Notice on the Processing of Personal Data collected through this website
Last revised: 23 September 2025

1. Introduction and regulatory references
This notice describes the processing of personal data collected through this website, including data acquired by means of cookies, tracking technologies and — where present — contact forms and any other features that may be active on the site.
This notice is addressed to anyone who accesses or uses this website, describing how the user’s personal data is collected, used and protected, as well as the rights granted by law.
These provisions do not concern other websites, pages or online services accessible through external links that may be present on the site, in respect of which you are invited to consult the relevant privacy notices.
This notice is provided in compliance with the principal national and international regulations on the protection of personal data, including:

  • Regulation (EU) 2016/679 (GDPR) and Directive 2002/58/EC, known as the ePrivacy Directive
  • Other regulations that may be applicable.

2. Who manages your data and how can you contact us?
Your personal data is processed by:
Corefab Srl - Società Benefit
Via Po,77 20032 Cormano (MI)
info@corefab.it
VAT ID: 09935390964

For any information concerning the processing of personal data or to exercise the rights granted by law, data subjects may contact the Data Controller.

3. On what legal bases do we process your data?
The processing of personal data collected through this site (including data collected by means of cookies, similar technologies, contact forms and any other features that may be active on the site) is based on one or more of the following legal bases:

  1. Performance of pre-contractual or contractual measures: where processing is necessary to respond to user requests, provide requested services and, where the site so provides, manage orders, accounts or contractual relationships.
  2. Compliance with legal obligations: where processing is necessary to comply with tax, accounting, administrative or security obligations or with requests from the authorities.
  3. Express consent of the user in relation to communications of an informational or commercial nature;

A further legal basis, the legitimate interest of the Data Controller, may be used for specific purposes (e.g. ensuring IT security, preventing fraud, protecting the Data Controller’s rights in legal proceedings).

Failure to accept or the withdrawal of consent may limit certain features or services of the site, such as receiving commercial communications or subscribing to the newsletter.

4. What data do we collect when you visit the site?
While browsing this site, the following data may be collected, including by means of cookies and similar technologies such as pixel tags, web beacons, local storage and equivalent technologies – namely:

  • Navigation and technical data: information such as IP address, device identifiers, data relating to the operating system and browser, requested URLs, connection times, technical logs, technical preferences, and usage data collected through cookies and tracking technologies (pixel tags, web beacons, local storage and equivalent tools).

5. How do we process your data, how do we protect it and how long do we keep it?
The personal data collected through this site is processed mainly by electronic and digital means in accordance with the principles of lawfulness, fairness, data minimisation, integrity and confidentiality.

Data is retained according to the following timeframes:

  • Cookie preferences and consents: retained for 180 days, as set out in the Cookie Policy on this site.
  • Navigation and technical data: retained for the time strictly necessary for security purposes and, as a rule, no longer than 12 months, after which it is deleted or anonymised, save for longer periods imposed by legal obligations or by the need to establish, exercise or defend a right in legal proceedings.
  • Data connected to any contractual relationships established with the Data Controller: where they exist, it is retained for the duration of the relationship and, thereafter, for the time required by the applicable legal obligations (for example in accounting and tax matters).
  • Data processed for marketing purposes: retained until consent is withdrawn or a deletion request is made.
  • Data entered through forms or specific requests: retained for the time necessary to respond to the request and to fulfil the related purpose, and thereafter for any period required by legal obligations.

6. Who can receive your data?
The following may access the personal data collected through this site, within the limits of their respective responsibilities and purposes:

  • Authorised internal persons designated by the Data Controller, duly instructed on privacy and security matters;
  • Suppliers and third parties appointed as Data Processors (for example: technical providers and IT services, site maintenance, e-mail providers, consultants, where applicable);
  • Third parties that provide services integrated into the site (e.g. fonts, maps, image display), which may process technical data as independent controllers in accordance with their own notices (in which case please also consult the individual notices of such third parties);
  • Competent public authorities and supervisory bodies, within the limits imposed by law or in order to comply with requests from the judicial authority;

The updated list of external recipients can be made available on request by writing to the Data Controller’s contact details.

7. Where can your data be transferred?
The personal data collected through this site may be processed within the European Union / European Economic Area. In some cases, the use of third-party services may involve a transfer to third countries. Where transfers to the United States take place, these are made to providers that adhere to the EU-US adequacy framework (Data Privacy Framework) or, failing that, on the basis of Standard Contractual Clauses.

8. What are your rights regarding the data collected?
The user, under the applicable legislation, has the right to:

  • Obtain confirmation as to whether or not personal data concerning them is being processed and, if so, obtain access to that data and the related information (right of access).
  • Request the rectification, updating or erasure of data that is inaccurate or no longer necessary (right to rectification and erasure).
  • Request the restriction of, or object to, the processing of data, including for promotional/profiling purposes, where provided for.
  • Request the portability of data in a structured and interoperable format (where technically possible).
  • Withdraw at any time any consent given, without affecting the lawfulness of processing based on consent carried out before the withdrawal (for example for the sending of commercial communications or newsletters, where active).
  • Withdraw the consent given to the use of non-technical cookies and to the processing of data collected through tracking tools.
  • Report any irregularities or abuses to the competent supervisory authorities.

