Privacy policy

Privacy notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018

Mital Srl cares about the privacy of everyone who visits this website. This notice explains which personal data we collect through mital.com, why we collect them, how long we keep them and which rights you can exercise.

Data controller

Mital Srl
Via Cherso, 21 — 31045 Motta di Livenza (TV), Italy
VAT and tax code 01110170261
Email: mital@mital.com — Phone: +39 0422 768522

Any request concerning the processing of personal data should be addressed to the Controller at the contact details above.

Data protection officer (DPO)

The Controller has not appointed a Data Protection Officer, as none of the mandatory conditions set out in Article 37 GDPR applies. For any data protection matter you may contact the Controller directly.

What data we process, for which purposes and on which legal basis

1. Contact form

Data: full name, email address, phone number (optional), profession (optional), the content of your message, date and time of submission, acknowledgement of this notice.
Purposes: receiving and answering your enquiry, providing the commercial or technical information requested, managing any follow-up related to that enquiry.
Legal basis: steps taken at the data subject’s request prior to entering into a contract (Art. 6.1.b GDPR) and, for the ordinary handling of correspondence with professionals and companies, the Controller’s legitimate interest in replying to those who get in touch (Art. 6.1.f GDPR).

2. Newsletter subscription

Data: email address, profession (optional), browsing language, date and time of subscription, acknowledgement of this notice.
Purposes: sending news about products, projects and initiatives of Mital Srl.
Legal basis: the freely given, specific and revocable consent of the data subject (Art. 6.1.a GDPR), expressed by ticking the relevant box in the subscription form. Consent is optional: refusing it has no consequence other than not receiving the newsletter.

3. System and security logs

Data: IP address, date and time of the request, page requested, browser type and operating system, request outcome. These data are implicitly transmitted by internet communication protocols and are automatically recorded by the systems hosting the website.
Purposes: ensuring the operation, stability and security of the website, detecting abuse and intrusion attempts, establishing liability in the event of computer crimes against the website.
Legal basis: the Controller’s legitimate interest in the security of its infrastructure (Art. 6.1.f GDPR).

4. Technical cookies

Data: language preference and dismissal of the cookie notice, stored on the user’s device.
Purposes: delivering the service requested by the user.
Legal basis: Article 122 of Italian Legislative Decree 196/2003, which does not require consent for technical cookies, together with the Controller’s legitimate interest (Art. 6.1.f GDPR). Full details are given in the Cookie policy.

Whether providing data is mandatory

Providing the data marked as required in the forms is necessary in order to handle your request or subscription: without them we cannot reply. All other data are optional and their absence does not affect the service.

Retention periods

Data are kept only for as long as is strictly necessary for the purposes for which they were collected, and in any case according to the periods below, unless a legal obligation or the need to establish or defend a legal claim requires otherwise.

Contact form 24 months from the last exchange of correspondence. If the enquiry leads to a business relationship, the data become part of the contractual and accounting records and follow the statutory periods (10 years, Art. 2220 of the Italian Civil Code).
Newsletter Until consent is withdrawn or the subscription is cancelled. Evidence of the consent given is kept for 24 months after withdrawal, for the sole purpose of demonstrating the lawfulness of the processing (Art. 7.1 GDPR).
System logs Normally 12 months, unless a longer retention is required by the judicial authorities.
Technical cookies Durations are listed in the Cookie policy (12 months at most).

Recipients of the data and external processors

Data are processed by staff of the Controller who are expressly authorised and instructed under Article 29 GDPR and Article 2-quaterdecies of Legislative Decree 196/2003.

The following parties may also access the data, within the limits of their respective duties and as data processors appointed under Article 28 GDPR:

  • the provider of hosting and technical maintenance for the website and the email service;
  • consultants and professionals assisting the Controller, where access to the data is necessary for their work.

An up-to-date list of the data processors is available on request by writing to mital@mital.com. Data are never disseminated and are never sold or transferred to third parties for their own marketing purposes.

Transfers outside the European Union

Data collected through this website are processed and stored on servers located within the European Union. No transfer of personal data to third countries or international organisations takes place. Should such a transfer become necessary in the future, it will only occur on the basis of an adequacy decision of the European Commission or of appropriate safeguards under Articles 44 et seq. GDPR, and this notice will be updated accordingly.

Automated decision-making and profiling

The Controller carries out no profiling and applies no automated decision-making producing legal effects or similarly significantly affecting the data subject, within the meaning of Article 22 GDPR.

Security of processing

The website is only reachable over an encrypted HTTPS connection. The Controller implements technical and organisational measures appropriate under Article 32 GDPR to protect data against destruction, loss, unauthorised access or unlawful processing, including access control, systems updating and regular backups.

Your rights (Articles 15-22 GDPR)

You may exercise the following rights at any time:

  • Access (Art. 15): obtain confirmation as to whether your data are being processed and receive a copy together with all the prescribed information.
  • Rectification (Art. 16): have inaccurate data corrected or incomplete data completed.
  • Erasure (Art. 17): obtain the deletion of your data, where no retention obligation applies.
  • Restriction (Art. 18): ask for processing to be suspended in the cases provided for by law.
  • Portability (Art. 20): receive, in a structured, commonly used and machine-readable format, the data you provided on the basis of consent or a contract, and have them transmitted to another controller.
  • Objection (Art. 21): object at any time, on grounds relating to your particular situation, to processing based on legitimate interest.
  • Not to be subject to automated decisions (Art. 22), which does not apply here.

How to exercise your rights

Simply send a request, in any form, to mital@mital.com or by post to Mital Srl — Via Cherso, 21 — 31045 Motta di Livenza (TV), Italy, stating the right you wish to exercise. The Controller may ask for information needed to verify your identity. The reply is free of charge and is provided within one month of receipt of the request; this may be extended by a further two months where the request is particularly complex, in which case you will be informed within the first month (Art. 12 GDPR).

Withdrawing consent

Where processing is based on consent, you may withdraw it at any time, as easily as it was given, without having to give reasons and at no cost (Art. 7.3 GDPR). For the newsletter, use the unsubscribe link included in our messages or write to mital@mital.com. Withdrawal does not affect the lawfulness of processing carried out before it.

Complaint to the supervisory authority

If you believe that the processing of your data infringes data protection law, you may lodge a complaint with the supervisory authority of the country where you live or work, or where the alleged infringement took place (Art. 77 GDPR). In Italy:

Authority Garante per la protezione dei dati personali (Italian Data Protection Authority)
Address Piazza Venezia 11 — 00187 Rome, Italy
Phone +39 06 696771
Email garante@gpdp.it
Certified email protocollo@pec.gpdp.it
Website www.garanteprivacy.it

Your right to an effective judicial remedy under Article 79 GDPR remains unaffected.

Children

This website addresses professionals, dealers and adult customers and is not intended for children under 14. The Controller does not knowingly collect personal data from children; should it become aware of such data, it will delete them without delay.

Changes to this notice

This notice may be updated to reflect changes in the law or in the service offered. The version published on this page is the one in force and the date below indicates its latest revision. Newsletter subscribers will be informed of any substantial change.

Last updated: 2 September 2026