1. Introduction
This notice explains how personal data of users who visit www.temagroup.eu (Italian and English versions) and use its forms is processed, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). It does not cover third-party websites reached through links (for example YouTube, Google Maps and the websites of the group companies), which have their own notices.
2. Data controller
The data controller is Consorzio TEMAGroup, with registered office at Via della Transumanza 5, 74123 Taranto (Italy), VAT no. 02860500731.
Contacts for any matter relating to the processing of personal data: email info@temagroup.eu — certified email (PEC) consorziotemagroup@pec.it — telephone +39 099 4724607.
3. Data processed while browsing
When you visit the website, the systems hosting it automatically record some technical information: IP address, date and time of the request, requested page, outcome, browser and device data. This information is needed for the operation and security of the website and is not used to profile you. The website does not use statistical analytics or advertising tools.
4. Data you provide voluntarily
We process the data you choose to give us by writing to us by email or phone or by filling in the website forms described below. Fields marked with an asterisk are mandatory: without them we cannot handle your request.
5. Contact form
- Data collected: full name, email address, company, message.
- Purpose: to handle the request sent through the form and reply to you.
- How: the message is sent by email to the Controller’s company mailbox and is not stored in the website database. It remains in the mailbox and in its backup systems.
- To prevent automated spam, the form keeps for about one hour a technical counter linked to your IP address in hashed form; it does not contain the text of your message.
- The form does not subscribe you to newsletters and has no marketing purpose.
6. Flashover form
- Data collected: full name, email, telephone, shipping address (street, postal code, city, province), number of copies, optional notes and the copy of the payment receipt you attach (.jpg, .pdf or .png file).
- Purpose: to handle the book request, check the payment, arrange shipping and meet the related administrative and accounting obligations.
- Attachment: the receipt may contain further personal data (for example those of the person who made the payment). Please attach only the document needed to prove the payment and hide any irrelevant information.
- How: the data and the attachment are sent by email to the Controller’s staff in charge of order management. The attachment is transmitted as a temporary file of the website and is deleted after sending; it remains in the mailbox and its backups.
7. Security systems — reCAPTCHA
The Flashover form is protected by Google reCAPTCHA, used for security and fraud and abuse prevention purposes (telling people from automated programs). reCAPTCHA is loaded only on the Flashover form page and performs an automated risk analysis of your interaction with the page; the outcome is used only to accept or reject the submission and has no legal effect on you. For this service Google acts as a processor on behalf of the Controller, according to its own data processing terms. The service involves sending technical information about your device and browsing to Google and may set a technical cookie (see the Cookie Policy).
8. Cookies and similar tools
The website only uses technical tools described in the Cookie Policy. It does not use analytics, marketing or profiling cookies.
9. Purposes of processing
- Handling requests sent through the Contact form and replying.
- Handling Flashover book requests, payment checks, shipping and related administrative and accounting tasks.
- Website security, prevention of abuse and spam, technical operation (logs, reCAPTCHA).
- Compliance with legal obligations and defence of legal claims, where necessary.
10. Legal bases
- Information requests (Contact): steps taken at the data subject’s request prior to entering into a contract (Art. 6(1)(b) GDPR) and, for requests of a different nature, the Controller’s legitimate interest in replying (Art. 6(1)(f)).
- Book request and purchase (Flashover): performance of the relationship with the data subject (Art. 6(1)(b)) and administrative/accounting legal obligations (Art. 6(1)(c)).
- Website security, logs and reCAPTCHA: legitimate interest in security and abuse prevention (Art. 6(1)(f)).
Providing the data marked as mandatory is necessary to handle the request; failing to do so makes it impossible to follow it up. No special categories of data are processed.
11. How data is processed
Data is processed with IT and electronic tools by authorised and instructed persons, with security measures appropriate to the risk. No decisions based solely on automated processing producing legal effects on you are taken.
12. Recipients and processors
Data may be processed by: authorised internal staff; suppliers acting as processors — the website hosting provider (Ergonet), the provider of the company email service, Google for the reCAPTCHA service and any IT support providers; public authorities where required by law. Data is not disseminated or transferred to third parties for their own purposes.
13. Transfers outside the EEA
The Controller does not directly transfer personal data to countries outside the EEA. The Google reCAPTCHA service, used only on the Flashover form, is provided by a company based in the United States and may involve processing data outside the European Economic Area, with the safeguards under Chapter V of the GDPR indicated by Google in its contractual terms.
14. Retention periods
Data is kept for the time needed for the purposes for which it was collected, according to these criteria:
- Contact form messages: the time needed to handle the request and the reply; if the request leads to a business relationship, data is kept for the duration of the relationship and for the legal terms. Deletion or archiving when the request is concluded and there is no other ground for retention.
- Flashover form data and receipts: the time needed to fulfil the order and, for data and documents relevant for accounting and tax purposes, for the terms set by law (generally ten years, Art. 2220 of the Italian Civil Code).
- Anti-spam counter of the Contact form: about one hour.
- Technical hosting logs: for the period set by the provider for security and operational reasons.
- Backup copies follow the provider’s systems rotation cycle.
15. Hosting and infrastructure
The website is hosted by Ergonet. Hosting involves processing technical data (IP address, HTTP requests, access and error logs) and creating backup copies, according to the provider’s configuration.
16. Your rights
Within the limits set by the GDPR you can ask the Controller for access to your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability where applicable (Art. 20), and you may object to processing based on legitimate interest (Art. 21). If a processing were based on consent, you may withdraw it at any time without affecting the lawfulness of the processing carried out before. To exercise your rights, write to the contacts in section 2: you will receive a reply within one month, extendable in the cases provided by law.
17. Complaint to the supervisory authority
You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the authority of the country where you live or work.
18. Changes to this notice
This notice may be updated, including for legal or technical changes. The version in force is always the one published on this page.
19. Last update
Last update: 7 October 2026