Personal Data Processing Information Notice pursuant to Article 13 of EU Regulation 2016/679

Updated as of April 2026

This Privacy Notice describes the management methods of the website (hereinafter also the “Site”) regarding the processing of personal data of users who engage with its services. It has been updated as of April 2026 and may be subject to change: users are therefore advised to consult it periodically.

The Site is managed within the framework of the “APT SAFETY GROUP” network agreement, a collaboration agreement between legally independent companies pursuant to Article 3, paragraph 4-ter, of Legislative Decree 5/2009. The member companies share certain technical and organizational tools, while maintaining legal, fiscal, and managerial autonomy. Depending on the various features of the Site, personal data may be processed by different entities, acting as independent data controllers or data processors, as further specified in the sections below.

This Notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter, the “Regulation” or “GDPR”) and describes the purposes and methods by which personal data are processed. Processing is based on the principles of lawfulness, fairness, transparency, data minimisation, storage limitation, integrity, and confidentiality.

1. Data Controller identity and contact data

    1. Browsing data

The data controller of personal data related to navigation on this Website is:

● APT ENGINEERING & MARKETING S.r.l. – Via delle Azalee, 24/26 – 27016 Sant’Alessio con Vialone (PV) – VAT registration number 01778510188 – e-mail: [email protected]

    1. Data provided via the contact form and newsletter subscription

The personal data provided by the data subject via the contact form and the newsletter subscription form are processed, in their capacity as independent data controllers, by the following companies within the APT Safety Group, which are the recipients of the requests:

● APT ANTINCENDIO S.r.l. – Via delle Azalee, 21 – 27016 Sant’Alessio con Vialone (PV) – VAT registration number 00611740184 – e-mail: [email protected]

● APT SERVICES S.r.l. – Via delle Azalee, 24/26 – 27016 Sant’Alessio con Vialone (PV) – VAT registration number 00953650181 – e-mail: [email protected]

APT ENGINEERING & MARKETING S.r.l. processes such data in its role as a Data Processor, pursuant to Article 28 of Regulation (EU) 2016/679, on behalf of the aforementioned companies, in connection with the technical management of the Website, and marketing and communication services.

2. Categories of processed personal data

Through this website, different categories of personal data can be collected and processed, depending on the nature of the user’s interaction:

a) Data provided voluntarily through online forms

● Contact form: name, family name, e-mail address, telephone number, and sent message

● Newsletter subscription form: name, family name, e-mail address, any indication of company/organization, and selection of the group company from which the user wishes to receive communications.

Provided data through forms are processed for meeting sent requests or for the subscription to the newsletter, within the limits of the stated purposes and in accordance with the consent given by the data subject (for the newsletter), and are transmitted to the competent owner companies. This data is processed by APT ENGINEERING & MARKETING S.r.l. as data processor on behalf of the aforementioned companies.

b) Browsing data: During normal operations, IT systems and software procedures used to operate the site acquire some personal data whose transmission is implicit in the use of Internet communication protocols. Such data may include, for example: IP addresses or domain names of the devices used, time of access, method used to submit the request to the web server, size of the file obtained in response, etc. This data are used from a technical point of view to ensure the proper functioning of the site and for security reasons.

c) Data collected through cookies and similar tools: For more details on the types of cookies used and the data collected through these tools, please refer to the site’s Cookie Policy.

3. Purpose of the processing

Data collected through this Site are processed for the following purposes:

3.1 Processing of contact requests

The data provided by the user through the contact form is processed to respond to requests for information, support, or commercial contact. The data are processed by the competent data controllers and by APT ENGINEERING & MARKETING S.r.l. acting as a data processor on their behalf.

Lawful grounds: performance of pre-contractual measures taken at the request of the data subject (Article 6, Paragraph 1, Point b) of the GDPR).

● Data provision: mandatory. Failure to provide this information will make it impossible to process the request.

3.2 Newsletter subscription

Data provided through the newsletter subscription form are used to periodically send informational and promotional communications by the company, who act as the data owner as listed in point 1.2.

Communications are sent on behalf of the aforementioned companies by APT ENGINEERING & MARKETING S.r.l., which has been appointed as data processor pursuant to Article 28 of the GDPR.

