Notice on the Processing of Personal Data collected through this website
Last revised: June 4, 2026
1. Introduction and regulatory references
This notice describes the processing of personal data collected through this website, including data acquired by means of cookies, tracking technologies and — where present — contact forms and any other features that may be active on the site.
This notice is addressed to anyone who accesses or uses this website, describing how the user’s personal data is collected, used and protected, as well as the rights granted by law.
These provisions do not concern other websites, pages or online services accessible through external links that may be present on the site, in respect of which you are invited to consult the relevant privacy notices.
This notice is provided in compliance with the principal national and international regulations on the protection of personal data, including:
- Regulation (EU) 2016/679 (GDPR) and Directive 2002/58/EC, known as the ePrivacy Directive
- UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, Privacy and Electronic Communications Regulations (PECR) and Data (Use and Access) Act 2025 (DUAA)
- Swiss Federal Act on Data Protection (nFADP / FADP)
- Canadian Personal Information Protection and Electronic Documents Act (PIPEDA)
- Brazilian General Personal Data Protection Law (LGPD)
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Delaware Personal Data Privacy Act (DPDPA)
- Minnesota Consumer Data Privacy Act (MCDPA)
- Montana Consumer Data Privacy Act (MTCDPA)
- Nebraska Data Privacy Act (NDPA)
- Nevada Privacy Law (NRS 603A)
- New Hampshire Privacy Act (NHPA)
- New Jersey Data Privacy Act (NJDPA)
- Oregon Consumer Privacy Act (OCPA)
- Tennessee Information Protection Act (TIPA)
- Texas Data Privacy and Security Act (TDPSA)
- Utah Consumer Privacy Act (UCPA)
- Virginia Consumer Data Protection Act (VCDPA)
- Other regulations that may be applicable.
2. Who manages your data and how can you contact us?
Your personal data is processed by:
Tisca Italia Srl
Via G. Donizetti 6, 24050, Lurano (BG), Italia
claudio.corti@tisca.it
VAT ID: 00421940164
For any information concerning the processing of personal data or to exercise the rights granted by law, data subjects may contact the Data Controller.
3. On what legal bases do we process your data?
The processing of personal data collected through this site (including data collected by means of cookies, similar technologies, contact forms and any other features that may be active on the site) is based on one or more of the following legal bases:
- Performance of pre-contractual or contractual measures: where processing is necessary to respond to user requests, provide requested services and, where the site so provides, manage orders, accounts or contractual relationships.
- Compliance with legal obligations: where processing is necessary to comply with tax, accounting, administrative or security obligations or with requests from the authorities.
- Express consent of the user in relation to communications of an informational or commercial nature;
A further legal basis, the legitimate interest of the Data Controller, may be used for specific purposes (e.g. ensuring IT security, preventing fraud, protecting the Data Controller’s rights in legal proceedings).
Additional legal bases for the US and similar jurisdictions:
In countries subject to laws such as the CCPA/CPRA (California), CPA (Colorado), CTDPA (Connecticut), DPDPA (Delaware), MCDPA (Minnesota), MTCDPA (Montana), NDPA (Nebraska), NRS 603A (Nevada), NHPA (New Hampshire), NJDPA (New Jersey), OCPA (Oregon), TIPA (Tennessee), TDPSA (Texas), UCPA (Utah), VCDPA (Virginia) and other US regulations, the following principles also apply:
- Opt-out and right to object: the user has the right at any time to opt for blocking the use, sale or sharing of their personal data for marketing, profiling or behavioural advertising purposes, through dedicated functions (browser settings, a “Reject” button, an “Unsubscribe” link or the like).
Additional legal bases for Brazil (LGPD):
Where processing falls under the jurisdiction of the LGPD, the following specific legal bases provided for by Brazilian law also apply:
- Credit protection: data may be processed for the purposes of credit management and protection, such as assessing creditworthiness, preventing financial fraud or granting financing.
- Implementation of public policies: in the cases provided for, public authorities may process personal data for the implementation of initiatives established by laws, public programmes or agreements.
