Privacy Policy

Information on the protection of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

THUX CODE S.r.l., with registered office at Via Dante Alighieri, no. 99, 20096, Limito di Pioltello (MI), VAT no. 14012250966 - tel. +39 02.00644600 - email: amministrazione@thux.it, as Data Controller (hereinafter, the "Company" or the "Controller"), provides the following information regarding the processing of personal data that will be carried out when users access its corporate website via an online connection from the address: http://thuxcode.it (hereinafter, the "Site").
As is known, through the Internet service provider, it is possible to trace the real and sensitive data of a natural person from the IP address of a PC.
In this regard, please note that the information is provided only for the Site and not for other websites that may be consulted via hyperlinks or widgets (e.g., social networks) published on the Site, but which refer to resources outside the Data Controller's domain or to processing that may result from the voluntary sending of messages.

1. Categories of data subjects and personal data processed

The Data Controller processes the personal data of natural persons (identified or identifiable) who visit and consult the Site or who voluntarily interact with the Data Controller within it (hereinafter, the "Users").

The personal data processed are:

  1. Navigation data: The computer systems and software procedures used to operate the Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes: IP addresses or domain names of computers and terminals used by users, URI/URL (Uniform Resource Identifier/Locator) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.), and other parameters relating to the operating system and IT environment of users;
  2. Data communicated: The optional, explicit, and voluntary sending of messages by completing and submitting forms on the Site and/or to the Company's contact addresses or institutional social media profiles/pages (where available) entails the acquisition of the User's contact information necessary to respond, as well as any additional personal data included in the registration form or in communications. Specific information will be published on the Site pages containing the form or dedicated to the provision of certain services.
  3. Cookies and other tracking systems: For more information on the types of cookies used, their management, and their purposes, please consult the cookie policy on the Site: https://code.thux.it/en/cookie-policy

2. Purpose of the Processing and legal bases:

The Data Controller processes the Personal Data collected in the context of the Site for the purposes and pursuant to the legal bases indicated in the following table:

 

What are the PURPOSES of the processing?

 

What are the LEGAL BASIS for the processing? 
1) Fulfillment of a legal obligation related to civil, fiscal, and administrative provisions, EU legislation, standards, codes, or procedures approved by competent authorities and other institutions, as well as to respond to requests from the competent administrative or judicial authority and, more generally, from public entities in compliance with legal formalities. Fulfillment of a legal obligation to which the Data Controller is subject.
2) Assert and defend your rights, including through out-of-court actions and through third parties, as well as prevent and detect fraudulent activity or abuse of the Site (for potentially criminal purposes, such as identity theft, computer crimes, etc.). Pursuit of the legitimate interest of the Data Controller.
3) To allow Users to access the Site and navigate it optimally and manage requests received through the Site. Execution of pre-contractual measures taken at the User's request.
4) Limited to the browsing data of Users referred to in paragraph 1, point a), for the security purposes of the Data Controller's systems and to obtain statistical information on the use of the Site (such as the most frequently visited pages of the Site, the average time spent on each page), as well as to monitor and manage the functioning of the Site and improve the services provided. Pursuit of the legitimate interest of the Data Controller.
5) To manage the contact section of the site and therefore to respond to any user requests received through the completion of any forms or by sending communications to the Data Controller's email address. Execution of pre-contractual measures taken at the User's request.

3. Mandatory provision of the requested data and consequences of failure to provide it

Except as specified for browsing data (and, in the specific policy, for cookie management), the user is free to provide their personal data (via forms - on pages that allow it - or by other means to the Data Controller's contact details) to send information requests or to receive commercial communications.
It is understood that failure to provide such data, even partially, may prevent the Data Controller from fulfilling the User's requests and from carrying out communication and marketing activities, as well as fulfilling any related obligations.

4. Treatment methods

Personal Data will be processed using both manual and automated computerized tools exclusively by authorized and specifically trained persons.

5. Recipients/categories of recipients of personal data

For the purposes indicated in this policy:

  • Users' Personal Data may be disclosed:
    • to those authorised to process data by the Data Controller (employees or collaborators);
    • to third-party service providers to the Data Controller (including IT service providers, hosting providers, web editors, as well as companies or individuals providing legal and insurance services) who will act, where applicable, as data controllers;

    • to third-party companies and professionals appointed to enforce the owner's rights, interests, and claims arising from the relationship with the Users;

    • to State Administrations, Judicial or Administrative Authorities, Public and Private Bodies, including following inspections and audits;
       
    • to subjects who can access the data pursuant to provisions of law or secondary or community legislation.

Only the category of recipients is indicated, as it is subject to continuous updates. To obtain an updated list of recipients, Users may contact the Data Controller directly using the contact details indicated in section 9 of this policy.

6. Personal data retention periods

Personal Data will be retained by the Data Controller for the time strictly necessary for the purpose for which it was collected; specifically, the Data Controller will retain:

  • Users' browsing data (indicated in paragraph 1, letter a) for the duration of the browsing session and in any case no longer than seven days, except in the case of system malfunctions, in which case they will be retained until the problem is resolved;
  • the data communicated by the Users (indicated in paragraph 1, letter b)

    • with regard to personal data communicated by filling out the forms on the website, for the time necessary to process the relevant request;
  • Personal Data whose processing is necessary in relation to legal obligations for the duration of the law;

and in any case, for the purposes referred to in paragraph 2, no. 2, for a maximum period equal to the statute of limitations for relevant actions, increased by a precautionary period of six months, in order to ensure the Company's right to defend itself against possible future disputes in court or administrative proceedings.
In all cases, upon expiration of the respective deadlines, all Personal Data will be deleted or anonymized. It is understood that the indicated deadlines may be extended in cases where retention for a longer period is required due to potential disputes, requests from competent authorities, or pursuant to applicable legislation.

