Policy for the processing of personal data on the website, pursuant to art. 13 of Regulation (EU) 2016/679 (“GDPR”)
This Privacy Policy explains the purposes and methods used by the Company, as identified below, to process the personal data of visitors (or “data subjects”) while they browse this website.
Please remember that this website may contain hyperlinks to other websites that are neither administered by nor otherwise associated with the Company. The Controller does not have any means of access to or control over those websites. Data subjects are invited to read the privacy policies of those third-party websites, in order to find out the purposes and methods used them to process personal data.
1. Joint controller
COMAS SpA (also referred to as the “Company”) with registered office at Via Cendon, 1, Silea (TV) and contactable as follows: tel. +39 0422 36 05 14, e-mail comas@comastm.it, acts as a joint controller together with Coesia S.p.a. Via Battindarno 91, 40133 Bologna, Italy, VAT no. 02221441203, contactable by e-mail at privacy@coesia.com, tel. +39 051 6474111. Data subjects may consult the essential contents of the joint controllership agreement at any time, by writing to the addresses given in this section.
The Data Protection Officer for all Italian companies within the Coesia Group may be contacted at this address dpo@coesia.com.
2. What data may be processed via the website?
The Company may process the following personal data of visitors:
a. browsing data, acquired automatically on connection with the website, including the IP addresses and domain names of the computers used by each visitor, the URI (Uniform Resource Identifier) addresses of the resources, the time of the request, the method used to query the server, the size of the file requested, the status code of the server (good, error etc.), and other parameters relating to the operating system and IT environment of each visitor. For more information about the use made of this data via cookies and other tracking tools, please read the Cookie Policy published on the website;
b. personal data provided voluntarily, even during the pre-contractual and contractual phases, by data subjects who contact the Company using addresses found on the website. Specifically with regard to any personal data gathered by the Company from on-line forms available on the website, please read the privacy policies presented at the foot of each form.
3. Purposes and legal basis for the processing of personal data. Data retention period
The following table indicates the purposes for which the Company processes personal data, as well as the legal basis for each type of processing and the related data retention period.
| Purpose | Legal basis | Retention period | |
| A. | Process browsing data to check and ensure the proper technical functioning and improvement of the website to which data subjects request access | Execute requests made by data subjects (art. 6(1.b) GDPR) | 12 months |
| B. | Manage communications and respond to requests about the activities of the Company and/or its pre-contractual or contractual relations with data subjects | Execute requests made by data subjects (art. 6(1.b) GDPR) | For the time needed to respond to the request and, in all cases, for a maximum period of 6 months, unless the request is necessary in relation to the execution and continuation of the contractual relationship |
| C. | Ensure the security of the website via the application of cyber security measures, including those taken after incidents occur | Legitimate interest of Coesia in ensuring the protection of its assets (art. 6(1.f) GDPR), as well as compliance with legal obligations (art. 6(1.c) GDPR) | 6 months |
| D. | Defend or exercise our legal rights | Legitimate interest in protecting our legal rights in court or in the phases preceding a court ruling, as well as in defending against claims made or actions taken by third parties (art. 6(1.f) GDPR) | From exercise of the relevant rights until completion of the protection work and the legal time expiry of the claims made |
4. Optional provision of personal data
The provision of personal data is entirely optional and free of charge. However, failure to provide personal data may make it impossible for the Company to execute requests made by the visitor.
5. Who may become aware of the personal data of visitors?
The personal data gathered while browsing the website may come to the attention of those employees and collaborators of the Controller who have been specifically authorised to process it. Personal data may also be communicated to professional advisors, if needed for the above-mentioned purposes, and to those parties appointed by the Controller to administer and maintain the website, including the providers of website hosting servers and the providers of cyber security services appointed as Processors pursuant to art. 28 GDPR.
The data may also be communicated to supervisory bodies, the judiciary, the police, public bodies and any other parties to which such communications must be made by law (art. 6(1.c) GDPR). The above parties will process this data in their capacity as independent controllers.
Personal data is not transferred outside of the European Union. However, should this become necessary, it is understood that we may transfer your personal data outside of the EEA, with the firm assurance that such transfer will comply with the applicable legal requirements:
- in the event of international transfers of personal data from the European Economic Area (EEA) to a non-EEA country, the transfer may take place if the European Commission has recognised that the non-EEA country provides adequate data protection guarantees: in such cases, your personal data may be transferred on this basis;
- for transfers to non-EEA countries whose level of protection has not been recognised as adequate by the European Commission, we may rely on an exception applicable in the specific situation and, therefore, sign - if and to the extent necessary - specific agreements that guarantee the adequate protection of your personal data or, in any case, adopt the standard contractual clauses stipulated by the European Commission for the transfer of personal data outside of the EU.
6. Rights of visitors to the website
Pursuant to and within the limits of arts. 15-21 GDPR, visitors are recognised the right to ask the Company for access to their personal data, for its rectification or erasure, and for the restriction of data processing that relates to them, as well as to object to the processing of their personal data and to request its portability.
Visitors are also entitled, at any time, to revoke consents given for the processing of their personal data, without this prejudicing the lawfulness of processing based on said consents prior to their revocation.
Lastly, visitors may lodge a complaint with a competent supervisory authority pursuant to art. 77(1) GDPR, this being the “Garante” in Italy (Italian Data Protection Authority). Complaints may also be lodged with a non-Italian supervisory authority, if that authority is responsible for the EU State in which the visitor habitually resides or works, or for the location where the alleged infringement took place.
Visitors may exercise the above rights by sending a written communication to the registered office of the Company indicated above, or to the addresses provided in the section entitled “Joint controller”.
Version: Agusut 2026