COOKIE POLICY
TECNOGEN S.p.A. (Tax Code and VAT No. 01126350337), with registered office at Strada per Ponteriglio, 25 – 29010 Pontenure (Piacenza) – Italy, in the person of its legal representative pro tempore (hereinafter also “TECNOGEN” and/or “Data Controller”), in its capacity as Data Controller pursuant to Articles 4 No. 7) and 24 of EU Regulation No. 2016/679 (GDPR),
HEREBY SETS OUT
below, the cookie policy (the “Policy”) applicable solely to this website https://tecnogen.com (the “Site”).
1. LEGAL FRAMEWORK
1.1. The Policy is based on the following EU and/or national regulatory provisions (of first and/or second level): (i) Directive No. 2002/58/EC of 12.7.2012 (so-called ePrivacy Directive), as amended by Directive No. 2009/136/EC; (ii) Art. 122 of the amended Legislative Decree No. 196/2003 (Italian Privacy Code), which transposed the ePrivacy Directive into the national legal system; (iii) GDPR: Articles 4 No. 11), 7, 12, 13, 25 and 95 (in addition, in particular, to Recitals No. 30, 32 and 173); (iv) Guidelines No. 5/2020 adopted on 4.5.2020 by the EDPB, replacing the Guidelines of 10.4.2018 issued by the Art. 29 WP; (v) Decision No. 231 of 10.6.2021 [web doc. No. 9677876] issued by the Italian Data Protection Authority (Garante Privacy); (vi) Recommendation No. 2/2001 of the Art. 29 WP; (vii) Opinion No. 2/2010 of the Art. 29 WP; (viii) Opinion No. 4/2012 of the Art. 29 WP; (ix) Guidelines No. 8/2020 of the EDPB; (x) Decisions No. 224 of 9.6.2022 [web doc. No. 9782890], No. 243 of 7.7.2022 [web doc. No. 9806053] and No. 254 of 21.7.2022 [web doc. No. 9808698] issued by the Garante Privacy.
2. COOKIES AND OTHER TRACKING TOOLS: DEFINITION AND CLASSIFICATION
2.1. “Cookies“1 are, as a rule, strings of text that a website (the “publisher” or “first party”) visited by the user, or a different website (a “third party”), places and stores, directly (in the case of the first-party website) or indirectly (through the latter, in the case of a third-party website), within a terminal device available to the user: in this regard, the Garante Privacy has specified that the information encoded in cookies may include both personal data pursuant to Art. 4 No. 1) of the GDPR (e.g. IP address; username; e-mail address; unique identifier) and non-personal data pursuant to Art. 3 No. 1) of EU Regulation No. 1807/2018 (e.g. language; type of device used).
Alongside (or beyond) these, there may exist (and therefore be used) “other tracking tools“, which can be divided into “active” tools (which have almost the same characteristics as cookies) and “passive” tools (e.g. fingerprinting).
2.2. Beyond the intrinsic characteristics described above, cookies (and other tracking tools) may have different features from a temporal standpoint (and may therefore be considered “session”2 or “persistent”3 cookies, depending on their duration), from a subjective standpoint (depending on whether the publisher acts independently or on behalf of a “third party”) and, finally (but in particular), based on the processing purpose pursued, so that they can be divided into two different (macro) categories:
- “technical” cookies, used for the sole purpose of “carrying out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for the provider of an information society service explicitly requested by the contracting party or user to provide that service” (Art. 122 paragraph 1) of the Italian Privacy Code). In this regard, the Garante Privacy pointed out, in Decision No. 231 of 10.6.2021 (in continuity with its previous 2014 Decision on the matter), that “analytics cookies“4 may well fall within the scope of “technical” cookies (or other tracking tools) (and may therefore be used without the prior acquisition of the data subject’s consent), provided that certain conditions are met, aimed at precluding the possibility of directly identifying the data subject (single out)5;
- “profiling/marketing” cookies (so-called non-technical), used to attribute specific actions or recurring behavioural patterns in the use of the functions offered to specific, identified or identifiable individuals, in order to group the various profiles into homogeneous clusters of different sizes, so that the Data Controller can, among other things, tailor the provision of the service in an increasingly personalised manner beyond what is strictly necessary for the provision of the service, as well as send targeted advertising messages (i.e. in line with the preferences expressed by the user while browsing the web).
