Information on the processing of personal data pursuant to Regulation (EU) 2016/679 (GDPR) and the applicable national data protection legislation.
Last updated: 18/06/2026. This privacy policy describes how the personal data of users who browse this website and interact with the services made available by the Data Controller is processed.
The Data Controller is KROLLIT di Sandra Gaspar, with registered office at Via Padule 6, 83024 Monteforte Irpino (AV), Italy, VAT no. IT02968120648, REA AV-302461. For any request relating to the processing of personal data, you may write to info@durendus.it or call +39 0825 1494022.
The personal data collected by this website, either independently or through third parties, includes: contact data (first name, surname, company name, email address, telephone number) provided voluntarily through forms or quote requests; browsing data and data collected through cookies or similar technologies (IP address, browser type, pages visited, access times); any further data spontaneously communicated by the user in communications with the Data Controller.
Personal data is processed in order to: respond to requests for information, quotes and support; manage the contractual relationship and the resulting obligations; ensure the correct operation of the website and guarantee its security; comply with legal, accounting and tax obligations; subject to consent, send commercial communications and informational material relating to the products and services of the Data Controller.
Depending on the purpose, the processing of personal data is based on: the performance of a contract or pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR); compliance with legal obligations to which the Data Controller is subject (Art. 6(1)(c) GDPR); the express consent of the data subject for marketing purposes (Art. 6(1)(a) GDPR); the legitimate interest of the Data Controller in the management and security of the website (Art. 6(1)(f) GDPR).
The Data Controller adopts appropriate technical and organisational security measures to prevent the loss, unlawful or incorrect use and unauthorised access to data. Processing is carried out using IT and/or electronic tools, following logic strictly related to the stated purposes. Data is processed at the operational premises of the Data Controller and in the places where the parties responsible for the processing are located.
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected and, in any case, in compliance with the applicable legal terms. Data processed for contractual purposes is retained for the duration of the relationship and for the following 10 years for tax and legal obligations; data processed on the basis of consent is retained until such consent is withdrawn.
Personal data may be disclosed to parties acting as Data Processors (e.g. IT service providers, hosting, email management, accounting and legal consultants) or to parties to whom disclosure is required by law. Data is not subject to dissemination nor to automated decision-making processes.
Should some providers involve the transfer of personal data to countries located outside the European Economic Area, the Data Controller ensures that such transfer takes place in compliance with Articles 44 et seq. of the GDPR, on the basis of adequacy decisions or appropriate safeguards such as the standard contractual clauses adopted by the European Commission.
The data subject may exercise at any time the rights provided for by Articles 15-22 of the GDPR, including: the right of access to their data (Art. 15); the right to rectification (Art. 16); the right to erasure or to be «forgotten» (Art. 17); the right to restriction of processing (Art. 18); the right to data portability (Art. 20); the right to object (Art. 21); the right not to be subject to automated decision-making (Art. 22). It is also possible to withdraw the consent given at any time. Requests may be submitted by writing to info@durendus.it.
Without prejudice to any other administrative or judicial remedy, a data subject who considers that the processing of their data infringes the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome – www.garanteprivacy.it) or with the supervisory authority of the Member State of residence.
The Data Controller reserves the right to modify or update this privacy policy at any time, notifying users by publishing it on this page. Users are therefore invited to consult this section periodically, referring to the date of last update indicated at the top.