Privacy Policy of the website weuni.com

PRIVACY POLICY OF THE "WEUNI" WEBSITE
Version July 2026

LADYBIRD S.r.l., as operator of this Website, provides you with the following information regarding the processing of your Personal Data as a Visitor, pursuant to Art. 13 of EU Regulation 2016/679 (the "GDPR").

"Processing of Personal Data", in plain terms, means any operation concerning any "information relating to an identified or identifiable natural person". For example, a name and surname, or an e-mail address with a "username" that identifies you (e.g. mariorossi@….), is considered "Personal Data", and the acts of collection, registration with us and use to send you a communication are considered "Processing" operations; likewise (also by way of example) the communication of Data to other organisations and archiving.

Our organisation is defined as the "Data Controller", as the entity that determines how and for what purposes to process information relating to natural persons.

You, as the "natural person to whom the Personal Data refers", are defined as the "Data Subject", and you have the right to receive information about who we are, what personal data we process, why, how and for how long we process it, and what obligations and rights you have in this regard.

The website of the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) contains further useful information to help you better understand the subject (see e.g.: http://www.garanteprivacy.it/home/diritti).

The definitions of the terms and expressions used are contained in the Glossary at the end of this page. For certain capitalised terms not defined herein, please refer to the glossary attached to the Website's Terms and Conditions of Use; in the event of any conflict between definitions, for the purposes of this Privacy Policy the definitions in the Glossary (at the bottom of the page) shall prevail over those in the Terms and Conditions.

Who are we ("Data Controller")?

LADYBIRD S.R.L., registered office in Turin, Via Leonardo da Vinci, 16, Tax Code and VAT No. 10816460017 REA: TO - 1164165 (also "Ladybird"), e-mail: PEC: ladybirdsrl@legalmail.it

Why do we process Personal Data (Purposes) and what is the legal basis for Processing each category of Data?

  1. Technical management, security and optimisation of the Website. This purpose includes:
    • making the Website available online and ensuring its correct functioning;
    • traffic analysis (e.g. pages visited, geographic origin, average connection time, browsers used, visitor source – from search engines or other websites –, searched phrases and keywords, etc.) in order to understand how the Website is used and to manage, optimise and improve it, or for statistical purposes alone;
    • analysing the composition of the user base in order to improve the Website and/or the Services;
    • resolving operational problems and technical anomalies (e.g. anomalies in page loading);
    • carrying out monitoring activities to repel and/or prevent cyber-attacks and fraud;
    • sending strictly necessary technical or informational communications (e.g. notices of service disruptions or maintenance work).

    Categories of Personal Data: Browsing Data, anonymous information (which does not allow us to identify you) and common Personal Data (e.g. full IP address, timestamps, browser and operating system parameters).

    Legal Basis: The necessity to make the Website available in accordance with the Terms of Use in force at the time of access (Art. 6 § 1.b GDPR) and, with regard to IT security and traffic analysis, the legitimate interest of the Company in ensuring the IT security of the Website and optimising its performance (Art. 6 § 1.f GDPR).

  2. Fulfilling Visitor requests regarding the Website and WeUni's Services, received via the Website's contact form or by any other means (e.g. e-mail, telephone).

    Categories of Personal Data: Common Personal Data.

    Legal Basis: The necessity to take pre-contractual measures at the request of the Visitor (Art. 6 § 1.b GDPR).

  3. Complying with obligations under applicable law (e.g. accounting, tax, compliance, security obligations, etc.) and/or executing orders issued by authorities.

    Categories of Personal Data: Common Personal Data.

    Legal Basis: Legitimate interest of the Controller or third parties (Art. 6.1.f GDPR).

  4. Establishing, exercising and/or defending a right before the competent authorities.

    Categories of Personal Data: Common Personal Data.

    Legal Basis: Legitimate interest of the Controller or third parties (Art. 6.1.f GDPR).

To whom do we disclose Data (Categories of Recipients)?

To the minimum extent necessary to achieve each of the Purposes, on the basis of Applicable Law and/or a contractual agreement with the Controller, to:

  1. entities required for the performance of activities connected with and consequent to the management of the Website, acting as Data Processors (e.g. IT service providers, etc.), bound by confidentiality and compliance with Privacy Law;
  2. entities Authorised by us (e.g. our employees), bound by confidentiality or subject to a legal obligation of confidentiality;
  3. consultants and/or professionals engaged by us, who may act as independent Data Controllers;
  4. public organisations and Authorities, where and to the extent required by Applicable Law or their orders, or for the establishment, exercise and/or defence of a right before a court.

Do we transfer Personal Data outside the European Economic Area?

