Information pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)
This information is provided, pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”), to all those who access and use the application called “EIMA International Application” (hereinafter, the “App”).
This information supplements and, as provided herein, specifies the general privacy policy of FederUnacoma Surl available on institutional channels at the link https://www.eima.it/en/privacy-registrazione-visitatori.php, with reference to the processing of personal data carried out through the App.
1. Data Controller
The Data Controller is FederUnacoma S.u.r.l., with registered office at Viale Aldo Moro 64, Torre I, 40127 Bologna (BO), contactable at the e-mail address: privacy@federunacoma.it.
2. Data Protection Officer (DPO)
The Data Controller has appointed a Data Protection Officer (DPO), who can be contacted at the following e-mail address: avvocatoandreabonoli@libero.it or at:
Data Protection Officer (DPO)
c/o FederUnacoma S.u.r.l.
Viale Aldo Moro, 64, Torre I, Bologna 40127 - Bologna (BO)
3. Type of Data Processed
“Personal data” means any information relating to an identified or identifiable natural person.
The following can be processed through the App:
- personal data, such as name, surname, nationality, company or sector of affiliation;
- contact details, such as telephone number and e-mail;
- technical and navigation data, such as IP address, requested URLs, time of the request, method used, size of the returned file and response status code;
- data relating to the device used, such as device ID, make, model, operating system, App version, last update and approximate location;
- data relating to the use of the App (interactions, number of accesses, performance, network coverage), also through analysis tools;
- data provided voluntarily by the user via the App;
- contact details shared via the QR code networking feature, such as: name, surname, company, e-mail address and telephone number.
4. Purpose and Legal Basis of the Processing
Personal data are processed for the following purposes:
- Downloading, installing and operating the App
The data is processed to allow the download, installation, and proper functioning of the App. The legal basis is Art. 6, paragraph 1, letter b) of the GDPR (performance of pre-contractual or contractual measures requested by the data subject). Providing your data is mandatory; otherwise, you will not be able to use the App. - Management of user requests
The data is processed to respond to requests for information or assistance. The legal basis is Art. 6, paragraph 1, letter b) GDPR (pre-contractual measures). Where not applicable, the processing is based on the Data Controller's legitimate interest in managing communications. Providing your data is optional, but necessary to receive a response. - Use of the services offered through the App
The data is processed to allow access to content and information services relating to initiatives and events organized by the Data Controller. The legal basis is Art. 6, paragraph 1, letter b) GDPR (performance of the contract). The provision of data is necessary for the provision of services. - Security and prevention of abuse
The data is processed to ensure IT security, monitor the proper functioning of the App, and prevent fraud or illicit use. The legal basis is Art. 6, paragraph 1, letter f) GDPR (legitimate interest of the Data Controller in system security). - Statistical analysis and service improvement
The data may be processed to analyze, in aggregate and where possible anonymized form, the use of the App in order to improve its performance and functionality. The legal basis is Art. 6, paragraph 1, letter f) GDPR (legitimate interest of the Data Controller). - Networking and Exchange of Contact Details Via QR Code
When purchasing a ticket, users are asked to consent to the generation and sharing of their contact details via QR code, in order to enable networking activities and the voluntary exchange of information with other participants or users. Without such consent, the personal QR code will not be generated and the user will not be able to share their contact information through this feature. The ability to use the App to scan and read QR codes made available by other users remains unchanged.
The QR code may be made available to the user in digital or paper format. Voluntary scanning of the QR code by other users or third parties involves the disclosure of the contact details contained therein, such as name, surname, company affiliation, e-mail address, and telephone number, as well as their possible storage in the App or in the tools used by the person who performed the scan. Data sharing occurs exclusively on the voluntary initiative of the user who owns the QR code, by displaying or making it available to the user.
The contact details associated with the networking feature are stored in an internal database managed by the Data Controller, which is not accessible to the public and is accessible only to authorized persons, in order to allow management of the feature itself and the generation of the QR code. The data is made available to other users only after they voluntarily scan the QR code.
The user can revoke consent at any time and request deactivation of the QR code by contacting the Data Controller. Revoking your consent will prevent further sharing of your data through this feature, but will not affect the lawfulness of any processing carried out prior to your consent being revoked. It is understood that data already acquired from third parties before the revocation may remain available to such parties and cannot be recovered or deleted by the Data Controller.
The contact information provided through this feature is intended exclusively for networking and professional relationship purposes and must be processed by the recipients in compliance with current data protection legislation.
The legal basis for the processing is the consent of the data subject, pursuant to Art. 6, paragraph 1, letter a) of Regulation (EU) 2016/679 (GDPR). Providing data for this purpose is optional and failure to provide consent does not imply any limitation on participation in the event or the use of other features of the App.
5. Nature of the Provision of Personal Data
Providing data for contractual purposes is necessary to use the App. Providing data for any additional purposes based on consent, including the QR code networking feature, is optional.
6. Method of the Processing
Processing is carried out using IT and electronic tools, in compliance with appropriate security measures aimed at guaranteeing the confidentiality, integrity, and availability of the data. No automated decision-making processes are envisaged.
7. Data Recipients
- IT service providers, hosting, technical support, and App maintenance providers, appointed as Data Processors pursuant to Art. 28 GDPR;
- persons authorized to process data who operate under the authority of the Data Controller;
- other users of the App or third parties, limited to contact data voluntarily shared through the networking and QR code scanning functionality, based on the data subject's consent;
- consultants, professionals, or service companies (e.g., legal, tax, administrative, or insurance), where necessary for purposes related to managing the service or fulfilling contractual and regulatory obligations;
- public authorities, bodies, supervisory bodies, or judicial authorities, if communication is required or foreseen by law or by order of the competent authority.
8. Transfer of Data Outside the EEA
Data is not transferred outside the European Economic Area. If necessary, the transfer will be carried out in compliance with Articles 44 et seq. of the GDPR, based on adequacy decisions or through standard contractual clauses approved by the European Commission.
9. Retention Period
Personal data is retained for a period of time proportionate to the purposes of the processing. Data related to the use of the App is retained for the entire duration of use and, subsequently, for a period appropriate to the management of any disputes or requests. Data processed for security and IT system protection purposes may be retained for a longer period, when necessary to prevent and detect illegal activities. In any case, the retention will not exceed the time necessary to protect the Data Controller's rights pursuant to current legislation.
10. Rights of the Data Subject
The data subject may exercise the rights set out in Articles 15–22 of the GDPR at any time, including:
- Right of access – to obtain confirmation as to whether or not personal data concerning you is being processed and receive information relating to such processing;
- Right to rectification – to obtain the rectification of inaccurate personal data or the completion of incomplete personal data;
- Right to erasure – to obtain the erasure of personal data in the cases provided for by Art. 17 of the GDPR;
- Right to restriction of processing – to obtain the limiting of processing in the cases provided for by Art. 18 of the GDPR;
- Right to data portability – to receive the personal data provided in a structured, commonly used, and machine-readable format and to transmit that data to another data controller, in the cases provided for by Article 20 of the GDPR;
- Right to object – to object at any time, for reasons relating to your particular situation, to the processing of personal data concerning you pursuant to Art. 6, paragraph 1, letters e) or f) of the GDPR;
- Right to withdraw consent – to withdraw any consent you have given at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
It is also possible to submit a complaint to the Authority for the Protection of Personal Data.
To exercise your rights, you can contact: privacy@federunacoma.it or avvocatoandreabonoli@libero.it.
11. Updates
This policy may be updated in the event of regulatory changes or technological developments of the App. Any changes will be communicated through the Data Controller's institutional channels and/or through the App itself.











