Privacy Policy
Privacy Policy for Clients and Suppliers
(Arts. 13 – 14 Regulation EU 2016/679 - GDPR)
Regarding the processing of personal data of clients and suppliers (specifically physical persons acting as contact individuals), the following privacy notice is provided.
1. Data Controller and Data Protection Officer (DPO)
The Data Controller is the company Inamari S.r.l., with registered office at Via G. di Vittorio, 15 - 53042 Chianciano Terme (SI), Italy (hereinafter referred to as the "Company" or "Controller").
The Company has appointed a Data Protection Officer (DPO), who can be contacted at the following e-mail address: dpo@inamari.it
2. Categories of Data Processed, Purposes, and Legal Basis for Processing
The Controller collects and processes:
a) Common personal data (contact details, full name, personal data, job role, e-mail) for pre-contractual and contractual execution purposes, as well as for administrative, accounting, and tax obligations related to invoicing. Legal basis: performance of contractual obligations and compliance with legal requirements.
b) Common personal data (contact details, full name, personal data, job role, e-mail) for marketing communications (newsletters, event invitations). Legal basis: data subject's consent.
c) Common personal data (contact details, full name, personal data, job role, e-mail) for sending commercial communications regarding products or services similar to those subject to the contract (soft spam), surveys, and corporate service updates, unless objected to. Legal basis: legitimate interest of the Controller in service improvement and customer satisfaction (Art. 130 par. 4 Italian Legislative Decree 196/2003).
d) Common personal data for internal organizational, administrative, and accounting purposes. Legal basis: legitimate interest of the Controller in optimizing and coordinating business operations.
e) Client's personal data (such as name, surname, e-mail, and phone number) for providing access to the Showroom B2B Italia portal and for security purposes (blocking unauthorized access to personal accounts). Legal basis: performance of a contract and legitimate interest of the Controller in protecting IT system security.
3. Communication of Data to Third Parties
The Company may communicate processed data to the following categories of recipients:
a) Authorized and trained personnel within the internal corporate organization;
b) External entities belonging to the following categories: external consultants, service providers (transport, shipping, marketing, IT, tax, and credit advisory services), sales network (agents), banking institutions, public authorities, and supervisory bodies.
4. Processing Methods and Data Retention Period
Data will be processed in both paper and digital formats and stored for the period strictly necessary to fulfill the above-mentioned purposes, specifically:
a) For contractual and accounting data: for the statutory limitation period governing contract and administrative record storage (10 years from contract termination or the last statutory interruption event).
b) For marketing purposes (point 2.b): until consent is withdrawn or an unsubscribe request is submitted, and in any case for no longer than 2 years from the last consent provided or expression of interest.
c) For soft spam, organizational, and security purposes (points 2.c, 2.d, 2.e): for the duration of the contractual relationship and until objection by the data subject, or up to a maximum of 2 years from the last interaction/expression of interest.
5. Provision of Data
a) Mandatory for the execution of the contractual relationship and compliance with statutory obligations. Failure to provide data makes it impossible to establish or continue the contract.
b) Optional for marketing communications.
c) Optional for surveys, service updates, and soft spam communications (with the right to object at any time).
6. Rights of the Data Subject, Revocation of Consent, and Complaints
Data subjects have the right at any time to request access to their personal data, rectification, erasure, restriction of processing, to object to processing, and to exercise the right to data portability.
Data subjects also have the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
In the event of an alleged violation, data subjects have the right to lodge a complaint with the competent Supervisory Authority (Garante per la Protezione dei Dati Personali in Italy or equivalent EU authority).
7. Profiling and Automated Decision-Making
Processing is not carried out using automated decision-making processes, including profiling.
8. Contacts and Inquiries
To exercise rights provided under the GDPR or to request further information regarding processing, you can contact the Controller via e-mail at: info@inamari.it or contact the Data Protection Officer (DPO) at: dpo@inamari.it
Last updated: January 2026