PRIVACY POLICY
DATA CONTROLLER – WHO WE ARE AND HOW TO CONTACT US
This section contains information on who processes the data, how to contact us for any need, and the main contents of this policy (what data we collect, why we use it, how long we keep it and what rights you can exercise).
Conversion Media S.r.l., with registered office at Via Bagutta, n. 13, Milan – 20121 (Italy), VAT no. 10430480961 (“Controller”) is the entity acting as data controller and providing this privacy policy (“Policy”) pursuant to art. 13 of EU Regulation 2016/679 of 27 April 2016 (hereinafter, the “Regulation”).
This policy concerns the processing carried out by the Controller on data collected through the website https://conversion-m.com (“Website”), provided directly (for example, by filling in the forms present) or even only indirectly (for example, by accessing the Website) by the users who browse the Website (“Data Subjects”).
The policy explains clearly: which data we collect; for which purposes and on which legal bases; for how long we keep them and where they are processed; and what your rights are.
The Controller attaches the utmost importance to the right to the protection of the personal data of Data Subjects who, for any information regarding this Policy or for the exercise of the rights guaranteed to them by law, may contact the Controller at any time: (i) by sending a registered letter with return receipt to the registered office of the Controller; or (ii) by sending an email to: [email protected].
Users may also contact the Data Protection Officer (DPO) of the Company, Shibumi S.r.l., in the person of Lapo Curini Galletti, reachable at the following email address: [email protected].
PURPOSES OF PROCESSING AND LEGAL BASIS – WHAT WE DO (AND HOW) WITH PERSONAL DATA
This section explains for which purposes we collect and use the data, which legal bases authorize us to do so, and in which cases the provision is mandatory or optional.
The personal data of Data Subjects will be lawfully processed by the Controller for the processing purposes and according to the legal bases indicated below.
| Browsing the Website | The personal data of data subjects will be processed by the Controller to allow the Data Subject to browse the Website and to obtain anonymous statistical information on the use of the Website and ensure its proper functioning.The data collected by the Controller include all personal data whose transmission is implicit in the use of Internet communication protocols, which the computer systems and software procedures responsible for the operation of the Website acquire in the course of their normal operation. These may include: the IP addresses or domain names of the computers used by Data Subjects, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the operating system and IT environment of the Data Subject.The provision of such data is necessary to allow the Data Subject to enjoy the contents of the Website by browsing it. In the absence of provision, the Data Subject will not be able to visit the Website. | The legal basis is art. 6, par. 1 lett. b) of the Regulation, i.e. the processing is necessary for the performance of a contract to which the Data Subject is party or to take steps prior to entering into a contract at the request of the Data Subject. |
|---|---|---|
| Management of project and contact requests | The personal data of Data Subjects will be processed by the Controller to manage and respond to project and contact requests submitted through the dedicated form on the Website (“Contact”), as well as to prepare any commercial proposals or quotes and manage pre-contractual activities and the possible establishment of the commercial relationship.The data collected by the Controller for this purpose are those provided directly by the Data Subject through the form, such as, by way of example, first name, last name, email address, telephone number and the content of the message sent, as well as any further information voluntarily communicated by the Data Subject.The provision of the Data Subject's contact data and the other data marked as mandatory within the form is necessary to allow the Controller to receive, evaluate and manage the request and provide the requested response. Failure to provide the data marked as mandatory may prevent the Controller from following up on the Data Subject's request. | The legal basis is art. 6, par. 1 lett. b) of the Regulation, i.e. the processing is necessary for the performance of a contract to which the Data Subject is party or to take steps prior to entering into a contract at the request of the Data Subject. |
| Submission of a spontaneous application | The personal data of Data Subjects will be processed by the Controller to allow the latter to evaluate the professional profile of the candidate for the purposes of any personnel selection processes, as well as to manage the related contact and communication activities during the selection procedure, following the submission of a spontaneous application through the form on the Website (“Application”). Personal data may also be retained and used to evaluate the application also with reference to future professional positions compatible with the candidate's profile.The data collected by the Controller for this purpose are those provided by the Data Subject (such as, by way of example, first name, last name and email, as well as all other personal information of the Data Subject possibly and voluntarily provided when submitting the request).The provision of the Data Subject's contact data or the other requested data (for example, by indicating their mandatory nature within the form on the Website) is necessary to submit a request to the Controller and allow the latter to follow up on it. | The legal basis is art. 6, par. 1 lett. b) of the Regulation, i.e. the processing is necessary for the performance of a contract to which the Data Subject is party or to take steps prior to entering into a contract at the request of the Data Subject. |
| Legal obligations | The personal data of Data Subjects will be processed by the Controller to comply with obligations provided for by law or by an authority (such as, by way of example, handling requests for access to the personal data processed submitted by the Data Subject). | The legal basis is art. 6, par. 1, lett. c) of the Regulation, as the processing is necessary to comply with a legal obligation to which the Controller is subject. |
Data Subjects are hereby informed that this Website, as well as the services offered by the Controller, are intended for persons who have reached eighteen years of age (as also specified in the Terms of Use on the Website). The Controller therefore does not intentionally collect personal data relating to minors. Upon request, the Controller will promptly delete all personal data inadvertently collected relating to minors.
