Privacy Policy
This notice explains how FB Digital Solutions S.r.l. processes the personal data of people who visit fbdigitalsolutions.it and of people who use the contact and support forms. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Data controller
FB Digital Solutions S.r.l., registered office at Piazza Diodoro Siculo 19/20, 90141 Palermo (PA), Italy, VAT number 07339320827.
For any matter concerning personal data you may write to info@fbdigitalsolutions.it or to the certified address fbdigitalsolutions@pec.it.
The controller has not appointed a Data Protection Officer, as the conditions set out in Article 37 GDPR do not apply.
What data is processed
Data you provide
When you fill in the Request a project form you give us: first name, last name, company, role (optional), email address, telephone number, city, and the information you describe about the project — sector, type of solution, installation environment, quantity, available space, viewing distance, project stage, indicative budget, timeline, contact preference and the free text of your message.
When you fill in the Support request form you give us: name, company, email address, telephone number, product type, installation reference (optional), a description of the problem and an urgency level.
Optional fields are marked as such in the form. You are not asked for any data belonging to special categories (Article 9 GDPR) and we ask you not to include any in the free-text field.
Data collected automatically
For the technical operation of the site alone, the systems that serve it record the data every browser transmits when it requests a page: IP address, date and time of the request, the page requested, browser type and operating system. This data is retained for short periods by the providers listed below and is used to deliver the service, keep it secure and diagnose faults.
The anti-spam system protecting the forms analyses, at the moment of submission, the IP address and certain technical characteristics of the browser in order to establish whether the request comes from a person or from an automated program. This analysis produces no profiling and is not used for any purpose other than protecting the forms.
What this site does not do
This site uses no cookies, neither its own nor third-party ones, neither technical nor profiling. No analytics, audience measurement or advertising tools are active. No profiling and no automated decision-making within the meaning of Article 22 GDPR takes place.
The only information stored in your browser is the record of the choice you make in the tracking-technologies banner, saved in the browser's local storage under the key fbds.consent. It is never transmitted to any server. Details are in the Cookie Policy.
Why we process this data, and on what legal basis
- Responding to your project, quotation or information request — pre-contractual measures taken at your request, Art. 6(1)(b) GDPR.
- Handling a support request concerning a product or an installation — performance of a contract or pre-contractual measures, Art. 6(1)(b) GDPR.
- Sending you the automatic acknowledgement that your request was received — pre-contractual measures, Art. 6(1)(b) GDPR.
- Protecting the forms against automated submissions and abuse — legitimate interest in keeping the service working and secure, Art. 6(1)(f) GDPR.
- Keeping the site secure and diagnosing faults — legitimate interest, Art. 6(1)(f) GDPR.
- Sending you commercial communications, if you expressly asked for them — consent, withdrawable at any time, Art. 6(1)(a) GDPR.
- Complying with legal, accounting and tax obligations — legal obligation, Art. 6(1)(c) GDPR.
Consent to commercial communications is optional, separate and never pre-selected: you can request a project without giving it, and withdraw it later without this affecting how your request is handled.
Is providing data mandatory?
No, but some data is necessary. Without the fields marked as required we cannot take on your request or reply to you: that is the only consequence of not providing them.
Who the data is disclosed to
Data is not disseminated and is never sold, transferred or disclosed to third parties for marketing purposes.
It is accessed by authorised staff of the controller who handle commercial relations and support, and by the suppliers who provide the technical services the site needs, appointed as processors under Article 28 GDPR:
- Vercel Inc. — hosting of the site and of the functions that receive the forms. Processing in the Frankfurt region; supplier established in the United States.
- Keliweb S.r.l. — mailbox and SMTP server through which requests are delivered and retained. Italy.
- Cloudflare, Inc. — anti-spam system protecting the forms (Turnstile). Distributed network; supplier established in the United States.
- Sanity AS — content management system for the site's editorial content. Norway (EEA).
The content of requests sent through the forms is delivered by email and retained in the company mailbox hosted by Keliweb S.r.l.
Data may also be disclosed to public authorities where required by law.
Transfers to third countries
Some of the suppliers listed above are established in the United States. For such transfers the controller relies on the safeguards provided for in Chapter V GDPR, such as the standard contractual clauses adopted by the European Commission or the supplier's adherence to the EU–US Data Privacy Framework.
You may request a copy of the safeguards adopted by writing to the addresses given in this notice.
How long we keep the data
- Project and quotation requests that do not lead to a relationship — 24 months from the last contact.
- Support requests — 24 months from the closure of the report.
- Data relating to contractual relationships — for the duration of the relationship and for the following 10 years, under civil and tax obligations.
- Consent to commercial communications — until withdrawn.
- Technical logs held by hosting providers — according to each provider's retention periods, which are short.
At the end of the period, data is deleted or anonymised.
Your rights
You may at any time ask the controller:
- to access your personal data and obtain a copy of it (Art. 15);
- to rectify inaccurate data or complete it (Art. 16);
- to erase your data, in the cases provided for (Art. 17);
- to restrict processing (Art. 18);
- to receive your data in a structured, machine-readable format, or to have it transmitted to another controller (portability, Art. 20);
- to object to processing based on legitimate interest (Art. 21);
- to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)).
To exercise these rights write to info@fbdigitalsolutions.it or to the certified address fbdigitalsolutions@pec.it. The controller replies within one month of the request, extendable by two months in particularly complex cases.
If you believe the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory authority of the country where you reside, or to bring proceedings before a court.
Links to external sites
The site may contain links to sites operated by third parties. The controller is not responsible for the data processing those sites carry out: please read their own notices.
Changes to this notice
This notice may be updated to reflect changes to the site, to the services used or to the applicable law. The version in force is always the one published at this address, with the date of last update shown at the top of the document.