PRIVACY POLICY
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018
Last updated: May 15, 2026
This Policy describes how FAS S.p.A. processes the personal data of users who visit the fasspa.net website and interact with the Company through digital channels.
Transparency in the processing of personal data is a core value that FAS S.p.A. considers fundamental in its relationship with customers, partners, and visitors. For this reason, we have drafted this policy using clear and accessible language.
1. Data Controller
The Data Controller is:
FAS S.p.A.
Via della Meccanica, 18 – 27010 Cura Carpignano (PV) – Italy
Tax Code and VAT No.: IT00183770189
Phone: +39 0382 483494
Certified Email (PEC): ammi@pec.fasspa.net
Email for privacy requests: privacy@fasspa.net
FAS S.p.A. has not appointed a Data Protection Officer (DPO) as the conditions set out in Article 37 of the GDPR are not met. For any questions regarding the processing of personal data, the data subject may contact the Data Controller directly using the contact details provided above.
2. Types of Personal Data Processed
During navigation and use of the website, the following categories of data are processed:
2.1 Navigation Data
The computer systems and software procedures used to operate the website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.
This information is not collected to be associated with identified individuals, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category includes:
- IP addresses and domain names of the devices used by users
- URI/URL addresses of the requested resources
- time of the request
- method used to submit the request to the server
- size of the file obtained in response
- numerical code indicating the status of the response from the server
- other parameters relating to the user's operating system and IT environment
These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning, and are deleted immediately after processing.
2.2 Data Provided Voluntarily by the User
When the user fills out the contact form on the site, the following data are collected:
- First and Last Name (mandatory)
- Email address (mandatory)
- Company (mandatory)
- Phone number (optional)
- Message (mandatory)
The optional, explicit, and voluntary sending of messages to the Company's contact addresses also involves the acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the communication.
2.3 Data Collected via Cookies and Similar Technologies
For detailed information on cookies and similar technologies used by the site, please refer to the Cookie Policy available in the dedicated section of the footer.
3. Purposes and Legal Basis of Processing
The personal data collected are processed for the following purposes:
| Purpose | Legal Basis |
|---|---|
| To respond to contact requests, commercial inquiries, quotes, or technical assistance submitted via the contact form | Art. 6.1.b GDPR — performance of pre-contractual measures taken at the request of the data subject |
| To ensure the correct functioning, security, and maintenance of the website | Art. 6.1.f GDPR — legitimate interest of the Data Controller |
| To comply with legal, regulatory, or EU obligations | Art. 6.1.c GDPR — legal obligation |
| To defend the rights of the Data Controller in judicial or extrajudicial proceedings | Art. 6.1.f GDPR — legitimate interest of the Data Controller |
Providing data to respond to contact requests is optional, but failure to provide mandatory information in the form will prevent the request from being sent.
FAS S.p.A. does not use the contact data collected through the website for direct marketing, newsletters, or unsolicited commercial communications.
4. Processing Methods
Personal data is processed using IT and telematic tools, with organizational and logical methods strictly related to the stated purposes. The data is stored on servers located within the European Union (Italy) and is protected by appropriate technical and organizational security measures to prevent data loss, illicit or incorrect use, and unauthorized access, in compliance with Article 32 of the GDPR.
Data collected via the contact form is processed by personnel expressly authorized by the Data Controller and bound by specific confidentiality obligations.
5. Data Retention Period
Personal data collected via the contact form is kept for a maximum period of 24 months from the last meaningful contact with the data subject, unless:
- the continuation of the commercial relationship requires longer retention
- specific legal provisions dictate different time limits (e.g., for tax, accounting, or to protect the rights of the Data Controller in court)
After this period, the data will be irreversibly deleted or anonymized.
Navigation data (logs) is kept for the time strictly necessary for security and diagnostic purposes, generally not exceeding 12 months.
6. Data Recipients
The personal data collected may be communicated to the following categories of subjects, exclusively for the purposes indicated above:
- authorized internal personnel of FAS S.p.A. (commercial, administrative, and technical departments)
- technical service providers acting as Data Processors pursuant to Art. 28 GDPR, specifically:
- Aruba S.p.A. — website hosting provider (servers located in Italy)
- Google Ireland Limited — provider of Google Maps, Google reCAPTCHA, YouTube embed, and Google Fonts services (see Cookie Policy for details)
- professionals and consultants (accountants, lawyers, IT consultants) strictly to the extent necessary
- public authorities when required by law or by an authority's order
Personal data is not disseminated in any way.
7. Data Transfer Outside the European Union
Personal data collected via the contact form is stored on servers located within the European Union (in Italy, on the Aruba infrastructure).
However, some third-party services used on the website (specifically Google services such as Maps, reCAPTCHA, Fonts, and YouTube) may involve the transfer of navigation data outside the European Economic Area, particularly to the United States of America. Such transfers take place on the basis of Standard Contractual Clauses approved by the European Commission (Decision 2021/914) and, where applicable, within the framework of the EU-US Data Privacy Framework, providing adequate protection guarantees pursuant to Articles 44 and following of the GDPR.
For more information on the privacy policies of individual providers, please refer to the Cookie Policy.
8. Rights of the Data Subject
In relation to the processing described in this Policy, the data subject may, at any time, exercise the rights provided for by Articles 15-22 of the GDPR, specifically:
- right of access to personal data (Art. 15)
- right to rectification of inaccurate or incomplete data (Art. 16)
- right to erasure ("right to be forgotten"), in the cases provided for by law (Art. 17)
- right to restriction of processing (Art. 18)
- right to data portability (Art. 20)
- right to object to processing (Art. 21)
- right not to be subject to automated decision-making, including profiling (Art. 22)
Requests can be sent in writing:
- by email to privacy@fasspa.net
- by Certified Email (PEC) to ammi@pec.fasspa.net
- by standard mail to the registered office: Via della Meccanica, 18 – 27010 Cura Carpignano (PV) - Italy
The Data Controller will respond to the data subject's requests without undue delay and, as a rule, within one month of receiving the request. This period may be extended by two further months where necessary, taking into account the complexity and number of the requests.
The exercise of rights is free of charge. However, in the case of requests that are manifestly unfounded or excessive, in particular because of their repetitive character, the Data Controller may charge a reasonable fee or refuse to act on the request.
9. Right to Lodge a Complaint with the Supervisory Authority
If the data subject believes that the processing of their personal data violates current regulations, they have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali):
Piazza Venezia, 11 – 00187 Rome – Italy
Phone: +39 06 696771
Email: protocollo@gpdp.it
PEC: protocollo@pec.gpdp.it
Website: www.garanteprivacy.it
Alternatively, the data subject may contact the competent supervisory authority in their Member State of residence or workplace, or bring the matter before the competent courts.
10. Changes to this Policy
The Data Controller reserves the right to modify this Policy at any time, publishing the updates on this page, which will always indicate the date of the last update. Users are therefore invited to consult this document regularly.
In the event of substantial changes, the Data Controller will also provide notice via a visible alert on the website.