Skip to main content

IMS S.p.A.

Information Notice pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR)

I – GENERAL INFORMATION

1. Information Relating to the Website

1.1​This information notice describes how the website https://imspiping.com/ is managed with regard to the processing of the personal data of users who consult it. The website illustrates the activities and services of I.M.S. S.p.A., with registered office in Genoa, Via Evandro Ferri 26, 16161, Italy – VAT No. IT02806150104 – Certified E-mail (PEC): imsspa@pec.imspiping.com.

1.2​This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter, the “GDPR”) and Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (hereinafter, the “Privacy Code”), for individuals interacting with the website.

1.3​This notice applies exclusively to the website https://imspiping.com/ and not to any other websites that may be accessed by users through links contained therein.

1.4​The use of cookies and other tracking technologies is governed by the Cookie Policy available on the website, which forms an integral part of this notice.

1.5​The website is intended for users over 14 years of age, pursuant to Article 8, para. 1GDPR and Article 2-quinquies of the Privacy Code. By accessing the website and providing personal data, the data subject declares that he or she is over 14 years of age.

 

II – PARTIES INVOLVED IN THE PROCESSING

2. Data Controller

2.1​The Data Controller is I.M.S. S.p.A., represented by its legal representative pro tempore, with registered office in Genoa, Via Evandro Ferri 26, 16161, Italy.

2.2​For any clarification or to exercise the rights set out in Section IV below, the Data Controller may be contacted at: info@imspiping.com.

3. Data Processors

3.1​Data Processor is a natural or legal person who processes personal data on behalf of the Data Controller.

3.2​Pursuant to Article 28 GDPR, the Data Controller appoints as Data Processors third-party service providers that may access the personal data of data subjects, including, by way of example, the provider of hosting and domain registration services and the provider of the cookie consent management platform.

3.3​The updated list of Data Processors is maintained at the Data Controller’s registered office and may be requested by writing to info@imspiping.com.

4. Place of Data Processing

4.1​Processing activities relating to the website services take place at the Data Controller’s premises and at the data centers of the providers appointed as Data Processors, except as specified in Section 10 below.

 

 

III – DATA PROCESSED

5. Categories of Data and Processing Methods

5.1​Navigation Data. The IT systems and software procedures used to operate the website acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols. These data include, in particular:

● URI/URL addresses of the resources requested;
● time of the request;
● method used to submit the request to the server;
● size of the file obtained in response;
● numerical code indicating the status of the server response;
● IP address and other parameters relating to the user’s operating system and IT environment.

5.2​These data are processed in aggregated form in order to obtain anonymous statistical information on the use of the website, verify its proper functioning, and ensure security. They are deleted within 90 days of collection.

5.3​Contact Form. When completing the form available in the “Contacts” section, the following personal data are collected: first and last name, e-mail address, subject and content of the request, as well as any additional personal data voluntarily provided by the user within the message.

5.4​Job Application Form. When completing the form available in the “Careers” section, the following personal data are collected: first and last name, e-mail address, professional qualification, and the curriculum vitae uploaded by the user, including any personal data contained therein. Users are invited not to include special categories of personal data (such as health-related data) in their CV unless strictly necessary.

5.5​The optional, explicit and voluntary sending of e-mails to the addresses indicated on the website entails the acquisition of the sender’s address and any other personal data contained in the message.

5.6​Google reCAPTCHA. The pages containing the forms referred to in Sections 5.3 and 5.4 use the reCAPTCHA service provided by Google Ireland Limited and Google LLC, aimed at protecting the website against spam and misuse of the forms. The service operation involves the communication to Google of certain user data, such as the IP address and information relating to the device and browsing activity, necessary to distinguish real users from automated systems. Further information is available in Google’s Privacy Policy (https://policies.google.com/privacy).

5.7​The navigation data referred to in Section 5.1 may be used to ascertain liability in the event of cybercrimes against the website and, for security purposes (anti-spam filters, firewalls, detection of malicious software), to block attempts to damage the website or other unlawful activities. Such data are deleted within 60 days.

6. Purposes of Processing and Retention Periods

6.1​The data referred to in Section 5.3 are processed in order to respond to requests for information or quotations submitted by users, including at the pre-contractual stage, as well as, where a contractual relationship follows, for its performance and for compliance with related legal obligations (accounting, tax and similar obligations). Such data are retained for the time strictly necessary to respond to and manage the request and, in the event of a contractual relationship, for the retention periods established by the applicable legislation.

 

6.2​The data referred to in Section 5.4 are processed for the assessment of applications and any subsequent contact with the data subject. CVs are retained for the period strictly necessary for evaluation and, in the event of a negative outcome, for a maximum period of 12 months from receipt, after which they are deleted.

6.3​In any event, data are retained no longer than necessary for the purposes for which they were collected, unless retention is required by law, and may be retained for the period necessary to establish, exercise or defend a legal claim within the applicable limitation periods.

6.4​Navigation data and data processed for security purposes are retained for the periods specified respectively in Sections 5.2 and 5.7.

