PRIVACY POLICY

pursuant to Article 13 of EU Regulation 2016/679 (GDPR)


1. DATA CONTROLLER

The Data Controller of personal data is:

FP Solution – NCC Service
VAT No.: IT03106240348
Data Controller: Pasquale Fracassi
Tel: +39 347 449 6409
Email: info@fpsolution-ncc.it
Website: www.fpsolution-ncc.it


2. TYPES OF DATA COLLECTED

The website collects and processes the following categories of personal data:

2.1 Data Provided Voluntarily by the User

Through the contact form (Contact Form 7) available on the website, the following data are collected:

First and last name

Email address

Telephone number

Any other information provided in the message

Data relating to quotation requests (e.g. date, time, destination of the NCC service)

2.2 Browsing Data

The computer systems and software procedures used to operate the website collect, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. These include:

IP addresses

Type of browser used

Operating system

Domain names and addresses of websites from which access was made

Information on pages visited

Time of access

These data are used solely to obtain anonymous statistical information on website usage and to monitor its correct functioning.


3. PURPOSES AND LEGAL BASIS OF PROCESSING

The personal data collected are processed for the following purposes:

3.1 Management of Quotation Requests

Purpose: To respond to quotation requests and provide information on the NCC services offered.
Legal basis: Performance of pre-contractual measures taken at the data subject’s request (Article 6(1)(b) GDPR).

3.2 Performance of the Contract

Purpose: Provision of the requested NCC services and management of the contractual relationship.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).

3.3 Legal Obligations

Purpose: Compliance with obligations arising from laws, regulations, EU legislation, and instructions issued by competent authorities.
Legal basis: Compliance with a legal obligation (Article 6(1)(c) GDPR).

3.4 Marketing (Subject to Prior Consent)

Purpose: Sending commercial communications, newsletters, and promotional material relating to the services offered.
Legal basis: Explicit consent of the data subject (Article 6(1)(a) GDPR). Consent may be withdrawn at any time.


4. METHODS OF PROCESSING

Personal data are processed using IT and telematic tools, with organisational and logical methods strictly related to the stated purposes. In addition to the Data Controller, data may be accessed by personnel involved in website management (administrative, commercial, marketing staff) or by external parties (such as technical service providers, hosting providers, and IT companies).

Data are processed using appropriate security measures designed to prevent unauthorised access, disclosure, alteration, or destruction.


5. COMMUNICATION AND DISCLOSURE OF DATA

Personal data may be disclosed to:

Data processors: IT and hosting service providers, maintenance service providers, communication agencies, and consultants.

Payment service providers: where external payment services (PayPal, Stripe) are used, the data necessary for the transaction are transmitted directly to these platforms, which act as independent data controllers in accordance with their own privacy policies.

Public authorities: where required by law or necessary to fulfil legal obligations.

Personal data will not be disseminated.


6. TRANSFER OF DATA TO NON-EU COUNTRIES

Some service providers may transfer personal data to countries outside the EU. In such cases, the Data Controller ensures that such transfers take place in compliance with applicable regulations and through the adoption of appropriate safeguards (e.g. Standard Contractual Clauses approved by the European Commission).


7. DATA RETENTION PERIOD

Personal data will be retained for the time necessary to achieve the purposes for which they were collected, and in any case:

Quotation request data: retained for the time necessary to manage the request and subsequently for 12 months.

Contractual data: retained for the duration of the contractual relationship and subsequently for the period required by tax and civil law (generally 10 years).

Marketing data: retained until consent is withdrawn or for a maximum period of 24 months from the last contact.

After the retention period has expired, data will be deleted or irreversibly anonymised.


8. RIGHTS OF THE DATA SUBJECT

As a data subject, you have the right to:

Access (Article 15 GDPR): obtain confirmation as to whether personal data concerning you are being processed and, if so, access to such data.

Rectification (Article 16 GDPR): obtain the rectification of inaccurate data or completion of incomplete data.

Erasure (Article 17 GDPR): obtain the deletion of personal data in cases provided for by law.

Restriction (Article 18 GDPR): obtain restriction of processing.

Portability (Article 20 GDPR): receive personal data in a structured, commonly used, and machine-readable format and transmit them to another controller.

Objection (Article 21 GDPR): object to the processing of your personal data.

Withdrawal of consent (Article 7 GDPR): withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Lodging a complaint (Article 77 GDPR): lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

To exercise your rights, you may contact the Data Controller using the details provided in Section 1.


9. NATURE OF DATA PROVISION

The provision of personal data for the purposes referred to in Sections 3.1, 3.2, and 3.3 is:

Optional for quotation requests, but necessary in order to process such requests.

Mandatory for contract performance and compliance with legal obligations.

The provision of data for marketing purposes (Section 3.4) is optional, and refusal does not affect the ability to request or use the services offered.


10. COOKIES AND SIMILAR TECHNOLOGIES

The website uses cookies and similar technologies. For detailed information on the use of cookies, please refer to the specific Cookie Policy available on the website.


11. WHATSAPP INTEGRATION

The website includes direct integration with WhatsApp, allowing automatic opening of a chat with the relevant contact. By clicking the WhatsApp button, users are redirected to the WhatsApp application installed on their device. WhatsApp is a messaging service operated by Meta Platforms Ireland Limited. For further information on WhatsApp’s data processing practices, please consult its Privacy Policy at:
https://www.whatsapp.com/legal/privacy-policy


12. EXTERNAL PAYMENT SERVICES

The website allows payments through external platforms (PayPal and Stripe) that are not directly integrated into the website. These services are provided by third parties acting as independent data controllers.

When users use these services, they are redirected to the respective platforms, where payment data are processed in accordance with the following privacy policies:

PayPal: https://www.paypal.com/it/webapps/mpp/ua/privacy-full

Stripe: https://stripe.com/it/privacy


13. CHANGES TO THIS PRIVACY POLICY

This Privacy Policy may be updated from time to time, including as a result of changes in applicable legislation. Users are therefore encouraged to check this page periodically for updates.


Last updated: February 2026