Lawful grounds: explicit consent from the data subject (Article 6, Paragraph 1, Point a) GDPR) given through the specific checkbox.

Data provision: optional. Failure to provide information does not affect the possibility of using the site or sending contact requests.

3.3 Technical management of the Site and security

Browsing data are processed to enable the proper technical functioning of the website, ensure information security, and prevent improper or illegal use of the system.

Lawful grounds: legitimate interest of data controller (APT ENGINEERING & MARKETING S.r.l.) (Article 6, Paragraph 1, Point f) of the GDPR) and legal obligations regarding IT security (Article 6, Paragraph 1, Point c) of the GDPR).

● Data provision: necessary for technical reasons. The processing happens automatically during browsing.

3.4 Cookies management

For detailed information on the types of cookies used by the Website, their purposes, and how to manage user preferences, users should refer to the Cookie Policy available on this website, accessible through the provided link.

The user’s consent constitutes lawful ground for the processing of personal data collected through cookies pursuant to Article 6, Paragraph 1, Point a) of the GDPR, if required by current legislation.

4. Processing methods

Personal data are processed using IT and telematic tools in a lawful, fair, and transparent manner, in accordance with the principles of data minimisation, integrity, accuracy, and confidentiality, in compliance with the provisions of Regulation (EU) 2016/679 and current national legislation.

The processing is carried out through operations such as the collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, limitation, deletion, and destruction of data.

The data is processed by authorized staff under the authority of the respective data controllers, who have received appropriate training, as well as by third parties acting as data processors in accordance with Article 28 of the GDPR.

Specifically, APT ENGINEERING & MARKETING S.r.l. processes data both as the data controller, for activities related to the technical management of the Site, and as the data processor on behalf of other companies within the APT Safety Group, for activities related to the management of contact forms and communications.

Processing is carried out mainly electronically and appropriate technical and organizational measures are taken to ensure the security and protection of the data processed.

5. Recipients of personal data

Personal data collected through the Site can be processed by the following recipient categories:

The companies of the APT Safety Group as listed in section 1.2, which operate as independent data controllers for the purposes of managing requests and communications.

Those authorized to process data under the authority of the controllers, who have been specifically trained and are bound by confidentiality obligations.

External suppliers who provide technical, organizational, or professional services functional to the management of the Site and related activities, and who act as data processors pursuant to Article 28 of the GDPR. Such suppliers may include, by way of example and may be not limited to: ○ ICT service providers, hosting, cloud, maintenance, and IT security management;

○ suppliers of managing contacts and commercial communications tools (e.g., newsletters);

○ suppliers of services related to cookies management.

APT ENGINEERING & MARKETING S.r.l., which processes data as a data processor on behalf of the data controllers for the technical management of the website, contact forms, and communications.

Third parties whose right to access personal data is recognized by provisions of law, regulations, or European Union legislation (e.g., public authorities, legal bodies, supervisory or control authorities).

The updated list of data processors is available upon request at the contact details provided in this notice. Personal data will not be shared, unless required by law.

6. Personal data storage period

Personal data collected through the Site will be stored for the period strictly necessary to achieve the purposes for which it is processed, in accordance with the principles of data minimization and storage limitation established by Regulation (EU) 2016/679 (GDPR). Storage periods may vary depending on the data controller and the specific purpose pursued. In particular:

Requests through contact form: Data entered in the contact form are stored for a period of 12 months from the last contact with the data subject, unless regulatory obligations require longer storage. For administrative management and operational simplification reasons, the data will be deleted no later than December 31st of the year in which the 12-month storage period since the last processing expires.

Newsletter subscription and promotional communications: Personal data provided to receive newsletters or promotional communications are stored until consent is revoked by the data subject. Consent may be revoked at any time by clicking on the unsubscribe link in each message or by writing to the address provided in this notice.

Browsing data and activity log: Browsing data necessary for the functioning of the website, security management, and prevention of misuse are stored for a period of 12 months from the date of collection, unless legally required or for proven technical and organizational reasons. For administrative management and operational simplification purposes, the data will be deleted no later than December 31st of the year in which the 12-month storage period since the last processing expires.

