STEP Engineering S.R.L. Privacy and Cookie Policy

1. General Information

  • Company name: STEP Engineering S.R.L.
  • Head office: Via Castellana 199/A, Resana, Treviso, Italia
  • Owner: Marco Salvador
  • E-mail: info@step-lab.com
  • Phone number: +39 0423 1999 391

2. Collection of Personal Data

Among the Personal Data collected by this Website, either independently or through third parties, are: Usage Data; Tracking Tool; email; first name; last name; profession; province; country; city; company name; Universal Unique Identifier (UUID); Data disclosed during the use of the service; unique identifiers of advertising devices (Google Advertiser ID or IDFA identifier, for example); telephone number; various types of Data.

Full details on each type of Personal Data collected are provided in the relevant sections of this privacy policy or through specific information texts displayed prior to the collection of the Data.
Personal Data may be freely provided by the User or, in the case of User Data, automatically collected during the use of this Web Site.
Unless otherwise specified, all Data requested by this Website are mandatory. If the User refuses to communicate them, it may be impossible for this Website to provide the Service. In cases where this Website indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Controller.
Any use of Cookies – or of other tracking tools – by this Website or by the owners of third party services used by this Website is for the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website.

3. Method and place of processing of collected Data

The Owner takes appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
Processing is carried out by means of computer and/or telematic tools, with organisational methods and logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other subjects involved in the organisation of this Web Site (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Owner, may have access to the Data. The updated list of Data Processors can always be requested from the Owner.

The Data are processed at the premises of the Owner and at any other place where the parties involved in the processing are located. For further information, please contact the owner.
The User’s Personal Data may be transferred to a country other than the country where the User is located. To obtain further information on where the processing takes place, the User may refer to the section on Personal Data Processing Details.

Unless otherwise stated in this document, Personal Data is processed and kept for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligation or on the basis of Users’ consent.

4. Purposes of Data Processing

The User’s Data are collected to enable the Controller to provide the Service, to comply with legal obligations, to respond to requests or enforcement actions, to protect its rights and interests (or those of Users or third parties), to detect any malicious or fraudulent activities, as well as for the following purposes: Displaying content from external platforms, Tag Management, Contact Management and Message Sending, Contacting the User, Gathering of privacy preferences, Statistics, Remarketing and behavioral targeting, Hosting and backend infrastructure and Registration and Authentication.

In order to obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User may refer to the section ‘Personal Data Processing Details’.

5. Details of the processing of Personal Data

Contacting the User

  • Mailing list or newsletter (this website)

By registering to the mailing list or newsletter, the User’s email address is automatically included in a list of contacts to whom email messages containing information, including of a commercial and promotional nature, relating to this Website may be sent. The User’s e-mail address may also be added to this list as a result of registering on this Website or after making a purchase.

Personal data processed: city; surname; email; country; name; profession; province; company name.

Legal basis for processing: Consent.

  • Contact form (this Website)

The User, by filling in the contact form with his or her Data, consents to their use to respond to requests for information, quotations, or any other nature indicated in the header of the form.

Personal Data processed: city; surname; email; country; name; phone number; profession; province; company name; various types of Data.

Legal basis for processing: Contract.

Period of Data Storage: Storage of data for as long as necessary for statistical purposes.

Managing contacts and sending messages

This type of service makes it possible to manage a database of email contacts, telephone contacts or contacts of any other kind used to communicate with the User.
These services may also collect data on the date and time the User views the messages, as well as the User’s interaction with them, such as information on clicks on links in the messages.

  • Brevo (Sendinblue Inc)

Brevo is an address management and mailing service provided by Sendinblue Inc.

Personal data processed: email.

Tag Management

This type of service is functional for the centralised management of tags or scripts used on this website.
The use of such services entails the flow of User Data through them and, where applicable, their retention.

  • Google Tag Manager

Google Tag Manager is a tag management service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data.

Personal data processed: Usage Data.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

Hosting and backend infrastructure

These types of services have the function of hosting data and files that allow this Website to function, enable its distribution and provide a ready-to-use infrastructure to deliver specific functionalities of this Website.

Some of the services listed below, if any, may operate on geographically dispersed servers, making it difficult to determine the actual location where Personal Data is stored.

  • Register

Register is a hosting and backend service provided by Register S.p.A.

Personal data processed: Usage Data.

Collecting privacy preferences

This type of service allows this Website to collect and save Users’ preferences regarding the collection, use and processing of their personal information, as required by applicable privacy legislation.

Remarketing e behavioral targeting

This type of service allows this Website and its partners to communicate, optimise and serve advertisements based on the User’s past use of this Website.
This activity is facilitated by the tracking of Usage Data and the use of Tracking Tools to collect information that is then transferred to partners handling remarketing and behavioral targeting activities.
Some services offer a remarketing option based on email address lists.
Generally, services of this type offer the possibility of deactivating such tracking. In addition to any opt-out function provided by any of the services listed in this document, the User can read more about how to deactivate interest-based advertisements in the section ‘How to deactivate interest-based advertising’ in this document.