3. COOKIES INSTALLED ON THE SITE
3.1. The following types of cookies have been installed (or may be installed, subject to obtaining the user’s specific consent) on the Site:
| Name | Type | Function | First/Third party | Duration |
|---|---|---|---|---|
| __wpdm_client | Technical | Used by the WordPress Download Manager plugin to track downloads and manage user sessions for download access control purposes. | First party | Session |
| _ga – Google Analytics | Technical/Analytics | Used to collect a unique ID in order to generate statistical data on visitor behaviour on the website. | First party | 13 months |
| _ga_7B8GDDH25N | Technical/Analytics | Used to collect a unique ID in order to generate statistical data on visitor behaviour on the website. | First party | 13 months |
| iub_cs-33200867 | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | 11 months |
| iub_cs-57645335 | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | 11 months |
| iub_cs-76733308 | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | 12 months |
| iub_cs-88975235 | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | 11 months |
| iub_cs-75620206 | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | 11 months |
| iub_cs_s1 | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | 10 months |
| iub_previous_preference_id | Technical/Functional | Stores the cookie consent preferences expressed by the user (e.g. acceptance or refusal) while browsing the site. | First party | Approx. 1 year |
| __Secure-ROLLOUT_TOKEN – YouTube | Profiling/Tracking | Used to track user interaction with embedded content. | Third party | 13 months |
| __Secure-YNID – YouTube | Profiling/Tracking | Stores information such as preferred page configuration and playback preferences, e.g. explicit choices regarding autoplay, content shuffle and player size. | Third party | 13 months |
| VISITOR_INFO1_LIVE – YouTube | Tracking | Estimates the user’s connection speed on pages with embedded YouTube videos. | Third party | 6 months |
| VISITOR_PRIVACY_METADATA – YouTube | Tracking | Mainly used to store the user’s cookie consent status for videos embedded on third-party websites. | Third party | 6 months |
| YSC – YouTube | Technical/Tracking | Tracks user actions and stores their preferences while browsing. | Third party | Session |
| yt-icons-last-purged – Local Storage YouTube | Tracking | Required for the implementation and functionality of YouTube video content on the site. | Third party | 1 year |
| rl_anonymous_id | Analytics | Collects statistical data on anonymous user interactions, optimising the browsing experience and supporting marketing activities, where applicable. | First party | 11 months |
| rl_page_init_referrer | Tracking | Records how a website was reached (the referring page). It is used to enable referral commissions, optimise the browsing experience and target personalised advertisements. | First party | 11 months |
4. BROWSER SETTINGS
4.1. TECNOGEN highlights that the user may delete and block the operation of the cookies described in Art. 3 above at any time using the appropriate settings available within the browser used: in this regard, TECNOGEN adds that, should the user decide to disable the technical cookies referred to in Art. 2.2. point i), the quality and speed of the services and functions offered and made available on the Site may deteriorate.
Information on how to manage cookies in some of the most popular browsers can be found at the following web pages:
In addition, Tecnogen lists below the main web pages of the third parties described in Art. 3 above:
5. RIGHTS OF THE DATA SUBJECT
5.1. In relation to the user’s personal data, TECNOGEN informs that the relevant data subject pursuant to Art. 4 No. 1) of the GDPR may exercise the following rights, possibly subject to the limitations provided for by Articles 2-undecies and 2-duodecies of the Italian Privacy Code:
- right of access pursuant to Art. 15 of the GDPR: the right to obtain confirmation as to whether or not personal data concerning the data subject are being processed, as well as the information referred to in Art. 15 of the GDPR (e.g. purposes of processing, retention period);
- right to rectification pursuant to Art. 16 of the GDPR: the right to correct, update or supplement personal data;
- right to erasure pursuant to Art. 17 of the GDPR: the right to obtain the erasure, destruction or anonymisation of personal data, where the conditions listed in that article are met;
- right to restriction of processing pursuant to Art. 18 of the GDPR: a right of a markedly precautionary nature, aimed at obtaining the restriction of processing where the circumstances governed by Art. 18 apply;
- right to data portability pursuant to Art. 20 of the GDPR: the right to receive the personal data provided to TECNOGEN in a structured, commonly used and machine-readable format (and, where requested, to have them transmitted directly to another Data Controller), where the specific conditions set out in that article apply (e.g. legal basis of consent and/or performance of a contract; personal data provided by the data subject);
- right to object pursuant to Art. 21 of the GDPR: the right to obtain the permanent cessation of a specific processing of personal data;
- right to lodge a complaint with the Supervisory Authority (i.e. the Italian Data Protection Authority, “Garante Privacy”) pursuant to Art. 77 of the GDPR: the right to lodge a complaint where you believe that the processing in question infringes national and EU legislation on the protection of personal data.
5.2. In addition to the rights described in Art. 5.1. above, TECNOGEN specifies that, in relation to the data subject’s personal data, they may, where possible and relevant, exercise, on the one hand, the (sub-)right provided for by Art. 19 of the GDPR (“The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it”), to be considered connected and linked to the exercise of one or more of the rights governed by Articles 16, 17 and 18 of the GDPR; on the other hand, TECNOGEN specifies that, in relation to the data subject’s personal data, they may, where possible and relevant, exercise the right provided for by Art. 22 paragraph 1) of the GDPR (“The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her”), without prejudice to the exceptions provided for in paragraph 2) thereof.
5.3. In accordance with Art. 12 paragraph 1) of the GDPR, TECNOGEN undertakes to provide the user with the communications referred to in Articles 15 to 22 and 34 of the GDPR in a concise, transparent, intelligible and easily accessible form, using clear and plain language: such information will be provided in writing or by other means, including electronic means, or, at the user’s request, orally, provided that the identity of the user is proven by other means.
