Bordignon Group S.p.A. (hereinafter the “Company” or the “Data Controller”) provides this notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (hereinafter the “GDPR”) and Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (hereinafter the “Italian Privacy Code”), to explain how the personal data of users (hereinafter the “Users”) who browse the website www.zincherie.com (hereinafter the “Site”) or interact with the services available through it are processed.
The Site is the corporate website of the group headed by Bordignon Group S.p.A. It presents the group companies and their activities and allows Users to contact them through the email addresses and forms available on the Site, as well as to submit job applications. The Site also contains embedded videos and links to the group’s social media profiles.
“Personal data” means any information relating to an identified or identifiable natural person, including a person who can be identified indirectly.
Pursuant to Article 4 of the GDPR, “processing of personal data” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, and disclosure.
“User” means any individual who browses our website (hereinafter the “Site”).
This notice applies solely to the Site and not to any third-party websites that may be accessed through links. It contains the following sections:
- Data Controller
- Categories of Data Processed (Including Cookies and Social Networks)
- Purposes, Legal Basis, and Retention Periods
- Nature of Data Provision and Consequences of Refusal
- Processing Methods and Security Measures
- Recipients of Personal Data
- Location of Personal Data and Transfers Outside the European Economic Area
- Automated Decision-Making
- Data Subject Rights
- Changes to This Notice
1. Data Controller
The Data Controller is Bordignon Group S.p.A., with registered office at Via dell’Artigianato 6, 36027 Rosà (VI), Italy, VAT No. 02255290245, and may be contacted:
- by mail, at its registered office address;
- by email at info@zincherie.com;
- by certified email (PEC) at bordignonsrl@postemailcertificata.it.
The Company has not appointed a Data Protection Officer (DPO), as the requirements set forth in Article 37 of the GDPR are not met.
The Site also presents the activities of the group’s operating companies, which are subject to the management and coordination of the Company (Zincheria Seca S.r.l., Zincheria Valbrenta S.r.l., Zincheria BeB S.r.l., and DMW S.r.l.). If a request concerns the services of one of these companies, the data necessary to handle the request are disclosed to the relevant company, which processes them as an independent data controller for the purposes described in this notice.
2. Categories of Data Processed
2.1 Browsing Data
The information systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data whose transmission is inherent in the use of Internet communication protocols. This category includes, for example, the IP addresses or domain names of the devices used to connect to the Site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server response (successful, error, etc.), and other parameters relating to the User’s operating system, browser, and IT environment.
These data are not collected for the purpose of associating them with identified data subjects; however, by their very nature, they could make it possible to identify Users through processing and association with data held by third parties. They are used to ensure the proper operation and security of the Site and may also be used to establish liability in the event of suspected cybercrimes committed against the Site.
2.2 Data Voluntarily Provided by the User
The optional, explicit, and voluntary sending of email messages to the addresses indicated on the Site, or the completion of forms available on the Site, results in the collection of the sender’s data necessary to respond (for example, first name, last name, company, email address, and telephone number), as well as any other personal data included in the message.
Users are requested not to include in messages or forms any special categories of personal data (Article 9 GDPR, such as health data) or personal data relating to criminal convictions and offenses (Article 10 GDPR), unless strictly necessary. If such data are provided when they are not necessary, they will be deleted.
The Site is intended for a professional audience and is not directed to individuals under the age of 18. The Company does not knowingly collect personal data from minors. If the Company becomes aware that it has collected such data, it will delete them.
Job applications. If a résumé/CV is submitted through the Site or by email, the data contained therein are processed for the purpose of evaluating the application. Pursuant to Article 111-bis of the Italian Privacy Code, consent is not required for data contained in résumés/CVs submitted on the applicant’s own initiative; applicants are nevertheless requested not to include data that are not relevant to the recruitment process. Where necessary, a specific privacy notice will be provided at the first appropriate contact.
2.3 Cookies and Other Tracking Technologies
The information in this section is also provided pursuant to Article 122 of the Italian Privacy Code and in accordance with the “Guidelines on Cookies and Other Tracking Technologies” issued by the Italian Data Protection Authority on June 10, 2021. For the exercise of data subject rights, please refer to Section 9.
What Are Cookies?
