Privacy Policy

Privacy Notice on the Processing of Personal Data

Last updated: 8 July 2026

This notice describes how Futura Srl collects and processes the personal data of users who visit the Futura Group website, use the contact forms or submit a job application.

Personal data are processed in accordance with Regulation (EU) 2016/679 (“GDPR”), applicable Italian data protection legislation and the principles of lawfulness, fairness, transparency, data minimisation and security.


1. Data Controller

The Data Controller is:

Futura Srl

Registered office: Vicolo Santa Maria alla Porta 1 – 20123 Milan, Italy
Tax Code and VAT Number: 10850400960
Share capital: €1,000,000, fully paid up
Business Register of Milan, Monza Brianza and Lodi
REA Economic and Administrative Index No.: MI – 2561838

Email: info@futuragroup.it Certified email (PEC): info.futurasrl@legalmail.it

For any request concerning personal data protection or the exercise of data protection rights, the Data Controller may be contacted using the details provided above.


2. Categories of Personal Data Processed

The following categories of personal data may be processed through the website.

Browsing Data

The information systems and software procedures used to operate the website acquire, during their normal operation, certain information whose transmission is implicit in the use of internet communication protocols.

This category may include:

  • IP address;
  • type of browser and device used;
  • operating system;
  • date and time of the visit;
  • pages visited;
  • addresses of the requested resources;
  • technical information relating to interaction with the website.

These data are mainly used to ensure the proper operation and security of the website, obtain aggregated statistical information and prevent or detect anomalous or fraudulent activities.


Data Provided Through the Contact Form

When a user submits a form available on the website, the following data may be collected:

  • first name;
  • surname;
  • email address;
  • company or organisation;
  • telephone number, where provided;
  • content of the message;
  • any additional information voluntarily provided by the user.

Data Provided Through Direct Communications

When a user contacts Futura Group by email, certified email or other communication channels, the sender’s contact details and any additional information contained in the communication may be processed.


Data Relating to Job Applications

When a person submits an application through the “Careers” section, the following data may be processed:

  • first name and surname;
  • contact details;
  • place of residence or address, where provided;
  • information contained in the curriculum vitae;
  • education and training history;
  • professional experience;
  • technical and language skills;
  • information relating to the applicant’s professional profile;
  • any cover letter;
  • links to professional profiles or portfolios voluntarily provided;
  • any additional information submitted by the applicant as part of the recruitment process.

Applicants are requested not to include in their CV or submitted documentation any information that is not relevant to the recruitment process and, in particular, any special categories of personal data that are not necessary for the professional assessment.


3. Purposes and Legal Bases of Processing

A. Website Operation and IT Security

Technical and browsing data may be processed in order to:

  • enable the website to be displayed and operate correctly;
  • ensure the security of the systems;
  • prevent misuse, unauthorised access and fraudulent activities;
  • carry out technical maintenance and diagnostic activities.

Legal basis: the Data Controller’s legitimate interest in ensuring the security, efficiency and proper operation of its digital systems.


B. Responding to Contact and Information Requests

Data submitted through the contact form or by direct communication are processed in order to:

  • respond to requests received;
  • provide information about the Group’s activities;
  • assess commercial, industrial or professional proposals;
  • manage requests from partners, suppliers, investors, institutions and other stakeholders;
  • initiate any pre-contractual or contractual relationship.

Legal basis: taking steps at the request of the data subject prior to entering into a contract, performance of a contract or the Data Controller’s legitimate interest in managing its institutional, professional and commercial relationships.


C. Management of Applications and Recruitment

Applicants’ data are processed in order to:

  • receive and assess applications;
  • verify whether the applicant’s profile is consistent with the Group’s requirements;
  • organise interviews and further assessments;
  • contact the applicant;
  • manage the various stages of the recruitment process;
  • propose any professional opportunities consistent with the profile received.

Legal basis: taking steps at the request of the data subject prior to entering into a contract and compliance with obligations established by applicable legislation.

The provision of the data required for an application is voluntary. However, failure to provide essential information may prevent the applicant’s profile from being assessed.


D. Compliance with Legal Obligations

Personal data may be processed where necessary to comply with obligations established by laws, regulations, measures issued by public authorities or other applicable provisions.

Legal basis: compliance with a legal obligation to which the Data Controller is subject.


E. Establishment, Exercise or Defence of Legal Claims

Data may be retained and used where necessary to:

  • prevent or manage disputes;
  • protect the rights and interests of the Data Controller;
  • respond to requests from the competent authorities;
  • establish, exercise or defend a legal claim in judicial or out-of-court proceedings.

Legal basis: the Data Controller’s legitimate interest in protecting its rights and interests.


F. Cookies and Similar Technologies

The website may use technical cookies that are necessary for its operation and, subject to consent where required by law, additional analytics, measurement or third-party service integration tools.

Detailed information concerning the categories of cookies used, their purposes, their duration and the methods available to modify user preferences is provided in the Cookie Policy and through the consent management panel.

Users may modify their preferences concerning non-essential cookies at any time.


4. Nature of the Provision of Personal Data

The provision of data marked as mandatory in the forms available on the website is necessary in order to process the user’s request.