7. Legal Basis for Processing

7.1​The processing of navigation data referred to in Sections 5.1 and 5.7, as well as the data processed through the reCAPTCHA service referred to in Section 5.6, is based on the legitimate interest of the Data Controller (Article 6(1)(f) GDPR) in ensuring the proper functioning and security of the website and related forms.

7.2​The processing of data provided through the contact form is based on the performance of pre-contractual measures taken at the request of the data subject or on the performance of a contract to which the data subject is a party (Article 6, para. 1, letter b) GDPR); processing aimed at complying with accounting, tax and legal obligations is based on Article 6, para. 1, letter c) GDPR.

7.3​The processing of data provided through the job application form is based on the performance of pre-contractual measures taken at the request of the data subject (Article 6(1)(b) GDPR); any processing of special categories of personal data voluntarily included by the applicant in the CV is based on Article 9, para.2, letter b) and h) GDPR and on the applicable national employment legislation, insofar as relevant.

7.4​The provision of the data referred to in Sections 5.3 and 5.4 is optional; however, failure to provide such data will make it impossible for the Data Controller to respond to the request or evaluate the application.

8. Data Recipients

8.1​Data may be processed by personnel specifically authorised by the Data Controller pursuant to Article 29 GDPR and may also be disclosed to the Data Processors appointed pursuant to Article 28 GDPR referred to in Section 3.2 and, solely in relation to the reCAPTCHA service, to Google.

8.2​Data may also be disclosed to competent authorities in compliance with legal obligations. Under no circumstances are data disclosed to the public.

9. Absence of Automated Decision-Making

9.1​Processing does not involve automated decision-making processes producing legal effects concerning the data subject, including profiling, pursuant to Article 22 GDPR.

 

10. Transfers of Data to Third Countries

10.1​The provider of the cookie consent management platform is established in the United Kingdom, a country covered by an adequacy decision of the European Commission pursuant to Article 45 GDPR.

10.2​The use of the Google reCAPTCHA service referred to in Section 5.6 may involve the transfer of data to the United States of America. Such transfer is carried out on the basis of the European Commission adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework, to which Google LLC adheres, as well as, where applicable, the Standard Contractual Clauses referred to in Article 46 GDPR.

 

10.3​No further transfers are made to third countries that do not provide the safeguards required under Articles 44 et seq. of the GDPR.

IV – DATA SUBJECT RIGHTS

11. Data Subject Rights

11.1​Subject to the limits and conditions established by applicable law, the data subject may exercise the following rights: access to personal data (Article 15 GDPR); rectification (Article 16 GDPR); erasure (Article 17 GDPR); restriction of processing (Article 18 GDPR); data portability (Article 20 GDPR); and objection to processing (Article 21 GDPR).

11.2​Where processing is based on consent, the data subject has the right to withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

11.3​Requests may be submitted to the Data Controller without formalities at info@imspiping.com or at the registered office referred to in Section 2.1. The Data Controller shall respond within one month of receipt of the request, which may be extended by two additional months in cases of complexity or a high number of requests.

11.4​The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it), as the competent supervisory authority, or to seek judicial remedy before the competent courts.

V – SECURITY

12. Security Measures

12.1​The Data Controller implements appropriate technical and organisational measures pursuant to Article 32 GDPR, proportionate to the identified risks, in order to prevent personal data breaches, including unauthorised access, disclosure, alteration or destruction of data.

12.2​Processing is carried out by means of IT and electronic tools, using procedures strictly related to the stated purposes and organisational measures suitable to ensure the confidentiality, integrity and availability of data.

VI – INTELLECTUAL PROPERTY AND LIABILITY

13. Intellectual Property

13.1​All texts, graphic elements, audio files, videos, images, animations and, more generally, all information contained on the website are the property of I.M.S. S.p.A. and are protected by national and international copyright and intellectual property laws.

13.2​None of the contents referred to above may be copied, modified or resold, in whole or in part, for profit or for any other form of benefit.

13.3​Any icons, trademarks and product names appearing on the website pages are the property of their respective owners and are protected under applicable law.

14. Disclaimer of Liability

14.1​I.M.S. S.p.A. shall not be liable for any malfunction of the website, nor for any damages that may arise to users from accessing it, nor for damages deriving from third-party websites accessible through links. The presence of such links does not imply approval of those websites, for whose content I.M.S. S.p.A. accepts no responsibility.

 

14.2​I.M.S. S.p.A. makes every reasonable effort to ensure that the contents published on the website are accurate and up to date; however, it disclaims any liability for damages arising from errors, inaccuracies or omissions in such contents, as well as for any use made of them by third parties.

14.3​Any materials made available for download (technical documentation, commercial documentation, software and similar materials) are provided under the conditions established by I.M.S. S.p.A., which assumes no liability regarding their content or operation.

VII – AMENDMENTS

15. Amendments to This Notice

15.1​This notice may be subject to amendments or updates. Where material changes are made, users shall be informed by means of a dedicated notice published on the website with appropriate visibility.

15.2​Users are invited to consult this page periodically.

Version 2.0 – updated on 18/07/2026