Skip to content
Caricamento… / Loading…

Privacy Policy

PERSONAL DATA PROCESSING NOTICE

Privacy Policy of the website wsbarrier.com

Data Controller Wood & Steel S.r.l.
Website wsbarrier.com
Document Notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
Version 1.0
Publication date 6 August 2026

Table of contents

1. Introduction, legal framework and scope

2. Definitions

3. Data Controller and contact details

4. Categories of data subjects and of personal data processed

5. Purposes, legal bases and retention periods

6. Nature of data provision and consequences of failure to provide data

7. Processing methods and security measures

8. Use of artificial intelligence systems

9. Absence of automated decision-making

10. Recipients and categories of recipients

11. Transfers of data to third countries

12. Data subjects’ rights and how to exercise them

13. Complaints to the supervisory authority

14. Personal data not obtained from the data subject

15. Minors

16. Updates to this notice and version history

Art. 1 – Introduction, legal framework and scope

1.1 Wood & Steel S.r.l. (hereinafter, the “Controller“) regards the protection of personal data as a fundamental value of its business and processes personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality set out in Article 5 of Regulation (EU) 2016/679.

1.2 This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR“) and to Italian Legislative Decree no. 196 of 30 June 2003 (the “Italian Privacy Code“), as amended by Legislative Decree no. 101 of 10 August 2018, and in accordance with the decisions and guidelines of the Italian Data Protection Authority (Garante per la protezione dei dati personali).

1.3 This notice applies to: (a) users browsing the website wsbarrier.com (the “Website“) and using its services (contact form, newsletter subscription, material downloads); (b) individuals interacting with the Controller outside the Website, such as senders of commercial and technical enquiries, contact persons of customers, suppliers and partners, and candidates spontaneously submitting their CVs.

1.4 This notice does not apply to other third-party websites, platforms or services that may be reached via links on the Website, over which the Controller has no control and for which it accepts no responsibility. For the use of cookies and other tracking tools, please refer to the Website’s Cookie Policy, which forms an integral part of this notice.

Art. 2 – Definitions

For the purposes of this notice, in accordance with Article 4 GDPR:

Term Definition
Personal data Any information relating to an identified or identifiable natural person (“data subject”)
Processing Any operation performed on personal data, such as collection, recording, organisation, storage, consultation, use, disclosure, erasure
Data controller The natural or legal person which determines the purposes and means of the processing of personal data
Data processor The natural or legal person which processes personal data on behalf of the controller, pursuant to Article 28 GDPR
Data subject The natural person to whom the personal data relate
Consent Any freely given, specific, informed and unambiguous indication of the data subject’s wishes
Special categories of data Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, sex life or sexual orientation (Article 9 GDPR)

Art. 3 – Data Controller and contact details

3.1 The Data Controller is:

Wood & Steel S.r.l.

Registered office: Via Volturno, 31 – 25126 Brescia (BS), Italy

VAT no. / Tax code: 04714280981

Email: info@wsbarrier.com

Phone: +39 030 7778981

3.2 The Controller has not appointed a Data Protection Officer (DPO), as the conditions making such appointment mandatory under Article 37(1) GDPR do not currently apply. Any request or communication concerning the protection of personal data may be addressed to the contact details set out in paragraph 3.1, specifying “Privacy” in the subject line.

Art. 4 – Categories of data subjects and of personal data processed

4.1 Website users – browsing data. The IT systems and software procedures used to operate the Website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP addresses, domain names of the devices used, URI/URL addresses of the requested resources, time of the request, method used to submit the request to the server, size of the file obtained in response, numerical code indicating the status of the server’s response, and other parameters relating to the user’s operating system and IT environment.

4.2 Website users – data provided voluntarily. Identification and contact data (by way of example: first name, surname, company, email address, telephone number) and any other information provided by the user through: (a) the contact form; (b) newsletter subscription; (c) forms for downloading informational and technical material; (d) spontaneous messages sent to the email addresses or telephone numbers published on the Website.

