1. Types of data, purposes of processing and retention period
In the course of the activity carried out by the Controller through byonda.it, different data may be collected for different purposes, as follows:
- Browsing data: the site is hosted by Netlify, Inc. Like every web server, the hosting infrastructure processes the IP address, the pages requested, the time of the request and basic browser information, solely to deliver the pages and keep the service secure. This data is not used to identify visitors. Legal basis: the Controller's legitimate interest in running a secure website (Art. 6(1)(f) GDPR). It is retained by the hosting provider for a limited period, stated in its own privacy policy.
- Data collected through the "Request a demo" form: name, practice or yard, email address, type of patients treated, any notes and the language of the page. The form is handled by the Netlify Forms service, which stores the request and forwards it to the Controller by email. The data is used only to the extent necessary to answer the request and arrange the demonstration, and is deleted once the processing is complete, and in any case within 24 months, unless the user becomes a customer. Legal basis: pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR). Requests are screened by a spam filter (Akismet). Providing the data is optional, but without it the request cannot be handled.
- Data for promotional activities and newsletters: the site does not collect newsletter subscriptions. Any promotional communication will be sent only with the data subject's specific and optional consent, which can be withdrawn at any time by writing to the contacts below or by using the link included in each communication, so that the data is immediately removed from the mailing lists.
- Data required for administrative and accounting purposes: should the data subject become a customer, the data collected under the contract is processed exclusively for administrative, accounting and tax purposes; it is strictly necessary to conclude the contract or provide the service, and failure to provide it makes it impossible to obtain the service requested. This data is kept for the whole duration of the relationship and for the period required by accounting and tax law.
- Preferences stored in the browser: the language chosen (EN/IT) and the choices made in the cookie banner are saved only in the local storage of the user's browser and are never transmitted to the Controller or to third parties. This is strictly necessary technical storage, which does not require consent under Article 122 of the Privacy Code. See the Cookie policy for details.
Data is processed by electronic means, with logic strictly related to the purposes stated and with security measures adequate to prevent loss, unlawful use or unauthorised access. The site performs no profiling and no automated decision-making.
2. Recipients
For the purposes listed above, the data collected may be made accessible to:
- employees and collaborators of the Controller in Italy and abroad, as persons authorised to process data, internal data processors or system administrators;
- third-party companies or other entities performing outsourced activities on behalf of the Controller, as external data processors: in particular Netlify, Inc. (website hosting and contact-form handling), Google Ireland Ltd. (Google Workspace email service), Automattic Inc. (Akismet spam filter), and the Controller's professional advisers and consultants;
- judicial authorities and any entity to which disclosure is required by law for the purposes stated. These entities process the data as independent controllers.
Data is not transferred abroad except for the hosting and anti-spam services mentioned above, whose providers are established in the United States and guarantee compliance with European requirements through Standard Contractual Clauses and the further safeguards provided for in Chapter V GDPR. Data is never disclosed to the public or sold to third parties for marketing purposes.
3. Rights of the data subject
Under Chapter III of Regulation (EU) 2016/679 the data subject has the right to:
- request access to their personal data and ask for it to be rectified, erased or its processing restricted;
- know the purposes of processing, the categories of data processed, the recipients to whom the data is disclosed and the retention period;
- withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- request the erasure, where possible, of data no longer necessary for the purpose for which it was collected;
- obtain the portability of the data provided;
- object to processing based on legitimate interest, to profiling and to direct marketing;
- lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of their own country;
- know the entities to which personal data may be disclosed.
Requests may be addressed to B&M as follows:
- by registered letter with return receipt to B&M s.r.l. Marketing nel Benessere – Via Leonardo Bruni 25 – 20158 Milan (Italy);
- by email to privacy@baldangroup.it.
The Controller replies within one month of receiving the request.
4. Changes to this notice
This notice may be updated to reflect changes in the law or in the website. The version published on this page, with its update date, is the one in force.