Cookies and other tracking tools: The storage period of cookies is governed by the Cookie Policy. In general, technical cookies are deleted at the end of the browsing session, while other cookies (e.g., cookies for statistical or

marketing purposes) are stored in accordance with applicable legislation and the user’s default choices in the consent banner.

Once the above-mentioned terms have expired, personal data will be deleted or anonymized, in compliance with current regulations.

7. Data subjects’ rights

Pursuant to Article 15 of the Regulation, the data subject has the right to obtain confirmation as to whether or not data concerning them are being processed and, if so, to also obtain a copy of the data and access to them and also to the following information:

● Purposes of the processing;

● Types of personal data processed;

The recipients or categories of recipients to whom the personal data have been or will be transmitted, in particular if they are recipients in third countries or international organizations;

If possible, the planned storage period of personal data. If this is not possible, the criteria used to determine such period;

● All available information on the source of the data if it has not been collected from the data subject;

● The existence of automated decision-making, including profiling.

The data subject also has the right to:

Obtain the rectification from the data controller of inaccurate personal data concerning them without undue delay (Article 16 of the Regulation);

Obtain from the data controller the erasure (“right to be forgotten”) of personal data concerning them without undue delay (Article 17 of the Regulation);

● Obtain from the data controller the restriction of processing (Article 18 of the Regulation);

Receive, in a structured, commonly used, and machine-readable format, personal data concerning them, if possible (Article 20 of the Regulation);

Object at any time, on grounds relating to their particular situation, to the processing of personal data (Article 21 of the Regulation);

Withdraw their consent at any time without affecting the lawfulness of the processing carried out prior to the withdrawal (Article 7 of the Regulation);

Be informed of the existence of adequate safeguards, should personal data be transferred to a third country or to an international organization (Article 46 of the Regulation);

● file a complaint with a supervisory authority (Article 77 of the Regulation);

To exercise these rights, the data subject may contact the data controller responsible for the specific purpose using the contact information provided in section “1 Data Controller identity and contact data”.

Concerning the processing carried out through the contact and newsletter subscription forms, the data subject may also exercise their rights with respect to the respective data controllers.

8. Mandatory provision of data and consequences of failure to provide data

The provision of browsing data is necessary to allow access to and proper use of the Site and its contents.

The provision of data in the contact and newsletter subscription forms is optional, but necessary in order to send the request or receive promotional communications from data controller companies listed in section 1.2. Failure to provide such data will make it impossible to process the request or proceed with the newsletter subscription.

Regarding cookies and non-technical tracking tools, data provision is optional and based on consent. Failure to consent does not affect the navigation through the site in any way, but may limit the personalized experience or the receipt of targeted content. More information is available in the Cookie Policy.

9. Transfer of data to third countries or international organizations

Personal data processed through the Website are stored on servers located within the European Union.

However, some services related to website management, newsletters, and corporate communications (e.g., marketing emails providers, CDN services, or analytical tools) may involve the transfer of personal data to third countries, such as the United States. Such transfers may be carried out either by the data controllers or by APT ENGINEERING & MARKETING S.r.l. in its capacity as data processor, on behalf of the data controllers.

In such cases, the transfer takes place in compliance with the conditions set out in Chapter V of the GDPR, in particular pursuant to adequacy decisions by the European Commission, standard contractual clauses (SCC) approved by the Commission, or other appropriate safeguards provided for by law.

Upon request, more detailed information about the third countries to which the data is transferred and applicable safeguards can be obtained by writing to the following email address: [email protected].

10. Cookie policy

The Website uses technical cookies and, subject to consent, may also use statistical analysis and profiling cookies, either its own or those of third parties. The management of cookies and tracking tools is handled by APT ENGINEERING & MARKETING S.r.l., acting as the data controller with respect to browsing the Website, and is managed by a consent management platform (CMP) that complies with current legislation.

When visiting the Site for the first time, users can configure their preferences using the cookie banner. For detailed information on the categories of cookies used, their purposes, and their duration, please refer to the Cookie Policy, which is available at any time from the banner or by clicking on the link at the bottom of each page of the Website.