Last updated: June 17, 2025
Data Controller
M.C.M. Srl - Via Provinciale C.da Castagnara - Cittanova (RC) 89022 IT Data Controller’s email address: info@groupmcm.com
Types of Data We Collect
Among the Personal Data collected by this Application, independently or through third parties, are: Usage Data Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or via specific information texts displayed before the Data collection. Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application. Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide it, it may be impossible for this Application to provide the Service. In cases where this Application indicates some Data as optional, Users are free to refrain from providing such Data without any consequence on the availability or functioning of the Service. Users who have doubts about which Data is mandatory are encouraged to contact the Controller. Any use of Cookies—or other tracking tools—by this Application or by the controllers of third-party services used by this Application is aimed at providing the Service requested by the User, as well as for the additional purposes described in this document and in the Cookie Policy. The User assumes responsibility for Personal Data of third parties obtained, published or shared through this Application.
Methods and Place of Processing of Collected Data
Processing methods The Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data. Processing is carried out using IT and/or telematic tools, with organizational methods and procedures strictly related to the purposes indicated. In addition to the Controller, in some cases other parties involved in the organization of this Application (administrative, commercial, marketing, legal staff, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, and may be appointed as Data Processors by the Controller when necessary. The updated list of Data Processors can always be requested from the Controller. Place Data is processed at the Controller’s operational offices and at any other locations where the parties involved in the processing are located. For further information, contact the Controller. The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section relating to details on the processing of Personal Data. Retention period If not otherwise specified in this document, Personal Data will be processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to legal obligations or based on the User’s consent.
Purpose of the Processing of Collected Data
User Data is collected to allow the Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), detect any fraudulent or malicious activity, as well as for the following purposes: Hosting and backend infrastructure
Details on the Processing of Personal Data
Hosting and backend infrastructure This type of service has the purpose of hosting Data and files that allow this Application to function and be distributed, or to provide an infrastructure ready to use for running specific functionalities or parts of this Application. Some of the services listed below, if present, may operate on geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored. Vercel Vercel is a hosting and backend service provided by Vercel Inc. Personal Data processed: • Usage Data • various types of Data as specified in the service’s privacy policy Service provided by: • Vercel Inc. (United States) - Privacy Policy
Additional information for users in the European Union
Legal basis of processing The Controller processes Personal Data relating to the User when one of the following applies: • the User has given consent for one or more specific purposes; • processing is necessary for the performance of a contract with the User and/or to take steps at the User’s request prior to entering into a contract; • processing is necessary to comply with a legal obligation to which the Controller is subject; • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller; • processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party. It is always possible to request the Controller to clarify the specific legal basis of each processing and, in particular, to specify whether the processing is based on law, contract or consent. Additional information on retention time Unless otherwise specified in this document, Personal Data is processed and stored for as long as required by the purpose for which it was collected and may be stored for a longer period due to legal obligations or based on the User’s consent. Therefore: • Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be retained until the contract has been fully performed. • Personal Data collected for purposes related to the Controller’s legitimate interests will be retained until such interests are fulfilled. The User may obtain further information regarding the Controller’s legitimate interests from the related sections of this document or by contacting the Controller. When processing is based on the User’s consent, the Controller may retain Personal Data longer until such consent is revoked. Furthermore, the Controller may be obliged to retain Personal Data for a longer period to comply with a legal obligation or by order of an authority. At the end of the retention period, Personal Data will be deleted. Therefore, upon expiry of this term the rights of access, erasure, rectification and data portability can no longer be exercised. User rights under the General Data Protection Regulation (GDPR) Users have the right to exercise certain rights in relation to the Data processed by the Controller. In particular, within the limits provided by law, the User has the right to: • withdraw consent at any time. The User may withdraw consent to the processing of their Personal Data previously given. • object to processing of their Data. The User may object to the processing of their Data when it is carried out on a basis other than consent. • access their Data. The User has the right to obtain information on Data processed by the Controller, on specific aspects of the processing and to receive a copy of the Data processed. • verify and request correction. The User may verify the accuracy of their Data and request its updating or correction. • obtain restriction of processing. The User may request restriction of processing of their Data. In this case, the Controller will not process the Data for any purpose other than storage. • obtain erasure or removal of their Personal Data. The User may request erasure of their Data by the Controller. • receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller without hindrance. • lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take judicial action. Users have the right to obtain information regarding the legal basis for transfers of Data abroad, including to any international organization governed by public international law or consisting of two or more countries, such as the UN, as well as the security measures adopted by the Controller to protect their Data. Details on the right to object When Personal Data is processed in the public interest, in the exercise of official authority vested in the Controller or for the purposes of the Controller’s legitimate interests, Users have the right to object to processing for reasons related to their particular situation. Users are informed that, if their Data is processed for direct marketing purposes, they may object to such processing at any time, free of charge and without providing any reason. If Users object to processing for direct marketing purposes, Personal Data will no longer be processed for such purposes. How to exercise your rights Any requests to exercise User rights may be addressed to the Controller using the contact details provided in this document. The request is free of charge and the Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any corrections, deletions or restrictions of processing will be communicated by the Controller to each recipient to whom Personal Data have been disclosed, unless this proves impossible or involves disproportionate effort. The Controller will inform the User of such recipients if requested.
Additional Information on Processing
Legal defense The User’s Personal Data may be used by the Controller in legal proceedings or in the preparatory stages of such proceedings for the defense against abuse in the use of this Application or related Services. The User declares to be aware that the Controller may be obliged to disclose Data by order of public authorities. Specific notices Upon User request, in addition to the information contained in this privacy policy, this Application may provide specific and contextual notices regarding specific Services, or the collection and processing of Personal Data. System logs and maintenance For operational and maintenance requirements, this Application and any third-party services used by it may collect system logs, i.e. files recording interactions which may also contain Personal Data, such as the User’s IP address. Information not contained in this policy Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided. Changes to this privacy policy The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application and, if technically and legally feasible, by sending a notice to Users via one of the contact details they have provided. Please therefore consult this page frequently, referring to the date of last modification indicated at the bottom. If the changes concern processing based on consent, the Controller will collect new consent from the User if necessary.
Definitions and Legal References
Personal Data (or Data) Personal Data means any information that, directly or indirectly, alone or in combination with any other information, including an identification number, identifies or makes identifiable a natural person. Usage Data Usage Data are the information collected automatically through this Application (including by third-party applications integrated into this Application), such as: IP addresses or domain names of the computers used by the User connecting to this Application, URIs (Uniform Resource Identifiers), request time, method used in submitting the request to the server, size of the file obtained in response, numeric code indicating the status of the server response (success, error, etc.), country of origin, browser and operating system characteristics used by the visitor, various time-related details of the visit (e.g., time spent on each page) and details about the path followed within the Application, with particular reference to the sequence of pages visited, parameters related to the operating system and the User’s computing environment. User The individual using this Application who, unless otherwise specified, is the Data Subject. Data Subject The natural person to whom the Personal Data refers. Data Processor (or Processor) The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy. Data Controller (or Controller) The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing Personal Data and the tools adopted, including security measures related to the operation and use of this Application. Unless otherwise specified, the Data Controller is the owner of this Application. This Application The hardware or software tool through which the Users’ Personal Data is collected and processed. Service The Service provided by this Application as defined in the related terms (if any) on this site/application. European Union (or EU) Unless otherwise specified, all references to the European Union in this document are extended to all current member states of the European Union and the European Economic Area.
Legal References Where not otherwise specified, this privacy notice applies exclusively to this Application.