Privacy notice
Privacy Policy
Last updated: August 2026
This notice describes how the personal data of users who visit the nrc.company website and its language versions is processed, pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter the “GDPR”) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
Data controller
Data protection officer
The Controller does not fall within the cases of mandatory designation set out in Article 37 of the GDPR and has not appointed a Data Protection Officer. Any request concerning data protection may be addressed directly to the Controller at info@nrc.company.
Categories of data processed
Data provided voluntarily by the user. The contact form on the site collects first and last name, email address, company name (optional field) and the content of the message. Sending a message to the published email address entails acquiring the sender's address and any further personal data contained in the message.
Browsing data. The computer systems and software procedures that operate the site acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP address, browser type and operating system, date and time of the request, address of the requested resource and response status code. When the contact form is submitted, the sender's IP address and the date of submission are included in the message delivered to the Controller, as a security measure against abuse.
Special categories of data. The site does not request and does not knowingly process special categories of personal data within the meaning of Article 9 of the GDPR. Users are asked not to enter data of that nature in the contact form.
Purposes and legal bases
Nature of the provision of data
Providing the data marked as mandatory in the contact form is necessary in order to respond to the request: without it, the message cannot be sent. Providing optional data has no consequence. The acquisition of browsing data is implicit in the operation of Internet protocols.
How data is processed
Data is processed by electronic means, using technical and organisational measures appropriate under Article 32 of the GDPR, including encryption of traffic in transit via HTTPS, access control to systems and restriction of processing to authorised personnel. The Controller neither sells nor transfers personal data to third parties.
Retention period
Recipients and processors
Data may be processed by parties that supply the Controller with ancillary technical services, appointed as Data Processors under Article 28 of the GDPR. As at the date of this notice these are:
- Hostinger International Ltd., for web hosting and email services. The servers hosting the site are located within the European Union.
Data may also be disclosed to public authorities, professionals and advisers where necessary to comply with legal obligations or to establish, exercise or defend a legal claim. Data is neither disseminated nor transferred to third parties for marketing purposes.
Transfers to third countries
The site loads certain technical resources from a provider located outside the European Economic Area. The mere request for such resources entails disclosing the user's IP address to the provider, which may record it in its logs.
Google LLC adheres to the EU-US Data Privacy Framework, in respect of which the European Commission adopted its adequacy decision of 10 July 2023 pursuant to Article 45 of the GDPR. The transfer therefore takes place on the basis of that decision. Users who wish to avoid these connections may block the domains listed above through their browser settings or a dedicated extension: the site remains fully usable, with different typography.
Automated decision-making and profiling
The Controller carries out no automated decision-making, including profiling, within the meaning of Article 22 of the GDPR. The site uses no statistical analytics, no advertising trackers and no tools that measure user behaviour.
Your rights
At any time you may exercise the following rights under Articles 15 to 22 of the GDPR against the Controller:
- Access (Art. 15): obtain confirmation that processing is taking place and a copy of the data processed.
- Rectification (Art. 16): obtain the correction of inaccurate data or the completion of incomplete data.
- Erasure (Art. 17): obtain the deletion of data in the cases provided for by law.
- Restriction (Art. 18): obtain the restriction of processing in the cases provided for by law.
- Portability (Art. 20): receive the data in a structured, commonly used and machine-readable format.
- Objection (Art. 21): object at any time, on grounds relating to your particular situation, to processing based on legitimate interest.
Requests should be addressed to info@nrc.company. The Controller responds without undue delay and in any event within one month of receipt, a period that may be extended by two months for particularly complex requests.
Complaint to the supervisory authority
If you consider that the processing of your data is unlawful, you may lodge a complaint with the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy, or through the website garanteprivacy.it. You may also lodge a complaint with the supervisory authority of your habitual residence. The right to seek a judicial remedy remains unaffected.
Cookies and local storage
The site uses no cookies. The storage technologies in use and the connections to third parties are described in detail in the Cookie Policy.
Changes to this notice
The Controller may update this notice to reflect regulatory changes or changes in the processing carried out. The applicable version is the one published on this page, and the date shown at the top indicates when it was last updated.