5.4. In accordance with Art. 12 paragraph 3) of the GDPR, TECNOGEN informs that it undertakes to provide the user with information on the action taken on a request pursuant to Articles 15 to 22 of the GDPR without undue delay and, in any event, within one month of receipt of the request; this period may be extended by 2 months where necessary, taking into account the complexity and number of requests (in such case, the Data Controller undertakes to inform the user of such extension and the reasons for the delay within one month of receipt of the request).
5.5. The user may exercise the rights described above (with the exception of the right under Art. 77 of the GDPR) at any time using the contact details set out in Art. 6.
6. CONTACT DETAILS
6.1. TECNOGEN may be contacted at the following address: privacy@tecnogen.com
7. SOCIAL PLUG-INS
7.1. In compliance with Guidelines No. 7/2020 of the EDPB, TECNOGEN also specifies that it acts as joint Data Controller pursuant to Articles 4 No. 7) and 26 of the GDPR with certain social media providers (e.g. LinkedIn; YouTube), due to the installation, within the Site, of the related social plug-ins, which are easily visible and accessible on the Site.
TECNOGEN finally specifies that the cookie banner displayed on the Site complies, as required by the Garante Privacy in its Decision No. 231 of 10.6.2021, with the level “AA” success criteria, applicable in this case, of the “Web Content Accessibility Guidelines” (WCAG) 2.1, a document referred to in Art. 2.2. of the “Guidelines on the accessibility of IT tools” issued by AgID on 13.2.2020.
Pontenure (PC), 04.06.2026 (date of last update)
TECNOGEN SPA
(in the person of its legal representative pro tempore)
Notes
1 See Recital No. 30) of the GDPR (“Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them”), and Art. 122 paragraphs 1) and 2) of the Italian Privacy Code (“1. The storing of information in the terminal equipment of a contracting party or user, or access to information already stored, shall only be permitted on condition that the contracting party or user has given their consent after being informed by simplified means. This shall not prevent any technical storage or access to information already stored if it is solely intended to carry out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for the provider of an information society service explicitly requested by the contracting party or user to provide that service. For the purposes of determining the simplified means referred to in the first sentence, the Garante shall also take into account the proposals made by the most representative national consumer associations and the economic categories involved, also with a view to ensuring the use of methodologies that ensure the effective awareness of the contracting party or user. 2. For the purposes of expressing the consent referred to in paragraph 1, specific configurations of computer programs or devices that are easy and clear for the contracting party or user to use may be employed…”); see also p. 15 of Decision No. 231 of 10.6.2021 issued by the Garante Privacy: “…there is still no universally accepted system of semantic coding of cookies and other tracking tools that makes it possible to objectively distinguish, for example, technical cookies from analytics or profiling cookies, other than on the basis of the indications provided by the controller itself in the privacy policy […] the hope that a general coding system will be achieved quickly”.
2 Cookies designed to collect and store data while a user accesses a website, which disappear once the user closes the relevant browsing session.
3 Cookies designed to last for a predetermined period of time (e.g. minutes; months; years).
4 Analytics cookies are usually used to assess the effectiveness of an information society service provided by a publisher, for the design of a website or, finally, to help measure its traffic (i.e. the number of visitors, possibly broken down by geographical area, connection time slot).
5 See Decision No. 231 of 10.6.2021 issued by the Garante Privacy, pp. 13-14: “The structure of the analytics cookie must therefore provide for the possibility that it may be attributable not only to one, but to several devices, so as to create reasonable uncertainty as to the digital identity of the person receiving it. As a rule, this effect is achieved by masking appropriate portions of the IP address within the cookie. Given the 32-bit representation of IP version 4 (IPv4) addresses, which are usually represented and used as a sequence of four decimal numbers between 0 and 255 separated by a dot, one of the measures that can be implemented in order to benefit from the exemption consists in masking at least the fourth component of the address, an option that introduces an uncertainty in the attribution of the cookie to a specific data subject equal to 1/256 (approximately 0.4%). Similar procedures should be adopted with reference to IP version 6 (IPv6) addresses, which have a different structure and an enormously larger address space (consisting of binary numbers represented with 128 bits). The Garante also stresses the need for the use of analytics cookies to be limited solely to the production of aggregate statistics and for them to be used in relation to a single site or a single mobile application, so as not to allow the tracking of the browsing of a person using different applications or browsing different websites. It is therefore understood that third parties providing the publisher with the web measurement service must not in any case combine the data, even if minimised in this way, with other processing (customer files or statistics of visits to other sites, for example) nor transmit them in turn to further third parties, on pain of an unacceptable increase in the risks of user identification; except where the production of statistics carried out by them with the minimised data concerns several domains, websites or apps attributable to the same publisher or business group. However, it is possible to consider lawful, even in the absence of the adoption of the prescribed minimisation measures, the use of statistical analyses relating to several domains, websites or apps attributable to the same controller, provided that the latter carries out the statistical processing itself, without in any case such analyses resulting in an activity which, going beyond the boundaries of a mere statistical count, actually takes on the characteristics of processing aimed at making commercial decisions”.