Privacy Policy – Cookie Policy
Protecting the privacy of our supporters and safeguarding their personal data is a commitment we take very seriously.
The personal data you provide to us is processed in accordance with European and Italian law; here you can find the privacy policies governing the use of and access to such data.
You can email us atengim@legalmail.it for any questions, concerns, or requests regarding this matter.
About Us
Engim is a nongovernmental organization (NGO) registered on the list of “Civil Society Organizations and Other Nonprofit Entities” maintained by the Italian Agency for Development Cooperation, pursuant to Art. 26, paragraphs 2 and 3, of Law 125/2014 and Article 17 of Ministerial Decree 113/2015.
Registered office: Rome 00185, via degli Etruschi 7
Our website address is: https://www.engiminternazionale.org
Data Controller and Data Protection Officer
The Data Controller is ENGIM ETS – Ente Nazionale Giuseppini del Murialdo, Via Degli Etruschi 7 – 00185 Rome, which can be contacted at the following certified email (PEC) address: engim@legalmail.it
The Data Protection Officer (DPO) appointed by the Data Controller pursuant to Articles 37 et seq. of the GDPR can be contacted at the following email address: dpo@engim.org
The updated list of Data Processors is kept at the Data Controller’s registered office.
What personal data we collect and why we collect it
- Personal data voluntarily provided by the User
The processing of your personal data contained in communications sent to the email addresses indicated on the website or provided via telephone is intended to:
a) respond to the contact request or request for information received from the User.
To this end, the following categories of data will be collected:
- Personal details (First Name, Last Name);
- Contact information (email address, phone number)
- Additional data contained in the text of the communication or provided by phone.
Providing personal data for the purposes described in subparagraph (a) is mandatory, as it is an essential requirement for us to be able to respond to your requests. Any refusal to provide such data or the provision of inaccurate and/or incomplete information could prevent the Data Controller from responding to you correctly.
- Browsing/Usage Data
The computer systems and software procedures used to operate the website www.engimstartup.org automatically collect, during normal operation, certain personal data that is implicitly transmitted through the use of Internet communication protocols. This information, by its nature, could—through association and processing with data held by third parties—allow for the identification of users/visitors (e.g., IP address, etc.).
This data, which is collected automatically, is used solely for the purpose of obtaining anonymous statistics on website usage and to verify its proper functioning; furthermore, in the event of any cybercrimes committed against the website, it is used for the defense, investigation, or exercise of the Data Controller’s rights in court or before judicial authorities.
- Cookies and Tracking Tools
This website, including through third parties to whom the Data Controller has outsourced certain services, uses tracking tools to monitor and analyze traffic data, as well as to track individual users’ behavior by, for example, viewing their interactions with social networks, external platforms, or live chat services. The processing of personal data collected through cookies is described in the specific “Cookie Policy,” to which you are referred for further details.
Legal Basis for Processing
With regard to the conditions for the lawfulness of processing, the following is specified:
- The processing of personal data provided by the User as described in Section A for the purposes set forth in subparagraph (a) is based on the Data Controller’s legitimate interest in managing the request made by the Contact, pursuant to Article 6(1)(f) of Regulation (EU) 2016/679;
- The processing of browsing and usage data referred to in Section B is based on the Data Controller’s legitimate interest in managing the website and resolving any operational issues, as well as in obtaining anonymous statistical information on the use of the website and identifying any anomalies and/or abuses in its use, including the determination of liability in the event of any cybercrimes committed against the website, pursuant to Article 6(1)(f) of Regulation (EU) 2016/679.
Methods of Processing
The data requested from you and provided by you is used in accordance with the principles of fairness, lawfulness, and transparency, as well as purpose limitation and data minimization, pursuant to Article 5 of the GDPR.
All processing is carried out using technical and organizational security measures appropriate to the processing itself, as set forth in Article 32 of the GDPR. All data is processed using IT and/or telecommunications tools by specifically authorized or designated individuals and in compliance with the provisions of Article 29 of the GDPR 2016/679.
The personal data referred to in sections A. and B. of this notice are not subject to automated decision-making processes.
Recipients of the Processed Personal Data
In addition to the Data Controller, in some cases, other individuals involved in the organization (administrative, sales, and legal staff, as well as system administrators) or external parties (such as third-party technical service providers, hosting providers, and IT companies) may have access to the data.
The recipients may themselves be Data Controllers; in other cases, the third parties are designated as Data Processors.
Under no circumstances will your personal data be disclosed to unspecified parties.
Transfer of Personal Data to Third Countries
The User’s Personal Data may be transferred to a third country outside the European Economic Area. In such cases, the Data Controller will carry out this transfer in accordance with the safeguards set forth in Articles 45, 46, and 47 of EU Regulation 679/2016.
Retention Period for Personal Data
The personal data provided by the User as described in Section A for the purposes set forth in subparagraph (a) will be retained for the time necessary to respond to the request received and, in any case, for a maximum of two years from the date of initial contact, subject to any further retention required in the event of a detected violation or dispute (until the facts are resolved).
The browsing and usage data referred to in Section B will be retained for a maximum period of 30 days from the date of collection, unless a longer retention period is required in the event of a dispute (until the dispute is resolved).
At the end of the retention period, the Personal Data will be deleted.
What Rights Do You Have Regarding Your Data
Users may exercise certain rights with respect to their Personal Data processed by the Data Controller. Specifically, the User has the right to request:
- access: you may request confirmation as to whether or not data concerning you is being processed, as well as further clarification regarding the information set forth in this privacy policy, and to receive the data itself, within reasonable limits;
- correction: you may request that the data you have provided to us or that is otherwise in our possession be corrected or supplemented if it is inaccurate;
- deletion: you may request that your collected or processed data be deleted if it is no longer necessary for our purposes or where there are no pending disputes or controversies, in the event of withdrawal of consent or your objection to processing, in the event of unlawful processing, or if there is a legal obligation to delete the data;
- Restriction: You may request the restriction of the processing of your personal data when one of the conditions set forth in Article 18 of the GDPR applies; in such cases, your data will not be processed, except for storage, without your consent, except as specified in paragraph 2 of that same article.
- Objection: You may object at any time to the processing of your data based on our legitimate interest, unless we have legitimate grounds for the processing that override your interests, such as for the exercise or defense of our legal rights in court;
- Data portability: You may request to receive your data, or to have it transmitted to another data controller of your choice, in a structured, commonly used, and machine-readable format.
Furthermore, pursuant to Article 7, paragraph 3 of EU Regulation 679/2016, with regard to the processing of personal data based on consent, we inform you that you may exercise your right to withdraw your consent at any time, without this affecting the lawfulness of the processing based on the consent you previously provided.
Finally, we inform you that you have the right to file a complaint with the Supervisory Authority, which in Italy is the Italian Data Protection Authority.
How to Exercise Your Rights
To exercise your rights, report issues, or request clarification regarding the processing of your personal data, you may send an email to the certified email address (PEC):engim@legalmail.it .
We also inform you that you may submit your requests by mail as well, by writing to the Data Controller, as identified above, specifying the subject of your request.
Changes to this Privacy Policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page.
Please check this page regularly, referring to the date of the last update indicated at the bottom.
If you do not accept the changes made to this Privacy Policy, you must stop using this Website and may request that the Data Controller delete your Personal Data.
Unless otherwise specified, the previous privacy policy will continue to apply to Personal Data collected up to that point.
