Privacy notice

Privacy Policy

Information on the processing of personal data provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated: August 18, 2026

This notice describes how the personal data of users who browse this website and use the contact form made available on it are processed. It applies to this website only and not to any other site that may be reached through links contained herein.

1. Data controller

The controller of the personal data collected through this website is:

Reggiana Packaging S.r.l.

Address
Via Giovanni Falcone 8, 42124 Reggio nell'Emilia (RE), Italia

No Data Protection Officer (DPO) has been appointed, as none of the conditions making such appointment mandatory under Article 37 of the GDPR applies. For any matter relating to the processing of personal data you may contact the controller directly using the details set out above.

2. Categories of data collected

The following categories of personal data are processed through this website.

2.1 Data provided voluntarily through the contact form

By filling in the form available in the Contacts section, the user provides their first and last name (and, where applicable, the name of the company they represent), telephone number, email address and the free-text content of the message. Providing this data is optional, but failure to complete the fields marked as mandatory makes it impossible to respond to the request.

Users are asked not to include in the message field any data belonging to the special categories referred to in Article 9 of the GDPR (for example data concerning health or personal beliefs), as such data is not necessary for the purpose pursued.

2.2 Browsing data

The computer systems and software procedures used to operate this website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP addresses, browser and operating system type, date and time of the request, address of the requested resources and the response status code. This data is used solely to obtain aggregate statistical information on the use of the site and to verify that it is functioning correctly and securely.

2.3 Cookies and similar technologies

This website uses technical cookies only, which are necessary for it to work correctly; no profiling cookies and no third-party cookies are installed. Full details of the technologies used, their purposes and how to manage them are set out in a dedicated document.

Read the Cookie Policy

3. Purposes of processing and legal basis

The data collected is processed solely for the purposes set out below, each with its corresponding legal basis under Article 6 of the GDPR.

Purpose

Responding to requests for information, quotations and contact submitted through the website form or by email.

Legal basis

Article 6(1)(b) of the GDPR: steps taken at the request of the data subject prior to entering into a contract. Providing the data is necessary in order to receive a reply.

Purpose

Managing any commercial relationship established following the initial contact and fulfilling the resulting accounting and tax obligations.

Legal basis

Article 6(1)(b) of the GDPR for the performance of the contract and Article 6(1)(c) for compliance with the legal obligations to which the controller is subject.

Purpose

Ensuring the security of the website, diagnosing malfunctions and preventing abuse and unauthorised access attempts (browsing data and technical logs).

Legal basis

Article 6(1)(f) of the GDPR: the controller's legitimate interest in preserving the integrity, availability and confidentiality of its systems.

Purpose

Establishing, exercising or defending legal claims, whether in or out of court.

Legal basis

Article 6(1)(f) of the GDPR: the controller's legitimate interest in protecting its rights.

No automated direct marketing, user profiling or automated decision-making within the meaning of Article 22 of the GDPR is carried out.

4. Recipients and categories of recipients

Personal data may be accessed by persons authorised to process it, acting under the authority of the controller and specifically instructed pursuant to Article 29 of the GDPR. Data may also be disclosed to the following categories of recipients, acting as processors appointed pursuant to Article 28 of the GDPR:

  • the provider of the hosting and infrastructure services on which the website runs;
  • the provider of the email service used to receive and manage requests;
  • the suppliers of website development, maintenance and technical support services;
  • the professionals and advisers who assist the controller in accounting, tax and legal matters.

Personal data is never disseminated, nor is it transferred to third parties for their own marketing purposes. An up-to-date list of the appointed processors is available on request by writing to the controller.

5. Transfers of data to third countries

Data is normally processed within the European Economic Area, on servers located in the European Union.

The website does not embed any third-party content that would trigger automatic connections to servers located outside the European Union. The Contacts section simply provides a hyperlink that opens Google Maps in a new browser tab: no data is sent to Google unless the user actively chooses to follow that link. If the user does open it, browsing continues on an external platform and the related processing, including any transfer of data to the United States of America, is carried out by Google as an independent controller, on the basis of the adequacy decision adopted by the European Commission on 10 July 2023 concerning the EU-U.S. Data Privacy Framework.

For full details of the purposes and methods of the processing carried out by Google on its own platforms, please refer to the privacy notice published by the provider.

Google Privacy Policy

6. Data retention period

Data is retained for no longer than is necessary to achieve the purposes for which it was collected and, in any event, according to the following criteria:

  • data submitted through the contact form: 24 months from the request, unless the contact leads to the establishment of a contractual relationship;
  • data relating to contractual relationships and the associated documentation: 10 years from the end of the relationship, in accordance with civil and tax record-keeping obligations (Article 2220 of the Italian Civil Code);
  • technical logs and browsing data: a maximum of 12 months, unless a longer period is required in order to investigate unlawful conduct or to defend a legal claim.

Once these periods have elapsed, the data is deleted or irreversibly anonymised.

7. Rights of the data subject

In relation to the data processed, the data subject may exercise at any time the rights granted by Articles 15 to 22 of the GDPR and in particular:

  • right of access (Article 15): to obtain confirmation as to whether their data is being processed and to receive a copy of it, together with information on the purposes, the recipients and the retention periods;
  • right to rectification (Article 16): to obtain the correction of inaccurate data and the completion of incomplete data;
  • right to erasure (Article 17): to obtain the deletion of data in the cases provided for by law, commonly known as the right to be forgotten;
  • right to restriction of processing (Article 18): to obtain that data be processed for storage purposes only in the cases provided for by law;
  • right to data portability (Article 20): to receive the data provided in a structured, commonly used and machine-readable format and to transmit it to another controller without hindrance;
  • right to object (Article 21): to object at any time, on grounds relating to their particular situation, to processing based on the controller's legitimate interest;
  • right not to be subject to a decision based solely on automated processing, including profiling (Article 22).

The data subject also has the right to lodge a complaint with the competent supervisory authority, which in Italy is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome), or to bring proceedings before the courts.

Website of the Italian Data Protection Authority

8. How to exercise your rights

Requests to exercise these rights may be sent to the controller using the contact details set out in section 1, quoting «Exercise of privacy rights» in the subject line and enclosing, where necessary to verify the identity of the applicant, a copy of a valid identity document.

A reply will be provided without undue delay and in any event within one month of receipt of the request, a period that may be extended by a further two months where the request is particularly complex, pursuant to Article 12 of the GDPR. Exercising these rights is free of charge, except in the case of manifestly unfounded or excessive requests, in particular because of their repetitive character.

9. Processing methods and security measures

Processing is carried out mainly by electronic and telematic means and, to a residual extent, on paper, using logic strictly related to the stated purposes and in such a way as to guarantee at all times the security and confidentiality of the data.

The controller implements appropriate technical and organisational measures pursuant to Article 32 of the GDPR, including transmission of data over the encrypted HTTPS protocol, access control to systems through individual credentials, regular updating of the software used and the performance of backup procedures.

10. Changes to this notice

The controller reserves the right to amend or simply update the content of this notice, in whole or in part, including as a result of changes in the applicable legislation or in the services offered through the website. The version in force from time to time is published on this page, together with the date of the latest update shown at the top of the document.

11. Note on legal review

This document has been drafted on the basis of the processing activities actually carried out through the website as at the date of the latest update. Before final publication, we recommend that it be reviewed by the company's legal adviser or trusted professional, in order to confirm that the controller's identification details are complete, that the retention periods indicated are appropriate and that the list of processors matches the company's actual organisation.