• Via U. Boccioni, 7 - 20900 Monza (MB) Italy

PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA

(Pursuant to Articles 13 and 14 of EU Regulation 2016/679 – GDPR)
Last updated: 24 July 2026 – Version no.2

 

This notice describes how FM FILTER MONZA SRL (“Data Controller”) processes your personal data when you visit our website, browse our online catalogue, interact with our social media channels, contact us, or engage in B2B commercial and professional dealings with us. It is compliant with legal requirements and ISO 9001:2015 quality management standards.

 

1. Data Controller and contact details

The data controller is: FM FILTER MONZA SRL, Via Umberto Boccioni 7, 20900 Monza – MB – Italy – Tax Code 02106930965, VAT No. 02106930965, Tel. +39 039 834707.
If you have any questions about how we process your data or if you wish to exercise your rights, please contact us by email at fm@fmfilter.com or via certified email (PEC) at fmfiltermonzasrl@pec.it.

2. Purposes, legal basis and data retention period

We process the personal data of employees, contractors or contact persons at client or supplier companies, as well as users of our online channels, exclusively for the purposes listed below:

A. Performance of the contract and compliance with legal obligations

Management of quotations, orders, supplies of materials or products, delivery notes, outgoing invoices, general ledger accounting, VAT compliance, data transmission to the Interchange System (SDI), management of depreciable assets, management control, debt recovery and the procurement of consultancy and training services from external suppliers (e.g. for maintaining company certifications).

–  Categories of data: personal details (first name, surname, role), business contact details (email address, telephone number), bank and tax details (IBAN, VAT number/tax code), financial statement data.
–  Legal basis: performance of a contract (Article 6(1)(b) of the GDPR) and compliance with legal obligations (Article 6(1)(c) of the GDPR).
–  Retention period: 12 years, in line with prudential criteria for the stability of company accounting records.

This retention period also covers operational communications necessary for the continuation of the commercial relationship, such as changes to the company name or bank details, and technical or contractual communications essential for the performance of the supply. As these communications are not promotional, they are also sent to those who have opted out of receiving informational communications from the company, as referred to in point B.

B. Company informational communications (newsletters via SendPulse)

Sending courtesy communications to existing customers via the SendPulse platform, particularly notices of company closure during the summer and Christmas holidays, updates to the price list, and any technical or catalogue changes. These communications are sent at an indicative frequency of one every 4–12 months. Using a professional mailing platform also reduces the risk of communications being mistakenly classified as spam by recipients’ security systems.

–  Data categories: professional contact details (email).
–  Legal basis: legitimate interest (so-called ‘soft spam’ – Article 130(4) of the Italian Data Protection Code and Article 6(1)(f) of the GDPR) as the recipients are existing customers and the communications concern similar products/services to those already purchased.
–  Retention period: until the data subject objects (opting out), which can be done via the link at the bottom of each email.

C. Interactions on social media channels (Facebook/Meta)

Manual responses to commercial or information requests sent by users via the chat function on the company’s Facebook/Meta page, with an approximate frequency of once a month.

–  Data categories: social media username and any data voluntarily provided in the chat.
–  Legal basis: performance of pre-contractual measures at the data subject’s request (Article 6(1)(b) of the GDPR).
–  Retention period: the time strictly necessary to acknowledge and process the commercial enquiry.

D. Advertising on third-party digital platforms (e.g. Meta/Facebook Ads and similar platforms)

Promotion of our products through the paid dissemination of photographs and corporate content on third-party digital advertising platforms (e.g. Meta/Facebook Ads and other advertising platforms that may be used in the future). This is targeted at an audience selected based on geographical, demographic, and interest-based criteria, which are defined independently by the platform used. There is no sales funnel, redirection to a landing page, or direct collection of contact details via forms.

–  Data categories: we do not transmit any customer or supplier data to advertising platforms for audience profiling purposes. The selection of users to whom the content is shown is carried out independently by the platform in question, in accordance with its own criteria and privacy policy.

–  Legal basis: the data controller’s legitimate interest in promoting its commercial activities (Article 6(1)(f) of the GDPR).

–  Retention period: for the duration of the active advertising campaign on the platform used.

Please note that the operator of each advertising platform used (e.g. Meta Platforms Ireland Limited, and for certain purposes, Meta Platforms, Inc.) acts as an independent data controller for the data collected via its own platform. For information on the processing carried out by each individual platform, please refer to the relevant privacy policy published by the operator.

Please note that the Data Controller does not request or process special categories of personal data in any way (Articles 9/10 of the GDPR, e.g. health data, criminal records, political or religious opinions).

3. Methods of processing and security

Your data will be processed using paper-based and IT tools (company servers, desktop computers, laptops and management software) in compliance with the appropriate technical and organisational security measures designed to prevent data loss, unlawful use or unauthorised access. These measures are in accordance with the ISO 9001:2015-certified quality management system. Access to the data is restricted to expressly authorised and trained company staff only.

4. Disclosure and transfer of data (geographical restrictions)

The data collected will not be disclosed. However, it may be disclosed to parties whose activities are strictly necessary for the fulfilment of legal mandates or obligations, such as:

–  Credit institutions and the Post Office, for the management of financial flows.
–  The state tax authorities (the Revenue Agency, via the SDI).
–  External professionals bound by a duty of confidentiality (e.g. accountants, employment consultants and solicitors).
–  IT service providers and operators of email marketing platforms (e.g. SendPulse.com) and online advertising platforms (e.g. Meta Platforms), acting as external data processors pursuant to Article 28 of the GDPR where applicable, or as independent data controllers for their respective platforms.

Transfers outside the EU: For commercial and insurance reasons, our company does not operate in or sell to the US, Canadian or Mexican markets. Our main target markets are Italy, the European Union and Switzerland, as well as any other country without import restrictions. Although Switzerland is not part of the European Economic Area, it is covered by an adequacy decision issued by the European Commission. Therefore, the transfer of data to entities established there does not require additional contractual safeguards.

For customers in countries outside the EU without an adequacy decision, we transfer their contact details on the basis of the derogation provided for in Article 49(1)(b) of the GDPR, as this is necessary for us to perform the commercial contract entered into at the customer’s request.

Data is stored within the European Economic Area (EEA). Using the SendPulse and Meta platforms may involve transferring technical data to servers in third countries (e.g. the USA). Such transfers are carried out in full compliance with the GDPR, based on adequacy decisions or the signing of Standard Contractual Clauses (SCCs) approved by the European Commission.

5. Rights of the data subject

As a data subject, you have the right to exercise the rights set out in Articles 15–22 of the GDPR at any time:

–  Access: to obtain confirmation of processing and a copy of your data.
–  Rectification: to have inaccurate or incomplete data corrected.
–  Erasure: to have your data erased (‘right to be forgotten’) where there are no longer any legal obligations to retain it.
–  Restriction and objection: to request the restriction of processing, or to object to processing for the purpose of sending informational communications and price lists (‘soft spam’) or advertising on Meta.
–  Portability: to receive your data in a structured, machine-readable format.
–  Complaint: to lodge a formal complaint with the supervisory authority, the Italian Data Protection Authority (Garante per la ProtezionedeiDatiPersonali).

To exercise your rights, you can contact us at any time via email at fm@fmfilter.com.

6. Updates

This privacy notice may be updated in line with regulatory developments or changes to business processes (including any new methods of using advertising platforms or email marketing). The most recent version is always available on our main website fmfilter.com.