ServicesAboutTeamExpertiseLegalContact
Legal information

Privacy, Cookie & Terms

Transparency on how we process data, which cookies we use, and the conditions under which we offer this site and our services. Below you'll find the three complete policies.

Last updated: 04/06/2026

Notice pursuant to Art. 13-14 Reg. EU 2016/679

Privacy Policy

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 («GDPR») and Italian Legislative Decree no. 196 of 30 June 2003 as amended by Legislative Decree no. 101 of 10 August 2018 («Privacy Code»), in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality set out in Art. 5 GDPR. It describes the processing of personal data carried out by GEMP SRL in relation to the use of this website and the provision of its services.

1. Data controller

The data controller, pursuant to Art. 4(7) GDPR, is GEMP SRL (the «Controller» or «Company»), registered office at Corso Lodi 18, 20135 Milan (MI) and operating office at Via Vicenza 1, 20822 Seveso (MB), Tax Code and VAT no. 14290170969, e-mail info@gempservice.it. Following a specific assessment, the Controller has determined that the obligation to appoint a Data Protection Officer (DPO) under Art. 37 GDPR does not apply; any request regarding data protection may nonetheless be sent to the contact details above.

2. Categories of personal data processed

The following categories of personal data are processed:

  • Navigation data. The IT systems and software procedures responsible for the operation of the site acquire certain data whose transmission is implicit in the use of Internet communication protocols (IP addresses, browser and device type, operating system, domain names, URI/URL addresses of requested resources, time of request, method used, response status code). Such data, necessary for the use of web services, are also processed to verify the proper functioning and security of the site.
  • Contact data provided voluntarily. Identification and contact data (first name, surname, company name, e-mail address, telephone number, business role) and any further personal data contained in communications sent via contact forms, the optional sending of e-mail, or in the context of negotiations and contractual relationships.
  • Data collected via cookies and similar technologies, as detailed in the Cookie Policy set out on this page.

The site is not intended for minors and the Controller does not knowingly collect data relating to minors. Special categories of data under Art. 9 GDPR are not normally processed; should the data subject spontaneously provide such data, their processing shall be deemed authorised solely for handling the specific request.

3. Purposes and legal basis of processing

In accordance with Art. 6 GDPR, personal data are processed for the purposes and on the legal bases set out below:

  • a) Response to requests and management of pre-contractual and contractual relationships — handling requests, preparing quotations, concluding and performing the contract. Legal basis: Art. 6(1)(b) GDPR.
  • b) IT security and proper functioning of the site — prevention of fraud, abuse and unauthorised access, diagnostics and service continuity. Legal basis: Art. 6(1)(f) GDPR (legitimate interest), balanced against data subjects' rights.
  • c) Compliance with legal obligations — accounting, tax, administrative and IT-security obligations arising from applicable legislation. Legal basis: Art. 6(1)(c) GDPR.
  • d) Possible establishment, exercise or defence of a legal claim. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting its rights).

The provision of navigation data is necessary for the technical functioning of the site; the provision of contact data is optional, but any refusal makes it impossible to act upon the data subject's requests and, where relevant, to conclude or perform the contract.

4. Processing methods and security measures

Processing is carried out using manual, IT and electronic tools, with logic strictly related to the stated purposes and in compliance with the minimisation principle. The Controller adopts technical and organisational measures adequate pursuant to Art. 25 and Art. 32 GDPR — including access controls, encryption where appropriate, system segregation, backups, access logging and incident-management procedures — to ensure a level of security appropriate to the risk and to prevent unauthorised destruction, loss, alteration, disclosure of or access to data.

5. Recipients and categories of recipients

Personal data may be processed, on behalf of the Controller, by persons authorised pursuant to Art. 29 GDPR and disclosed to third parties appointed as Data Processors pursuant to Art. 28 GDPR. This category includes, by way of example, hosting and infrastructure providers, IT and maintenance service providers, professional advisers (accounting, legal, tax). Data may also be disclosed to public and judicial authorities in the cases provided for by law. Data are not disseminated nor transferred to third parties for marketing purposes.

6. Transfer of data to third countries

Data processing generally takes place within the European Economic Area (EEA). Should data need to be transferred to third countries, the Controller ensures that such transfer complies with Chapter V GDPR, i.e. on the basis of an adequacy decision (Art. 45) or by means of appropriate safeguards pursuant to Art. 46 — namely the Standard Contractual Clauses — and, where necessary, supplementary measures suitable to ensure a level of protection substantially equivalent to the European one.

7. Data retention period

In compliance with the storage-limitation principle (Art. 5(1)(e) GDPR), data are retained for the time strictly necessary: contact data and pre-contractual negotiation data for the time necessary to handle the request and, if the contract is not concluded, for a maximum of 24 months; contractual-relationship data for the entire duration of the relationship and, thereafter, for the ordinary ten-year limitation period (Art. 2946 of the Italian Civil Code) and for the further periods imposed by accounting and tax legislation; navigation data for the strictly necessary technical time. Once these periods elapse, data are erased or irreversibly anonymised.

8. Rights of the data subject

The data subject may exercise the rights provided by Art. 15-22 GDPR: access (Art. 15), rectification (Art. 16), erasure or «right to be forgotten» (Art. 17), restriction (Art. 18), notification (Art. 19), portability (Art. 20), objection (Art. 21) and the right not to be subject to automated decision-making, including profiling (Art. 22). Where processing is based on consent, the data subject may withdraw it at any time (Art. 7(3) GDPR). Requests should be addressed to info@gempservice.it; the Controller responds without undue delay and in any event within one month of receipt, save for extension in cases of particular complexity.

