Privacy Policy
(in accordance with Regulation (EU) 2016/679 – the “GDPR”)
1. Data Controller and contact details
The website marcodimarzio.com (hereinafter, the “Website”) is owned and operated by:
marcodimarzio.com
VAT no. 07472470967
Via Coluccio Salutati 7, 20144 – Milan (MI) – Italy
(referred to as the “Company”)
The Company is the Data Controller for all personal data collected through the Website.
You can contact us for any information regarding the processing of your personal data or to exercise your rights at the following addresses:
- Postal address: Via Coluccio Salutati 7, 20144 – Milan (MI), Italy
- Email: privacy@marcodimarzio.com
The Company has appointed a Data Protection Officer (“DPO”).
You can contact the DPO by writing to: privacy@marcodimarzio.com
and indicating “Data Protection Officer” in the subject line.
2. What personal data we collect
When you browse or use the services offered on marcodimarzio.com, we may process different categories of personal data:
- Data for purchases and invoicing
- First name and surname
- Email address
- Billing address
- Payment details (processed through secure payment providers)
- Data for newsletters and free content
- Email address and any additional information you decide to provide
- Data may be collected through:
- forms available on marcodimarzio.com
- social campaigns (e.g. Facebook, Instagram)
- connected websites such as iniziareacorrere.it and bicidacorsa.info (e.g. PDF downloads or newsletter sign-ups)
- Data for support and contact requests
- Data you voluntarily provide in contact forms or emails (e.g. name, email address, message content) in order to receive support or information.
- Website account data (if/when available)
- First name and surname
- Email address
- Password
- Information about your logins and use of any reserved area
- If you log in via social media (e.g. Facebook): the minimum data required for registration/authentication (usually email address and profile identifier).
- Browsing data
- Information on how you use the Website (pages visited, time spent on each page, clicks), collected through analytics tools and stored on our servers or on those of third-party providers (e.g. web analytics systems).
- Third-party data
- If you purchase a product to be delivered to someone else (e.g. as a gift), you may provide us with the recipient’s name, email address or postal address. In doing so, you undertake to provide such data lawfully. The Company will send the recipient, at the earliest appropriate opportunity, a privacy notice explaining how their data is processed.
- CVs and applications
- If you send us your CV for collaboration or job opportunities, we will process the personal data included in your CV solely to assess your application.
The Company does not knowingly process personal data of minors. By using the Website, you confirm that you are at least 18 years of age.
3. Why we use your personal data
We use your personal data for the following purposes:
- Order and contract management
- To conclude and perform purchase contracts (e.g. eBooks, printed books, training services, consultancy).
- To manage payments, invoicing, returns (where applicable) and post-sales support.
- To perform anti-fraud checks in case of card payments.
- Registration and reserved area services (if available)
- To create and manage your user account.
- To provide services reserved to registered users (order history, stored data, preferences).
- Provision of digital services and customer support
- To provide digital content (PDFs, training programs, downloadable materials).
- To handle your information or support requests via email or contact forms.
- Newsletters and “soft opt-in” communications
- If you purchase a product on the Website, we may send you emails about products or services similar to those you have already purchased (so-called “soft spam” or “soft opt-in”), unless you object.
- Marketing and promotion (only with your consent)
- To send newsletters and promotional communications about marcodimarzio.com, digital books, training services and related products.
- To contact you using the channels you have indicated: email, SMS, phone, regular mail, WhatsApp.
- To carry out surveys and research aimed at measuring customer satisfaction and improving our services.
- Personalisation of your experience (only with your consent)
- To analyse your purchases, preferences and navigation on the Website, in order to suggest content, offers and products that are more relevant to your interests.
- Statistical analysis
- To perform analyses, in aggregate and anonymised form, on how the Website is used, with the aim of improving our offer, content structure and services.
- Management of applications
- To evaluate CVs and collaboration or job requests.
4. Legal bases for processing
We process your personal data only where at least one of the legal bases provided for by the GDPR applies:
- Performance of a contract
- For managing orders, payments, invoicing, customer care, registration to the Website and provision of the related services.
- Compliance with legal obligations
- For example, for accounting and tax requirements, storing invoices, and complying with other statutory obligations.
- Legitimate interests of the Company
- To prevent and combat fraud related to payments.
- To improve the services we offer and ensure IT security.
- To send “soft opt-in” communications about products/services similar to those you have already purchased, while respecting your rights and interests.