- Study by research bodies: data may be used by scientific or statistical research bodies, preferably in anonymised form, for study or analysis purposes.
Failure to accept or the withdrawal of consent may limit certain features or services of the site, such as receiving commercial communications or subscribing to the newsletter.
4. What data do we collect when you visit the site?
While browsing this site, the following data may be collected, including by means of cookies and similar technologies such as pixel tags, web beacons, local storage and equivalent technologies – namely:
-
Navigation and technical data: information such as IP address, device identifiers, data relating to the operating system and browser, requested URLs, connection times, technical logs, technical preferences, and usage data collected through cookies and tracking technologies (pixel tags, web beacons, local storage and equivalent tools).
-
Identifying data provided voluntarily: information entered in the digital forms on the site (e.g. first name, last name, e-mail, telephone) and/or provided by sending e-mails or through other contact channels, used to respond to requests, provide services and any consultations, and — subject to consent — to send informational or commercial communications.
5. How do we process your data, how do we protect it and how long do we keep it?
The personal data collected through this site is processed mainly by electronic and digital means in accordance with the principles of lawfulness, fairness, data minimisation, integrity and confidentiality.
Appropriate technical and organisational measures are adopted to prevent unauthorised access, loss, alteration or unauthorised disclosure of data, including:
- Encryption of communications (https): communications between your browser and the site are protected by HTTPS encryption, a measure aimed at reducing the risk of interception or manipulation of the data transmitted during browsing;
- Log monitoring: the system records and monitors accesses and activities in order to detect suspicious or unauthorised attempts and ensure the security of the data;
- Periodic backups: data is copied and stored periodically to protect it from any accidental loss or technical incidents;
- Security audits and checks: security checks and tests are carried out regularly to identify and correct any system vulnerabilities;
Data is retained according to the following timeframes:
- Cookie preferences and consents: retained for 180 days, as set out in the Cookie Policy on this site.
- Navigation and technical data: retained for the time strictly necessary for security purposes and, as a rule, no longer than 12 months, after which it is deleted or anonymised, save for longer periods imposed by legal obligations or by the need to establish, exercise or defend a right in legal proceedings.
- Data connected to any contractual relationships established with the Data Controller: where they exist, it is retained for the duration of the relationship and, thereafter, for the time required by the applicable legal obligations (for example in accounting and tax matters).
- Data processed for marketing purposes: retained until consent is withdrawn or a deletion request is made. In the absence of such requests, the data is retained for a maximum period of 24 months from the last significant interaction (e.g. opening a communication, opening / clicking on a communication, or submitting a request from the site).
- Data entered through forms or specific requests: retained for the time necessary to respond to the request and to fulfil the related purpose, and thereafter for any period required by legal obligations.
6. Who can receive your data?
The following may access the personal data collected through this site, within the limits of their respective responsibilities and purposes:
- Authorised internal persons designated by the Data Controller, duly instructed on privacy and security matters;
- Suppliers and third parties appointed as Data Processors (for example: technical providers and IT services, site maintenance, e-mail providers, consultants, where applicable);
- Third parties that provide services integrated into the site (e.g. fonts, maps, image display), which may process technical data as independent controllers in accordance with their own notices (in which case please also consult the individual notices of such third parties);
- Competent public authorities and supervisory bodies, within the limits imposed by law or in order to comply with requests from the judicial authority;
The updated list of external recipients can be made available on request by writing to the Data Controller’s contact details.
7. Where can your data be transferred?
The personal data collected through this site may be processed within the European Union / European Economic Area. In some cases, the use of third-party services may involve a transfer to third countries. Where transfers to the United States take place, these are made to providers that adhere to the EU-US adequacy framework (Data Privacy Framework) or, failing that, on the basis of Standard Contractual Clauses.
