Privacy Policy
In accordance with Regulation (EU) 2016/679, we hereby provide the necessary information regarding the processing of the personal data you have provided. This information does not apply to other websites that may be consulted via links on the Controller’s domain websites, for which the Controller is in no way responsible.
This privacy notice is also provided pursuant to Article 13 of Regulation (EU) 2016/679. It is also based on Recommendation No. 2/2001, adopted on 17 May 2001 by the European data protection authorities meeting within the Working Party established under Article 29 of Directive 95/46/EC, in order to identify certain minimum requirements for the online collection of personal data, with particular reference to the methods, timing, and nature of the information that data controllers must provide to Users when they access web pages, regardless of the purposes of the access. It is also based on the provisions of Directive 2002/58/EC, as amended by Directive 2009/136/EC, concerning Cookies, and on the provisions of the Italian Data Protection Authority’s decision of 08/05/2014 regarding Cookies.
1. Data Controller and Data Processor
The Data Controller, pursuant to Article 4(7) of Regulation (EU) 2016/679, is Exa MP Srl, Via Cappuccini 2 – 20122 Milan, Italy, tel. +39 0575 315354, email: info@exa-mp.com.
The Data Processor, pursuant to Article 4(8) of Regulation (EU) 2016/679, is, among others, WEBSOLUTE S.p.A., with registered office at Strada della Campanara, 15 – 61122 Pesaro (PU), Italy.
2. Types of Data Processed
Personal and Identifying Data
Identifying data: personal data that allow the direct identification of the Data Subject (such as name, surname, email address, address, telephone number, etc.).
Personal data: any information relating to an identified or identifiable natural person, even indirectly, by reference to any other information, including a personal identification number.
Browsing Data
The computer systems and software procedures used to operate this Website acquire, during their normal operation, certain personal data whose transmission is implicit in Internet communication protocols. Such information is not collected to be associated with identified Data Subjects but, by its very nature, could, through processing and association with data held by third parties, allow Users to be identified.
This category of data includes IP addresses or domain names of the computers used by Users who connect to the Website, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response provided by the server (successful outcome, error, etc.), and other parameters relating to the User’s operating system and IT environment. These data are used solely to obtain anonymous statistical information on the use of the Website and to check its correct functioning.
Legal Defense
The User’s Personal Data may be used by the Data Controller for legal defense purposes or in the preparatory stages of any related legal proceedings. The data may also be used to ascertain liability in the event of hypothetical computer crimes against the Website.
Maintenance
The User’s Personal Data may be processed using additional methods and for purposes related to system maintenance.
Data Voluntarily Provided by the User
The optional, explicit, and voluntary sending of emails to the addresses indicated on this Website or the completion of any data collection forms entails the subsequent acquisition of the sender’s email address, which is necessary to respond to requests, as well as any other personal data included.
Specific Notices
Specific privacy notices may be provided on the Website pages in relation to particular services or processing of data provided by the User or the Data Subject.
Cookies
This Application uses Cookies. For more information and a detailed cookie notice, please refer to our Cookie Policy.
Curriculum Vitae
A specific privacy notice is also provided for the processing of personal data contained in CVs received. This notice is automatically sent to the User at the time a CV is submitted to one of our email addresses.
3. Legal Basis, Purpose of Processing, and Legitimate Interest
Pursuant to Article 6(1)(b), personal data voluntarily provided will be processed for the following purposes, unless opposed:
browsing this Website;
managing contact requests and sending the requested information;
submission of curriculum vitae;
completion of data collection forms in dedicated areas.
4. Methods of Processing and Data Retention
Processing will be carried out both by automated and manual means, using tools and methods suitable to ensure maximum security and confidentiality, by specifically authorized personnel, in compliance with Article 32 of Regulation (EU) 2016/679. Data will be retained for no longer than is necessary to achieve the purposes for which they were collected and subsequently processed. Processing related to the web services offered by this Website is physically hosted by third-party hosting providers.
5. Scope of Communication, Disclosure, and Transfer of Data Abroad
Your data will not be disclosed and may be communicated to companies contractually linked to Exa Srl within the European Union, in compliance with and within the limits of Article 44 of Regulation (EU) 2016/679, for the fulfillment of contractual obligations or related purposes.
Data may be communicated to third parties belonging to the following categories:
professional firms or companies in the context of assistance and consultancy relationships;
competent authorities, for the fulfillment of legal obligations and/or provisions of public bodies, upon request.
The entities belonging to the above categories act as Data Processors or operate independently as autonomous Data Controllers. The list of Data Processors is constantly updated and is available at the registered office of Exa MP Srl, Via Cappuccini 2 – 20122 Milan, Italy.
6. Automated Decision-Making and Profiling
The processing of your data will not be subject to automated decision-making processes or profiling activities.
7. Nature of Data Provision and Refusal
Except as specified for browsing data, the User is free to provide their personal data. The provision of data is optional but necessary.
Failure to provide data marked with an asterisk (*) may make it impossible to obtain what is requested or to use the services of the Data Controller.
8. Minors
This Website and the services of the Data Controller are not intended for persons under the age of 18. The Controller does not knowingly collect personal information relating to minors. Should information relating to minors be inadvertently recorded, the Controller will promptly delete it upon request by Users.
9. Rights of the Data Subject
You may exercise the rights provided for by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 by contacting the Data Controller by telephone at +39 0575 315354, by email at info@exa-mp.com, or by post at the company’s registered office at Via Donat Cattin 123 – 52100 Arezzo, Italy.
Pursuant to Article 13(2) and Articles 15 to 22 of the Regulation, you are informed that, with regard to the processing of your personal data, you may exercise the following rights:
Right of access to personal data and the following information:
confirmation as to whether or not personal data concerning you are being processed;
purposes of the processing;
categories of personal data processed;
recipients or categories of recipients to whom the personal data have been or will be disclosed;
where the data are not collected from the Data Subject, any available information as to their source;
the existence of automated decision-making processes, including profiling;
a copy of the personal data undergoing processing.
Right to rectification and right to completion of incomplete personal data.
Right to erasure (“right to be forgotten”), in the cases provided for by law, including:
where the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
withdrawal of consent where there is no other legal basis;
objection to processing where there are no overriding legitimate grounds;
unlawful processing of data;
compliance with a legal obligation.
Where the Controller has made the personal data public and is obliged to erase them, it shall inform other data controllers of the request to erase any links to, or copies or reproductions of, those data.
Right to restriction of processing, in the cases provided for by law.
Right to lodge a complaint with the Supervisory Authority for the protection of personal data, in accordance with the procedures indicated on the official website www.garanteprivacy.it.
Right to data portability, in the cases provided for by Article 20 of the Regulation.
Right to object at any time to the processing of personal data, including profiling, in the cases provided for by law, in particular for direct marketing purposes.
Right not to be subject to a decision based solely on automated processing, including profiling, except in the cases provided for by law.
Right to withdraw consent at any time.
The exercise of these rights is free of charge and not subject to any restriction.
10. Changes to the Privacy Policy
The Data Controller reserves the right to modify, update, add to, or remove portions of this privacy notice at its own discretion and at any time. Data Subjects are required to periodically check for any changes. In order to facilitate this review, the notice will indicate the date of the last update. Use of the Website following the publication of changes constitutes acceptance of those changes.
Date of last update: 22/12/2025