Skip to main content
IT EN
Legal notice

Legal Notice and Privacy Policy

The websites eurokleis.com, eurokleis.it and eurokleis.eu (hereinafter, the "Websites") are owned by eurokleis s.r.l.

01 / Legal notice

Company identification

Below are the identifying details of the company that owns the Websites.

Registered office
Via dei Monti della Farnesina, 77 — 00135 Rome
VAT number
06077951009
REA number
RM - 946886
Companies Register
06077951009 (RM-2000-127347)
Registered since
30/05/2000 (ordinary section)
Innovative SME since
11/02/2020 (special section)
Share capital
EUR 50,000
PEC
eurokleis@pec.it
02 / Copyright

Copyright protection

The contents published on the Websites, unless otherwise expressly indicated, are protected by current legislation on copyright (Italian Law No. 633/1941 and subsequent amendments and additions).

Full or partial reproduction of the contents on any medium is prohibited without prior written authorisation from eurokleis s.r.l.

Partial reproduction is permitted for informational or citation purposes, provided that:

  • the reproduced content does not exceed 20% of the original work
  • a clear and visible link to the original page is included
  • the source is indicated
03 / Liability

Limitation of liability

eurokleis s.r.l. is not liable for direct or indirect damages arising from the use of information present on the Websites.

Any links to external sites not managed by eurokleis s.r.l. are provided for informational purposes only; the Data Controller is not responsible for the contents, cookies or privacy policies of such sites.

04 / Privacy

Privacy Policy

This privacy notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) to users who interact with the Websites and describes how personal data are processed.

4.1 Controller

Data controller

The data controller is eurokleis s.r.l., with registered office at Via dei Monti della Farnesina, 77 — 00135 Rome. For any request regarding personal data protection, please write to privacy@eurokleis.com.

4.2 Type

Type of data collected

During navigation on the Websites, technical data transmitted by browsers (IP address, user agent, pages visited, date and time of request) are automatically collected. Such data are used exclusively in aggregate and anonymous form for security and diagnostic purposes.

Personal data voluntarily provided by the user — for example through the contact form — are processed solely to respond to the request and are not used for further purposes.

4.3 PoW measure

Anti-Spam Proof-of-Work measure

The contact form is protected by a computational proof-of-work anti-spam measure that runs entirely in the user's browser. The SHA-256 calculation verifies that the request originates from a real client before being forwarded. The protection operates with these characteristics:

  • Client-side execution: the SHA-256 calculation runs entirely in the user's browser.
  • No cookies, no fingerprinting, no tracking.
  • No communication with third-party servers during verification.
  • Token generated client-side and verified server-side.

The proof-of-work measure is a technical anti-spam filter and does not constitute automated processing intended to produce legal effects on the data subject pursuant to Article 22 of Regulation (EU) 2016/679.

4.4 Cookies

Cookies and similar technologies

The Websites do not use technical session cookies, profiling cookies or third-party analytics tools. There is therefore no cookie consent banner, as there is nothing to consent to.

4.5 Purposes

Purposes of processing

Personal data provided through the contact form are processed solely to respond to the user's request and to manage the resulting communication. Navigation data (in aggregate form) are used for IT security purposes and technical traffic analysis.

For requests submitted through the contact form, processing is based on the legitimate interest of the Controller in efficiently responding to communications from website users (Article 6(1)(f) of Regulation (EU) 2016/679); the Controller has carried out a balancing test between this interest and the rights of data subjects, finding that the interest in processing prevails. For sending informational communications about services, events and editorial content, the legal basis is the data subject's express consent (Article 6(1)(a)), which can be withdrawn at any time. Legal obligations of the Controller (Article 6(1)(c)) also apply for the retention of fiscal, civil and anti-money-laundering documentation.

Provision of the data requested by the form (first name, last name, email, area of interest, message) is optional, but necessary in order to process and respond to the user's request. Failure to provide the data prevents the Controller from handling the request. Data related to marketing consent is optional: providing or refusing it has no consequences on the response to the main request.

4.6 Communication

Communication and transfer of data

Data collected through the contact form is not communicated to third parties, save for specific legal obligations. It may be processed by internal authorised staff (IT managers) and by technical service providers appointed as external data processors pursuant to Article 28 of Regulation (EU) 2016/679. In particular, the email delivery service is operated by Mailgun (Sinch Email AB), whose Data Processing Agreement (DPA) ↗ is publicly available and applies to the service relationship. Messages are transmitted through servers located within the European Economic Area (api.eu.mailgun.net endpoint). Any sub-processors used by Mailgun (e.g. cloud infrastructure providers) are covered by Standard Contractual Clauses pursuant to Article 46 of Regulation (EU) 2016/679. No further transfers of personal data take place outside the European Economic Area.

4.7 Rights

Data subject rights

The user has the right to access, rectify, erase or restrict the processing of their data, receive it in a structured format (portability), object to processing and lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali). Consent given for receiving informational communications may be withdrawn at any time, without affecting the lawfulness of processing based on consent before its withdrawal, pursuant to Article 7(3) of Regulation (EU) 2016/679. Withdrawal can be exercised by writing to privacy@eurokleis.com or by using the unsubscribe link present in every communication.

To exercise these rights, please contact the Data Controller by writing to privacy@eurokleis.com.

4.8 Retention

Data retention period

Data collected through the contact form is retained for 24 months from the date of submission, unless the request results in a contractual relationship: in that case, the retention periods provided by civil and tax legislation apply (10 years from the end of the relationship).

Data of those who consent to informational communications is retained until consent is withdrawn, in any case for no longer than 36 months from the last active contact.

Technical navigation logs (HTTP requests collected by the web server in aggregated form) are retained for the time strictly necessary for IT security purposes and for the investigation of possible service abuse, in accordance with Article 6(1)(f) of Regulation (EU) 2016/679 (legitimate interest of the Controller in protecting its infrastructure).

On the email provider's systems (Mailgun), the body of transmitted messages is retained for a maximum of 7 days (for re-delivery purposes), while transmission metadata (sender, recipient, subject, origin IP address) is retained for a maximum of 30 days, in accordance with the provider's official policies.