  • Google Ads Remarketing

Remarketing Google Ads is a remarketing and behavioral targeting service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the activity of this Website with the Google Ads advertising network and the DoubleClick Cookie.

For an understanding of Google’s use of data, please refer to the Google Partner Policy.

Users can opt out of Google’s Tracking Tools for ad customisation by visiting Google’s Ad Settings.

Personal data processed: Usage Data; Tracking Tool.

Legal basis for processing: Consent.

Place of processing: United States – Privacy PolicyOpt Out; Ireland – Privacy PolicyOpt Out.

  • Remarketing with Google Analytics

Remarketing with Google Analytics is a remarketing and behavioral targeting service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the tracking activity performed by Google Analytics and its Tracking Tools with the Google Ads advertising network and the Doubleclick cookie.

Personal data processed: Usage Data; Tracking Tool.

Legal basis for processing: Consent.

Place of processing: United States – Privacy PolicyOpt Out; Ireland – Privacy PolicyOpt OutOpt Out.

  • Facebook Remarketing

Facebook Remarketing is a remarketing and behavioral targeting service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the activity of this Website with the Facebook advertising network.

Personal data processed: Usage Data; Tracking Tool.

Legal basis for processing: Consent.

Place of processing: United States – Privacy PolicyOpt Out; Ireland – Privacy PolicyOpt Out.

Statistics

The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User’s behaviour.

  • Google Analytics with anonymous IP

Google Analytics is a web analytics service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, (‘Google’). Google will use the Personal Data collected for the purpose of evaluating your use of this website, compiling reports and sharing them with other services provided by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
This Google Analytics integration anonymises your IP address. Anonymisation works by shortening the IP address of users within the borders of the member states of the European Union or other countries that are party to the Agreement on the European Economic Area. Only in exceptional cases will the IP address be sent to Google’s servers and shortened within the United States.

Personal data processed: Usage Data; Tracking Tool.

Legal basis for processing: Contract.

Place of processing: United States – Privacy PolicyOpt Out; Ireland – Privacy PolicyOpt Out.

  • Monitoring Google Ads conversions

Google Ads conversion tracking is a statistical service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the data from the Google Ads ad network with the actions performed within this Website.

Personal data processed: Usage Data; Tracking Tool.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

  • Google Analytics demographics and interest reports

Google Analytics Demographic and Interest Data Reports is an advertising report generation feature that makes Demographic and Interest Data available within Google Analytics for this Website (Demographic Data means Age and Gender Data).

Users may opt out of Google cookies by visiting Google’s [Impostazioni annunci](https://adssettings.google.com/authenticated).

Personal Data Processed: Unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example); Tracking Tool.

Place of processing: United States – Privacy PolicyOpt Out; Ireland – Privacy PolicyOpt Out.

  • Facebook Ads conversion monitoring (Facebook pixel)

Facebook Ads conversion tracking (Facebook pixel) is a statistics service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the processing of the Data, which links data from the Meta ad network with actions taken within this Website. The Facebook pixel monitors conversions that can be attributed to Facebook, Instagram and Audience Network advertisements.

Personal data processed: Usage Data; Tracking Tool.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

  • Advertising report generation functionality in Google Analytics

Google Analytics on this website has activated the advertising report generation functionality, which collects additional information from the DoubleClick cookie (web activity) and the advertising IDs of the device (application activity). This allows the Data Controller to analyse specific Data related to Users’ behaviour and interests (Traffic Data and Ad Interaction Data by Users) and, if enabled, Demographic Data (age and gender information).

Users may opt out of Google cookies by visiting Google’s [Impostazioni annunci](https://adssettings.google.com/authenticated).

Personal Data processed: unique identifiers of advertising devices (Google Advertiser ID or IDFA identifier, for example); Tracking Tool; various types of Data as specified by the privacy policy of the service.

Place of processing: United States – Privacy PolicyOpt Out; Ireland – Privacy PolicyOpt Out.

  • Meta Events Manager (Meta Platforms Ireland Limited)

Meta Events Manager is a statistics service provided by Meta Platforms Ireland Limited. By integrating the Meta pixel, Meta Events Manager can give the Owner information about traffic and interactions on this website.

Personal data processed: Usage Data; Tracking Tools.

Place of processing: Ireland – Privacy Policy.

  • Google Analytics 4 (Google Ireland Limited)

Google Analytics is a statistics service provided by Google Ireland Limited (‘Google’). Google will use the Personal Data collected for the purpose of evaluating your use of this website, compiling reports and sharing them with other services provided by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data are recorded in any data centre or server. To find out more, you can consult Google’s official documentation.

