Privacy Policy
Introduction
Pursuant to and for the purposes of Article 13 of Regulation (EU) 2016/679 (hereinafter, "GDPR"), this Privacy Policy is provided by LIDIA S.r.l. (hereinafter, the "Controller" or the "Company") and is intended for all users (hereinafter, "Users" or "Data Subjects") who use the services offered by the Controller. The Controller is committed to protecting Users' privacy and to processing personal data in compliance with the applicable data protection legislation, in particular the GDPR, Legislative Decree 196/2003 (“Privacy Code”), and its subsequent amendments and additions.
The Controller makes the generative artificial intelligence platform “LIDIA” (hereinafter, the “Platform”) available as part of a contract entered into with its client, who provides specific instructions for identifying the Users who will use the Platform.
This Privacy Policy aims to clarify how the Users’ personal data is collected, used, and protected by the Controller, as well as to outline the Users’ rights concerning their personal data and how to exercise those rights. Users are encouraged to read this Privacy Policy carefully before using any services offered by the Controller.
Data Controller
In accordance with the provisions of the GDPR and the Privacy Code, Users are informed that the Data Controller for their personal data is LIDIA S.r.l., VAT number 02976860995, with registered office at Corso Andrea Podestà 8/3, 16128 Genoa (GE), Italy.
Purpose of data processing
The processing of Users’ personal data collected by the Controller through the Platform or other means serves the following purposes:
- To provide the services requested by the Users, including managing requests for information or assistance.
- To improve the Users’ experience on the Platform, including content personalization.
- To carry out anonymous statistical analyses to evaluate Users’ behavior and improve the services offered.
- To comply with legal obligations, regulations, national and EU laws, or to execute orders from judicial authorities.
- To prevent or detect fraudulent activities or abuses harmful to the Platform; and
- To inform Users about changes to the services offered by the Controller or concerning company conditions and policies.
Types of personal data
In accordance with the provisions of the GDPR and the Privacy Code, the Controller informs Users that, through its Platform or the services offered, the following types of personal data may be processed:
- Personal identification data (e.g., first name, last name);
- Contact data (e.g., e-mail address, phone number);
- Authentication data (e.g., username, password);
- Navigation data (e.g., IP addresses, system logs);
- Data related to service usage (e.g., usage preferences, feedback);
- Other personal data voluntarily provided by Users during their use of the Platform.
The processing of such personal data by the Controller is carried out in compliance with the purposes set forth in this Privacy Policy, based on the consent provided by the User, where necessary, and in accordance with applicable legal provisions.
Legal Bases for Processing
In accordance with the GDPR and the Privacy Code, the Controller processes Users’ personal data based on the following legal bases:
- Consent: the Controller may process personal data where the User has explicitly given their consent for one or more specific purposes.
- Contract: processing is necessary for the performance of a contract to which the client of LIDIA S.r.l. is a party, or to take steps at the request of the client prior to entering into a contract.
- Legal obligations: processing is necessary to comply with a legal obligation to which the Controller is subject.
- Legitimate interests: processing is necessary for the legitimate interests pursued by the Controller or by third parties, provided that these interests are not overridden by the interests or fundamental rights and freedoms of the Users that require the protection of personal data.
Disclosure and Sharing of Personal Data
The Controller may share Users’ personal data with various categories of recipients, including, but not limited to, third-party service providers who assist in managing the Platform, providing the services requested by Users, conducting analyses and market research, or carrying out promotional and advertising activities. These third parties are carefully selected and appointed by the Controller. They have access only to the personal data necessary to perform their functions and are not permitted to use it for any other purpose. Furthermore, they are required to process personal data in accordance with the Controller’s instructions and in compliance with the applicable data protection laws.
Transfer of Personal Data Abroad
In accordance with applicable data protection laws, the Controller may transfer Users’ personal data to recipients located outside the European Union (EU). Such transfers will only take place to countries that ensure an adequate level of data protection or on the basis of appropriate safeguards, such as adequacy decisions or standard contractual clauses approved by the European Commission.