A cookie is a small file that is sent to the browser and stored on the User’s device when visiting a website such as zincherie.com. Cookies help the Site operate efficiently and enable the use of certain services, such as viewing videos. Similar technologies (for example, pixels or local storage) are treated in the same manner as cookies. The Site uses first-party cookies (set and managed by Bordignon Group S.p.A.) and third-party cookies (set and managed by third parties under their own privacy policies and outside the control of Bordignon Group S.p.A.). An explanatory table is provided below.
| COOKIE CATEGORY | FUNCTION |
| Strictly necessary cookies (session or browsing cookies) | They enable normal browsing and use of the Site and are therefore intended to make the Site functional and optimize navigation. They do not require consent and cannot be disabled through the cookie banner because the Site would not function properly without them. |
| Functionality cookies | They are strictly necessary to provide services explicitly requested by the User (for example, remembering the preferences selected through the cookie banner). They do not require consent. |
| Third-party cookies for embedded content and services | They are set by providers of services integrated into the Site (YouTube videos and Google reCAPTCHA), as described below. |
The Site does not use analytics cookies or other statistical tools (such as Google Analytics or Google Tag Manager), nor does it use profiling or marketing cookies. If any such tools are activated in the future, this notice will be updated and the relevant cookies will be installed only in accordance with the choices expressed by the User through the cookie banner.
Third-Party Services Integrated into the Site
Our Site may include links to third-party websites, plug-ins, and applications, such as links to our Facebook, LinkedIn, and Twitter pages. By clicking on these links, the User may allow the operators of external websites to collect or share the User’s personal data. Please note that we do not control these websites and are not responsible for their privacy notices. After leaving our Site, Users are therefore encouraged to review the privacy notice of each website they visit.
List of Cookies
Cookie and consent management is handled through the Cookiebot platform, provided by Usercentrics A/S. The current list of cookies used on the Site, including their name, provider, purpose, category, and duration, is generated automatically by Cookiebot.
How to Manage Consent
On the first visit, a banner informs the User about the use of cookies and allows the User to:
- close the banner using the “X,” retaining the default settings, which allow only strictly necessary cookies;
- accept all cookies;
- reject all non-essential cookies;
- choose in detail which categories of cookies to allow.
Choices may be changed or withdrawn at any time using the dedicated link or icon available on every page of the Site. The User’s choice is stored, and the banner will not be displayed again for six months unless there are material changes to the cookies used.
Cookies may also be managed or deleted through the browser settings; however, disabling strictly necessary cookies may impair the operation of the Site.
2.4 Links to Social Networks
The Site contains links to the group’s profiles on LinkedIn, Facebook, and Instagram. These are simple links: merely displaying the related icons does not result in the transmission of data to the social network operators. When Users click on these links, they are redirected to external platforms, which may collect data in accordance with their own privacy notices, over which the Company has no control; Users are therefore encouraged to review those notices. With respect to data processed in connection with the group’s social media pages, the Company and the relevant platform operator may act as joint controllers in accordance with the arrangements established by the platforms.
3. Purposes, Legal Basis, and Retention Periods
The Company processes personal data for the purposes set out in the table below, each on the legal basis and for the retention period indicated. At the end of the applicable retention periods, the data are deleted or anonymized, unless further retention is necessary to comply with legal obligations or to establish, exercise, or defend legal claims. If the data subject exercises the right to erasure or the right to object, the data may be deleted before the end of those periods.
| Purpose | Legal Basis | Retention Period |
| a) Enable browsing, ensure the operation and security of the Site, and protect forms against spam and bots (browsing data, Google reCAPTCHA) | The Data Controller’s legitimate interest in operating and protecting the Site (Article 6(1)(f) GDPR) | Up to 6 months from collection, unless retention is necessary to investigate unlawful activity |
| b) Respond to requests for information, quotations, or contact submitted by email or through the Site forms | Performance of pre-contractual measures taken at the data subject’s request (Article 6(1)(b) GDPR) or, for general inquiries, the legitimate interest in responding (Article 6(1)(f) GDPR) | 24 months from the last contact; if the request results in a contractual relationship, for the duration of the relationship and for 10 years after its termination (Article 2220 of the Italian Civil Code) |
| c) Evaluate unsolicited job applications or applications submitted in response to job postings | Pre-contractual measures taken at the data subject’s request (Article 6(1)(b) GDPR) and Article 111-bis of the Italian Privacy Code | 24 months from receipt, unless earlier deletion is requested |
| d) Comply with legal obligations or requests from competent authorities | Legal obligation (Article 6(1)(c) GDPR) | For the period required by applicable law |
| e) Establish, exercise, or defend the Data Controller’s rights in judicial or out-of-court proceedings | The Data Controller’s legitimate interest (Article 6(1)(f) GDPR) | For the duration of the dispute and until the applicable time limits for appeals have expired |
The Company’s legitimate interest has been determined to prevail following a balancing assessment against the rights and freedoms of data subjects, taking into account that these processing activities are reasonably expected by individuals who visit a corporate website or contact a business. Data subjects may object to such processing at any time as described in Section 9.
