Policy on the processing of personal data pursuant to articles 13 and 14 of Regulation (EU) 2016/679
Cefla S.c., as the Data Controller (hereinafter: “Cefla” or “Data Controller”) pursuant to Regulation (EU) 2016/679 (known as the General Regulation for the Protection of Personal Data, hereinafter “Regulation”) and Legislative Decree no. 196/2003 (known as the Personal Data Protection Code, hereinafter “Code”) – considers privacy and the protection of personal data one of the primary objectives of its business.
We therefore ask you to carefully read this Privacy Policy before submitting any personal data to the Data Controller, as it contains important information on the protection of personal data.
This policy:
- it is intended as provided for the website www.cefla.com;
- forms an integral part of the Website and the services we offer;
- is provided, pursuant to Articles 13 and 14 of the Regulation, to all those who interact with the Site’s web services, either through simple consultation or through the use of specific services made available through the Site, as well as with other services provided through the Website.
With regard to the processing of navigation data and the processing of personal data through cookies, please refer to the specific Cookie Policy, accessible via the link in the footer of the website or at www.cefla.com/it/cookie-policy – which forms an integral part of this policy.
The processing of personal data will be based on the principles of fairness, lawfulness, transparency, purpose and retention limitation, minimisation and accuracy, integrity and confidentiality, as well as the principle of accountability pursuant to art. 5 of the Regulation. Personal data will therefore be processed in compliance with personal data protection legislation and the required confidentiality obligations.
- DATA CONTROLLER
The data controller is Cefla S.c., Via Selice Provinciale, 23/A – 40026 – Imola (BO), Italy, VAT number IT 00499791200, PEC (certified e-mail) ceflasc@legalmail.it,
The Data Controller has not appointed a Data Protection Officer (“DPO”) pursuant to art. 37 GDPR.
- PERSONAL DATA TO BE PROCESSED
Please note that the personal data to be processed, depending on your interactions with the Website, may include:
- Personal and contact information voluntarily submitted in order to use the Website’s services, such as name, surname, email address, telephone number, company and position, as well as any other information included in communications sent via contact forms or other communication channels made available by the Data Controller.
- Navigation data: the IT systems and software procedures used to operate this Website will capture, during their normal operation, some personal data the transmission of which is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of computers used by users who log in to the website, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the digital code indicating the status of the response sent by the server (success, error, etc.) and other parameters relating to the operating system and to the user’s IT environment. On this subject, please refer to the Cookie Policy.
- Data collected through cookies: for details on the data collected through cookies please refer to the specific Cookie Policy.
- Data relating to CVs, submitted voluntarily through the “Careers” section of the website to apply for job positions, in accordance with the relevant policy provided.
- DATA PROCESSING PURPOSES
Personal data will be processed, subject to consent where necessary, for the following purposes, where applicable:
3.1 Allow the use of the Website, in compliance with the applicable general conditions [link to the terms and conditions of use of the website.]
3.2 Respond to specific requests submitted to the Data Controller, including any relating to after-sales services, including requests for Customer Service and information submitted by completing the contact forms specially provided on the Website;
3.3 Send communications and commercial proposals, including newsletters, through automated tools (SMS, MMS, email, instant messaging and online chat) and non-automated tools (postal mail, telephone);
3.4 Allow the sending of CVs, as defined in the relevant “Careers” area in accordance with the information policy provided locally.