Before carrying out any transfer of personal data outside the EU, the Controller undertakes to ensure that all necessary measures have been adopted to guarantee that Users’ personal data is processed securely and in compliance with this Privacy Policy and with applicable legislation.
For further information regarding the transfer of personal data outside the EU or the security measures adopted by the Controller, Users may contact the Controller using the contact details provided in this Privacy Policy.
Data Subjects’ Rights
In accordance with applicable data protection laws, Users have the right to exercise the following rights in relation to the personal data processed by the Controller:
- Right of access: Users have the right to obtain confirmation from the Controller as to whether or not personal data concerning them is being processed, and, if so, to access such data and information related to its processing.
- Right to rectification: Users have the right to obtain from the Controller the rectification of inaccurate personal data concerning them without undue delay.
- Right to erasure ("right to be forgotten"): Users have the right to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller is obliged to erase such data where certain conditions set out in Article 17(1) of the GDPR are met.
- Right to restriction of processing: Users have the right to obtain from the Controller the restriction of the processing of their personal data in the situations described in Article 18(1) of the GDPR.
- Right to data portability: Users have the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and have the right to transmit such data to another controller without hindrance from the Controller.
- Right to object: Users have the right to object at any time to the processing of personal data concerning them for reasons related to their particular situation.
- Right not to be subject to automated decision-making: Users have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
- Right to withdraw consent: Users have the right to withdraw their consent at any time, acknowledging any consequences this may have. However, the Controller may still retain personal data where necessary to comply with a legal obligation or to perform a task carried out in the public interest or in the exercise of official authority vested in the Controller.
Users may exercise their rights by contacting the Controller directly, using the contact details provided in this Privacy Policy. Additionally, Users have the right to lodge a complaint with the Data Protection Authority if they believe that the processing of their personal data by the Controller violates applicable legislation.
Data Retention Period
In accordance with applicable regulations in Italy, the Controller retains Users’ personal data for the period strictly necessary to fulfill the purposes for which it was collected and, in any case, for no longer than 10 years from the time of collection for purposes related to compliance with legal or contractual obligations, or for longer periods if necessary for the establishment, exercise, or defense of legal claims.
At the end of the retention period, personal data will be deleted or otherwise anonymized, unless there is a further purpose justifying its continued storage. The Controller undertakes to periodically assess the necessity of retaining personal data in order to minimize the retention period.
Security Measures
The Controller is committed to protecting Users’ personal data by adopting all necessary technical and organizational security measures to prevent unauthorized access, disclosure, alteration, or destruction of personal data. These measures include, but are not limited to, physical security procedures for the spaces where data is stored, IT security procedures for accessing information systems (such as encryption), as well as procedures to ensure the secure transmission of data.
The Controller uses servers located within the European Union for the storage of personal data.
The Controller is also committed to regularly training its staff on the proper handling and protection of personal data, in order to ensure its security throughout all stages of processing.
The Controller will periodically review and update the security measures in place, if necessary, to ensure the continued protection of Users’ personal data against emerging risks. In the event of a personal data breach, the Controller undertakes to notify the competent authorities and, where necessary, the affected Users, in accordance with applicable regulations.
Contact information
For any questions or requests regarding the processing of personal data by the Controller, Users may contact the Controller at the following address:
• E-mail address: privacy@mesagroup.eu
• Postal address: LIDIA S.r.l., Corso Andrea Podestà 8/3, 16128 Genova (GE)
The Controller undertakes to respond without undue delay and, in any case, within one month of receiving the request. This period may be extended by two additional months if necessary, taking into account the complexity and number of the requests. The User will be informed of any such extension and the reasons for the delay within one month of receiving the request.
Privacy Policy Updates
The Controller reserves the right to make changes to this Privacy Policy at any time by publishing the updated version on the Platform or by notifying Users through other communication channels used. Users are encouraged to review it regularly.
Continued use of the services offered by the Controller after the publication or communication of any changes shall constitute acceptance of those changes by the Users.
[Last updated: May 2025]