Our providers may use, for the management and storage of Website data and content, services provided by companies established outside the European Economic Area (e.g. the United States; in such cases the transfer is carried out on the basis of standard contractual clauses and supplementary measures to ensure data protection). Furthermore, the use of certain social communication platforms linked to the Website involves the transfer of personal data outside the European Economic Area.

In general, we ensure that data transfers take place only to countries that guarantee an adequate level of protection, for which an adequacy decision by the European Commission exists, or on the basis of one of the other guarantees provided for in Chapter V of the GDPR.

Further information on transfers of personal data outside the European Economic Area is available by writing to the Company at dpo@weuni.com.

Do we carry out automated decision-making processes and/or Profiling activities?

Yes, through cookies and the other processing tools detailed in the cookie policy.

How long do we retain Data?

The Company retains personal data for the time strictly necessary to achieve the purposes for which it was collected, according to the following criteria:

  • browsing data: retained for the period necessary for the correct functioning of the website and for anonymous statistical purposes. In the event of cybercrime, they may be retained for longer periods to establish liability;
  • commercial requests and pre-contractual contacts: data collected through the Website's contact form for commercial information requests are retained for a period not exceeding five years from the request or last interaction, unless longer retention is necessary for the protection of the rights of the Controller or third parties.

Are you required to provide us with Personal Data?

Due to the nature of Internet operation, it is not possible to refuse the transmission of Browsing Data; the refusal to communicate certain Personal Data (such as the device's IP address) is not provided for. You are, of course, not obliged to contact us at the details provided on the "Contact" page, but if you wish to do so you must provide us with the Personal Data we request.

What happens if you refuse to provide your Data?

If you do not agree to provide your Data, we will be unable to respond to requests you send us at the contact details on the "Contact" page or by other means.

What rights do you have as a "Data Subject"?

As the person to whom the data refers ("Data Subject") you have the right to:

  1. access the data held by the Controller, and to request a copy thereof, except where the exercise of this right prejudices the rights and freedoms of other natural persons;
  2. request the rectification of any incomplete or inaccurate data;
  3. request the erasure of the data, subject to the exclusions or limitations established by Applicable Law (e.g. Art. 17 § 3 GDPR);
  4. request the restriction of processing, where the conditions apply, subject to the exclusions set out in Art. 18 § 2 GDPR;
  5. request data portability (i.e. to receive the data in a structured, commonly used and machine-readable format, in order to transmit it to another Controller without hindrance), to the extent that processing is based on consent or on the necessity to perform a contract, where technically feasible and except where the exercise of this right prejudices the rights and freedoms of other natural persons;
  6. lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (in Italy, www.garanteprivacy.it), or with the Data Protection Authority of the EU Member State in which you habitually reside or work, or of the place where the alleged infringement occurred.

Right to object

You may object to processing based on Ladybird's legitimate interest for all purposes based on that legal basis, on grounds relating to your particular situation, unless Ladybird demonstrates compelling legitimate grounds for the processing which override your interests pursuant to Art. 21 § 1 GDPR, and except where the processing is necessary for the establishment, exercise or defence of a right before a court. The exercise of the rights referred to above may also be delayed, restricted or excluded in the cases provided for by Art. 2-undecies of Legislative Decree 196/2003.

Who can you contact for questions or to exercise your rights?

You may contact Ladybird on any matter relating to the processing of personal data and to exercise your rights by sending an e-mail to the designated DPO at: dpo@weuni.com.

PLEASE NOTE:

  1. The information provided herein relates exclusively to the processing carried out in connection with Personal Data collected through this Website. Should you enter into a relationship with us that goes beyond mere browsing of the Website and the request for information, you may be provided with additional and/or different information regarding the processing of your personal data.
  2. This Privacy Policy is in force from the date indicated in the heading; we reserve the right to amend its content, in whole or in part, also as a result of changes to Privacy Law; we will publish the updated version of the Privacy Policy on the Website and it will be binding from that moment: you are therefore invited to visit this section regularly; previous versions of the privacy policy are available in the Legal and Privacy Archive section of the Website.
  3. We do not intentionally collect personal information relating to natural persons who, under their national law, lack the legal capacity to enter into contracts. Should information about such individuals be recorded, we will delete it promptly, upon request by the Data Subject or by the person exercising parental authority over them.

GLOSSARY

"Supervisory Authority": the independent public authority established by a Member State of the European Union, or by the European Union itself, entrusted with monitoring the application of Privacy Law (for Italy, the Garante per la Protezione dei Dati Personali, http://www.garanteprivacy.it).

"Authority": a public or private body or organisation with administrative, judicial, police, disciplinary or supervisory powers.

"Authorised Person": the natural person placed under the direct authority of the Controller who receives instructions from the Controller regarding the Processing of Personal Data, pursuant to and for the purposes of Art. 29 of the GDPR.

