LUMIFOLD
ITBack to site
Privacy & Data Protection

Privacy Policy

Comprehensive notice under Articles 12, 13 and, where applicable, 14 GDPR for the LUMIFOLD portal and B2B activities of the Architectural Cladding and Habitable Containers divisions.

Version 5.0Last update: 22/08/2026UESE ITALIA S.p.A.
Privacy PolicyRFQ Privacy NoticeCookie PolicyLegal NoticeTerms of UseTerms of Supply

Contents

1. Controller2. Scope3. Principles4. Data categories5. Sources6. Purposes and bases7. RFQs and files8. Newsletter9. Logs and security10. Recipients11. Transfers12. AI and automation13. Retention14. Security15. Breaches16. Rights17. Complaints18. Cookies19. Minors20. Updates
Document control
CodeLF-LEG-PRV-01Version5.0
IssuerUESE ITALIA S.p.A. · LUMIFOLD
Scopelumifold.uese.eu · Architectural Cladding · Habitable Containers

1. Data controller

UESE ITALIA S.p.A.
Registered office: Piazza Trivulziana 4/A · 20126 Milan · Italy
Technical office: Corso del Popolo 58/B · 30172 Venice · Italy
Commercial office: Via Guantai Nuovi 11 · 80133 Naples · Italy
Tel. +39 02 5656 8416 · info@uese.eu
Share capital €1,145,000 fully paid · Tax/VAT ID IT04398760274 · REA MI 2679515 · SDI 3ZJY534
https://uese.eu

UESE ITALIA S.p.A. acts as data controller for personal data collected through LUMIFOLD and related contact, quotation, technical assessment, commercial, newsletter and website-security activities. Privacy requests may be sent to info@uese.eu with the subject “Privacy – LUMIFOLD”. Where a Data Protection Officer is formally appointed for a relevant processing activity under Articles 37-39 GDPR, the applicable contact details will be communicated through the appropriate corporate channels.

2. Scope and data subjects

This policy applies to visitors, customer/prospect contacts, architects, engineers, designers, façade consultants, general contractors, developers, distributors, dealers, installers, suppliers, advisers, logistics operators, persons requesting samples or technical documentation, newsletter subscribers and persons submitting RFQs or attachments.

Where a user provides data about colleagues, clients, designers or other third parties, the user must be authorised to do so and, where required, must have provided the relevant information to those individuals. UESE may request clarification or restrict use of third-party data that is unnecessary or excessive.

3. Principles, privacy by design and accountability

Processing is organised around lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, confidentiality and accountability. UESE applies a risk-based approach and separates public content, commercial data, technical attachments and administrative information, reviewing controls when services, suppliers or technical architecture change.

4. Categories of personal data

CategoryExamplesSource
Identification and contactname, surname, e-mail, telephone, countryuser / organisation
Professional and corporatecompany, studio, role, function, sectoruser / organisation / professional sources
Project datalocation, areas, heights, intended use, finishes, quantities, timing, indicative budgetRFQ / correspondence
Logisticsdestination, transport, access, unloading, crane and site constraintscontainer RFQ
Technical attachmentsPDF, DWG, DXF, IFC, RVT, SKP, images, Office, ZIPvoluntary upload
Usage and securityIP or IP hash, timestamps, user agent, logs, errors, security eventsIT systems
Preferences and consentnewsletter, cookies, language, themeuser / browser
Data not requested. Forms are not intended to collect special-category data under Article 9 GDPR, criminal-conviction data under Article 10, credentials, passwords, unnecessary identity documents, health information or excessive personal data. Unnecessary content may be redacted, restricted or deleted.

5. Data sources

Data is primarily collected directly from the individual via forms, e-mail, calls, meetings, trade fairs, commercial requests and uploads. In B2B contexts, professional contact data may also be obtained from customer organisations, partners, distributors or lawfully accessible public/professional sources, subject to Article 14 GDPR where applicable.

