This English version is provided for convenience. If meanings differ, the Italian version prevails.
1. Data controller
The controller is PU.RO. CAR SNC di Vezzosi Stefano e Brito Marlon Joel, VAT number 14774390968, Via della Liberazione 67/3, 20068 Peschiera Borromeo (MI), Italy.
Privacy requests may be sent to the certified email address pu.ro.car@pec.it.
2. Data processed
The website has no contact form, private area, newsletter or online purchasing system.
- Technical browsing data: IP address, request date and time, requested page, response code, browser and device type, referrer and security events generated by Internet, hosting and security systems.
- Data provided voluntarily: contact details, message content and any other data sent by certified email, telephone or, once enabled, WhatsApp.
- Display preference: the browser stores only the choice between light and dark theme. See the Cookie Policy for details.
3. Purposes and legal bases
- Delivering, maintaining and protecting the website: the controller's legitimate interest under Article 6(1)(f) GDPR.
- Answering enquiries and preparing requested estimates or services: pre-contractual or contractual steps under Article 6(1)(b) GDPR.
- Meeting administrative, tax, accounting or authority requirements: legal obligation under Article 6(1)(c) GDPR.
- Establishing, exercising or defending legal claims: the controller's legitimate interest.
4. Providing data
Connection data is processed automatically. Providing information in a message is optional, but PU.RO. CAR may be unable to answer without the necessary details. Please do not send special-category or irrelevant data.
5. Processing and retention
Data is handled electronically using measures designed to reduce unauthorised access, loss and unlawful use. Technical and security data is kept only as long as needed to run and protect the website and under the technical provider's applicable retention terms, unless longer retention is needed to investigate an incident or comply with law.
Enquiries are normally kept no longer than 24 months after they are closed. If a contract is formed, administrative and accounting data may be retained for 10 years or for the different period required by law. Data needed for legal claims may be retained until the applicable limitation periods expire.
6. Recipients and providers
Data may be handled by authorised personnel and providers supporting hosting, content delivery, security, technical maintenance and communications, acting as processors where required. It may also be disclosed to advisers or authorities where required by law or to protect a right.
The website is delivered through Cloudflare infrastructure. Data and access are limited to what is needed for the service.
7. Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where applicable, transfers rely on an adequacy decision or safeguards under Chapter V GDPR, such as standard contractual clauses and any necessary supplementary measures.
8. External links
The website contains ordinary links to Google Maps and Instagram but does not embed their maps, feeds or tracking tools. After following a link, the external provider processes data under its own privacy notice.
9. Your rights
Where provided by the GDPR, individuals may request access, correction, erasure, restriction, portability and object to processing. Consent, if used for a future service, may be withdrawn at any time without affecting earlier lawful processing.
Requests may be sent to the controller's certified email address. Identity verification may be required before a response is provided.
10. Complaints and updates
Individuals may complain to the Italian Data Protection Authority or another competent supervisory authority. This notice may be updated when the website, services or law change; the current version is published on this page.