3.5 Allow the use of the Social Wall.
- LAWFULNESS AND MANDATORY OR OPTIONAL NATURE OF DATA PROCESSING
| Section | Purposes | Lawfulness (Article 6 GDPR) | Nature of consent | Consequences of refusal |
| 3.1 | Provision of services | Letter b) – execution of the contract | None required | Consent is not required; however, failure to submit personal data will prevent the supply of services associated with the use of the website. |
| 3.2 | Response to requests | Letter f) – legitimate interest | None required | Consent is not required; however, failure to submit personal data will prevent us from responding to your requests |
| 3.3 | Marketing | Letter a) – consent | Optional | Consent is optional and can be withdrawn at any time; it will not affect services. Your failure to consent will mean that it will not be possible for us to send you marketing communications |
| 3.4 | Applications | Please refer to the relevant information. | – | – |
| 3.5 | Social Wall |
- RECIPIENTS OF PERSONAL DATA
Personal data may be shared, for the purposes set out in section 3 of this Privacy Policy, with:
5.1. Persons authorised by the Data Controller to process personal data pursuant to Articles 29 and 2-N (quaterdecies) of the Code (e.g. personnel working in sales, administration, accounting and after-sales, CRM and information systems management);
5.2. Third parties who, in providing services (e.g. technology, accounting, administrative, legal, tax and financial support and consultancy services, technical maintenance, transportation services, banking and insurance services), act as data processors pursuant to Article 28 of the Regulation. The Data Controller maintains an updated list of appointed data processors and ensures that the data subject may view it at the above-mentioned headquarters or upon request addressed to the above-mentioned contact details;
5.3. Commercial partners, Group companies, suppliers or other third parties who act, as applicable, as independent data controllers or processors, exclusively to the extent necessary to achieve the purposes indicated in this policy and in compliance with applicable legislation;
5.4. subjects, entities or authorities to whom the communication of personal data is mandatory pursuant to legal provisions or orders of the authorities.
These subjects are, hereinafter, collectively referred to as “Recipients”.
- TRANSFER OF PERSONAL DATA
Some personal data are shared with Recipients who may be located outside the European Economic Area. The Data Controller ensures that the processing of personal data by these Recipients is carried out in compliance with Articles 44 – 49 of the Regulation.
The Data Controller intends to transfer Personal Data to entities established in a third country outside the European Union or to an international organisation. Such entities could be, by way of example:
- communications companies that carry out communication activities on behalf of the Data Controller;
- companies that offer hosting services;
- suppliers of services to the communications company;
- Data Controller’s partner companies.
The Data Controller will take the utmost care to ensure that the level of personal protection is not affected in the event of transfer of your personal data to a third country outside the European Union or to an international organisation. Some of the services offered by the Data Controller, as detailed in this policy, may involve the transfer of personal data to third countries, particularly to the United States of America.
Such transfers take place according to the following methods:
- Transfers based on an Adequacy Decision: if the European Commission has determined that a third country ensures an adequate level of data protection, the transfer of your personal data to that country will not require any further authorisation.
- Transfers in the absence of an Adequacy Decision: for transfers to third countries for which there is no existing adequacy decision, the Data Controller primarily refers to the Standard Contractual Clauses adopted by the European Commission, carrying out, where necessary, a transfer impact assessment to verify whether the legislation and practices of the destination third country could undermine the effectiveness of the guarantees offered by the aforementioned clauses. Additional technical, contractual and organisational measures may also be adopted if the impact assessment shows that the rights and freedoms of data subjects are at risk. These measures are intended to fill regulatory gaps in the third country and to ensure that the transferred data benefit from a level of protection essentially equivalent to that ensured within the EEA. Where technically possible and appropriate according to the level of risk, the technical measures adopted include the use of advanced encryption for data in transit and at rest, with management of encryption keys under the exclusive control of the Data Controller or a trusted third party established in the European Union. If, despite the adoption of the aforementioned measures, it is not possible to guarantee a substantially equivalent level of protection, the Data Controller undertakes not to carry out the transfer or to suspend it.
For more information on data transfers and to receive a copy of the adopted adequate guarantees (e.g. the Standard Contractual Clauses), please send your request to the Data Controller.
- STORAGE OF PERSONAL DATA
As a Data Subject, you may exercise the rights set forth in Articles 15-22 of the GDPR and withdraw your consent at any time, without prejudice to the lawfulness of the processing carried out before such withdrawal.
| Section | Purposes | Retention time |
| 3.1 | Provision of services related to the website | 24 months |
| 3.2 | Response to requests | 24 months |
| 3.3 | Marketing | 24 months |
- RIGHTS OF THE DATA SUBJECTS
As a Data Subject, you may exercise the rights set forth in Articles 15-22 of the GDPR and withdraw your consent at any time, without prejudice to the lawfulness of the processing carried out before such withdrawal.
