Privacy Policy

Privacy Statement

FOREWORD
This information, provided pursuant to art. 13 and 14 of Regulation (EU) 2016/679 (“Regulation” or “GDPR”) and art. 13 of Legislative Decree 196/2003 (“Privacy Code”), illustrates the methods of processing the personal data of users who interact with the www.isati-srl.com site and related services, including the management of applications and the receipt of curricula vitae (CVs) from parties interested in establishing an employment relationship with the Company.
The information applies exclusively to this website and not to, nor through other sites that may be consulted by the user via links.

DATA CONTROLLER
Isati Srl
C.F. 04484470960
Via Felice Broggi 9, 21049 Tradate (VA)
Email: info@isati-srl.com

DATA CONTROLLER
The Company may appoint, pursuant to art. 28 GDPR, external data processors for purposes strictly related to the organization of the activities managed through the site (e.g. IT suppliers, hosting providers, consultants, communication agencies and HR). The updated list of Data Processors is available upon request at the address of the Data Controller.

DATA PROCESSED
a) Browsing data
During normal operation, the site collects some personal data whose transmission is implicit in the use of Internet communication protocols (e.g. IP addresses, type of browser, pages visited, date and time of visit). Such data are processed in aggregate form or, where necessary, for security and service improvement purposes, on the basis of the legitimate interest of the Data Controller.
b) Data provided voluntarily by the user
The optional, explicit and voluntary sending of e-mails to the addresses indicated, the compilation of contact forms, the use of services and the transmission of Curriculum Vitae (CV) involve the subsequent acquisition of personal data necessary for the management of the request and the provision of the service. The user is responsible for the truthfulness and correctness of the data provided.

PURPOSES, LEGAL BASES AND STORAGE TIMES
Personal data are processed:
1. Technical and security management of the site
Purpose: To ensure the proper functioning of the platform, prevent fraud and protect IT security.
Legal basis: Legitimate interest of the Data Controller (art. 6, par. 1, lett. f) GDPR).
Retention: 12 months, unless further storage is required for the purpose of ascertaining crimes or disputes.
2. Response to requests and management of contractual or pre-contractual relationships
Purpose: To follow up on your requests (including requests for information, reports, subscriptions to services, requests for quotes) and to allow the establishment or execution of contractual relationships.
Legal basis: Execution of pre-contractual or contractual measures adopted at the request of the data subject (Art. 6, para. 1, lit. b) GDPR).
Retention: For the duration of the relationship and for an additional 10 years in accordance with the law.
3. Management of applications and Curriculum Vitae spontaneously sent
Purpose: Receiving, examining, filing and evaluating applications for the purpose of establishing an employment relationship, including for future positions.

LEGAL BASIS:
Execution of pre-contractual measures adopted at the request of the candidate (Art. 6, para. 1, lit. b) GDPR).
Legitimate interest of the Data Controller to evaluate professional profiles for present and future needs, in compliance with the limits and rights of data subjects (Article 6, paragraph 1, letter f) GDPR).
Within the limits of the purposes referred to in art. 6 (1) (b) GDPR, consent is not required. Only if the CV contains particular data, explicit consent will be required for its processing.
Retention: Until a request for cancellation, rectification or updating by the data subject and in any case no later than 24 months from the last update. The data subject has the right to request the removal of their data at any time, in line with the company’s policy of re-contacting for future opportunities.

PROVISION OF DATA AND CONSEQUENCES OF ANY REFUSAL
The provision of data is:
Mandatory for technical navigation data (in the absence of it, the site may not function properly).
Optional for any other contribution, including the sending of CVs. However, failure to provide the necessary data may preclude the possibility of processing the user’s requests or carrying out selection activities.

PROCESSING METHODS AND SAFETY
Personal data are processed:
• with manual, IT and telematic tools;
• adopting technical and organisational measures aimed at guaranteeing security, integrity and confidentiality, aimed at preventing unauthorised access, loss, alteration or dissemination of data;
• in compliance with the principles of minimisation, accuracy, transparency and storage limitation.

RECIPIENTS OR CATEGORIES OF RECIPIENTS OF THE DATA
The data can be accessed:
to expressly authorized internal personnel and, if appointed, to Data Processors (IT companies, professionals, HR agencies);
to third parties, appointed as Data Processors where necessary (e.g. hosting providers, consultants, IT/HR service providers), whose updated list is available upon request;
to the competent authorities, compliance with legal obligations or in case of specific requests.
The data will not be disseminated. Any transfer outside the EU is excluded, unless specifically disclosed and in the presence of adequate guarantees.

RIGHTS OF THE DATA SUBJECT
The interested party, at any time, may exercise the rights provided for by art. 15-22 of Regulation (EU) 2016/679, including:
• right of access to personal data;
• the right to obtain rectification, erasure (“right to be forgotten”) or restriction of processing;
• right to object to processing for legitimate reasons;
• the right to withdraw consent (if given), without prejudice to the lawfulness of processing based on consent before its withdrawal;
• right to data portability;
• right to lodge a complaint with the Data Protection Authority.
Requests should be addressed to the Data Controller at the addresses indicated above.

PROCESSING OF CURRICULUM VITAE DATA
In particular, pursuant to art. 111-bis of Legislative Decree 196/2003 and art. 13 GDPR:
• CVs received spontaneously are processed for the purpose of selecting and evaluating candidates;
• The complete information is provided at the time of the first useful contact following the sending of the CV;
• The express consent to the processing of data is not due if the purpose falls within the pre-contractual purposes (art. 6, par. 1, lett. b) GDPR); if special data are present (art. 9 GDPR), consent must be acquired;
The storage of data relating to CVs takes place until the data subject requests cancellation, correction or updating and in any case no later than 24 months from the last update, unless otherwise provided for by law or the need for defence in court;
It is the right of the data subject to request at any time the updating, deletion, correction or limitation of processing and the withdrawal of consent for any special data.

PLUGIN SOCIAL NETWORK E COOKIE
With regard to the use of cookies and social plugins, please refer to the specific Cookie Policy published on the site, which details the purposes, types of cookies and the possibilities of management/authorization by the user.

CHANGES AND UPDATES
This policy may be subject to changes or updates. In the event of significant changes, we will notify you by means of appropriate notices. The user is invited to consult this page periodically.

Last update: 26/01/2026

For information, requests on rights or updates relating to the personal data processed by the Company, you can write to: info@isati-srl.com.