4.3 Cookies and tracking tools. For information on cookies and similar technologies, please refer to the Website’s Cookie Policy.

4.4 Contact persons of customers, suppliers and partners. Identification, contact and professional data of owners, legal representatives, employees and collaborators of customers, suppliers and business partners, processed in connection with commercial and technical enquiries, offers, quotations, projects, orders, contracts and related obligations, including where collected outside the Website (email, telephone, meetings, trade fairs and events).

4.5 Candidates. Data contained in CVs and cover letters sent spontaneously by email. The “Work with us” section of the Website is purely informational and does not collect applications through forms.

4.6 Special categories of data and judicial data. The Website and the Controller’s services are not intended to collect special categories of data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR). Users are requested not to provide such data through forms or communications addressed to the Controller. Any such data spontaneously included in CVs will be processed within the limits of Article 9(2)(b) GDPR and of the applicable general authorisations; in all other cases, irrelevant data will be erased.

Art. 5 – Purposes, legal bases and retention periods

The Controller processes personal data for the purposes, on the legal bases and for the retention periods set out in the table below.

Ref. Purpose of processing Legal basis Retention period
A Enabling browsing of the Website, ensuring its proper functioning and security, preventing and detecting abuse, fraudulent activity and cyber attacks (including through Google reCAPTCHA) Legitimate interest of the Controller in the functionality and security of the Website – Art. 6(1)(f) GDPR Maximum 12 months (server logs), unless needed to investigate unlawful conduct
B Responding to requests for information and to commercial and technical enquiries received via the contact form, email or telephone Performance of pre-contractual measures taken at the data subject’s request – Art. 6(1)(b) GDPR Time needed to respond and, thereafter, up to 24 months from the last contact
C Sending the newsletter containing updates and informational and promotional content on the Controller’s products, solutions and activities Consent of the data subject – Art. 6(1)(a) GDPR Until consent is withdrawn (unsubscription)
D Providing the download service for informational and technical material requested by the user Performance of the service requested by the data subject – Art. 6(1)(b) GDPR Up to 24 months from the request, unless the user subscribes to the newsletter
E Sending, by email, promotional communications concerning products or services similar to those already provided to the customer (“soft spam” – Art. 130(4) of the Italian Privacy Code) Legitimate interest of the Controller – Art. 6(1)(f) GDPR, subject to the right to object at any time Until the data subject objects or the commercial relevance of the relationship ceases
F Managing contractual relationships with customers and suppliers: offers, quotations, orders, projects, contract performance, invoicing, administrative, accounting and tax management Performance of a contract – Art. 6(1)(b) GDPR; compliance with legal obligations – Art. 6(1)(c) GDPR Duration of the relationship and, thereafter, 10 years (Art. 2220 of the Italian Civil Code; tax legislation)
G Receiving and assessing unsolicited applications with a view to possible employment or collaboration Pre-contractual measures – Art. 6(1)(b) GDPR; Art. 111-bis of the Italian Privacy Code; for any special categories of data, Art. 9(2)(b) GDPR 12 months from receipt, unless the candidate consents to a longer period
H Establishing, exercising or defending a right of the Controller in judicial, arbitration or out-of-court proceedings Legitimate interest of the Controller – Art. 6(1)(f) GDPR Until the dispute is settled and appeal deadlines have expired
I Complying with obligations under laws, regulations and national and EU legislation, or with lawful orders and requests of the authorities Legal obligation – Art. 6(1)(c) GDPR Periods set by the legislation applicable from time to time

Once the above periods have elapsed, personal data are erased, destroyed or irreversibly anonymised, subject to technical back-up procedures and legal obligations.

Art. 6 – Nature of data provision and consequences of failure to provide data

6.1 Providing data for the purposes under letters B and D of Art. 5 is optional but necessary to fulfil the request: failure to provide the data marked as mandatory in the forms will make it impossible to respond or to provide the requested service.

6.2 Providing data for the purpose under letter C (newsletter) is optional and subject to consent, which may be freely withdrawn at any time via the unsubscribe link at the bottom of each communication or by writing to info@wsbarrier.com, without affecting the lawfulness of processing carried out before withdrawal.

