Privacy notice

This notice explains which personal data we collect through azienda.borz.it, why we do so, how long we keep it and which rights you can exercise. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated:

01 Who processes your data

The data controller is Borz S.r.l., registered office at Via del Garda 42, 38068 Rovereto (TN), Italy, VAT number IT02389140225. You can contact us about any personal data matter at info@borz.it or on +390464437719.

  • We have not appointed a Data Protection Officer: we do not process data on a large scale nor special categories of data, so the conditions of Article 37 GDPR do not apply.

02 When you write to us through the contact form

The form on the Contact page collects your name, your company if you give one, your email address, your phone number if you give one, and the text of your message. Name, email and message are required: without them we cannot reply. Company and phone number are optional.

  • Purpose: to answer your enquiry and, if a relationship follows, to handle pre-contractual steps.
  • Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR). We do not ask for your consent: writing to us IS the request, and a consent you must give in order to get an answer would not be freely given. The tick box in the form confirms that you have read this notice; it does not grant us anything.
  • Recipients: the message reaches our mailbox, hosted by Aruba S.p.A. We do not pass it on to anyone else and we do not use it to send you advertising.
  • Retention: 24 months from the last exchange of messages, then the message is deleted. If a contract follows, the data is kept for as long as contractual and tax documents require.
  • At any time you can ask us, by writing to info@borz.it, to delete your enquiry and the data it contained, or to object to any further use.

03 How we keep the form from being used for spam

To stop automated bulk messages, the site records that a request has already been sent from your connection in the last 48 hours. We do not keep your IP address: we store only an encrypted fingerprint of it, together with a random browser identifier.

  • Purpose: preventing abuse and protecting our mailbox.
  • Legal basis: our legitimate interest in keeping the service working and secure (Art. 6(1)(f) GDPR).
  • Retention: 48 hours, after which the records are deleted automatically.
  • The fingerprint does not allow anyone to trace your identity and is not cross-referenced with any other data.

04 When you browse the site

Like every website, the server hosting azienda.borz.it automatically logs the requests it receives. These logs are generated and managed by the hosting provider.

  • Data: IP address, date and time of the request, page address, browser and operating system.
  • Purpose: infrastructure security, fault diagnosis, defence against attacks.
  • Legal basis: our legitimate interest in system security (Art. 6(1)(f) GDPR).
  • Retention: according to the terms applied by Aruba S.p.A., which manages the server logs; we do not access them except in the event of a security incident.
  • The site uses no third-party analytics, no profiling cookies and no behavioural advertising.

05 Visit statistics

To know how many people visit the site and which content matters, we use our own statistics system, running on the same server as the site. It uses no cookies, does not follow you across other sites and sends nothing to anyone.

  • Data collected: page visited, chosen language, device category (phone, tablet or computer), country and — for Italy — region, the site you came from, clicks on our contact details (phone, email, WhatsApp) and how far down the page you read.
  • Your IP address is never kept: it is used for an instant, in memory, to derive country and region, then discarded.
  • No cookies and nothing stored on your device. To tell whether two pages belong to the same visit we use a code computed on the fly with a key that changes every day at midnight: tomorrow’s visit cannot be linked to today’s, by us or by anyone else.
  • Purpose: understanding which content is actually useful and where to act.
  • Legal basis: our legitimate interest in improving the site (Art. 6(1)(f) GDPR). Being first-party statistics with no IP retention and no sharing with third parties, consent is not required (Italian Data Protection Authority guidelines of 10 June 2021).
  • Retention: detailed data for 30 days; afterwards only overall counts remain, which no longer concern any particular person.
  • Recipients: none. The data never leaves the server hosting the site.
  • If your browser sends the Global Privacy Control or Do Not Track signal, we record nothing.

06 The Google map

A map provided by Google is available on the Contact page. It is not loaded automatically: it stays switched off until you ask for it. Until then no data is sent to Google.

  • If you switch the map on, your IP address, browser data and any Google cookies already on your device are transmitted to Google Ireland Limited and may be transferred to the United States.
  • Legal basis: your consent, given by clicking the activation button (Art. 6(1)(a) GDPR). The transfer to the United States relies on the safeguards adopted by Google (standard contractual clauses and the EU-US Data Privacy Framework).
  • What happens next is Google’s responsibility, under its own notice: policies.google.com/privacy
  • If you would rather not switch it on, our address is written out in full on the same page and you can open the map in a separate window whenever you prefer.

