Privacy Notice on the Processing of Personal Data
INTRODUCTION
Pursuant to Articles 12 and 13 of Regulation (EU) 2016/679 / General Data Protection Regulation (GDPR), and in general compliance with the transparency principle established therein, Alperia S.p.A. (hereinafter also referred to as the “Company” or “Alperia”) provides the following information regarding the processing of Personal Data (i.e. any information relating to an identified or identifiable natural person: the “Data Subject”) of newsletter subscribers (hereinafter also referred to as the “Subscriber”).
- DATA CONTROLLER
The data controller (i.e. the entity that determines the purposes and means of the processing of personal data, the “Data Controller” or “Controller”) is Alperia S.p.A., with registered office in Bolzano, Via Dodiciville 8, I-39100, Tax Code and VAT Number 02858310218, Certified Email (PEC):
For matters specifically relating to the protection of Personal Data, including the exercise of the rights referred to in section 9 below, please contact:
to which any requests should be sent.
- CONTACT DETAILS OF THE DATA PROTECTION OFFICER (DPO)
Please note that the Data Controller has appointed, pursuant to Article 37 GDPR, a Data Protection Officer (“DPO”), who may be contacted through the following channels:
- Data Protection Officer (DPO) c/o Alperia S.p.A., Via Dodiciville 8, 39100 Bolzano
- Email:
This email address is being protected from spambots. You need JavaScript enabled to view it.
- PURPOSES OF PROCESSING
Personal data may be processed for the following purposes:
- allowing users to browse the Website and use all Website functionalities, ensuring the proper functioning of the Website, and enabling a better use of content and services, including through registration and/or access to restricted areas;
- interaction between Website users and Alperia Group companies (newsletter, responses to questions submitted by the Data Subject through voluntarily provided data, appointment bookings);
- carrying out security checks required by law;
- ascertaining liability in the event of cybercrimes against the Website;
- detecting, preventing, mitigating and investigating fraudulent or unlawful activities related to the services provided through the Website;
- collecting aggregated and anonymous data relating to Website usage through analytics cookies, which are equivalent to technical cookies;
- (subject to optional consent) collecting data relating to the use of the Website by individual users through analytics and statistical cookies;
- (subject to optional consent) sending, directly or indirectly, advertising messages aligned with users’ preferences and browsing activities through profiling and third-party cookies.
For further information concerning cookies, please refer to the Cookie Policy.
- TYPES OF DATA PROCESSED
Alperia will process Personal Data provided by the user and/or lawfully collected. In particular, the following categories of Personal Data may be processed:
- Browsing Data: the IT and telematic systems and software procedures used for the operation and use of the Website made available by Alperia acquire certain data, such as date and time of access, pages visited, Internet Service Provider name, Internet Protocol (IP) address through which access to the Internet is obtained, the Internet address from which the user accesses the Website (URL), etc. The transmission of such data is inherent in the use of web communication protocols or is useful for the management and optimisation of data and email transmission systems.
- Data collected during browsing through cookies and/or other tracking technologies used on the Website: for further information, please refer to the https://www.expea.it/en/cookie-policyCookie Policy.
- LEGAL BASIS FOR PROCESSING AND MANDATORY NATURE OF DATA PROVISION
The Controller will process the user’s Personal Data where one or more of the legal bases provided by the GDPR apply:
- following the user’s freely given, specific, informed and unambiguous consent: for third-party cookies, profiling cookies, and non-aggregated analytics and statistical cookies;
- for the performance of a contract to which the user is a party or in order to take pre-contractual steps at the request of the user: for the use of Website functionalities, to ensure proper Website operation, to respond to questions/requests from the Data Subject, and for customer experience purposes;
- for compliance with a legal obligation to which the Controller is subject: for legally required security checks and for establishing liability in the event of alleged cybercrimes against the Website;
- for the purposes of the Controller’s legitimate interests: to ensure proper Website operation and security, to detect, prevent, mitigate and investigate fraudulent or unlawful activities relating to services provided through the Website, to improve and measure customer satisfaction and customer experience, and to monitor the quality of services provided.