For transfers subject to the UK GDPR, lawfulness is based on the United Kingdom’s adequacy decisions (for the United States, the UK Extension to the EU-US Data Privacy Framework, the so-called “UK-US Data Bridge”, limited to certified providers) or on appropriate safeguards such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the Standard Contractual Clauses, subject to a transfer risk assessment based on the “data protection test” criterion (protection not materially lower than that of the United Kingdom).
8. What are your rights regarding the data collected?
The user, under the applicable legislation, has the right to:
- Obtain confirmation as to whether or not personal data concerning them is being processed and, if so, obtain access to that data and the related information (right of access).
- Request the rectification, updating or erasure of data that is inaccurate or no longer necessary (right to rectification and erasure).
- Request the restriction of, or object to, the processing of data, including for promotional/profiling purposes, where provided for.
- Request the portability of data in a structured and interoperable format (where technically possible).
- Withdraw at any time any consent given, without affecting the lawfulness of processing based on consent carried out before the withdrawal (for example for the sending of commercial communications or newsletters, where active).
- Withdraw the consent given to the use of non-technical cookies and to the processing of data collected through tracking tools.
- Exercise the right to opt out of the “sale/sharing” of personal data, where provided for by US and Canadian laws.
- Report any irregularities or abuses to the competent supervisory authorities.
Notes for users residing in the United States
Users residing in the United States have, under local legislation, the following additional and specific rights with respect to data collected through cookies, tracking technologies and similar tools:
- Right to know the categories of personal data collected, sold or shared with third parties, as well as the purposes of such processing;
- Right to request the deletion, where applicable, of personal data collected through tracking tools;
- Right to exercise the opt-out from the “sale” or “sharing” of personal data;
- Right not to suffer discrimination as a result of exercising these rights.
To exercise these rights, it is sufficient to send a request to the Data Controller’s contact details. The Data Controller will respond without undue delay and, in any case, within one month of receiving the request, a period that may be extended by a further two months in the case of particular complexity or a high number of requests, in which case the data subject will be informed.
In the United Kingdom, the time limit for responding may be paused where the Data Controller reasonably requests the information needed to confirm the user’s identity or to clarify the subject of the request; the Data Controller carries out reasonable and proportionate searches in order to comply with access requests.
9. How is minors’ data processed?
The protection of minors is a fundamental priority.
This site is not directed at minors and does not intentionally collect their data through its forms. Where, in the context of a request or query, the user provides personal data relating to third parties — including any minors — they must ensure that they are authorised to do so; such data will be processed within the limits and for the purposes of the request, in compliance with the applicable legislation. For requests for rectification, restriction or erasure, you may write to the Data Controller’s contact details.
10. How can you make reports or complaints to the authorities?
If you believe that the processing of your personal data through this site does not comply with the applicable legislation, you may lodge a complaint free of charge with the competent supervisory Authorities, including:
- The Data Protection Authority or personal data protection authority of your country of citizenship or residence;
- Swiss Authority (FDPIC)
- Information Commission – formerly the Information Commissioner’s Office (ICO), United Kingdom
- California Authority
- Attorney General of Colorado
- Attorney General of Connecticut
- Attorney General of Delaware
- Attorney General of Minnesota
- Montana Department of Justice – Office of Consumer Protection
- Attorney General of Nebraska
- Attorney General of Nevada
- New Hampshire Department of Justice – Consumer Protection
- New Jersey Division of Consumer Affairs
- Oregon Department of Justice – Oregon Consumer Privacy Act
- Attorney General of Tennessee
- Attorney General of Texas – Texas Data Privacy and Security Act
- Attorney General of Utah
- Virginia Authority
- Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/
- Autoridade Nacional de Proteção de Dados (Brazil): https://www.gov.br/anpd/pt-br
For users in the United Kingdom, before approaching the competent supervisory authority, it is possible to lodge a complaint directly with the Data Controller, who will handle it according to a documented procedure and provide a response within the timeframes provided for by the applicable legislation.
11. How do we inform you of changes to this notice?
This notice is subject to periodic revision to reflect regulatory changes or modifications to the services offered through the site. Any significant change will be communicated through this page.
Last revised: June 4, 2026
