Privacy Policy
The purpose of this document is to inform the natural person (hereinafter the “Data Subject”) about the processing of their personal data (hereinafter “Personal Data”) collected by the data controller, Hidoly srl, with registered office at Via Alessandro Riberi 4, 10124 Turin, Tax Code/VAT No. 10678120014, email address privacy@hidoly.com, certified email (PEC) address hidolysrl@legalmail.it, telephone +39 011 0266830 (hereinafter the “Data Controller”), through the website www.hidoly.com (hereinafter the “Application”).
Any changes and updates will be binding as soon as they are published on the Application. If the Data Subject does not accept the changes made to this Privacy Policy, they must stop using this Application and may request that the Data Controller delete their Personal Data.
- Categories of Personal Data Processed
The Data Controller processes the following types of Personal Data voluntarily provided by the Data Subject:
- Contact data: first name, last name, address, email address, telephone number, images, authentication credentials, any additional information provided by the Data Subject, etc.
- Employment-related data: data included in the curriculum vitae, data relating to a spouse or children, social security data, etc.
The Data Controller processes the following types of Personal Data collected in an automated manner:
- Technical data: Personal Data generated by devices, applications, tools, and protocols used, such as, for example, information about the device used, IP addresses, browser type, and Internet Service Provider (ISP) type. Such Personal Data may leave traces that, in particular if combined with unique identifiers and other information received from servers, may be used to create profiles of natural persons.
- Browsing and Application usage data: such as, for example, pages visited, number of clicks, actions performed, session duration, etc.
Failure by the Data Subject to provide the Personal Data for which there is a legal or contractual obligation, or where such data are required for the conclusion of a contract with the Data Controller, will result in the Data Controller being unable to establish or continue the relationship with the Data Subject.
The Data Subject who provides the Data Controller with Personal Data relating to third parties is directly and exclusively responsible for the origin, collection, processing, communication, or disclosure of such data.
- Cookies and similar technologies
The Application uses cookies, web beacons, unique identifiers, and other similar technologies to collect the Data Subject’s Personal Data regarding pages viewed, links visited, and other actions performed when the Data Subject uses the Application. Such data are stored and then transmitted upon the Data Subject’s subsequent visit. The full Cookie Policy can be consulted at the following address: https://hidoly.com/cookie-policy-ue/
- Legal basis and purposes of the processing
The processing of Personal Data is necessary:
- for the performance of the contract with the Data Subject, and specifically:
- to fulfil any obligation arising from the pre-contractual or contractual relationship with the Data Subject
- registration and authentication of the Data Subject: to allow the Data Subject to register on the Application, access it, and be identified, including through external platforms
- support and contact with the Data Subject: to respond to the Data Subject’s requests
- to comply with legal obligations, and specifically:
- the fulfilment of any obligation required by applicable laws, regulations, and rules, in particular those relating to tax and fiscal matters
- on the basis of the Data Controller’s legitimate interest, for:
- email marketing purposes relating to the Data Controller’s products and/or services, for the direct sale of the Data Controller’s products or services using the email address provided by the Data Subject in the context of the sale of a product or service similar to that which was the subject of the sale
- management, optimization, and monitoring of the technical infrastructure: to identify and resolve any technical issues, improve the performance of the Application, and manage and organize information within an IT system (e.g. servers, databases, etc.)
- statistics with anonymous data: to carry out statistical analyses on aggregated and anonymized data in order to analyze the Data Subject’s behavior, improve the products and/or services provided by the Data Controller, and better meet the Data Subject’s expectations
- on the basis of the Data Subject’s consent, for:
- retargeting and remarketing: to reach the Data Subject, who has already visited or shown interest in the products and/or services offered by the Application, with personalized advertising using their Personal Data. The Data Subject may opt out by visiting the Network Advertising Initiative page.
- marketing purposes relating to the Data Controller’s products and/or services: to send information or commercial and/or promotional materials, to carry out direct sales activities of the Data Controller’s products and/or services, or to conduct market research using automated and traditional methods
On the basis of the Data Controller’s legitimate interest, the Application allows interactions with external platforms or social networks, the processing of Personal Data of which is governed by their respective privacy policies, to which reference should be made. The interactions and information acquired by this Application are in any case subject to the privacy settings chosen by the Data Subject on such platforms or social networks. In the absence of specific consent for processing for additional purposes, such information is used solely to enable use of the Application and to provide the information and services requested.
The Data Subject’s Personal Data may also be used by the Data Controller in order to protect its rights before the competent judicial authorities.
- Methods of processing and recipients of Personal Data
The processing of Personal Data is carried out using paper-based and electronic tools, in accordance with organizational procedures and logic strictly related to the purposes indicated, and through the adoption of appropriate security measures.
Personal Data are processed exclusively by:
- persons authorized by the Data Controller to process Personal Data, who have undertaken confidentiality obligations or are subject to an appropriate legal obligation of confidentiality;
- entities that operate independently as separate data controllers or entities appointed as data processors by the Data Controller in order to carry out all processing activities necessary to pursue the purposes set out in this Privacy Policy (for example, business partners, consultants, IT companies, service providers, hosting providers);
- entities or authorities to whom the communication of Personal Data is mandatory by law or by order of the competent authorities.
The entities listed above are required to implement appropriate safeguards to protect Personal Data and may access only the data necessary to perform the tasks assigned to them.
Personal Data will not be disclosed indiscriminately in any manner.
- Location
Personal Data will not be transferred outside the territory of the European Economic Area (EEA).
- Retention period of Personal Data
Personal Data will be retained for the period of time necessary to fulfill the purposes for which they were collected, in particular:
- for purposes related to the performance of the contract between the Data Controller and the Data Subject, they will be retained for the entire duration of the contractual relationship and, after its termination, for the ordinary statutory limitation period of 10 years. In the event of judicial proceedings, for the entire duration thereof, until the expiration of the time limits for exercising any available remedies or appeals.
- for purposes related to the Data Controller’s legitimate interest, they will be retained until such interest has been fulfilled
- for the fulfillment of a legal obligation, by order of an authority, and for the protection of rights in judicial proceedings, they will be retained in accordance with the time limits set out by such obligations and applicable laws, and in any case until the expiry of the statutory limitation period provided for by the regulations in force
- for purposes based on the Data Subject’s consent, they will be retained until such consent is withdrawn
At the end of the retention period, all Personal Data will be deleted or stored in a form that does not allow the identification of the Data Subject.
- Rights of the Data Subject
Data Subjects may exercise certain rights with regard to the Personal Data processed by the Data Controller. In particular, the Data Subject has the right to:
- be informed about the processing of their Personal Data
- withdraw consent at any time
- restrict the processing of their Personal Data
- object to the processing of their Personal Data
- access their Personal Data
- verify and request the rectification of their Personal Data
- obtain the restriction of the processing of their Personal Data
- obtain the erasure of their Personal Data
- transfer their Personal Data to another data controller
- lodge a complaint with the competent data protection supervisory authority and/or take legal action before the competent courts.
To exercise their rights, Data Subjects may submit a request to the following email address: privacy@hidoly.com. Requests will be taken into charge by the Data Controller without delay and handled as soon as possible, in any case within 30 days.
Last update: 10/15/2025