Privacy Policy
This Privacy Policy is issued pursuant to Article 13 of the European Regulation No. 679/2016 and applies exclusively to all Data collected through the website https://www.hicmilano.com. This Privacy Policy is subject to updates, which will be published promptly on the website. This Privacy Policy and the Cookie Policy establish the basis upon which the Data Subject’s personal data will be processed.
Data Controller
The Data Controller for the data collected by this website is HIC Srl, Tax ID and VAT No. 08553750962, Via Privata Cadore, 10, 20098 San Giuliano Milanese (MI). Email: info@hicmilano.com.
Personal Data
“Personal Data” means any information relating to an identified or identifiable natural person (Data Subject). A natural person is considered identifiable if they can be identified, directly or indirectly, with particular reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical identity.
Categories of Personal Data Processed
Among the Personal Data processed by this website, either independently or through third parties, are common data such as:
-
Contact data (first name, last name, company, email, address, phone number)
-
Requests: If a request is sent through the “Contact” section of the site, the provision of certain Personal Data is necessary for the Data Controller to fulfill the requests; therefore, the relevant fields in the registration form are marked as mandatory.
-
Cookies and Usage Data
Methods of Personal Data Processing
The Personal Data provided or acquired will be subject to processing based on the principles of fairness, lawfulness, transparency, and confidentiality in accordance with applicable regulations. The Data Controller processes Users’ Personal Data by adopting appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of the Personal Data. Processing is carried out using computer and/or electronic tools, with organizational methods and logic strictly related to the indicated purposes.
Purposes of Personal Data Processing and Legal Basis
Personal Data may be collected independently by the Data Controller or through third parties. In this case, the computer systems and software procedures used to operate this website acquire certain technical-informatic Personal Data of Users (e.g., IP address, browser type used, operating system, domain name, and addresses of websites from which access or exit was made, etc.), the transmission of which is inherent to the normal functioning of the internet. This Data may be processed for the sole purpose of obtaining anonymous statistical information on the use of the site and/or checking its correct functioning and will be deleted immediately after processing.
Data that the Data Subject chooses to provide spontaneously will be processed in compliance with the conditions of lawfulness pursuant to Art. 6 GDPR and will be processed to allow the website to provide its services, as well as for the purposes indicated below, and will be stored for the time necessary to fulfill said purposes. Specifically, the purposes of processing are:
-
Responding to information requests sent via the contact form or email.
-
Legal basis: Execution of pre-contractual measures adopted at the request of the Data Subject (Art. 6, para. 1, letter b GDPR).
-
-
Technical management, security, and correct functioning of the website.
-
Legal basis: Legitimate interest of the Data Controller (Art. 6, para. 1, letter f GDPR).
-
-
Aggregated statistical analysis of site usage.
-
Legal basis: Consent of the Data Subject expressed through the cookie banner (Art. 6, para. 1, letter a GDPR).
-
Providing data for contact purposes is optional, but failure to provide it may make it impossible to respond to the Data Subject’s requests.
Data Communication
In addition to the Data Controller, in some cases, the following may have access to the Data: a) Categories of specifically trained personnel involved in the organization of the website (administrative, sales, marketing, legal staff, system administrators); b) External parties (such as third-party technical service providers, hosting providers, IT companies, communication agencies) also appointed as Data Processors by the Data Controller pursuant to Art. 28 GDPR. The updated list of Processors, if appointed, can always be requested from the Data Controller; c) Public or private entities that may access the Data in compliance with legal obligations; d) Parties that perform auxiliary and instrumental tasks for the Data Controller’s business.
Processing Times
As expressly provided by Art. 5, para. 1, letter e) of the GDPR, Data is kept for the time necessary for its processing in relation to the performance of the service requested by the Data Subject, or required by the purposes described above in this document. At the end of the retention period, the Personal Data will be deleted or anonymized in compliance with applicable legal provisions.
Cookies
This website uses cookies. Cookies are small text files that can be used by websites to make the user experience more efficient and to personalize content and ads, provide social network features, and analyze traffic. [Cookie Policy]
Place of Processing and Transfer of Data Abroad
Data is processed at the Data Controller’s operating office. For further information, you can contact the Data Controller. Data may be processed by natural persons and/or legal entities acting on behalf of the Data Controller and under specific contractual constraints, based in EU or non-EU member countries. In the event that Data is transferred outside the EEA, the Controller will adopt any contractual measure suitable to ensure adequate data protection pursuant to Art. 44 et seq. of the GDPR.
Exercise of Data Subject Rights
The Data Subject has the right to exercise the faculties provided for in Articles 7 and 15-22 of the European Regulation 679/2016. In particular, they have the right to withdraw any consent given at any time, without prejudice to the lawfulness of the processing based on consent before the withdrawal, and may request access to their Personal Data, receive the personal data provided to the Data Controller and, where possible, transmit them to another Data Controller without hindrance (so-called portability), obtain the update, limitation of processing, rectification of the data, and the deletion of data processed in violation of current legislation. They have the right, for legitimate reasons, to object to the processing of their personal data and to processing for the purpose of sending advertising material, direct sales, and for carrying out market research. They also have the right to lodge a complaint with the Privacy Guarantor as the supervisory authority for the protection of personal data or to take appropriate legal action. The Data Subject may exercise their rights by contacting the Data Controller via email at: info@hicmilano.com.
Tools Used for Processing Personal Data
-
Content Management System (WordPress): The site is created using the WordPress platform, which allows for the management of the site’s content and features. WordPress does not collect personal data independently but may process data voluntarily entered by the Data Subject through features on the site (e.g., contact forms). Data collected via WordPress is processed exclusively for the purposes indicated above.
-
Contact Form: By filling out the contact form on the site, the Data Subject voluntarily provides their personal data to request information. The data collected is: name and surname, company, email address, phone number. This data is used exclusively to respond to received requests.
-
Email Communications: The spontaneous sending of communications to the email addresses indicated on the site involves the acquisition of the sender’s personal data, used solely to manage and respond to requests.
-
Google Analytics: The site uses Google Analytics to collect aggregated statistical information on the use of the site, in order to improve its content and functionality. Processing occurs with the prior consent of the Data Subject expressed through the cookie banner, in compliance with the GDPR. For further details, please refer to the Cookie Policy.
-
Security and Spam Protection Systems: The site uses the HTTPS/SSL security protocol and protection tools to prevent unauthorized access, cyberattacks, and spam traffic.
-
Social Networks – LinkedIn: The site may contain links to the LinkedIn social network. Interaction with these services is governed by the privacy policies of the respective provider. The site does not provide features for job applications or the collection of personal data for personnel selection purposes.
Changes to this Privacy Policy
The Data Controller reserves the right to make changes to this Privacy Policy at any time by notifying Users on this page. We therefore ask you to consult this page frequently, taking as a reference the last modification date indicated at the bottom. In case of non-acceptance of the changes made to this Privacy Policy, the Data Subject is required to cease using this website and may request the Data Controller to remove their Personal Data. Unless otherwise specified, the previous Privacy Policy will continue to apply to the Personal Data collected until that moment. The Data Controller is not responsible for updating all links visible in this Privacy Policy; therefore, whenever a link is not functioning and/or updated, Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by such link.
Privacy Policy updated as of January 2026