The provision of Personal Data by the user shall be:
- necessary in all cases where processing is based on a legal obligation, is required for the performance of a contract, or for pre-contractual measures (for example, contacts relating to the purchase of museum tickets). In the event of refusal, the Controller will be unable to process the user’s requests or provide the requested services;
- voluntary for all other purposes.
- DATA COLLECTION, PROCESSING METHODS AND RETENTION PERIOD
Data are collected from the Data Subject, meaning data provided by the user and data resulting from the use of the Website.
The Personal Data collected will be processed, using IT and telematic tools and, where appropriate, manually, for the purposes specified above. Processing of Personal Data means any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, extraction, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
The IT systems and software used to operate the Website collect certain Personal Data whose transmission is inherent in the use of Internet communication protocols (e.g. IP addresses or domain names of users’ computers, URI – Uniform Resource Identifier – addresses of requested resources, time of request, method used to submit the request to the server, size of the file received in response, numerical code indicating the server response status – success, error, etc. – and other parameters relating to the user’s operating system and IT environment). Although such information is not collected in order to be associated with identified individuals, by its nature it may, through processing and association with data held by third parties, allow users to be identified.
Such data are used solely to obtain statistical information, not associated with any identifying data of the user, relating to the use of the Website and to verify its proper functioning, and are deleted after 30 days.
Furthermore, cookies are used to collect data in order to manage and improve the browsing experience:
- technical cookies strictly necessary for the functioning of the Website or to allow users to make better use of its content and services;
- analytics/statistical cookies that allow data relating to Website usage to be collected;
- profiling and third-party cookies used to send, directly or indirectly, advertising messages in line with users’ preferences and browsing activities.
For further information, including data retention periods, please refer to the Cookie Policy.
- DATA DISCLOSURE
The data collected and processed may be disclosed, exclusively for the purposes specified above, to:
- all entities entitled by law, regulations or authorisations to access such data;
- employees, collaborators and suppliers of the Controller, within the scope of their duties and/or contractual obligations relating to the performance of the contractual relationship with Data Subjects; suppliers may include, for example, other companies of the Alperia Group providing intercompany services to the Controller, as well as consultants, IT service providers and other entities carrying out activities on behalf of the Controller under cooperation agreements;
- companies appointed to carry out activities related to the specific processing operations.
The above-mentioned parties shall process the data as independent Data Controllers, Data Processors, or Authorised Persons specifically appointed for that purpose.
Appropriate instructions are provided by the Controller to any appointed Data Processors and Authorised Persons in order to ensure the adoption of adequate security measures aimed at protecting the confidentiality, security and integrity of the data.
- PLACE OF DATA PROCESSING
Processing activities take place within the European Economic Area (EEA), namely the EU plus Norway, Liechtenstein and Iceland, as well as by certain sub-processors of Brevo operating in compliance with Chapter V of the GDPR, namely: Canada, based on a European Commission adequacy decision; the United States, based on the EU-US Data Privacy Framework, Standard Contractual Clauses and supplementary measures; India, based on Standard Contractual Clauses and supplementary measures.
Apart from the cases described above, there is no intention to transfer data to countries outside the EEA or to international organisations.
- RIGHTS OF THE DATA SUBJECT
The GDPR grants Data Subjects a number of rights with regard to their Personal Data. Reference should therefore be made to Articles 15–21 GDPR (the summary below is for information purposes only).
In relation to the Personal Data processed, the Data Subject has the right to:
- access their Personal Data;
- request the rectification of their Personal Data;
- withdraw consent (where processing is based on consent, the Data Subject may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal);
- request erasure of Personal Data (the so-called “right to be forgotten”);
- obtain restriction of processing;
- object to processing;
- receive their Personal Data in a structured, commonly used and machine-readable format;
- not be subject to a decision based solely on automated processing.
The Data Subject always has the right to lodge a complaint with the Data Protection Authority. The Italian Data Protection Authority may be contacted via the contact details available on its website: www.garanteprivacy.it
To exercise their rights, withdraw consent provided for the purposes indicated in section 3 above, or obtain further information relating to Personal Data, the Data Subject may send a communication, indicating the subject matter of the request in the email subject line, to:
or to the other contact details of the Data Controller and/or the Data Protection Officer (DPO) indicated above.
The updated version of this Privacy Notice is available on alperia.eu.
Updated October 2026