To exercise these rights, it is sufficient to send a request to the Data Controller’s contact details. The Data Controller will respond without undue delay and, in any case, within one month of receiving the request, a period that may be extended by a further two months in the case of particular complexity or a high number of requests, in which case the data subject will be informed.

9. How is minors’ data processed?
The protection of minors is a fundamental priority.

This site is not directed at minors and does not intentionally collect their data through its forms. Where, in the context of a request or query, the user provides personal data relating to third parties — including any minors — they must ensure that they are authorised to do so; such data will be processed within the limits and for the purposes of the request, in compliance with the applicable legislation. For requests for rectification, restriction or erasure, you may write to the Data Controller’s contact details.

10. How can you make reports or complaints to the authorities?
If you believe that the processing of your personal data through this site does not comply with the applicable legislation, you may lodge a complaint free of charge with the competent supervisory Authorities, including:

11. How do we inform you of changes to this notice?
This notice is subject to periodic revision to reflect regulatory changes or modifications to the services offered through the site. Any significant change will be communicated through this page.
Last revised: 23 September 2025

_____________________________________________________________

Privacy Policy for the Basic Version of Svista Track

Effective Date: 10/02/2025

1. Introduction

This Privacy Policy describes how location data is processed within the basic version of the Svista Track app (“App”). In this version:

No registration is required, and no user database is maintained.
Location data is used exclusively to detect proximity to identifier devices (e.g., RFID or BLE beacons) that mark the totems and checkpoints along the route.
Data processing takes place solely on the user’s device and only for the time necessary to operate the app’s features. By using the App, the user consents to the processing of location data as described in this policy.

This notice is provided in conjunction with and in accordance with the provisions contained in the Corefab Srl Privacy Policy.

2. Data Controller

The Data Controller for the data processed through the App is:

Corefab Srl – Società Benefit
Via Po,77 20032 Cormano (MI)
info@corefab.it
Partita IVA: 09935390964

3. Data Collected

a. Location Data (GPS)

Purpose of Use:
The App accesses the device’s location services solely to verify proximity to identifier devices (totems and checkpoints) along the route.
Collection Method:
Location data is acquired in real time and used exclusively to trigger multimedia content or other location-related functionalities.
No Storage:
Location information is not stored, recorded, or transmitted to external servers; processing occurs solely on the device and only for as long as necessary to operate the function.
b. Other Data

Technical and System Data:
The App may use technical information about the device (e.g., model and operating system version) to ensure compatibility and optimize performance, without associating such data with any personal identity.

4. Purpose of Data Processing

Location data is processed solely for the following purposes:

Proximity Detection:
To verify in real time that the user is in the immediate vicinity of an identifier device (totem or checkpoint) in order to activate the associated content.
App Functionality:
To enable the correct functioning of the App’s features, such as the automatic activation of multimedia content when the user is near a device.

5. Method of Processing

Local Processing:
Location data is processed directly on the user’s device and is not transmitted to any third parties.
Transitory Processing:
Data is used only for the time necessary to verify proximity to the devices and manage the functionalities of the App.
No Storage:
No persistent logs or temporary files containing location data that could identify the user are created.

6. Consent and Management of Location Permissions

Request for Consent:
Upon launching the App, the user is informed and asked to authorize access to the device’s location services.
Consent Management:
The user may revoke location access at any time via the device settings.
Implications of Revocation:
Revoking location access may compromise the proper functioning of the features that rely on proximity detection to totems and checkpoints.
ù

7. Data Security

Technical and Organizational Measures:
Since location data is processed solely on the device and not transferred externally, the best practices are adopted to ensure data security and integrity during its brief usage.
Data Protection:
As no sensitive data is stored, the risk of unauthorized access or data breaches is minimized.

8. User Rights

Even though this version of the App does not store personal or location data, the user retains the following rights:

Access and Information:
To request information about how the data used by the App is processed.
Revocation of Consent:
To modify or withdraw the location access permissions at any time via the device settings.
Request for Clarification:
To contact the Data Controller for further information or clarifications regarding this Privacy Policy.
To exercise these rights or for any requests related to data protection, the user may contact us using the details provided in Section 2.

9. Changes to the Policy

We reserve the right to update this Privacy Policy at any time in accordance with applicable laws and industry best practices. Any changes will be published within the App and, if necessary, communicated to the users. We recommend that you periodically review this page for any updates.

10. Contact

For questions, clarifications, or additional information regarding this Privacy Policy, please contact:

Corefab Srl – Società Benefit
Via Po,77 20032 Cormano (MI)
info@corefab.it
Partita IVA: 09935390964

Warning: some page functionalities could not work due to your privacy choices: