Back

Privacy Policy

If you are reading this policy, it means you have arrived on our website. We provide this information so that you can understand how we handle your personal data when you browse our website or when you interact with us through it: for example, when you write to us. On all these occasions, and not only these, we process some of your personal data. We do so in compliance with EU Regulation 679/2016 (GDPR) and in compliance with the Italian Privacy Code as amended by Legislative Decree 101/2018. This notice is provided pursuant to Articles 13 and 14 of the GDPR and concerns only the processing carried out through the website matchsrl.it and the forms contained therein (contact area, submission of job applications, Job Alert service, whistleblowing channel).

Who is the Data Controller for your data?

The Data Controller for the data collected through this website is Match S.r.l., with registered office in Viale Carlo Espinasse 143 – 20156 Milano, C.F. e P. IVA 02844730123. You can contact the Data Controller at the following e-mail address: privacy@matchsrl.it

Why do we process your data and when do we collect it?

BROWSING DATA

The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This category of data includes the IP addresses or domain names of the computers and terminals used by users, the URI/URL addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numeric code indicating the status of the response given by the server (success, error, etc.), and other parameters relating to the user’s operating system and computer environment.

Can we do this without your consent? Yes, as the data is necessary for Internet communication, to allow you to use the website, and to ensure the security of the website and networks, a legitimate interest of the Data Controller (Art. 6(1)(f) GDPR, also in relation to Art. 32 GDPR).

How long do we retain this data? Browsing data is not retained for more than seven days (except for any need to ascertain offenses on the part of the Judicial Authority). Technical logs generated by the hosting provider are retained for the period indicated in the Data Processor appointment document and, in any case, for the time strictly necessary to ensure the security of the systems.

COOKIE-RELATED DATA

As Data Controllers, while you browse our website, we collect certain data from you for the purposes of analyzing and processing information related to your preferences and browsing experience. To carry out this activity, we use technologies such as cookies (our own or third-party).

Can we do this without your consent? Partly. The collection of data through the use of technical cookies, necessary for the correct functioning and security of the website, does not require your consent pursuant to Art. 122(1) of Legislative Decree 196/2003 and the Guidelines of the Italian Data Protection Authority (Garante Privacy) on the use of cookies of June 10, 2021. The collection of personal data through the use of first-party and third-party cookies that are not strictly necessary takes place only with your express consent (Art. 6(1)(a) GDPR and Art. 122(1) of Legislative Decree 196/2003). We notify you of this via a dedicated banner found at the bottom of the site the first time you connect. You can change or withdraw your choices at any time by accessing the preferences panel via the link present on every page of the site. There you can select in detail which cookies you want to install. For more information on what cookies are, their function, etc., you can read our cookie policy, available at https://www.iubenda.com/privacy-policy/42083247/cookie-policy.

How long do we retain this data? The retention period for this data is defined in the cookie banner, by choosing to view it in detail, or in the settings menu found at the bottom of every page of the site.

CONTACT AREA (INFORMATION REQUEST FORM)

If you decide to contact us through the form on our website, we will treat your personal identification data (name and surname), your e-mail address, your phone number (if provided), your company of affiliation, and the content of the message you send us. Providing the data marked as mandatory is necessary in order to respond to your request: without it, we will not be able to reply to you. To protect the website’s forms from automated message submissions, we use Google Ireland Limited’s reCAPTCHA service, which involves the collection of your IP address and information about your interaction with the page; the legal basis is our legitimate interest in the security of the website (Art. 6(1)(f) GDPR).

Can we do this without your consent? Yes, because we are following up on a request you have made (Art. 6(1)(b) GDPR).

How long do we retain this data? We retain this data for the time necessary to process your request. It is understood that, should you decide to become our customer, the data will be retained for 10 years pursuant to Art. 2220 of the Italian Civil Code, or, in the event you request a quote or offer from us, we will retain your data for 2 years.

REPORTING OF VIOLATIONS (WHISTLEBLOWING)

From the “Whistleblowing” page of the website, you can report unlawful conduct pursuant to Legislative Decree 24/2023. Reports can be submitted through the IT platform made available by our provider, by ordinary mail addressed to the Supervisory Body, or, upon your request, through a direct meeting; anonymous reporting is also permitted. We process the data contained in the report, including data relating to third parties, exclusively for the purpose of investigating and managing the report.

Can we do this without your consent? Yes. The processing is necessary to fulfill the obligations set out by Legislative Decree 24/2023 (Art. 6(1)(c) GDPR); for any special category data or data relating to criminal offenses and convictions, the legal bases are Art. 9(2)(g) and Art. 10 of the GDPR.

How long do we retain this data? The report and the related documentation are retained for the time necessary for its handling and, in any case, for no longer than five years from the communication of the final outcome of the procedure (Art. 14 of Legislative Decree 24/2023). The identity of the reporting person and any information from which it may be inferred, even indirectly, are covered by confidentiality. For further details, you can consult the Whistleblowing Policy published on the website.

MAPS AND OTHER THIRD-PARTY CONTENT

Some pages of the website (in particular the home page and the “Contacts” page) embed Google Maps, provided by Google Ireland Limited. Loading the map involves the communication to Google of your IP address and information relating to the device and browser you use.

