Privacy Policy

In compliance with the current regulations on personal data protection – Regulation (EU) 2016/679 (“GDPR”) and Legislative Decree 196/2003 (Privacy Code), as amended by Legislative Decree 101/2018 – we provide the following information regarding the processing of personal data of users who visit and use the website NetCaffé.biz (hereafter also referred to as the “Website”). This notice describes the purposes and methods of data processing, the legal bases legitimizing such processing, and the rights granted to users, in language compliant with European legal standards.

Data Controller

The Data Controller for personal data collected through the Website is NetCaffé.biz, represented by its manager (a private individual), hereafter referred to as “Controller”. The Controller has chosen to remain anonymous as NetCaffé.biz (or Management of NetCaffé.biz) being a private entity and not a company. For any requests regarding personal data processing or to exercise rights provided under GDPR (listed below), you can contact the Controller at the following email address: privacy@netcaffe.biz.

Types of Data Collected

Various types of personal data may be collected during navigation and interaction with the Website:

Navigation Data

The IT systems and software procedures enabling the Website's operation automatically collect some personal data, whose transmission is implicit in Internet protocols. This data is not collected to identify users but could, by its nature, allow indirect identification through processing and association with data held by third parties. Navigation data includes, for example, IP addresses or domain names of user devices connecting to the Website; the time of request; requested URL; the method used to submit the request; response status code; size of data obtained in response; and other parameters regarding the user's operating system and IT environment. These data are used solely to obtain anonymous statistical information on Website usage and ensure correct operation. Navigation data are normally deleted immediately after processing (e.g., log files are retained for a few days, not exceeding 7 days, unless necessary for criminal investigations by competent authorities).

Data Voluntarily Provided by Users

Optional, explicit, and voluntary communication with the Controller (e.g., via email addresses published on the Website or contact forms) results in subsequent acquisition of voluntarily provided personal data, such as sender's email address, name and surname, and the content of the request or message, along with any additional data submitted. These data are exclusively used to respond to user requests or provide requested services or assistance. Providing these data is optional, but failure to do so might prevent obtaining a response or accessing certain requested services.

Cookies and Tracking Technologies

The Website uses cookies and similar technologies solely to ensure proper functioning of offered services (technical cookies). NetCaffé.biz does not use profiling cookies for advertising or marketing purposes. However, as the Website is hosted on third-party platforms (e.g., hosting providers), some necessary third-party technical cookies may be automatically installed, which the Controller does not directly control. If analytics or profiling cookies are used in the future, they will only be activated with explicit user consent according to current regulations.

For detailed information on cookie types, purposes, and consent management, please refer to the separate Cookie Policy available on this Website. Users can manage and disable cookies through browser settings. Note that disabling or blocking technical cookies may impair certain Website functionalities or service usage.

Purposes and Legal Bases for Processing

Users’ personal data are processed lawfully, fairly, and transparently for the following purposes, each with its relevant legal basis according to GDPR Article 6:

  • Providing Website access and content display: based on contract performance and legitimate interest.

  • Responding to user requests or communications: based on contract performance or legitimate interest.

  • Compliance with legal obligations: processing necessary to comply with legal requirements.

  • Security management and abuse prevention: processing based on legitimate interests.

  • Use of technical and functional cookies: processing based on legitimate interests or necessary contract performance.

  • Use of third-party or profiling cookies (if applicable): processing based on user consent.

Data Processing Methods and Security Measures

Personal data are processed primarily through electronic and telematic means, employing suitable technical and organizational measures to ensure data security and confidentiality, in compliance with GDPR Article 32. Measures include HTTPS/SSL encryption, firewall protection, secure authentication, and regular backups. External providers (such as hosting providers) comply with Data Processing Agreements consistent with GDPR requirements.

Data Retention

Personal data are retained only for the duration necessary to fulfill processing purposes, in accordance with GDPR Article 5(1)(e) and legal obligations. Specifically:

  • Navigation data: stored for up to 7 days.

  • Data provided voluntarily: typically stored up to 12 months after the last communication.

  • Data processed for legal obligations: stored as required by applicable laws.

  • Consent-based data processing: stored until consent withdrawal.

Data Communication and Recipients

Personal data will not be publicly disclosed but may be shared with third-party service providers (IT services, consultants, authorities) under confidentiality agreements or legal requirements. Data will not be sold or commercially shared with third parties.

Location and International Transfers

Data processing occurs mainly within Italy and EU-based hosting data centers. International transfers outside the EU comply with GDPR Articles 44-49, including standard contractual clauses and adequacy decisions.

Data Subject Rights

Users have rights under GDPR Articles 15-22, including access, rectification, erasure, restriction, portability, objection, consent withdrawal, and the right to lodge a complaint with the supervisory authority (Italian Data Protection Authority – Garante per la Protezione dei Dati Personali).

Exercising Rights

Users can exercise these rights by contacting privacy@netcaffe.biz. Requests will be processed within 30 days unless an extension is necessary due to complexity.

Minors

The Website does not knowingly collect data from minors under 14 without parental consent. Any inadvertently collected minor's data will be promptly deleted upon notification.

Policy Updates

This Privacy Policy may be updated periodically due to service changes or regulatory updates. Users are advised to regularly check for updates.

Last updated: March 2025.