Failure to provide this information may make it impossible to:

  • submit a contact request;
  • receive a response;
  • complete the submission of a job application;
  • participate in a recruitment process.

The provision of any other data is optional.


5. Methods of Processing

Personal data are processed using IT and electronic tools and, where necessary, paper-based methods.

Futura Srl adopts technical and organisational measures appropriate to the level of risk, designed to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • unauthorised disclosure;
  • unlawful use or use incompatible with the purposes for which the data were collected.

Access to personal data is limited to persons who genuinely require such access in order to carry out their duties.


6. Recipients of Personal Data

Within the limits of their respective responsibilities, personal data may be processed by:

  • authorised personnel of Futura Srl;
  • companies belonging to or affiliated with the Group, where necessary to manage the specific request;
  • IT service providers;
  • hosting and technology infrastructure providers;
  • service providers responsible for system maintenance and security;
  • email and communication service providers;
  • professional advisers;
  • parties involved in recruitment processes;
  • public authorities and other parties to whom disclosure is required by law.

Service providers that process personal data on behalf of the Data Controller are appointed, where required, as Data Processors and operate on the basis of specific instructions.

Personal data are not disseminated.


7. Disclosure of Personal Data Within the Group

Depending on the nature of the request or application, certain data may be disclosed to companies belonging to or affiliated with Futura Group, exclusively where such disclosure is necessary to:

  • manage a specific request;
  • assess a potential collaboration opportunity;
  • identify the competent company or organisational department;
  • assess an application in relation to the professional requirements of the different companies within the Group.

Access is limited to the information that is strictly necessary and to authorised persons.


8. Transfers of Personal Data Outside the European Economic Area

Where possible, the Data Controller gives preference to service providers and infrastructure located within the European Economic Area.

Where the use of specific technology services involves the transfer of personal data to countries outside the European Economic Area, such transfers will be carried out in accordance with the conditions established by the GDPR.

In particular, the following safeguards may be used:

  • adequacy decisions adopted by the European Commission;
  • standard contractual clauses;
  • other safeguards recognised by applicable legislation.

Data subjects may request further information concerning the safeguards applied by contacting the Data Controller.


9. Retention Periods

Personal data are retained for no longer than is necessary for the purposes for which they were collected.

In particular:

Contact Requests

Personal data are retained for the time required to manage and conclude the request and, as a general rule, for no longer than 24 months from the last meaningful communication, unless:

  • a contractual relationship is established;
  • retention is required by law;
  • retention is necessary to protect a right or interest of the Data Controller.

Job Applications

Data relating to job applications are retained for the period required to assess the applicant’s profile and, as a general rule, for a maximum of 24 months from receipt of the application or its most recent meaningful update.

At the end of the retention period, the data are deleted or anonymised, unless they must be retained for a longer period in order to comply with legal obligations or protect a legal right.

Technical and Security Data

Technical data are retained for the period required to ensure the security and proper operation of the systems, without prejudice to a longer retention period in the event of anomalies, IT security incidents or investigation requirements.

Legal Obligations and Disputes

Data required to comply with legal obligations or protect a legal right may be retained for the periods established by applicable legislation and until any disputes have been definitively resolved.


10. Automated Decision-Making

The data collected through the website are not used to make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.

Applicants are not selected or excluded solely on the basis of an automated decision-making process.


11. Rights of the Data Subject

In the cases and within the limits established by the GDPR, data subjects may exercise the following rights:

  • obtain confirmation as to whether or not personal data concerning them are being processed;
  • access their personal data;
  • request the rectification of inaccurate or incomplete data;
  • request the erasure of personal data;
  • request restriction of processing;
  • object to processing in the circumstances provided for by law;
  • receive their personal data in a structured, commonly used and machine-readable format, where applicable;
  • request the transmission of their personal data to another data controller, where technically feasible and in the cases provided for by law;
  • withdraw consent at any time in relation to processing based on consent, without affecting the lawfulness of processing carried out before consent was withdrawn.

Requests may be sent to:

Email: info@futuragroup.it Certified email (PEC): info.futurasrl@legalmail.it

The Data Controller may request the information strictly necessary to verify the identity of the person submitting the request.


12. Right to Lodge a Complaint

Data subjects who believe that their personal data are being processed in breach of applicable legislation have the right to lodge a complaint with the Italian Data Protection Authority.

This is without prejudice to the right to seek a remedy before the competent judicial authorities.


13. Protection of Children’s Personal Data

The website and Futura Group’s services are primarily intended for professional operators and adults.

The Data Controller does not knowingly collect children’s personal data through the website. Should the Data Controller become aware that such information has been collected unintentionally, it will take the necessary measures to manage or erase the data in accordance with applicable legislation.


14. Links to External Websites

The website may contain links to websites, platforms and services operated by third parties.

Futura Srl does not control how these third parties process users’ personal data. Users are therefore advised to read the relevant privacy notices before using external services.


15. Amendments to This Privacy Notice

This Privacy Policy may be updated in order to:

  • adapt it to changes in applicable legislation;
  • reflect changes to the services provided;
  • describe new processing activities;
  • reflect changes to the technological tools used by the website.

The updated version will be published on this page together with the date on which it was last updated.

Users are therefore advised to review this section periodically.