Right to object
As a Data Subject, you have the right to object under the following terms:
- The Data Subject has the right to object, on grounds relating to their particular situation, at any time to the processing of Personal Data of the Data Subject pursuant to Article 6, paragraph 1, letters e) or f) of GDPR. The Data Controller shall then no longer process personal data unless the Data Controller can demonstrate compelling legitimate grounds for data processing which override the interests, rights and freedoms of the Data Subject or for the establishment, enforcement or defence of legal claims;
- Where personal data are processed for direct marketing purposes, the Data Subject shall have the right to object at any time to the processing of their Personal Data for such purposes, which includes profiling to the extent that it is related to such direct marketing purposes;
- Where the Data Subject objects to processing for direct marketing purposes, their personal data shall no longer be processed for such purposes. Data subjects may object to the processing of their personal data for direct marketing purposes even only partially, e.g. by objecting to the sending of promotional communications via automated and/or digital tools, or to the sending of hard copy communications and/or to telephone communications;
- Where Personal Data of the Data Subject are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89, paragraph 1 of the GDPR, the Data Subject, on grounds relating to their particular situation, shall have the right to object to processing of their Personal Data, unless such processing is necessary for the performance of a task for reasons of public interest.
Additionally, as the Data Subject, you are entitled to other rights summarised below:
- Right of access: Right to obtain confirmation from the Data Controller as to whether or not your personal data are being processed and to access your personal data and specific information, pursuant to Article 15 of the GDPR;
- Right to rectification: Right to obtain from the Data Controller without undue delay the rectification of inaccurate Personal Data. In consideration of the purposes of data processing, you have the right to obtain the integration of incomplete personal data, including by providing a supplementary statement, pursuant to Article 16 of the GDPR;
- Right to erasure (“right to be forgotten”), including the right to withdraw consent: Right to obtain from the Data Controller the erasure of personal data without undue delay or to withdraw consent to the processing of personal data, if the grounds set out in Article 17 of the GDPR apply. Right to withdraw your consent at any time without prejudice to the lawfulness of any data processing based on consent previously granted;
- Right to restriction of processing: Right to obtain from the Data Controller restriction of processing, when the conditions defined in Article 18 of the GDPR apply;
- Right to data portability: Right to receive your Personal Data supplied to the Data Controller in a structured, commonly used and machine-readable format and right to transmit such data to another Data Controller without hindrance from the Data Controller mentioned in this Privacy Policy, as provided for by Article 20 of the GDPR;
- Contracting party’s right to object to commercial communications: As a contracting party, you have the right to object at any time, free of charge, to receiving commercial communications from the Data Controller;
- Right to lodge a complaint with a Supervisory Authority: Right to lodge a complaint with the Data Protection Authority to report a violation of personal data protection regulations, pursuant to Article 77 of the GDPR.Exercise of rights
- Requests may be submitted, subject to preliminary identification of the Data Subject, by sending:
- a certified email to ceflasc@legalmail.it
- a registered letter with return receipt to Cefla headquarters address, via Selice Provinciale 23/a Imola
- privacy@cefla.it
- LODGING A COMPLAINT WITH THE SUPERVISORY AUTHORITY
If you believe that the processing of your Personal Data by the Data Controller violates the provisions of the GDPR, you have the right to lodge a complaint with the Data Protection Authority as provided for by art. 77 of the GDPR, or to take appropriate legal action (Article 79 of the GDPR).
- AMENDMENTS
The Data Subject reserves the right to amend or simply update the content of this Privacy Policy, in part or completely, as a result of, among others, changes in the applicable legislation. The Data Controller therefore recommends to regularly visit this section to become aware of the most recent and updated version of this Privacy Policy, in order to always be up-to-date on the Personal Data collected and on the use made of such data by the Data Controller. Should the Data Controller substantially modify this Privacy Policy, introducing new processing purposes and/or categories of personal data, the Data Controller will see to informing you in order to obtain from you the required consent, via a pop-up on the website or through different methods and/or IT tools.
Latest update: Imola, 1 July 2026