"Privacy Code": Legislative Decree 196/2003 and subsequent amendments and/or additions (in particular as amended by Legislative Decree No. 101/2018).

"Committee" or "EDPB": the European Data Protection Board, established pursuant to Art. 68 of the GDPR and governed by Arts. 68 to 76 of the GDPR, which replaced the WP29 as of 25 May 2018.

"Communication": "disclosing personal data to one or more specific recipients other than the data subject, the representative of the controller in the territory of the European Union, the processor or its representative in the territory of the European Union, the authorised persons referred to in Article 2-quaterdecies, to the processing of personal data under the direct authority of the controller or processor, in any form, including by making available, consulting or interconnecting" (as defined in Art. 2-ter, paragraph 4, letter a of the Privacy Code).

"Cookie": short text fragments (letters and/or numbers) that allow the web server to store information on the browser for reuse during the same visit to the website (session cookies) or subsequently, even days later (persistent cookies). Cookies are stored, based on user preferences, by the individual browser on the specific device used (computer, tablet, smartphone). The following categories are taken into consideration:

  • Technical cookies: these are cookies essential for the correct functioning of the website and are used solely to "carry out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service" (cf. Art. 122, para. 1, of the Privacy Code).
  • Analytical cookies: these are cookies used to collect and analyse website traffic and usage anonymously. These cookies, without identifying the user, allow, for example, detection of whether the same user returns to the website at different times. They also allow monitoring of the system and improvement of its performance and usability. Disabling such cookies can be done without any loss of functionality.
  • Profiling cookies: these are persistent cookies used to identify (anonymously and otherwise) user preferences and improve their browsing experience.
  • Third-party cookies (analytical and/or profiling): these are cookies generated by organisations not affiliated with the Website, but integrated into parts of the Website page. Examples include Google "widgets" (e.g. Google Maps) or "social plugins" (Facebook, Twitter, LinkedIn, Google+, etc.).

"Browsing Data": data that computer systems and software procedures dedicated to the operation of the website automatically acquire during their normal operation, the transmission of which is implicit in the use of Internet communication protocols. This is information that is not collected in order to be associated with identified data subjects, but which by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of computers used by users connecting to the website, URI (Uniform Resource Identifier) notation addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the user's operating system and IT environment. Such data, necessary for the use of web services, are also processed in order to: obtain statistical information on the use of the services (most visited pages, number of visitors by hour or day, geographic areas of origin, etc.); check the correct functioning of the services offered.

"Personal Data": "any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person", as defined in Art. 4, paragraph 1, no. 1, of the GDPR.

"Recipient": "a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not", as defined in Art. 4, paragraph 1, no. 9, of the GDPR.

"GDPR": EU Regulation 2016/679 "on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)".

"Data Subject": "an identified or identifiable natural person", as defined in Art. 4, paragraph 1, no. 1, of EU Regulation 2016/679 (the "GDPR").

"Restriction": "the marking of stored personal data with the aim of limiting their processing in the future", as defined in Art. 4, paragraph 1, no. 3, of the GDPR.

"Law" or "Laws": one or more of the sets of rules referred to as Privacy Law and Applicable Law.

"Applicable Law": any provision, of any rank, belonging to Italian or European Union law, in any way applicable to the Website and/or the Services.

"Privacy Law": EU Regulation 2016/679 ("GDPR"), Legislative Decree 196/2003 and subsequent amendments and/or additions ("Privacy Code"), as well as measures adopted by the Supervisory Authority in performance of the tasks established by the GDPR and the Privacy Code, and further applicable legislation of any rank, including the opinions and guidelines drawn up by the Committee.

"Profiling": "any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's professional performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements", as defined in Art. 4, paragraph 1, no. 4, of the GDPR.

"Publication": the action by which the Controller makes information available on the Website, without implementing procedures that require the Visitor to view it.

"Processor": "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller", as defined in Art. 4, paragraph 1, no. 8, of the GDPR.

"Website": the web pages accessible at: https://www.weuni.com/, including subdomains.

"Third Party": "a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data", as defined in Art. 4, paragraph 1, no. 10, of the GDPR.

"Controller": "a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data", as defined in Art. 4, paragraph 1, no. 7, of the GDPR.

"Processing": "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction", as defined in Art. 4, paragraph 1, no. 2, of the GDPR.

"Visitor": the natural or legal person who uses a device to browse, via the Internet, the public pages of the Website.

"WP29": the Working Party on the Protection of Individuals with regard to the Processing of Personal Data, established pursuant to Art. 29 of Directive 95/46/EC, whose tasks are set out in Art. 30 of Directive 95/46/EC and Art. 15 of Directive 2002/58/EC.