Privacy Policy pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
Last updated: June 9, 2026
This privacy policy describes how we process the personal data of users who visit the website www.stsholding.it (hereinafter the “Site”) and interact with its contact forms. This policy is provided in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable national data protection legislation.
1. Data Controller
The Data Controller is S.T.S. Servizi, Tecnologie e Sviluppo S.r.l..
For any request regarding the processing of their personal data, the data subject may contact the Data Controller at the contact details indicated above.
2. Types of data processed
2.1 Browsing data
The computer systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This includes, for example, IP addresses, URI notation addresses of requested resources, the time of the request, the method used to submit the request to the server, and other parameters related to the user's operating system and computing environment. This data is used solely for the purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning and security.
2.2 Data provided voluntarily by the user
The optional, explicit, and voluntary sending of messages via the contact forms on the Site, as well as the sending of communications to the Data Controller's email addresses, involves the acquisition of the sender's contact details (e.g., name, surname, email, phone number, company) and any other personal data included in the communications.
2.3 Cookies and tracking tools
The Site uses technical cookies necessary for its operation and, potentially, third-party cookies and tracking tools for statistical and audience measurement purposes. For more information on the types of cookies used and how to manage consent, please refer to the specific Cookie Policy available on the Site.
3. Purposes and legal bases for processing
Personal data is processed for the following purposes and based on the corresponding legal bases:
4. Processing methods
Personal data is processed using electronic and telematic tools, with logic strictly related to the indicated purposes and in a manner that ensures data security and confidentiality. The Data Controller adopts appropriate technical and organizational measures to protect data from unauthorized access, loss, destruction, or unlawful disclosure.
5. Retention period
Personal data is stored for the time strictly necessary to achieve the purposes for which it was collected. In particular, data collected via contact forms is stored for the time necessary to fulfill the request and, subsequently, for the period required by any legal obligations. Browsing data is stored for a limited period, unless extended for the investigation of crimes.
6. Data recipients
Personal data may be processed by authorized personnel of the Data Controller who have been appropriately trained, and may be disclosed to third parties who perform activities on behalf of the Data Controller as data processors (e.g., IT, hosting, and website maintenance service providers). Data is not disseminated.
7. Data transfer outside the EU
If certain service providers (e.g., statistical analysis tools) involve the transfer of personal data to countries outside the European Economic Area, the Data Controller will ensure that such transfer complies with the safeguards provided for by Articles 44 et seq. of the GDPR, such as adequacy decisions or standard contractual clauses adopted by the European Commission.
8. Data subject rights
As a data subject, you may exercise the following rights at any time, within the limits provided by law:
To exercise these rights, the data subject may send a written request to the email address sts@stsholding.it or to the Data Controller's registered office.
9. Complaint to the Supervisory Authority
Data subjects who believe that the processing of their personal data violates the GDPR have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the competent supervisory authority in the Member State where they habitually reside, work, or where the alleged violation occurred.
10. Changes to this policy
The Data Controller reserves the right to modify or update this policy, including in response to changes in applicable regulations. Changes will be published on this page, indicating the date of the last update. Users are therefore encouraged to check this policy periodically.