6.3 Providing data for the purposes under letters F and I is necessary for the management of the contractual relationship and for compliance with legal obligations: failure to provide such data will make it impossible to establish or continue the relationship.

Art. 7 – Processing methods and security measures

7.1 Processing is carried out both by electronic and IT means and, residually, on paper, by persons authorised and instructed pursuant to Article 29 GDPR and Article 2-quaterdecies of the Italian Privacy Code, with logic strictly related to the stated purposes.

7.2 The Controller adopts adequate technical and organisational measures pursuant to Article 32 GDPR — by way of example: encrypted transmission protocols (HTTPS/TLS), access control, periodic back-ups, system updates, selection of qualified suppliers — in order to ensure a level of security appropriate to the risk and to prevent loss, unlawful or improper use of, and unauthorised access to, the data.

7.3 The Website’s hosting infrastructure is located in data centres in the Frankfurt region (Germany), within the European Union.

Art. 8 – Use of artificial intelligence systems

8.1 The Controller may use, as support tools for its activities (by way of example: managing, classifying and routing enquiries; document processing and summarisation; translations; preparation of draft replies), artificial intelligence systems that are proprietary or provided by third-party suppliers established in the European Union.

8.2 Such systems are used exclusively under human supervision and in accordance with the principles of data minimisation and purpose limitation. The system suppliers are appointed as data processors pursuant to Article 28 GDPR, under agreements which: (a) bind the processing to the Controller’s documented instructions; (b) impose adequate security measures; (c) restrict the supplier’s use of the data for its own purposes, including model training.

8.3 The use of such systems also complies, insofar as applicable to the Controller in its capacity as deployer, with Regulation (EU) 2024/1689 (the “AI Act“), with particular regard to the obligations concerning AI literacy of staff (Art. 4) and transparency (Art. 50). The Controller does not use artificial intelligence systems classified as high-risk under Annex III of the AI Act, nor practices prohibited under Article 5 of that Regulation.

Art. 9 – Absence of automated decision-making

The Controller does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning data subjects or similarly significantly affect them, within the meaning of Article 22 GDPR.

Art. 10 – Recipients and categories of recipients

10.1 Personal data may be disclosed, strictly within the limits relevant to the stated purposes, to the following categories of recipients:

Category of recipients Examples Privacy role
The Controller’s internal staff Sales, technical and administrative staff Authorised persons under Art. 29 GDPR
Hosting and infrastructure providers Hostinger (data centres in the Frankfurt region, Germany) Processor under Art. 28 GDPR
Email and productivity service providers Google Ireland Ltd (Google Workspace) Processor under Art. 28 GDPR
Domain management Register.it S.p.A. Processor under Art. 28 GDPR
Providers of the Website’s statistical and functional services Google Ireland Ltd (Google Analytics 4, Tag Manager, Maps, YouTube, reCAPTCHA – see Cookie Policy) Processor under Art. 28 GDPR / independent controller for its own processing
Newsletter platforms Email marketing service provider Processor under Art. 28 GDPR
Providers of artificial intelligence systems Suppliers established in the EU (see Art. 8) Processor under Art. 28 GDPR
IT and Website maintenance providers Web agency, system administrators Processor under Art. 28 GDPR
Professionals and consultants Legal, administrative, accounting, tax and labour advisors Processors under Art. 28 GDPR or independent controllers, depending on the engagement
Banks and payment institutions Banks for collections and payments Independent controllers
Public authorities and supervisory bodies Tax authorities, judicial authorities Independent controllers

10.2 The updated and complete list of data processors is kept at the Controller’s registered office and is available on request by writing to info@wsbarrier.com.

10.3 Personal data are in no case disseminated, nor transferred to third parties for their own marketing purposes.

Art. 11 – Transfers of data to third countries

11.1 Personal data are processed and stored within the European Union. The Controller does not transfer personal data to third countries or international organisations on its own initiative, and selects suppliers — including providers of artificial intelligence systems — established in the European Union.

