PRIVACY POLICY  WWW.AFIL.IT

Information notice on the processing of personal data pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)

Last updated: 27/02/2026

Dear Visitor or User,

The ASSOCIAZIONE FABBRICA INTELLIGENTE LOMBARDIA, with registered office in Via Ercole Oldofredi 23, 20124 Milan, Tax Code and VAT No. 08192390964 (hereinafter, the “Controller”), pursuant to Regulation (EU) 2016/679 (“GDPR”), hereby provides you with information regarding the processing of your personal data when you interact with the web services accessible from the website www.afil.it (hereinafter, the “Website”).

This privacy notice is provided pursuant to Article 13 GDPR to all individuals who interact with the Website and its specific sections—Membership (“Adesioni”), Members’ Reserved Area, Newsletter subscription, and Contact forms—and does not apply to third‑party websites or to project-related subdomains accessible via external links.

Your personal data will be processed in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, minimisation, accuracy, integrity, confidentiality and accountability, as set out in Article 5 GDPR.

DATA CONTROLLER AND DATA PROCESSORS

The Data Controller is the ASSOCIAZIONE FABBRICA INTELLIGENTE LOMBARDIA, as identified above.
The updated list of external Data Processors pursuant to Article 28 GDPR is available upon request by writing to direzione@afil.it.

CATEGORIES OF PERSONAL DATA PROCESSED

Browsing data

The IT systems and software procedures used to operate the Website acquire, during their normal functioning, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified individuals, but, by its very nature, could allow users to be identified through processing and association with data held by third parties.

This category of data includes IP addresses or domain names of computers used by users connecting to the Website, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained, the numerical code indicating the status of the server’s response (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.

Browsing data are retained for no longer than seven days, unless required by judicial authorities for investigation purposes.

Data voluntarily provided by the user

Contact section

The voluntary, explicit submission of data via the “Contact” form or via the email addresses published on the Website entails the acquisition of the sender’s address and any additional personal data included in the request, which are processed solely to respond to such requests.

Membership section (“Adesioni”)

Personal data voluntarily submitted for the purpose of requesting membership in the Association are processed exclusively in accordance with the purposes described in the Privacy Notice for Members and Members of Governing Bodies.

Members’ Reserved Area

Upon becoming a Member, the individual receives login credentials to access the Reserved Area, through which identification and contact data may be viewed or updated. Such processing falls under the purposes described in the above‑mentioned Privacy Notice.

Newsletter subscription

Subscription to the AFIL Newsletter via the dedicated form involves the voluntary provision of personal data and the expression of explicit consent under Article 6(1)(a) GDPR. The data are processed in accordance with the Newsletter Privacy Notice.

Newsletter delivery is managed via the Mailchimp platform (The Rocket Science Group LLC). For more information, please consult Mailchimp’s privacy practices.

Cookies

Information on the cookies used by the Website and on cookie management preferences is available in the Cookie Policy, accessible through the banner or directly from the Website footer.

PURPOSES AND LEGAL BASES OF THE PROCESSING

Personal data collected through the Website are processed by the Controller for the following purposes:

1) Technical functioning and security of the Website (browsing logs)

  • managing sessions, ensuring security, preventing abuse and malfunctions;
  • generating technical logs and event records.

Legal basis:

    • Legitimate interest of the Controller (Art. 6(1)(f) GDPR) in ensuring the proper functioning, security and availability of the Website.

2) Handling requests submitted via the “Contact” form

  • responding to information requests sent through the Website or via email.

Legal basis:

    • Performance of pre‑contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR).

3) Managing membership applications and the Members’ Reserved Area

  • receiving and assessing membership applications;
  • managing credentials and access to the Reserved Area.

Legal basis:

    • Performance of pre‑contractual measures and execution of the associative relationship (Art. 6(1)(b) GDPR), and fulfilment of statutory obligations. Further details are provided in the Privacy Notice for Members and Members of Governing Bodies.

4) Newsletter subscription and delivery

  • sending updates, communications and information relating to the Association’s activities, events and initiatives.

Legal basis:

    • Consent of the data subject (Art. 6(1)(a) GDPR). Further information is available in the Newsletter Privacy Notice.

5) Use of cookies and similar technologies

  • cookie management is governed by the Cookie Policy and the Website’s Consent Management Platform (CMP).

Legal bases:

    • technical cookies → strict necessity (no consent required)
    • anonymised analytics → legitimate interest (Art. 6(1)(f) GDPR)
    • non‑anonymised analytics and marketing cookies → consent (Art. 6(1)(a) GDPR) via the cookie banner.

NATURE OF DATA PROVISION

Providing personal data through the Website may be:

  • necessary for browsing, security, responding to requests, assessing membership applications or accessing the Reserved Area; in such cases, failure to provide data may prevent the Controller from fulfilling the requested service;
  • optional for newsletter subscription or for non‑essential cookies; refusal of consent prevents receipt of the Newsletter or activation of certain Website functionalities, without affecting general browsing.

PROCESSING METHODS AND DISCLOSURE TO THIRD PARTIES

Personal data are processed using electronic and, where necessary, paper-based tools, for the time strictly required to achieve the purposes described in this Privacy Policy or the specific notices referenced. The Controller adopts appropriate technical and organisational measures under Article 32 GDPR to prevent loss, destruction, unauthorized access or unlawful use.

Data may be accessed exclusively by personnel expressly authorised by the Controller and by service providers who support the operation of the Website (such as hosting providers, cloud services, IT maintenance providers, newsletter platforms), designated where necessary as Data Processors pursuant to Article 28 GDPR.

Pursuant to Article 6(1)(b) and (c) GDPR, without requiring consent, personal data may be disclosed to judicial authorities or public bodies when required by law.

Where recipients determine their own purposes and means of processing (e.g., public authorities), they will act as independent controllers.

Personal data will not be disseminated.

No automated decision‑making processes, including profiling under Article 22 GDPR, are carried out in connection with the Website.

TRANSFERS OF PERSONAL DATA OUTSIDE THE EU/EEA

Personal data processed through the Website are generally stored within the European Economic Area (EEA).
Where, for technical or operational reasons, transfers to third countries become necessary, the Controller will ensure compliance with Articles 44–49 GDPR, adopting one of the applicable safeguards (adequacy decisions, Standard Contractual Clauses, additional measures).

DATA SUBJECT RIGHTS

Data subjects may exercise at any time the rights established under Articles 15–22 GDPR, including:

  • right of access,
  • rectification,
  • erasure,
  • restriction of processing,
  • objection,
  • data portability,
  • right not to be subject to automated decision-making.

Data subjects also have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal, and to lodge a complaint with the competent Supervisory Authority.

Requests may be submitted by writing to: AFIL – Associazione Fabbrica Intelligente Lombardia c/o Innovhub, Via G. Colombo 83, 20133 Milan (MI) or via email to: direzione@afil.it

CHANGES TO THIS PRIVACY POLICY

The Controller reserves the right to update this Privacy Policy at any time. Updates will be published on this page. Users are invited to regularly consult this section to verify the most recent version.