For all processing based on the prior obtaining of the Data Subject's consent, the latter is free not to give consent, without this compromising the pursuit of the other processing purposes provided for in this Policy. Likewise, the Data Subject is free, at any time, to withdraw any consent given, without this affecting the lawfulness of the processing based on consent before withdrawal.
PROCESSING METHODS AND DATA RETENTION PERIODS
This section explains how we process the data and how long we keep it in relation to each purpose.
The Controller will process the personal data of Data Subjects using manual and electronic means, with logic strictly related to the purposes themselves and, in any case, in a manner that ensures the security and confidentiality of the data.
The personal data of Data Subjects will be kept for the time strictly necessary to fulfil the purposes illustrated above, for the periods indicated below:
The retention periods for each purpose are indicated below:
| Browsing the Website | The browsing data processed to allow the Data Subject to browse the Website do not persist for more than 7 days. |
|---|---|
| Management of project and contact requests | The personal data of the Data Subject will be processed for 24 months, which is the time necessary to handle the Data Subject's request. |
| Submission of a spontaneous application | The personal data of the Data Subject will be processed for 12 months, which is the time necessary to handle the Data Subject's request. |
| Legal obligations | The personal data of the Data Subject will be processed for the time strictly necessary to fulfil legal obligations and, in any case, for a period not exceeding 10 years from the termination of the contractual relationship with the Data Subject. |
In any case, the Controller reserves the right to further retain the personal data processed for the declared purposes where this is necessary to fulfil a legal obligation that subsequently arises, an order from an Authority and/or to defend a right of the Controller (for example, in the event of judicial litigation with the Data Subject).
SCOPE OF DATA COMMUNICATION AND TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION
This section explains to whom the data may be communicated (internal and external parties, partners, suppliers, etc.) and whether they are transferred outside the European Union, and with what guarantees.
The personal data of Data Subjects may be accessed by:
- the directors, employees and/or collaborators of the Controller, such as, by way of example, those responsible for managing the Website, providing services to Data Subjects and/or managing their requests. These parties, who have been instructed accordingly by the Controller pursuant to art. 29 of the Regulation, will process the data of Data Subjects exclusively for the purposes indicated in this Policy and in compliance with the provisions of the law;
- parties external to the Controller's organization, other than those indicated above, who may process personal data on behalf of the Controller as data processors pursuant to art. 28 of the Regulation, such as, by way of example, IT and logistics service providers functional to the operation of the Website, outsourcing or cloud computing service providers, professionals and consultants;
- competent public Authorities.
The Data Subject's personal data may be transferred outside the European Union to be stored on the servers of the hosting service providers and/or technological service providers entrusted by the Controller to third parties, in accordance with arts. 45 (Transfers on the basis of an adequacy decision) and 46 (Transfers subject to appropriate safeguards) of the Regulation. In the latter case, in particular, through the signing of the appropriate Standard Contractual Clauses and verification of the security measures applied by the providers to protect the personal data entrusted to them.
RIGHTS OF DATA SUBJECTS
This section provides a clear summary of data protection rights: access, rectification, erasure, restriction, objection, portability, withdrawal of consent and the right to lodge a complaint with the Italian Data Protection Authority.
Data Subjects may exercise the rights guaranteed to them by applicable law through the contacts indicated above.
In particular, pursuant to applicable law, Data Subjects are informed that they have:
- the right of access to their personal data;
- the right to data portability (the right to receive all personal data knowingly and actively provided by the Data Subject as well as personal data observed directly from the Data Subject through the use of the Website or the use of their device, in a structured, commonly used and machine-readable format);
- where one of the cases provided for by law applies, the right to obtain the restriction of the processing of personal data;
- the right to rectification (to obtain from the Controller the rectification of inaccurate personal data concerning the Data Subject);
- the right to the integration of incomplete personal data (also by providing a supplementary declaration);
- the right to the erasure of personal data concerning them where one of the reasons provided for by law applies;
- the right to object to the processing of personal data for direct marketing purposes including profiling to the extent that it is related to such direct marketing;
- where they consider that the processing concerning them infringes the Regulation, the right to lodge a complaint with a supervisory authority (in the Member State where they habitually reside, where they work or where the alleged infringement occurred). The Italian supervisory authority is the Garante per la protezione dei dati personali, with offices at Piazza Venezia, n. 11, 00187 - Rome (RM). The list of the supervisory authorities of the other Member States can be found on the website of the European Data Protection Board.
UPDATING THE POLICY AND LINKS
This section explains the reasons why we may, in the future, need to update the policy.
This policy – v. no. 1 of 19/06/2026 – may be subject to changes in the future, for example due to the entry into force of new personal data protection legislation, clarifications or indications provided by the Italian Data Protection Authority or other competent bodies, or decisions of the Controller. We therefore invite the Data Subject to consult it periodically: in any case, the purposes for which the data are processed will never be changed without first informing the Data Subject and, when required by law, obtaining their consent.
The Controller is not responsible for updating all the links displayed in the policy; therefore, whenever a link is not working and/or updated, Data Subjects acknowledge and accept that they must always refer to the document and/or section of the websites referenced by such link.