6. Purposes, legal bases and retention criteria

PurposeLegal basisRetention criterion
Respond to enquiriesArt. 6(1)(b); Art. 6(1)(f) for B2B contactsup to 24 months after the last useful interaction unless a relationship follows
Manage RFQs, samples, feasibility and quotationsArt. 6(1)(b); Art. 6(1)(f)up to 24 months after closure; longer if converted into a contract or needed for claims
Enter into and perform contracts and ordersArt. 6(1)(b)relationship duration plus statutory, tax and limitation periods
Accounting, customs, export and complianceArt. 6(1)(c)as required by law
Optional newsletter and marketingArt. 6(1)(a)until withdrawal, subject to periodic review
Security, abuse prevention and legal claimsArt. 6(1)(f)proportionate to risk; extended for incidents/disputes
Optional cookiesconsent under Art. 6(1)(a) and applicable ePrivacy rulesper Cookie Policy

7. RFQs, quotations and technical attachments

The RFQ process allows UESE to evaluate feasibility, materials, configurations, quantities, transport, logistics, finishes, utilities and applicable requirements. Uploaded files are intended for authorised personnel and, where necessary, advisers or technical partners involved in the project. Attachments are not intended for public web publication and are made available in a protected administrative area.

Users should remove unnecessary personal data before uploading. The RFQ & Technical Attachments Privacy Notice applies specifically to this process.

8. Newsletter and commercial communications

Newsletter subscription is voluntary and may be withdrawn at any time. Refusal or withdrawal does not affect website access, quotation requests or contract performance. Any communications to existing customers are assessed separately under applicable law and include an easy, free right to object.

9. Technical logs, security and abuse prevention

Systems may generate logs to maintain availability, integrity and security, prevent spam, anomalous uploads, malware, automated attacks and unauthorised access. Data is processed proportionately and may be retained longer where needed for a security incident, technical investigation or legal claim.

10. Recipients, authorised persons and processors

Data may be accessed by authorised UESE personnel and, where necessary, hosting providers, IT/cybersecurity suppliers, e-mail services, legal/tax advisers, designers, laboratories, manufacturing partners, installers, freight forwarders, carriers, customs brokers, insurers, conformity-assessment bodies, subcontractors and distributors involved in the request.

Processors acting on behalf of UESE are governed by Article 28 GDPR arrangements where applicable. Entities determining their own purposes and means act as independent controllers.

11. Transfers outside the EEA

Where international projects or suppliers involve transfers outside the EEA, UESE applies Chapter V GDPR through adequacy decisions, Standard Contractual Clauses, supplementary measures, transfer assessments or other lawful mechanisms.

12. Automated tools and artificial intelligence

The portal is not designed to make solely automated decisions producing legal or similarly significant effects under Article 22 GDPR. UESE may use software or AI-supported tools for classification, security, technical preparation or document analysis, with human oversight where appropriate. New AI functionality that materially changes processing will be assessed before deployment and the relevant notices updated.

13. Deletion, anonymisation, backups and legal hold

At the end of the applicable period, data is deleted, anonymised or made no longer actively available according to adopted procedures. Deletion may be suspended by statutory obligations, warranties, disputes, audits, debt recovery, litigation or legal hold. Backups follow separate cycles and are normally intended for restoration.

14. Technical and organisational measures

Measures are selected on a risk basis and may include access controls, segregated attachment storage, authentication, logging, backups, hardening, updates, least privilege, authorisation management, anomalous-request protection, incident response and staff training. No system is risk-free; controls are reviewed proportionately.

15. Personal data breach management

Potential breaches are handled through detection, containment, analysis, documentation and risk assessment. Where Articles 33 and 34 GDPR apply, UESE notifies the competent authority and/or affected individuals within the applicable requirements and timeframes.

16. Data subject rights

Where applicable under Articles 15-22 GDPR, individuals may request access, rectification, erasure, restriction, portability, objection, withdrawal of consent and information on automated processing. Requests may be sent to info@uese.eu. UESE may request reasonable information to verify identity and prevent unauthorised disclosure.

