Grifo Group · Legal Information
Privacy Policy
Information on the processing of personal data in connection with Grifo Group’s digital services and business relationships.
Privacy notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
This privacy notice describes how the personal data of users who visit the Grifo Group website, use its digital services or contact the Group through the tools made available online are processed.
Corso Garibaldi, 49
20121 Milan (MI), Italy
Milan REA No. 2544391
Tax Code and VAT No. 10600020969
Certified email (PEC): grifopremium@legalmail.it
Scope of this Privacy Notice
Grifo Premium places particular importance on the protection of personal data and processes information relating to users in compliance with Regulation (EU) 2016/679 (GDPR), applicable Italian data protection legislation and the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality.
This privacy notice applies to processing carried out through the Grifo Group website and the related contact tools. Any services offered by individual companies belonging to the Group may be governed by specific privacy notices provided by the relevant companies.
Personal Data That May Be Processed
Different categories of personal data may be processed in connection with the use of the website and the relationships established through it.
Data provided directly by the user
When a user uses the contact form or communicates voluntarily with Grifo Group, depending on the circumstances we may collect the user’s first and last name, email address, telephone number, subject of the request, content of the message and any further information that the user voluntarily chooses to provide.
Browsing data
The IT systems and software procedures used to operate the website may acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols, such as IP address, browser type, device used, date and time of the request and other technical parameters required for the proper operation, security and management of the website.
Cookies and similar technologies
The website may use cookies and similar technologies. For detailed information about the categories used, their purposes and how preferences can be managed, please refer to the Cookie Policy .
Purposes of Processing
Personal data may be processed for purposes strictly connected with the operation of the website and the management of relationships with users.
- to enable browsing and the proper provision of digital services;
- to manage requests for information, communications and contact requests;
- where necessary, to direct a request to the Group company competent for the relevant subject matter;
- to take pre-contractual steps requested by the data subject, where the communication concerns a possible professional or commercial relationship;
- to ensure the security, integrity and protection of IT systems and to prevent abusive or unlawful use of the website;
- to comply with obligations imposed by law, regulations or measures issued by competent authorities;
- to establish, exercise or defend a right of the Data Controller in judicial or extrajudicial proceedings.
Legal Bases for Processing
Personal data are processed only where one of the legal bases set out in Article 6 of the GDPR applies.
In particular, the management of requests relating to services, professional relationships or possible contractual relationships may be necessary in order to take pre-contractual steps at the request of the data subject.
The management of general or institutional enquiries, website security and the protection of the Data Controller’s rights may be based on the pursuit of a legitimate interest, following an assessment of its compatibility with the rights and fundamental freedoms of the data subject.
Where processing is necessary to comply with a legal obligation, the legal basis is compliance with that obligation.
For processing based on consent, including any cookies or tracking tools that are not technically necessary, processing takes place only after the user has expressed a free and specific choice, where required by applicable legislation.
Provision of Personal Data
The provision of data marked as required in the forms available on the website is necessary in order for Grifo Group to receive and manage the user’s request.
Failure to provide such data may make it impossible to respond to the communication. The provision of additional information that is not requested is optional.
Users are requested not to include information in free-text fields that is not necessary for the management of their request and, in particular, not to provide special categories of personal data unless this is strictly necessary.
Processing Methods and Security
Personal data are processed using IT and telematic tools and, where necessary, organisational or documentary methods, in ways that are appropriate to the purposes described above.
The Data Controller adopts technical and organisational measures appropriate to the risk in order to protect personal data against loss, destruction, unauthorised access, disclosure, alteration or unlawful processing, taking into account the state of the art, the nature of the data processed and the characteristics of the processing.
Authorised Persons and Recipients of Personal Data
Personal data may be processed by personnel and collaborators authorised by the Data Controller, within the limits of their respective duties and in accordance with the instructions received.
Where necessary for the purposes described above, personal data may also be made available to parties that provide technical, IT, hosting, maintenance, security, email, website management or other services supporting the activities of the Data Controller.
Depending on the specific relationship, such parties operate either as independent data controllers or as data processors pursuant to Article 28 of the GDPR.
Disclosure to Group Companies
Grifo Group brings together companies with different expertise and activities in the insurance, financial, pension, technology, healthcare and credit brokerage sectors.
Where a request received through the website specifically concerns services or expertise attributable to one of the Group companies, the personal data strictly necessary for that purpose may be disclosed to the relevant company solely in order to enable the request to be handled.
The recipient company will process the data in accordance with the privacy role applicable to the relationship actually established and, where necessary, will provide its own specific privacy notice.
Mere membership of Grifo Group does not result in the indiscriminate disclosure of personal data to all companies belonging to the Group.
Transfers of Personal Data to Third Countries
If, in connection with the technological services used to operate the website, certain personal data are processed in countries outside the European Economic Area, any transfer will be carried out in accordance with the requirements of Chapter V of the GDPR.
Depending on the circumstances, transfers may rely on adequacy decisions adopted by the European Commission, standard contractual clauses or other safeguards recognised under applicable legislation.
Data Retention
Personal data are retained for no longer than is necessary to achieve the purposes for which they were collected, without prejudice to any legal obligations or requirements relating to the protection of the Data Controller’s rights.
Data relating to contact requests are retained for the time necessary to handle the request and any subsequent relationship arising from it. Where the request gives rise to a contractual or professional relationship, the retention periods provided for by applicable legislation and the privacy notices relating to the specific relationship will apply.
Technical and security data are retained for periods proportionate to the purposes of operation, security, prevention of abuse and investigation of any anomalies.
Cookies and Tracking Tools
The use of cookies and similar technologies is governed by the website’s specific Cookie Policy, which describes the technologies used, their purposes, any third parties involved and the tools through which users may express or change their preferences.
Rights of the Data Subject
In the circumstances and subject to the conditions laid down by the GDPR, data subjects may exercise the rights granted under Articles 15 et seq. of the Regulation.
- to obtain confirmation as to whether or not personal data concerning them are being processed;
- to obtain access to their personal data and information relating to the processing;
- to request the rectification of inaccurate data or the completion of incomplete data;
- to request the erasure of personal data in the cases provided for by law;
- to request restriction of processing;
- to object to processing where the conditions set out in Article 21 of the GDPR are met;
- to receive their data in a structured, commonly used and machine-readable format and request that they be transmitted to another controller, where applicable;
- to withdraw any consent given at any time, without affecting the lawfulness of processing carried out before withdrawal.
Right to Object
Where the processing of personal data is based on the legitimate interests of the Data Controller, the data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them, in accordance with Article 21 of the GDPR.
Automated Decision-Making
Within the information and contact functions described in this privacy notice, no decisions based solely on automated processing are made on the basis of data collected through the contact form where such decisions produce legal effects concerning the data subject or similarly significantly affect them.
Complaint to the Supervisory Authority
A data subject who considers that the processing of their personal data infringes applicable legislation has the right to lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority), without prejudice to the right to seek judicial remedies before the competent courts.
For information on the available means of protection, please visit the official website of the Garante per la protezione dei dati personali .
Changes to this Privacy Policy
This privacy notice may be amended or updated over time to reflect changes in legislation, changes to services, technological developments or changes in the way personal data are processed.
The updated version is published on this page. Users are therefore encouraged to review it periodically.
How to Exercise Your Rights
For enquiries concerning the processing of personal data or in order to exercise the rights provided for by applicable legislation, data subjects may contact the Data Controller using the contact details set out in this privacy notice.
Grifo Premium
Corso Garibaldi, 49 · 20121 Milan (MI), Italy
Certified email (PEC): grifopremium@legalmail.it