7. Transfer of personal data to a third country or to an international organisation

For the purposes set out above, your data may be transferred to EU countries.

8. Rights

Users, if the circumstances apply, may exercise the following rights against the Data Controller:

  • Right of access: allows Users to obtain confirmation from the Data Controller as to whether or not Personal Data concerning them is being processed and, where that is the case, to obtain access to their personal data;

  • Right to rectification: allows Users to obtain the rectification/integration of inaccurate/incomplete Personal Data;
  • Right to erasure: allows Users to obtain, in the cases provided for by law, the erasure of their personal data;
  • Right to restriction of processing: allows Users to obtain, in the cases provided for by Art. 18, paragraph 1 of the GDPR, the restriction (i.e., the marking of stored personal data with the aim of limiting their processing in the future) of the processing of their personal data;

     

  • Right to data portability: allows Users - in cases where the processing is carried out by automated means on the legal basis of the contract or consent - to receive the personal data concerning them in a structured, commonly used and machine-readable format, limited to the data provided to the Data Controller, and similarly the right to transmit such data to another data controller.

Furthermore, Users have the right:
to object to the processing of their Personal Data for the purposes indicated in paragraph 2;
and, if they believe that the processing of their Personal Data carried out through this Site violates the provisions of the GDPR, to lodge a complaint pursuant to Art. 77 of the GDPR with the national supervisory authority of the European Union Member State in which the Data Subject has his or her habitual residence or place of work, or where the alleged violation of his or her rights occurred (if that State is Italy, the authority to which the Data Protection Authority may apply is the Italian Data Protection Authority), or to take appropriate legal action (Article 79 of the GDPR).

9. Contacts

To exercise all rights, the interested party may submit a request by contacting the Data Controller as follows:

By mail to THUX CODE S.r.l. at Via Dante Alighieri, 99 – 20096 Pioltello (Milan);
By sending an email to amministrazione@thux.it

10. Changes

This privacy policy was updated on September 1, 2025.
The Company reserves the right to modify this policy in whole or in part or update its content, for example, following changes in applicable law. Therefore, the Company encourages Users to regularly consult the policy to review the latest version, so as to remain informed about how Personal Data is collected and used.

11. Specific treatments related to the use of “Thuxbot”

Owner: THUX CODE S.r.l., Via Dante Alighieri 99, 20096 Pioltello (MI), C.F./P.IVA 14012250966, PEC: thuxcode@pec.it.


a) Data categories

  • Conversational content: text typed by the User in the widget and responses displayed.

  • Technical metadata: date/time, referring page, session identifiers, security events, IP address and user agent (in line with “Browsing Data”).
  • Any contact information (e.g., email) will only be provided for recontact or follow-up purposes.

     

b) Purposes and legal bases

  • Provision of the conversational service and management of pre-contractual responses/FAQs: art. 6.1.b GDPR (pre-contractual measures at the User's request).
  • Security, prevention of abuse/malfunctions, limited quality assurance, and service improvement (non-profiling tests): legitimate interest of the Data Controller (Article 6.1.f), with minimization and balancing.
  • Legal protection/compliance (if applicable): legal obligation or legitimate interest (art. 6.1.c/f).


c) Nature of the contribution

Optional; failure to provide conversational content will prevent the widget from being used.

d) Logic and measures

No solely automated decisions are made that produce legal effects on the User (Article 22 GDPR). Technical/organizational measures are adopted to reduce the data processed (e.g., pseudonymization, filters to block sensitive data, and prompt injection).


e) Recipients / categories of recipients

  • Internal Data Controller Authorized Persons (IT/ops/support).
  • The Data Controller's IT providers acting as Data Processors pursuant to Art. 28 GDPR (e.g., hosting/cloud, AI API tools, security monitoring); an updated list is available upon request using the contact information provided in section 9 of the Policy.


f) Transfers outside the EEA

Processing with foreign components/clouds may involve transfers to countries outside the EEA. In such cases, the Data Controller applies the safeguards set forth in Chapter V of the GDPR (e.g., Standard Contractual Clauses, supplementary measures) or uses adequacy decisions where available.
Updated information on the countries and safeguards is provided upon request using the contact details in section 9.


g) Conservation

  • Conversational content: for the time strictly necessary to provide the response and carry out technical protection/quality activities, and in any case no longer than 90 days, except for legal defense or security needs.

  • Technical/security metadata: in line with the Data Controller's logging policies (up to 6 months) where strictly necessary for security/diagnostics, subject to extension in the event of investigations/disputes.

Upon expiration of the terms, the data is deleted or anonymized.


h) Rights of interested parties

The rights indicated in paragraph 8 of the Policy (access, rectification, erasure, limitation, portability, objection, complaint to the Guarantor) remain unchanged. The User can request additional information on suppliers, third-party countries, and guarantees by writing to the contacts in paragraph 9.


i) Cookies/similar technologies

The widget may use cookies/technical technologies necessary for its operation (e.g., storing conversation status). For details and any non-essential metrics, please refer to the Site's Cookie Policy.