4. Nature of Data Provision and Consequences of Refusal
Except for browsing data, the processing of which is necessary for the operation of the Site, the provision of personal data is optional. However, failure to provide data marked as mandatory in the forms, or data necessary to identify and contact the person making the request, will make it impossible to respond to the request. Refusal to consent to non-essential cookies does not affect the ability to browse the Site or contact the Company.
5. Processing Methods and Security Measures
Personal data are processed primarily by electronic means, by authorized personnel, and in accordance with procedures strictly related to the purposes described above. Pursuant to Article 32 of the GDPR, the Company implements appropriate technical and organizational measures to prevent data loss, unlawful or improper use, and unauthorized access.
- collection only of the data necessary for the stated purposes and retention only for the period strictly necessary;
- encrypted connection (HTTPS) for data transmission between the User’s browser and the Site;
- access to personal data restricted to authorized personnel using individual credentials;
- backup copies and server protection systems against unauthorized access and cyberattacks;
- selection of service providers offering appropriate safeguards and their appointment as data processors under specific contractual agreements;
- instructions and training for personnel regarding personal data protection.
6. Recipients of Personal Data
For the purposes described above, personal data may be made accessible to:
- employees and contractors of the Company who are authorized to process personal data and instructed pursuant to Article 29 of the GDPR and Article 2-quaterdecies of the Italian Privacy Code;
- group companies concerned by the request, as described in Section 1;
- service providers that process personal data on behalf of the Company as data processors pursuant to Article 28 of the GDPR, such as providers of hosting services, Site development and maintenance services, and IT and telecommunications services;
- companies providing logistics and transportation services;
- consultants, professionals, public authorities, and judicial authorities, where necessary to comply with legal obligations or protect the Company’s rights.
Personal data are not publicly disclosed or transferred to third parties for marketing purposes. An up-to-date list of data processors may be requested using the contact details provided in Section 1.
7. Location of Personal Data and Transfers Outside the European Economic Area
Your Personal Data referred to in Section 1) of this Notice are stored on Chiesi’s servers or on the servers of service providers (specifically appointed as data processors) located in Italy or within the European Union.
Your personal data will not be transferred to non-European third countries.
8. Automated Decision-Making
Personal data are not subject to solely automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects the data subject (Article 22 GDPR).
9. Data Subject Rights
At any time, pursuant to Articles 15–22 of the GDPR, the data subject has the right to:
- access: obtain confirmation as to whether personal data are being processed and obtain a copy of such data;
- rectification: obtain the correction of inaccurate personal data or completion of incomplete personal data;
- erasure: obtain the deletion of personal data where the conditions set forth in Article 17 of the GDPR are met;
- restriction: obtain restriction of processing in the cases provided for in Article 18 of the GDPR;
- data portability: receive the personal data provided in a structured, commonly used, machine-readable format where processing is based on consent or a contract and is carried out by automated means;
- objection: object at any time, on grounds relating to the data subject’s particular situation, to processing based on the Company’s legitimate interests (Article 21 GDPR);
- withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing carried out before consent was withdrawn.
These rights may be exercised free of charge by writing to the contact details provided in Section 1. The Company will respond without undue delay and, in any event, within one month of receiving the request. This period may be extended by two additional months where necessary due to the complexity or number of requests. The Company may request information necessary to verify the identity of the requester.
Any person who believes that the processing of personal data violates applicable data protection law also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, Italy, https://www.garanteprivacy.it, or with the supervisory authority of the EU Member State in which the person resides or works, or to seek judicial remedies.https://www.garanteprivacy.it
10. Changes to This Notice
This notice may be amended, for example, as a result of changes in applicable law or the introduction of new Site features. Updates become effective when they are published on the Site; Users are therefore encouraged to review this page periodically. Any material changes will be highlighted on the Site.
Last updated: September 2026