17. Complaints and remedies

Individuals may lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority in the Member State of residence, work or alleged infringement, without prejudice to judicial remedies.

18. Cookies and other tracking technologies

The portal uses necessary technologies and a consent manager. Optional technologies requiring consent remain disabled until a valid choice. Categories, duration and withdrawal mechanisms are described in the Cookie Policy.

19. Minors and unsolicited data

The portal is intended for professional and B2B use and is not directed at children. Unnecessary minors’ data or special-category data may be deleted or restricted.

20. Updates, versions and precedence

This policy may be updated for legal, organisational, technical or service changes. The current version is identified by date and revision. A specific notice presented at the point of collection prevails for the processing it specifically governs.

21. Privacy governance, roles and accountability

UESE applies an accountability model in which purposes, legal bases, data categories, recipients, retention and security measures are assessed against the actual digital processes in operation. Personnel and business functions involved in the portal act under role-based authorisations and instructions appropriate to their duties.

Where a supplier processes personal data on UESE's behalf, the relationship is assessed and, where Article 28 GDPR applies, governed by appropriate processor terms. Supplier due diligence is proportionate to risk and may address security, hosting location, subprocessors, data-subject assistance, incident management, deletion/return and auditability.

22. Data lifecycle and minimisation

Portal data is managed across collection, validation, use, authorised disclosure, storage, periodic review and deletion/anonymisation. Forms are designed to request information relevant to the relationship or project. Optional fields should be used only where they add legitimate value to the request.

Technical attachments may accidentally contain excessive personal information. Users should remove unnecessary personal data, identity documents, credentials, health information or other particularly sensitive material unless strictly necessary and specifically agreed.

23. Legitimate interests and balancing

Where UESE relies on legitimate interests, it assesses the purpose pursued, necessity and reasonably foreseeable impact on individuals. Depending on the circumstances, this may cover cybersecurity, fraud/abuse prevention, defence of legal rights, business continuity, proportionate B2B relationship management and non-invasive process improvement. Individuals may object under Article 21 GDPR where applicable.

24. Technical and organisational security criteria

Measures are calibrated to the nature, scale, context and risk of processing and may include access segregation, authentication, logging, hosting protection, software patching, backups and recovery procedures, malware protection, upload restrictions, IP pseudonymisation in application logs, administrative access controls, encrypted transport channels and privilege management.

Security measures are not described at a level that would weaken system protection. No measure can eliminate all risk; controls are reviewed as threats and technology evolve.

25. Data-subject request handling

To protect personal data, UESE may request reasonable information to verify the identity of a requester while avoiding excessive identification data. Requests are logged and handled within applicable time limits. Manifestly unfounded or excessive requests are handled under Article 12 GDPR.

Where a request concerns information embedded in technical files, emails or project systems, the requester may need to identify the project, organisation or RFQ reference. Erasure may be limited where continued storage is required by law, for establishment/exercise/defence of claims or another overriding lawful basis.

26. Suppliers, subprocessors and service chain

The portal may rely on hosting, email, security, backup, IT support, communications and other providers. The exact supplier list may change over time. UESE maintains internal qualification records for relevant providers and updates this notice where new categories of recipients or international transfers materially affect the information that must be provided to individuals.

27. Traceability and compliance evidence

UESE may retain limited evidence needed to demonstrate receipt of requests, consent choices, provision of notices, data-subject request handling, RFQ status, security events and contractual compliance. Such records are access-controlled, retention-limited and not repurposed incompatibly.

28. Privacy change management and DPIA screening

New integrations, analytics, marketing technologies, automation or other processing that may materially affect privacy risk are assessed before deployment. Where required, UESE updates notices, records of processing, supplier terms and consent mechanisms and screens whether a Data Protection Impact Assessment under Article 35 GDPR is necessary.

LUMIFOLD · UESE ITALIA S.p.A.
Industrial spin-off · Architectural cladding · Habitable containers
Privacy · RFQ Privacy · Cookie · Legal Notice · Terms of Use · Supply
· uese.eu