11.2 However, the use of certain services provided by companies of the Google group (Google Workspace, Google Analytics 4, Google Tag Manager, Google Maps, YouTube, reCAPTCHA) may involve the transfer of personal data to the United States of America. Such transfers take place in compliance with Chapter V of the GDPR, on the basis of: (a) the European Commission’s adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework, under which Google LLC is certified; and, where applicable, (b) the standard contractual clauses approved by the European Commission pursuant to Article 46(2)(c) GDPR, supplemented where necessary by additional measures.

11.3 A copy of the safeguards applied may be requested from the Controller at the contact details set out in Art. 3.

Art. 12 – Data subjects’ rights and how to exercise them

12.1 Data subjects may exercise the following rights against the Controller under Articles 15-22 GDPR:

Right Content Reference
Access To obtain confirmation as to whether processing is taking place and a copy of the data, together with information on the processing Art. 15 GDPR
Rectification To obtain the correction of inaccurate data and the completion of incomplete data Art. 16 GDPR
Erasure (“right to be forgotten”) To obtain the erasure of the data, in the cases provided for Art. 17 GDPR
Restriction To obtain the restriction of processing, in the cases provided for Art. 18 GDPR
Portability To receive the data processed by automated means on the basis of consent or contract in a structured, commonly used and machine-readable format, and to transmit them to another controller Art. 20 GDPR
Objection To object at any time, on grounds relating to their particular situation, to processing based on legitimate interest; to object in any case to processing for direct marketing purposes, including the communications referred to in Art. 5, letter E Art. 21 GDPR
Withdrawal of consent To withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal Art. 7(3) GDPR

12.2 Requests may be submitted, without formalities, by writing to info@wsbarrier.com or by post to the registered office address (Art. 3). The Controller will respond within one month of receiving the request; this period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case the data subject will be informed with the reasons for the extension (Article 12 GDPR).

12.3 The exercise of rights is, in principle, free of charge. In the case of manifestly unfounded or excessive requests, in particular because of their repetitive character, the Controller may charge a reasonable fee or refuse to act on the request, pursuant to Article 12(5) GDPR.

Art. 13 – Complaints to the supervisory authority

Data subjects who consider that the processing of their personal data infringes the applicable legislation have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it — pursuant to Article 77 GDPR, or with the supervisory authority of the EU Member State in which they habitually reside, work or where the alleged infringement occurred, without prejudice to judicial remedies under Articles 78 and 79 GDPR.

Art. 14 – Personal data not obtained from the data subject

With regard to the personal data of company contact persons (employees and collaborators of customers, suppliers and partners) communicated to the Controller by parties other than the data subject, pursuant to Article 14 GDPR it is specified that: (a) the source of the data is the organisation on whose behalf the contact person acts, or publicly accessible sources (company websites, public registers); (b) the categories of data processed are those set out in paragraph 4.4; (c) the data are processed solely for the purposes under letters B, E, F, H and I of Art. 5. This notice is made available to such data subjects through publication on the Website and, where appropriate, by reference in the Controller’s communications.

Art. 15 – Minors

The Website and the Controller’s services are intended for a professional audience and are not directed at children under 14 years of age. The Controller does not knowingly collect personal data from minors. Should it become aware of the processing of minors’ data carried out without the conditions set out in Article 8 GDPR and Article 2-quinquies of the Italian Privacy Code, the Controller will promptly erase the data.

Art. 16 – Updates to this notice and version history

16.1 The Controller reserves the right to amend or update this notice at any time, including as a result of regulatory or organisational changes or changes in the services offered. Updated versions are published on this page with an indication of the version and date; in the event of substantial changes, the Controller may give notice thereof by additional means.

16.2 Version history:

Version Date Description
1.0 6 August 2026 First publication

Wood & Steel S.r.l. – Via Volturno, 31 – 25126 Brescia (BS), Italy – VAT/Tax code 04714280981 – info@wsbarrier.com – +39 030 7778981