| Code | LF-LEG-PRV-01 | Version | 5.0 |
|---|---|---|---|
| Issuer | UESE ITALIA S.p.A. · LUMIFOLD | ||
| Scope | lumifold.uese.eu · Architectural Cladding · Habitable Containers | ||
1. Data controller
Registered office: Piazza Trivulziana 4/A · 20126 Milan · Italy
Technical office: Corso del Popolo 58/B · 30172 Venice · Italy
Commercial office: Via Guantai Nuovi 11 · 80133 Naples · Italy
Tel. +39 02 5656 8416 · info@uese.eu
Share capital €1,145,000 fully paid · Tax/VAT ID IT04398760274 · REA MI 2679515 · SDI 3ZJY534
https://uese.eu
UESE ITALIA S.p.A. acts as data controller for personal data collected through LUMIFOLD and related contact, quotation, technical assessment, commercial, newsletter and website-security activities. Privacy requests may be sent to info@uese.eu with the subject “Privacy – LUMIFOLD”. Where a Data Protection Officer is formally appointed for a relevant processing activity under Articles 37-39 GDPR, the applicable contact details will be communicated through the appropriate corporate channels.
2. Scope and data subjects
This policy applies to visitors, customer/prospect contacts, architects, engineers, designers, façade consultants, general contractors, developers, distributors, dealers, installers, suppliers, advisers, logistics operators, persons requesting samples or technical documentation, newsletter subscribers and persons submitting RFQs or attachments.
Where a user provides data about colleagues, clients, designers or other third parties, the user must be authorised to do so and, where required, must have provided the relevant information to those individuals. UESE may request clarification or restrict use of third-party data that is unnecessary or excessive.
3. Principles, privacy by design and accountability
Processing is organised around lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, confidentiality and accountability. UESE applies a risk-based approach and separates public content, commercial data, technical attachments and administrative information, reviewing controls when services, suppliers or technical architecture change.
4. Categories of personal data
| Category | Examples | Source |
|---|---|---|
| Identification and contact | name, surname, e-mail, telephone, country | user / organisation |
| Professional and corporate | company, studio, role, function, sector | user / organisation / professional sources |
| Project data | location, areas, heights, intended use, finishes, quantities, timing, indicative budget | RFQ / correspondence |
| Logistics | destination, transport, access, unloading, crane and site constraints | container RFQ |
| Technical attachments | PDF, DWG, DXF, IFC, RVT, SKP, images, Office, ZIP | voluntary upload |
| Usage and security | IP or IP hash, timestamps, user agent, logs, errors, security events | IT systems |
| Preferences and consent | newsletter, cookies, language, theme | user / browser |
5. Data sources
Data is primarily collected directly from the individual via forms, e-mail, calls, meetings, trade fairs, commercial requests and uploads. In B2B contexts, professional contact data may also be obtained from customer organisations, partners, distributors or lawfully accessible public/professional sources, subject to Article 14 GDPR where applicable.
6. Purposes, legal bases and retention criteria
| Purpose | Legal basis | Retention criterion |
|---|---|---|
| Respond to enquiries | Art. 6(1)(b); Art. 6(1)(f) for B2B contacts | up to 24 months after the last useful interaction unless a relationship follows |
| Manage RFQs, samples, feasibility and quotations | Art. 6(1)(b); Art. 6(1)(f) | up to 24 months after closure; longer if converted into a contract or needed for claims |
| Enter into and perform contracts and orders | Art. 6(1)(b) | relationship duration plus statutory, tax and limitation periods |
| Accounting, customs, export and compliance | Art. 6(1)(c) | as required by law |
| Optional newsletter and marketing | Art. 6(1)(a) | until withdrawal, subject to periodic review |
| Security, abuse prevention and legal claims | Art. 6(1)(f) | proportionate to risk; extended for incidents/disputes |
| Optional cookies | consent under Art. 6(1)(a) and applicable ePrivacy rules | per Cookie Policy |
7. RFQs, quotations and technical attachments
The RFQ process allows UESE to evaluate feasibility, materials, configurations, quantities, transport, logistics, finishes, utilities and applicable requirements. Uploaded files are intended for authorised personnel and, where necessary, advisers or technical partners involved in the project. Attachments are not intended for public web publication and are made available in a protected administrative area.
Users should remove unnecessary personal data before uploading. The RFQ & Technical Attachments Privacy Notice applies specifically to this process.
9. Technical logs, security and abuse prevention
Systems may generate logs to maintain availability, integrity and security, prevent spam, anomalous uploads, malware, automated attacks and unauthorised access. Data is processed proportionately and may be retained longer where needed for a security incident, technical investigation or legal claim.
10. Recipients, authorised persons and processors
Data may be accessed by authorised UESE personnel and, where necessary, hosting providers, IT/cybersecurity suppliers, e-mail services, legal/tax advisers, designers, laboratories, manufacturing partners, installers, freight forwarders, carriers, customs brokers, insurers, conformity-assessment bodies, subcontractors and distributors involved in the request.
Processors acting on behalf of UESE are governed by Article 28 GDPR arrangements where applicable. Entities determining their own purposes and means act as independent controllers.