9. Right to lodge a complaint with the Supervisory Authority

Without prejudice to any other administrative or judicial remedy, a data subject who considers that the processing of their data infringes the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), pursuant to Art. 77 GDPR, or to bring proceedings before the competent judicial authority.

10. Network and information system security (NIS2)

As a managed-services provider and a component of its clients' ICT supply chain, GEMP SRL pays particular attention to the security of networks and information systems, also in light of Directive (EU) 2022/2555 («NIS2»), transposed in Italy by Legislative Decree no. 138 of 4 September 2024, and of the implementing measures of the National Cybersecurity Agency (ACN). The Controller adopts technical, operational and organisational measures aimed at safeguarding the confidentiality, integrity and availability of the data and systems processed, and cooperates with its clients subject to NIS2 obligations for supply-chain risk management and the timely notification of significant incidents. Where such measures involve the processing of personal data, they are implemented in compliance with the principles and safeguards of the GDPR.

11. Changes to this notice

The Controller reserves the right to amend or update this notice, including as a result of regulatory or organisational changes. Updated versions will be published on this page with an indication of the last-update date; data subjects are therefore invited to consult it periodically.

General conditions of use

Terms & Conditions

These general conditions («Terms») govern access to and use of this GEMP SRL website. Access to, consultation and use of the site entail full and unconditional acceptance of these Terms. Should the user not wish to accept them, they are invited to refrain from using the site.

1. Subject and nature of the site

The site has a purely informational and institutional purpose and is intended to illustrate the business, expertise and IT services offered by GEMP SRL. The information contained therein is of a general nature and does not constitute an offer to the public pursuant to Art. 1336 of the Italian Civil Code, nor a contractual proposal or binding commitment for the Company, unless expressly provided for in specific agreements signed in writing between the parties. The provision of services is in any case governed by the contractual conditions agreed on a case-by-case basis.

2. Intellectual and industrial property

All site content — texts, works, articles, trademarks, names, logos, distinctive signs, graphics, layouts, interfaces, photographs, illustrations, source and object code — is the exclusive property of GEMP SRL or used under a regular licence, and is protected by copyright legislation (Italian Law no. 633 of 22 April 1941) and industrial-property legislation (Legislative Decree no. 30 of 10 February 2005). Reproduction, copying, distribution, publication, modification or any other use, total or partial, is prohibited without the prior written authorisation of the Company. Third-party trademarks and product names possibly mentioned belong to their respective owners and are referred to solely for descriptive purposes, without implying any affiliation, sponsorship or endorsement.

3. User obligations and liability

The user undertakes to use the site in compliance with the law, these Terms, public order and morality, refraining from any conduct that may impair the operation, security or integrity of the site and the systems connected to it, or infringe the rights of third parties. In particular, any unauthorised access, the introduction of malicious code, unauthorised mass-scraping activities and any use likely to compromise its availability are prohibited. The user is liable for damage caused to the Company or third parties as a result of breaching these obligations.

4. Limitation of liability and warranties

The Company takes the utmost care to ensure that the information published is accurate, complete and up to date, but gives no warranty, express or implied, as to its accuracy, completeness or suitability to meet the user's specific needs. The site is provided «as is» and «as available». To the extent permitted by law, GEMP SRL assumes no liability for direct, indirect, incidental or consequential damages arising from access to, use of or inability to use the site, from errors or omissions in the content, or from interruptions or malfunctions, including those attributable to force majeure. The mandatory statutory liability for wilful misconduct and gross negligence, and liability towards consumers, remain unaffected.

5. Links to third-party sites

The site may contain hyperlinks to websites operated by third parties, provided merely as a courtesy and for informational purposes. The Company exercises no control over the destination sites and is not responsible for their content, their availability, or the data-protection practices adopted therein. Access to third-party sites via the links is at the user's sole risk.

6. IT security and service continuity

GEMP SRL adopts reasonable and adequate technical and organisational measures to ensure the security and availability of the site, consistently with the risk-management approach promoted by Directive (EU) 2022/2555 (NIS2) and the related transposition decree (Legislative Decree 138/2024). The Company does not, however, guarantee that the site is error-free or that access is uninterrupted, and reserves the right to suspend its provision at any time, even without notice, for maintenance, updating or security needs.

7. Changes to the Terms

GEMP SRL reserves the right to amend, supplement or update the site content and these Terms at any time, including in response to subsequent regulatory, technical or organisational needs. Changes take effect upon their publication on this page; users are therefore invited to consult the Terms periodically. Continued use of the site following the publication of changes constitutes acceptance thereof.

8. Applicable law and jurisdiction

These Terms are governed by Italian law. Any dispute relating to their interpretation, validity, performance or termination shall fall within the exclusive jurisdiction of the Court of Milan, save for the application of the consumer's mandatory jurisdiction (Art. 66-bis of Legislative Decree no. 206 of 6 September 2005 — Consumer Code) where the user qualifies as such. Should individual clauses prove invalid or ineffective, this shall not affect the validity of the remaining provisions.

For any query relating to these notices, or to exercise the rights granted by applicable law, you may write to info@gempservice.it. The Company will respond as soon as possible and, where applicable, within the time limits provided by law.