- Explicit consent
- For marketing activities, newsletters and general promotional communications.
- For profiling and personalisation of offers.
- For surveys, market research and customer satisfaction initiatives.
Providing your data for contractual and legal purposes is necessary: if you do not provide such data, we may not be able to offer you the requested services.
Providing your data for marketing and profiling purposes is optional: if you do not consent, you can still use the Website and purchase products.
5. Who processes your data
Your personal data may be processed by:
- Internal staff of the Company
- Employees and collaborators who are duly authorised and instructed.
- Service providers and third parties (Data Processors)
- IT and hosting service providers
- Payment platforms
- Couriers and logistics providers (for any physical shipments)
- Email marketing and campaign management providers
- Companies specialised in market research and web analytics
- These parties process personal data on the basis of written agreements and documented instructions from the Company, in compliance with applicable data protection laws.
- Public authorities
- Law enforcement bodies, judicial or administrative authorities, where required by law or to protect the rights and interests of the Company or third parties.
6. Transfers of data outside the European Union
Some of our service providers (for example, email marketing platforms or analytics tools) may be located in countries outside the European Union.
In such cases, any transfer of personal data:
- takes place to countries for which the European Commission has issued an adequacy decision, or
- is regulated through standard contractual clauses or other appropriate safeguards provided for by the GDPR.
7. Data retention periods
We retain your personal data only for as long as is strictly necessary to fulfil the purposes for which they were collected, in accordance with legal limits. In particular:
- Purchase and invoicing data: for the time necessary to manage the order and for up to 10 years from the invoice date (for accounting and tax obligations).
- User account data: until you request closure of your account or, in case of prolonged inactivity, for a reasonable period, in line with applicable legal or regulatory requirements.
- Data for digital services and support: until the service has been completed or the support request has been closed.
- Data for newsletters, marketing and profiling: until you withdraw your consent and, in any case, no longer than 2 years from your last significant interaction (e.g. opening an email, making a purchase, logging in).
- Data used for soft opt-in communications: until you object to the processing.
- CVs: for up to 6 months from receipt, unless a different period is required by applicable law.
Once the relevant retention period has expired, the data will be deleted or irreversibly anonymised.
8. Your rights
At any time, you may exercise the rights granted to you by the GDPR in relation to your personal data. In particular, you have the right to:
- Access your personal data and obtain information on how they are processed.
- Request the rectification of inaccurate data or the completion of incomplete data.
- Withdraw your consent at any time, for all processing activities based on consent (e.g. marketing, profiling).
- Object to processing based on the Company’s legitimate interest, explaining the reasons related to your particular situation.
- Request the deletion of your data (“right to be forgotten”) in the cases provided for by law.
- Request restriction of processing when the conditions laid down in the GDPR are met.
- Request data portability, receiving your personal data in a structured, commonly used and machine-readable format, or asking for them to be transmitted directly to another controller, where technically feasible.
You can exercise these rights:
- by accessing your personal area on the Website (if available); or
- by writing to privacy@marcodimarzio.com.
To protect your data, we may ask you for certain information necessary to verify your identity before acting on your request.
9. Data security
We implement appropriate technical and organisational measures to protect your personal data against:
- unauthorised access,
- unlawful or fraudulent use,
- accidental loss, destruction or damage.
These measures include, for example:
- use of secure communication protocols,
- pseudonymisation and/or encryption systems,
- access controls and authentication procedures,
- backup systems and disaster recovery procedures in case of security incidents.
These measures are tested and updated periodically to maintain an adequate level of protection.
10. Complaints and protection of your rights
If you believe that the processing of your personal data through the Website is in breach of applicable data protection laws, you may:
- contact us directly by writing to privacy@marcodimarzio.com; and/or
- lodge a complaint with the Italian Data Protection Authority (“Garante per la Protezione dei Dati Personali”).
Updated information on how to lodge a complaint is available on the Authority’s website: www.garanteprivacy.it
.
11. Changes to this privacy notice
This privacy notice may be updated over time, for example due to:
- changes in the services offered on the Website,
- organisational changes within the Company,
- regulatory updates.
The most recent version is always available on this page, indicating the date of the last update. We encourage you to review it periodically.
12. Legal framework
The processing of your personal data is carried out in compliance with:
- Regulation (EU) 2016/679 (the “GDPR”)
- Italian data protection law and the relevant decisions and guidelines issued by the competent Supervisory Authority (Garante per la Protezione dei Dati Personali).