11. Transfers outside the EEA
Where international projects or suppliers involve transfers outside the EEA, UESE applies Chapter V GDPR through adequacy decisions, Standard Contractual Clauses, supplementary measures, transfer assessments or other lawful mechanisms.
12. Automated tools and artificial intelligence
The portal is not designed to make solely automated decisions producing legal or similarly significant effects under Article 22 GDPR. UESE may use software or AI-supported tools for classification, security, technical preparation or document analysis, with human oversight where appropriate. New AI functionality that materially changes processing will be assessed before deployment and the relevant notices updated.
13. Deletion, anonymisation, backups and legal hold
At the end of the applicable period, data is deleted, anonymised or made no longer actively available according to adopted procedures. Deletion may be suspended by statutory obligations, warranties, disputes, audits, debt recovery, litigation or legal hold. Backups follow separate cycles and are normally intended for restoration.
14. Technical and organisational measures
Measures are selected on a risk basis and may include access controls, segregated attachment storage, authentication, logging, backups, hardening, updates, least privilege, authorisation management, anomalous-request protection, incident response and staff training. No system is risk-free; controls are reviewed proportionately.
15. Personal data breach management
Potential breaches are handled through detection, containment, analysis, documentation and risk assessment. Where Articles 33 and 34 GDPR apply, UESE notifies the competent authority and/or affected individuals within the applicable requirements and timeframes.
16. Data subject rights
Where applicable under Articles 15-22 GDPR, individuals may request access, rectification, erasure, restriction, portability, objection, withdrawal of consent and information on automated processing. Requests may be sent to info@uese.eu. UESE may request reasonable information to verify identity and prevent unauthorised disclosure.
17. Complaints and remedies
Individuals may lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority in the Member State of residence, work or alleged infringement, without prejudice to judicial remedies.
19. Minors and unsolicited data
The portal is intended for professional and B2B use and is not directed at children. Unnecessary minors’ data or special-category data may be deleted or restricted.
20. Updates, versions and precedence
This policy may be updated for legal, organisational, technical or service changes. The current version is identified by date and revision. A specific notice presented at the point of collection prevails for the processing it specifically governs.
21. Privacy governance, roles and accountability
UESE applies an accountability model in which purposes, legal bases, data categories, recipients, retention and security measures are assessed against the actual digital processes in operation. Personnel and business functions involved in the portal act under role-based authorisations and instructions appropriate to their duties.
Where a supplier processes personal data on UESE's behalf, the relationship is assessed and, where Article 28 GDPR applies, governed by appropriate processor terms. Supplier due diligence is proportionate to risk and may address security, hosting location, subprocessors, data-subject assistance, incident management, deletion/return and auditability.
22. Data lifecycle and minimisation
Portal data is managed across collection, validation, use, authorised disclosure, storage, periodic review and deletion/anonymisation. Forms are designed to request information relevant to the relationship or project. Optional fields should be used only where they add legitimate value to the request.
Technical attachments may accidentally contain excessive personal information. Users should remove unnecessary personal data, identity documents, credentials, health information or other particularly sensitive material unless strictly necessary and specifically agreed.
23. Legitimate interests and balancing
Where UESE relies on legitimate interests, it assesses the purpose pursued, necessity and reasonably foreseeable impact on individuals. Depending on the circumstances, this may cover cybersecurity, fraud/abuse prevention, defence of legal rights, business continuity, proportionate B2B relationship management and non-invasive process improvement. Individuals may object under Article 21 GDPR where applicable.
24. Technical and organisational security criteria
Measures are calibrated to the nature, scale, context and risk of processing and may include access segregation, authentication, logging, hosting protection, software patching, backups and recovery procedures, malware protection, upload restrictions, IP pseudonymisation in application logs, administrative access controls, encrypted transport channels and privilege management.
Security measures are not described at a level that would weaken system protection. No measure can eliminate all risk; controls are reviewed as threats and technology evolve.
25. Data-subject request handling
To protect personal data, UESE may request reasonable information to verify the identity of a requester while avoiding excessive identification data. Requests are logged and handled within applicable time limits. Manifestly unfounded or excessive requests are handled under Article 12 GDPR.
Where a request concerns information embedded in technical files, emails or project systems, the requester may need to identify the project, organisation or RFQ reference. Erasure may be limited where continued storage is required by law, for establishment/exercise/defence of claims or another overriding lawful basis.
26. Suppliers, subprocessors and service chain
The portal may rely on hosting, email, security, backup, IT support, communications and other providers. The exact supplier list may change over time. UESE maintains internal qualification records for relevant providers and updates this notice where new categories of recipients or international transfers materially affect the information that must be provided to individuals.
27. Traceability and compliance evidence
UESE may retain limited evidence needed to demonstrate receipt of requests, consent choices, provision of notices, data-subject request handling, RFQ status, security events and contractual compliance. Such records are access-controlled, retention-limited and not repurposed incompatibly.
28. Privacy change management and DPIA screening
New integrations, analytics, marketing technologies, automation or other processing that may materially affect privacy risk are assessed before deployment. Where required, UESE updates notices, records of processing, supplier terms and consent mechanisms and screens whether a Data Protection Impact Assessment under Article 35 GDPR is necessary.