Privacy Policy

Pursuant to and for the purposes of the combined provisions of Legislative Decree 196/2003 (Privacy Code) and European Regulation 2016/679 (General Data Protection Regulation or GDPR), the company BROXING SA, with registered office at Via ai Campi 9, CH-6982 Agno (TI), Switzerland, as Data Controller (hereinafter Controller), informs you of the following.

This privacy policy is made available and valid for the website https://www.broxing.com/.

Art. 1. Data Controller (the person or company deciding how and why data are processed).
BROXING SA | Via ai Campi 9, CH-6982 Agno (TI), Switzerland | CHE-112.404.907 | email: info@broxing.com

Art. 2. Purpose (the reason why we collect data) and legal basis (whether data are mandatory to perform a contract or whether your specific consent is required for their use).

The Controller carries out activities related to brand design, communication, and marketing.
This website does not track or collect data from connected users. A contact form is available, allowing users to communicate directly with the Data Controller. Data transmitted through the contact form are not automatically stored in databases, and no cookie data from users’ computers are collected.
The optional, explicit, and voluntary sending of data through the contact form entails the subsequent acquisition of the sender’s email address necessary to respond to requests, as well as any other personal data voluntarily entered by the user. The mandatory fields required to respond to user requests are: Name, Email address, and message.
Explicit consent for data processing is not required, as the Controller has a legitimate interest in using the information voluntarily provided by the user in order to pursue the following purposes:
– respond to submitted requests;
– issue quotations and formulate contract proposals;
– comply with obligations established by law, regulations, EU legislation, or orders from Authorities;
– exercise the Controller’s rights, such as the possible right of legal defense.

Art. 3. Duration of processing (how long we retain data).
Without prejudice to the retention period required by specific regulations (e.g. tax, anti-money laundering, etc.), for the entire duration of the contract and for the duration of any legal dispute, the Data Controller retains collected data for a maximum period of 3 (three) years from the end of the relationship with the Data Subjects, in order to respond to any possible requests from them.

Art. 4. Processing methods (how we use data).
Processing is carried out within the limits strictly necessary to achieve the purposes indicated above (see Art. 2), in compliance with the principle of proportionality in the choice of processing methods and with the adoption of all suitable measures to ensure the security and confidentiality of the personal data of the Data Subjects.

Art. 5. Where are the collected data stored?
Data are processed and stored at the Controller’s premises and on the company devices used (e.g. computers). All data (paper and digital) are protected by appropriate security systems in order to guarantee confidentiality and protection. All data are physically stored in Italy. Some digital files may be stored on cloud systems. Providers have been selected in order to ensure data confidentiality and protection. These systems are physically located within the European Union.

Art. 6. To whom are the data disclosed?
Data are not disclosed or disseminated to third parties, except where required by law. In compliance with such obligations, customer data may be transmitted to third parties processing data on behalf of the Controller in their capacity as External Processors appointed pursuant to Art. 28 GDPR (for example, accountants for invoicing-related data), to Credit Institutions, and to employees and/or collaborators of the Controller in the performance of their normal work and/or collaboration activities, as persons authorized to process data, whose updated list is available at the Controller’s offices.

Art. 7. Rights of Data Subjects (Articles 15 et seq. of the GDPR).
Art. 15: Right of access, including the right to obtain information on the expected retention period of personal data or, if not possible, the criteria used to determine such period. Right to obtain information regarding the origin of the collected data, as well as the purposes and methods of processing. Right to lodge a complaint at any time with the Supervisory Authority: Italian Data Protection Authority (Garante Privacy): Piazza di Monte Citorio no. 121, 00186 ROME Tel. +39 06 696771 – PEC: protocollo@pec.gpdp.it

Art. 16: Right of the Data Subject to obtain updating, rectification, or integration of personal data.
Art. 17: Right to erasure and right to be forgotten.
Art. 18: Right to restriction of processing, where applicable.
Art. 19: Obligation of the Controller to notify rectification, erasure, and/or restriction.
Art. 20: Right to data portability, where technically feasible.

Art. 8. Requests from Data Subjects.
Requests referred to in Art. 7 above may be submitted by Data Subjects to the Data Controller via registered mail or certified email (PEC) to the addresses indicated in Art. 1 above. In all cases, Data Subjects must attach a valid identity document to their request.