07 The restricted area

The site has a restricted area used by company staff to update some content. It is not open to the public and is reachable only through the link in the footer.

  • Data: first name, surname, work email address, password (kept only as a non-reversible encrypted fingerprint), role, date of last sign-in.
  • Activity log: for every operation (successful or failed sign-in, content change, creation or removal of a user) we record the user identifier, the action, the time, the IP address and — derived from it using an archive held on our own server, without querying any external service — the country, the region (for Italy only) and the type of device used, for example “Windows · Chrome”. They serve to spot an unusual sign-in: a numeric address on its own does not tell whether there is a colleague or a stranger behind it.
  • Purpose: allowing access, preventing unauthorised access, and being able to reconstruct who did what in the event of an incident.
  • Legal basis: legitimate interest in security (Art. 6(1)(f)) and the duty to adopt appropriate measures (Art. 32 GDPR).
  • Retention: the activity log is kept for 12 months, sign-in attempts for 24 hours, single-use verification codes for 24 hours. They are then deleted automatically.

08 Who we share data with

We do not sell, transfer or exchange your personal data. It is processed on our behalf and on our instructions only by those who provide the technical services the site needs to run.

  • Aruba S.p.A. — hosting of the site, the database and the email service, as a processor appointed under Article 28 GDPR. The servers are located in the European Union.
  • Google Ireland Limited — only if you choose to switch on the map, as explained above.
  • Public authorities, where we are required by law or by judicial order to disclose data.

09 Transfers outside the European Union

Data collected through this site stays on servers located in the European Union. The only exception is the voluntary activation of the Google map, which may involve a transfer to the United States on the basis of your explicit consent and the safeguards adopted by Google (standard contractual clauses and the EU-US Data Privacy Framework).

10 Your rights

Within the limits set by the GDPR you may exercise the following rights at any time, by writing to info@borz.it or to Borz S.r.l., Via del Garda 42, 38068 Rovereto (TN), Italy. We answer within one month; if the request is complex we may take two further months and will tell you so.

  • Access (Art. 15): find out which of your data we process and obtain a copy.
  • Rectification (Art. 16): correct inaccurate data or complete it.
  • Erasure (Art. 17): have data removed when it is no longer necessary or when you withdraw consent.
  • Restriction (Art. 18): ask that data be kept but not used further.
  • Portability (Art. 20): receive in machine-readable form the data you provided on the basis of consent or a contract.
  • Objection (Art. 21): object to processing based on our legitimate interest, explaining your reasons.
  • Withdrawal of consent (Art. 7(3)): at any time, without affecting what happened beforehand.
  • Complaint: if you believe your data is processed unlawfully you may contact the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or the supervisory authority of your country of residence, without prejudice to any legal action.

11 Whether providing data is mandatory

No data is required simply to browse the site. The fields marked as required in the contact form are needed only so that we can reply: if you do not fill them in, the message cannot be sent, but you can still contact us by phone or email.

12 Automated decisions and profiling

We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not carry out profiling through this site.

13 Children

This site addresses professional users and is not intended for children under sixteen. We do not knowingly collect children’s data. If you believe a child has given us their data, write to info@borz.it and we will delete it.

14 How we protect data

We adopt technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:

  • the whole site is served only over an encrypted connection (HTTPS);
  • access to the restricted area requires two-step verification through a code sent by email;
  • passwords are stored only as a non-reversible encrypted fingerprint, never in clear text;
  • repeated sign-in attempts are slowed down and blocked automatically;
  • service credentials are never written into the site’s code;
  • every operation performed in the restricted area is logged.

15 Changes to this notice

We may update this notice to reflect changes to the site or to the law. The version in force is always the one published here, with the update date shown at the top. If the changes concern processing based on your consent, we will ask for it again.

Borz S.r.l. — VAT IT02389140225 · REA TN-220932 · Share capital 30.000,00 € · PECborzsrl@pec.it — Via del Garda 42, 38068 Rovereto (TN)