide is accurate, up-to-date, and truthful. Requests should be sent to: [email protected];
• Right to Withdraw Consent (Article 7, paragraph 3 of the GDPR) If data processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal. To withdraw your consent, please write to: [email protected] ;
• Right to data portability (Article 20 GDPR) You have the right to receive your personal data in a structured, commonly used, and machine-readable format, as well as to transmit it, if technically feasible, to another data controller. You may exercise this right by contacting us at: [email protected];
• Right to Object (Article 21 GDPR) You have the right to object, at any time, to the processing of your personal data when it is based on a legitimate interest of the Data Controller or is carried out for direct marketing purposes. To exercise your right to object, you may write to us at: [email protected];
• Right not to be subject to automated decision-making (Article 22 GDPR) You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, except in the cases provided for by the Regulation;
• Right to lodge a complaint with the supervisory authority (Article 77 GDPR) If you believe that the processing of your personal data violates data protection regulations, you have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it – Tel. 06/69677.3785).

Log In with Your Personal Account

If you have an account, you can access your personal data directly through the member area to view, correct, update, or delete it. You also have the option to disable or close your account at any time.

Right to Object to Processing for Legitimate and Marketing Purposes

As provided for in Article 21 of the GDPR, you may object to the processing of your data if it is based on our legitimate interest (or that of a third party), by providing reasons related to your particular situation. We reserve the right to demonstrate the existence of compelling legitimate grounds for the processing that override your rights and freedoms. Furthermore, you always have the right to object to the processing of your data for direct marketing purposes, without having to provide a reason. In that case, your data will no longer be used for such purposes.

11. DATA SECURITY

We take appropriate physical, technical, and organizational measures to protect the personal data under our control against unauthorized access, collection, use, disclosure, alteration, or deletion. Your personal data is stored on secure servers protected by standardized security measures, such as encryption, firewalls, and other technologies that ensure a high level of security. If you have a password to access our website, it is your responsibility to keep it confidential and protect it from unauthorized use. We recommend that you choose a strong password and do not share it with third parties. If you suspect unauthorized access, please change your password promptly.

12. METHODS AND LOCATION OF DATA PROCESSING

Processing methods

The Data Controller implements appropriate security measures to protect Personal Data from unauthorized access, disclosure, alteration, or destruction. Processing is carried out using IT and telecommunications tools, in accordance with methods and procedures strictly related to the stated purposes. The Data may be accessible to internal parties (such as administrative, sales, marketing, and legal staff) and external parties (service providers, couriers, hosting providers, etc.), who are designated, if necessary, as Data Processors. An updated list of Data Processors is available upon request.

Place of Processing

Data is processed at the Data Controller’s facilities and at other locations involved in the processing. For more details, please contact the Data Controller. Data may be transferred to third countries.

13. DATA TRANSFER TO THIRD COUNTRIES

With explicit consent, Personal Data may be transferred to external entities, individuals, or companies (including consultants and service providers) used by the Data Controller to carry out activities related to, instrumental to, or resulting from the purposes pursued. These entities may be located in European or non-European countries and may not provide adequate data protection (a complete list of countries that provide adequate safeguards for data protection is available on the website of the Italian Data Protection Authority). In such cases, the Data Controller undertakes to ensure appropriate safeguards for the protection of Personal Data, for example through the use of standard contractual clauses approved by the European Commission, intra-group data transfer agreements (so that we can securely transfer personal data among group companies worldwide), or compliance with the provisions of the EU-U.S. Data Privacy Framework (DPF).

14. CHANGES TO THE PRIVACY POLICY

This Privacy Policy was last updated on April 7, 2025. In the event of substantial changes to the Policy, a notice will be posted on our homepage for a period of 30 days. We encourage you to check this section periodically to review any updates or changes to our policy.

15. CONTACTS

This website is operated by ILSA S.p.A. If you have any questions, concerns, or complaints regarding this Privacy Policy or how we manage your personal data, please contact us by email at [email protected]