Personal data processed: Usage Data.

Place of processing: Ireland – Privacy PolicyOpt Out.

Displaying content from external platforms

This type of service makes it possible to display content hosted on external platforms directly from the pages of this Website and to interact with them.
This type of service may still collect data on web traffic related to the pages where the service is installed, even when users do not use it.

  • Google Fonts

Google Fonts is a font style display service operated by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which enables this Website to integrate such content within its pages.

Personal data processed: Usage Data; Tracking Tool.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

  • YouTube

YouTube is a video content display service operated by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which enables this Website to integrate such content within its pages.
This widget is set up so that YouTube does not save information and cookies about Users on this Website, unless they play the video.

Personal data processed: Usage Data; Universal Unique Identifier (UUID); Tracking Tool.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

  • Vimeo

Vimeo is a video content viewing service provided by Vimeo, LLC that allows this Application to embed content of this type in its pages.
Personal data processed: Tracker; Usage Data.

Place of processing: United States – Privacy Policy.

  • Google Maps

Google Maps is a map display service operated by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which enables this Website to integrate such content within its pages.

Personal data processed: Usage Data; Tracking Tool.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

This Web Site makes use of Tracking Tools.

The Owner processes Personal Data relating to the User if one of the following conditions is met:

  • the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Controller may be authorised to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opts-out”) to such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • the processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
  • processing is necessary to comply with a legal obligation to which the Owner is subject;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
  • processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.

However, it is always possible to ask the Controller to clarify the concrete legal basis of each processing operation and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.

Unless otherwise stated in this document, Personal Data is processed and kept for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligation or on the basis of Users’ consent.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be retained until the performance of that contract is completed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

When the processing is based on the User’s consent, the Controller may keep the Personal Data longer until such consent is revoked. In addition, the Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the storage period, the Personal Data will be deleted. Therefore, upon expiry of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.

User Rights

Users may exercise certain rights with regard to the Data processed by the Data Controller.

In particular, within the limits of the law, the User has the right to

  • withdraw consent at any time. The User may revoke his or her previously expressed consent to the processing of his or her Personal Data.
  • oppose the processing of their Data. The User may object to the processing of his or her Data when it takes place on a legal basis other than consent.
  • access to their Data. The User has the right to obtain information on the Data processed by the Owner, on certain aspects of the processing and to receive a copy of the Data processed.
  • check and request rectification. The User may check the correctness of its Data and request that it be updated or corrected.
  • obtain restriction of processing. The User may request the restriction of the processing of its Data. In this case, the Owner will not process the Data for any purpose other than its storage.
  • obtain the deletion or removal of their Personal Data. The User may request the deletion of his/her Data by the Owner.
  • receive their Data or have them transferred to another data controller. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another data controller.
  • file a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.

Users have the right to obtain information about the legal basis for the transfer of Data abroad, including to any international organisation governed by international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Data Controller to protect their Data.

Where Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.

Users are informed that if their Data are processed for direct marketing purposes, they may object to the processing at any time, free of charge and without giving any reasons. If Users object to processing for direct marketing purposes, Personal Data are no longer processed for such purposes. To find out whether the Owner processes Data for direct marketing purposes, Users may refer to the respective sections of this document.

To exercise their rights, Users may address a request to the Owner’s contact details indicated in this document. The request may be filed free of charge and the Controller will reply as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectification, deletion or restriction of processing shall be communicated by the Controller to each of the recipients, if any, to whom the Personal Data have been transmitted, unless this proves impossible or involves a disproportionate effort. The Controller shall inform the User of these recipients if he so requests.

Further information on processing

The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages of such proceedings in order to defend against abuses in the use of this Web Site or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

At the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

For operation and maintenance purposes, this Website and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User’s IP address.

Further information in connection with the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Please therefore consult this page frequently, referring to the date of last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Controller will collect the User’s consent again, if necessary.

Personal Data (or Data)

Personal data is any information that, directly or indirectly, even in conjunction with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This is the information collected automatically through this Website (including by third party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User who connects with this Website, URI (Uniform Resource Identifier) notation addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time connotations of the visit (e.g. the time spent on each page) and details of the itinerary followed by the User. ), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.

User

The individual using this Website who, unless otherwise specified, is the Data Subject.

Interested

The natural person to whom the Personal Data refer.

Processor (or Manager)

The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Controller, as set out in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body which, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or this Application)

The hardware or software tool by which Users’ Personal Data are collected and processed.

Service

The Service provided by this Website as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.

Cookies

Cookies are tracking tools that consist of small portions of data stored within the User’s browser.

Tracking Tool

Tracking Tool means any technology – e.g. cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting – that allows Users to be tracked, for example by collecting or storing information on the User’s device.


Legal references

Unless otherwise specified, this privacy policy relates exclusively to this Website.