Can we do this without your consent? No. The content is loaded only after you have given consent via the cookie banner (Art. 6(1)(a) GDPR): without consent, the map will not be displayed.

How long do we retain this data? The retention periods for the cookies and identifiers used by these services are indicated in the cookie policy and in the preferences panel.

How do we process your data?

The processing of your data takes place through the use of tools and procedures suitable to ensure its security and confidentiality and may be carried out both through our website and through other electronic tools (for example, internal management systems) and sometimes also with the aid of paper records. In addition to the Data Controller, in some cases other parties involved in the organization of this Website (administrative staff, sales staff, system administrators, etc.) or external parties (such as third-party technical service providers, hosting providers, IT companies, communication agencies, data entry agencies) may have access to the data; such parties are appointed, in the cases provided for by law, as Data Processors on our behalf. The technical and organizational security measures are identified pursuant to Art. 32 GDPR within the scope of our ISO/IEC 27001-certified information security management system. We do not carry out automated decision-making processes or profiling activities that produce legal effects concerning you pursuant to Art. 22 GDPR; any profiling connected to non-essential cookies takes place only with your prior consent. You can obtain the full list of Data Processors by writing to us at the e-mail address privacy@matchsrl.it

Where is your data located?

The processing operations we carry out with your personal data mainly take place within European territory. Your browsing data (IP address), however, through the installation of cookies, may be transferred outside the European Union, in particular to the United States (by way of example and not exhaustively, Google). Transfers to third countries take place only where adequate safeguards are in place: an adequacy decision of the European Commission (for the United States, the EU-U.S. Data Privacy Framework of July 10, 2023, limited to certified organizations), or the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), supplemented where necessary by additional measures. You can request a copy of the safeguards adopted by writing to privacy@matchsrl.it

Who has access to your data?

Your data may be made accessible to employees and collaborators of the Data Controller in their capacity as persons authorized to process data pursuant to Art. 29 GDPR and/or system administrators and/or other parties (for example: professional firms, consultants, software houses that provide us with management systems, hosting and website maintenance providers, the provider of the consent management platform and the whistleblowing channel, e-mail and cloud storage service providers, etc.) who carry out outsourced activities on our behalf, in their capacity as external Data Processors.

Under no circumstances do we disseminate your data.

Recipients of the processing, on the other hand, are those who receive communications of personal data from the Data Controller but who, following such communication, act as independent Data Controllers. These include:

  • Facebook, Instagram, LinkedIn, and other platforms of the Data Controller. When you click on the social network and platform icons, you will be redirected to pages external to the website and you agree to share some of your data with the Controllers of that service. The information you share will therefore be governed by the privacy policies of the Social Network or Platform you have chosen.
  • Google Ireland Limited, for the reCAPTCHA and Google Maps services integrated into the website: this company acts as an independent controller for the purposes described in its own privacy notice (policies.google.com/privacy).
  • Public authorities and supervisory bodies (for example, ANAC in the context of whistleblowing reports), in the cases provided for by law.

What are your rights?

As a data subject, you have numerous rights. For example, the right to obtain, in the cases provided for, access to your personal data and their rectification or erasure, or the restriction of the processing concerning them, or to object to the processing (to find out all of your rights, you can consult the Regulation at Arts. 15 and following). To exercise your rights, you can write or call us at the contact details found at the beginning of this notice. In particular, you can exercise the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). Where the processing is based on consent, you may withdraw it at any time without affecting the lawfulness of the processing carried out prior to the withdrawal (Art. 7(3) GDPR). We will respond to you without undue delay and, in any case, within one month of the request, a period that may be extended by a further two months in cases of particular complexity (Art. 12 GDPR). The exercise of these rights is free of charge.

Right to lodge a complaint

Should you believe that the processing violates your rights in any way, you may lodge a complaint with the Data Protection Authority (Garante per la protezione dei dati personali), by checking the procedures on the website www.garanteprivacy.it. The complaint form can be viewed on the following page: https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/4535524.

Protection of minors’ privacy

This website is aimed at a general audience; however, its services are intended for people aged 18 or older. We do not request, collect, use, or disclose personal data provided by people under the age of 18 online. Should we discover that we have inadvertently collected data from a minor, we will delete it immediately. If you believe that a minor has provided us with their personal data, you can report this to privacy@matchsrl.it: we will verify and delete the data without delay.

Data Protection Officer

Pursuant to Articles 37 et seq. of EU Regulation No. 679/2016, please be informed that the Data Controller has appointed, as its DATA PROTECTION OFFICER (DPO), the company CONSULENTI PRIVACY SRL, with registered office at Via Valentini n. 11, 47923 Rimini (RN), C.F. e P. IVA 04391970409, Tel. 0541 1798723, e-mail dpo@matchsrl.it, certified e-mail (PEC) consulentiprivacy@postaleg.it. You may contact the DPO for any matter relating to the processing of your personal data and the exercise of your rights.

Updates to this Notice

This notice may be updated to bring it into line with new regulatory provisions, measures issued by the Supervisory Authority, or changes to the services offered by the website. The current version is always published on this page: we invite you to consult it periodically. If the changes concern processing based on your consent, we will ask you for new consent.

Last updated: 29th July 2026