PRIVACY POLICY
CASTLEX is committed to respect the privacy of individuals with whom it comes into contact, in accordance with the provisions of Regulation (EU) no. 679/2016 (“GDPR”) and the national legislation on privacy (Legislative Decree no. 196/2003 and subsequent amendments and additions). Pursuant to Article 13 of the GDPR, we provide you with some information necessary to illustrate how we will use and process your personal data.
Data Controller – Personal data of identified or identifiable persons are collected and may be handled following the visit to this site. The “Data Controller” is Avv. Stefano Cassamagnaghi, with registered office in 20122 Milano, Via Durini, 24.
Data Processing Place – Data processing connected to this site’s web services are carried out at the Milan office of Castlex and are only managed by technical staff in charge of processing, or in charge of maintenance.
Type of Data
Navigation Data
Information systems and software procedures which are set up to operate this web site, in the normal course of operations collect some personal data the transmission of which is implied when using internet communication protocols.
These are information that are not collected to be associated with identified subjects, but due to their intrinsic nature may, through processing and in conjunction with data held by third parties, allow the identification of users.
This category of data include: IP addresses or users’ computers domain names that connect to the site, URI (Uniform Resource Identifier) identifier for request of resources, request time, submission-to-server method request, obtained reply file size, code describing server’s services status (success, error, etc.) and other
parameters relating to the operating system and user’s environment variables.
These data are only used to collect anonymous statistical information about visits to the site and control its proper functioning and are immediately deleted after processing. The data may be used to determine responsibility in the event of piracy or site hacking: except for this risk, normally, contact details are stored for no more than seven days.
These are information that are not collected to be associated with identified subjects, but due to their intrinsic nature may, through processing and in conjunction with data held by third parties, allow the identification of users.
This category of data include: IP addresses or users’ computers domain names that connect to the site, URI (Uniform Resource Identifier) identifier for request of resources, request time, submission-to-server method request, obtained reply file size, code describing server’s services status (success, error, etc.) and other
parameters relating to the operating system and user’s environment variables.
These data are only used to collect anonymous statistical information about visits to the site and control its proper functioning and are immediately deleted after processing. The data may be used to determine responsibility in the event of piracy or site hacking: except for this risk, normally, contact details are stored for no more than seven days.
Data voluntarily supplied by user
Discretionary, explicit and voluntary transmission of electronic mail to the addresses of this site will cause the collection of user’s address in order to reply to requests, possibly in addition to other personal data contained in the dispatch. Upon request, certain summary lines shall progressively be visualized on the site’s web pages.
Cookies
The site does not intentionally collect any of the users’ personal data.
No cookies or tracing systems of any sort are used in the transmission of personal information.
The use of session cookies (that are not permanently saved on user’s computer and are deleted once the browser is closed) is strictly limited to identification of session’s information (server’s randomly generated numbers) which are necessary to move easily and securely around the site.
Session cookies avoid the use of other means of information technology, which may potentially prejudice users’ privacy when moving around the site, and do not allow the collection of user’s identifiable personal data.
In any event, if the user chooses to decline the download to his computer of any type of cookies either from Castòex site, the user may increase the privacy protection level by modifying the browser’s settings.
No cookies or tracing systems of any sort are used in the transmission of personal information.
The use of session cookies (that are not permanently saved on user’s computer and are deleted once the browser is closed) is strictly limited to identification of session’s information (server’s randomly generated numbers) which are necessary to move easily and securely around the site.
Session cookies avoid the use of other means of information technology, which may potentially prejudice users’ privacy when moving around the site, and do not allow the collection of user’s identifiable personal data.
In any event, if the user chooses to decline the download to his computer of any type of cookies either from Castòex site, the user may increase the privacy protection level by modifying the browser’s settings.
Castlex informs that pursuant to article 7 of legislative decree 30th June 2003, n. 196, users may require at any time the deletion of information collected through cookies.
Choice to Supply Data – In addition to what has been mentioned in connection with navigation data, the user has the choice to supply personal data on designated forms to request receipt of information or other type of communications.
In absence of such data it might be impossible to fulfill your request.
In absence of such data it might be impossible to fulfill your request.
Processing Methods – Personal data are automatically processed, strictly during the time required for the purposes of their intended use.
Appropriate security measures are set up to prevent loss, unlawful use and inappropriate or unauthorized access of data. Castlex has adopted all minimumsecurity measures provided by law.
Communication and Data Disclosure – Collected data may be transferred or communicated, strictly for the intended and necessary purposes, to other offices of Castlex, for service operations, such as information systems management, or for processing carried out by such offices for the same purposes.
Personal data furnished by users who request information (pamphlets and information etc.) are only used in connection with the fulfillment of such services or information offers and are only released to third parties only if
necessary to carry out the services (companies which provide envelopes, labeling and mailing).
Save for such cases, data shall not be disclosed or ceded unless:
1. Written consent to share data with third parties is available;
2. A need exists to share information with third parties in order to provide the requested service;
3. A need exists to comply with requests made by judicial or public security authorities.
No data collected from the web site is disclosed to third parties.
Personal data furnished by users who request information (pamphlets and information etc.) are only used in connection with the fulfillment of such services or information offers and are only released to third parties only if
necessary to carry out the services (companies which provide envelopes, labeling and mailing).
Save for such cases, data shall not be disclosed or ceded unless:
1. Written consent to share data with third parties is available;
2. A need exists to share information with third parties in order to provide the requested service;
3. A need exists to comply with requests made by judicial or public security authorities.
No data collected from the web site is disclosed to third parties.
Users Access Rights – The subjects whose personal data are processed, may at any time obtain confirmation of the presence or absence of such data, and are entitled to know their content and source, check for accuracy and request to supplement, update, or correct such data (art. 7 of Legislative Decree dated 30th June 2003, n. 196).
Also, pursuant to the same article, these subjects are entitled to request the destruction of data handled in violation of law, render data unidentifiable or inaccessible, and forbid their handling.
Also, pursuant to the same article, these subjects are entitled to request the destruction of data handled in violation of law, render data unidentifiable or inaccessible, and forbid their handling.



