Last updated: 17/09/2026
Information on the processing of personal data provided pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 ("Privacy Code") to users of the website www.sassrl.net.
This English version is provided for convenience only. In the event of any discrepancy, the Italian version shall prevail.
- Data controller
S.A.S. Servizi Aziendali Specialistici S.r.l., Via Val Trompia 140 – 00141 Rome (RM), Italy, tax code and VAT no. IT05580521002 ("S.A.S." or the "Controller").
For any request concerning the processing of personal data, please write to info@sassrl.net.
- Data processed, purposes, legal bases and retention periods
a) Browsing data
- Data: as with any website, the systems that run the site collect certain technical data automatically transmitted by the browser, such as IP address, date and time of the request, page requested and browser type.
- Purpose: to ensure the proper functioning and security of the website and to detect any abuse.
- Legal basis: the Controller's legitimate interest in the security of its systems (Article 6(1)(f) GDPR).
- Retention: for the time strictly necessary for these purposes, without prejudice to any need for the authorities to investigate unlawful acts.
b) Contact requests
- Data: name, email address and message content sent through the "Send us a message" form or by writing to the email addresses shown on the website.
- Purpose: to respond to requests for information.
- Legal basis: pre-contractual measures taken at the request of the data subject (Article 6(1)(b) GDPR) and the Controller's legitimate interest in responding to the communications received (Article 6(1)(f) GDPR).
- Retention: for the time needed to handle the request and, thereafter, for a maximum of 12 months. If the request leads to a contractual relationship, the data are kept for the duration of that relationship and for the subsequent periods required by law.
c) Job applications
- Data: first and last name, email address, telephone number, any message and the curriculum vitae sent through the "Work with us" form or by email.
- Purpose: to assess the application and, where appropriate, contact the candidate for the selection process.
- Legal basis: pre-contractual measures taken at the request of the data subject (Article 6(1)(b) GDPR). Pursuant to Article 111-bis of the Privacy Code, consent is not required for unsolicited applications.
- Special categories of data: please do not include in your CV any data that are not necessary for the assessment, in particular data concerning health, political or religious opinions or other special categories of data (Article 9 GDPR). If present, such data will only be processed where strictly necessary, for example to establish membership of protected categories, within the limits of Article 9(2)(b) GDPR.
- Retention: 12 months from receipt, unless an employment relationship is established.
d) Gender equality reports (UNI/PdR 125:2022)
- Data: the Anonymous Report Form in the "Certifications" section does not request any information identifying the sender, and the message sent does not contain the IP address, user agent or any other technical information about the sender. However, the content of the report may, at the writer's discretion, include information relating to the sender or to other people: please include only what is necessary to describe the matter.
- Purpose: to handle suggestions, reports and complaints within the gender equality management system adopted by S.A.S. The form is intended exclusively for these purposes.
- Legal basis: the Controller's legitimate interest in managing and improving its gender equality system and ensuring an inclusive and respectful working environment (Article 6(1)(f) GDPR).
- Access: reports are sent to a dedicated mailbox, accessible only to the people in charge of managing the gender equality system. The browsing data referred to in point a) are not linked to reports or used to identify their author.
- Retention: for the time needed to handle the report and to carry out the checks required by the management system, and in any case no longer than 36 months.
e) Protection of forms against spam and abuse
- Data: when the user opens or fills in one of the website's forms, the Google reCAPTCHA service is activated, which collects technical data about the device and the interaction with the page (for example IP address and browser information).
- Purpose: to verify that submissions do not come from automated systems.
- Legal basis: the Controller's legitimate interest in the security of the website (Article 6(1)(f) GDPR).
- Retention: according to the periods set by Google, available in the Google Privacy Policy.
- Provision of data
Providing data through the website's forms is optional. However, the fields marked with an asterisk are required: without them, the request, application or report cannot be submitted.
- Processing methods
Data are processed electronically by authorised staff, with appropriate technical and organisational measures to protect them against unauthorised access, loss or disclosure, within the ISO/IEC 27001-certified Information Security Management System adopted by S.A.S. Data are not used for marketing purposes, nor are they subject to automated decision-making, including profiling, producing legal effects on data subjects.
- Recipients of the data
Data may only be disclosed to:
- S.A.S. staff authorised to process them, according to their respective duties;
- providers of technical services (for example website hosting, email and IT support), acting as data processors pursuant to Article 28 GDPR;
- Google Ireland Limited, for the reCAPTCHA service described in point 2(e);
- public authorities, where disclosure is required by law.
Data are not disseminated.
- Transfer of data outside the European Union
The use of Google reCAPTCHA may involve the transfer of technical data to the United States. Such transfers are based on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework, to which Google LLC adheres. No other data are transferred outside the European Economic Area.
- Rights of the data subject
Data subjects may exercise at any time the rights provided for by Articles 15-22 GDPR: access to their data, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest. Requests may be sent to info@sassrl.net.
For anonymous reports, since their author cannot be identified, S.A.S. may be unable to act on requests that require the identification of the data subject (Article 11 GDPR).
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
- Cookies
For information on the cookies used by the website, please see the Cookie Policy.
- Changes to this notice
S.A.S. may update this notice, for example following changes in the law or new services offered through the website. Any changes will be published on this page together with the date of the update.