Privacy Policy

Notice on the processing of personal data pursuant to EU Regulation 2016/679 (GDPR)

1. Data Controller

This notice is provided by:

IDROAM SRL
Via della Piramide Cestia 1b
00153 Roma
VAT No.: 16940891001
Email: info@idroam.it

The Data Controller is responsible for the collection, processing and management of personal data in the manner described in this notice.

2. Types of Data Collected

2.1 Browsing Data

During navigation of the website, our system automatically collects certain technical information:

  • Device IP address
  • Browser type and operating system
  • Pages visited and time spent
  • Referring URL (referrer)
  • Date and time of access
  • Approximate geolocation data

This data is collected via server log files and web analytics tools.

2.2 Voluntarily Provided Data

When a user completes forms or contacts the Controller, the following personal data may be collected:

  • First and last name
  • Email address
  • Phone number
  • Company name and VAT number (for business clients)
  • Home or business address
  • Information provided in messages and communications
  • Data relating to the service requested

Such data is collected solely with the data subject's explicit consent.

2.3 Cookies and Similar Technologies

The website uses technical and profiling cookies to improve the browsing experience. Cookies are classified as follows:

  • Technical Cookies: Necessary for the functioning of the website and security
  • Session Cookies: Track the user's navigation during the visit
  • Persistent Cookies: Store user preferences
  • Profiling Cookies: Used for marketing and analytics purposes (subject to consent)

For further information on the cookies used, please refer to our Cookie Policy.

3. Purposes of Processing

Personal data collected is processed for the following purposes:

  • Provision of requested services: Performance of contracts and provision of consultancy in the hydraulic engineering sector
  • Commercial communications: Sending information about products and services (subject to authorisation)
  • Handling enquiries: Responding to questions and contact requests
  • Analysis and improvement: Analysing browsing data to improve the website and services offered
  • Regulatory compliance: Fulfilment of legal and fiscal obligations
  • Fraud prevention: Protection of website security and user data
  • Marketing purposes: Creation of profiles for personalised advertising (subject to consent)
  • Newsletter distribution: Periodic communications relating to company activities (following subscription)

4. Legal Basis for Processing

The processing of personal data is based on the following legal grounds pursuant to Art. 6 GDPR:

  • Art. 6(1)(a) GDPR: Consent of the data subject (for profiling cookies, marketing, newsletter)
  • Art. 6(1)(b) GDPR: Necessity for the performance of a contract (provision of services)
  • Art. 6(1)(c) GDPR: Compliance with legal obligations (taxation, sector-specific regulations)
  • Art. 6(1)(f) GDPR: Legitimate interests of the Controller (website security, fraud prevention)

For the processing of special categories of data (where applicable), reference is made to Art. 9 GDPR and its exceptions.

5. Processing Methods

Personal data is processed by means of:

  • Manual Processing: Direct management by authorised personnel
  • Automated Processing: Processing via IT systems and databases
  • Backup Systems: Secure storage of data on protected servers
  • Analytics Tools: Use of platforms to analyse user behaviour
Security Measures: All data is protected by appropriate technical and organisational measures, including: SSL/TLS encryption, authentication, access control, regular backups, and continuous security monitoring.

6. Data Retention Period

Personal data is retained according to the following criteria:

  • Browsing Data: Retained for a maximum of 13 months, unless otherwise required by law
  • Voluntarily Provided Data: Retained for the duration of the commercial relationship and subsequently for the period required by legal obligations (generally 10 years for tax purposes)
  • Newsletter Data: Retained until the subscription is cancelled
  • Profiling Cookies: Retained according to the set duration (maximum 13 months)

Once the retention period has expired, data is deleted or anonymised, unless retention obligations under applicable law apply.

7. Data Subject Rights

Under the GDPR, every data subject has the right to exercise the following rights by contacting the Controller:

7.1 Right of Access (Art. 15 GDPR)

The data subject has the right to access their personal data and to obtain confirmation of any ongoing processing.

7.2 Right to Rectification (Art. 16 GDPR)

The data subject may request the correction of inaccurate or incomplete data.

7.3 Right to Erasure (Art. 17 GDPR)

The data subject may request the deletion of their personal data ("right to be forgotten"), subject to limitations provided by law.

7.4 Right to Restriction of Processing (Art. 18 GDPR)

The data subject may request the restriction of processing of their data in certain circumstances.

7.5 Right to Data Portability (Art. 20 GDPR)

The data subject has the right to receive their personal data in a structured, commonly used format, and to transfer it to another controller.

7.6 Right to Object (Art. 21 GDPR)

The data subject may object to the processing of their data for direct marketing purposes and for profiling based on the legitimate interests of the Controller.

7.7 Rights Relating to Automated Decision-Making (Art. 22 GDPR)

The data subject has the right not to be subject to a decision based solely on automated processing of their data.

How to Exercise Your Rights

To exercise any of the rights listed above, the data subject must contact the Controller at info@idroam.it or by post at: Via della Piramide Cestia 1b, 00153 Roma. The request must contain sufficient information to identify the data subject.

The Controller will respond to the request within 30 days, or 60 days in the case of complex requests.

8. Transfer of Data to Third Countries

Personal data is not transferred to countries outside the European Union, except in the following cases:

  • The recipient country has been recognised by the European Commission as providing an adequate level of protection
  • Appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission
  • The data subject has given explicit consent to the transfer

In the event of a transfer, the Controller takes all necessary measures to ensure a level of protection equivalent to that guaranteed within the EU.

9. Cookies and Tracking Technologies

This website uses cookies and similar technologies to improve the user experience. For a detailed description of the cookies used, their purposes and how to manage them, please refer to our Cookie Policy, available in the website footer.

Users may at any time modify their cookie preferences via the controls in the "Cookie Preferences" section of the website.

10. Changes to this Privacy Policy

This privacy policy is subject to periodic changes and updates to reflect developments in legislation, data processing practices, or business operations. The Controller reserves the right to modify this policy at any time.

Material changes will be communicated to data subjects by email or via a prominent notice on the website. Continued use of the website following such changes constitutes acceptance of the updated policy.

Last updated: 3 March 2026

11. Controller and Data Protection Officer Contacts

Data Controller

IDROAM SRL
Via della Piramide Cestia 1b
00153 Roma
VAT No.: 16940891001
Email: info@idroam.it
Phone: Available on the website

Data Protection Officer (DPO)

For specific matters concerning the protection of personal data, please contact the Data Protection Officer (DPO) at: privacy@idroam.it (if appointed).

Right to Lodge a Complaint

The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante Privacy) if they believe that the processing of their data violates the provisions of the GDPR. The complaint may be submitted online at www.garanteprivacy.it or at the Authority's offices at Piazza di Monte Citorio 121, 00186 Roma.

Questions About Privacy?

If you have any queries or wish to submit a request regarding your personal data, please contact us today. Our team is available to assist you.

Contact Us