Privacy Policy

Data Controller:
NOUS S.R.L.
Piazzale Europa 12, 22074 Lomazzo (CO) – IT, VAT 02731320038, Tax Code 02731320038
GDPR: General Data Protection Regulation – Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016.
Personal Data (or Data): Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes an identified or identifiable natural person. By way of example and not limited to, name, surname, address, phone number, email, IP address.
User: The individual using this Website who, unless otherwise specified, coincides with the data subject (the person to whom the Data refers).
Data Processor (or Processor): The natural person, legal entity, public authority, and any other body that processes personal data on behalf of the Data Controller, as outlined in this privacy policy.
Website or Site: the site www.nous.energy
Service: The Services provided by this Website.
European Union: Unless otherwise specified, any reference to the European Union contained in this document is intended to extend to all current member states of the European Union and the European Economic Area.
Cookie: A small portion of data stored on the User’s device and collected during navigation.

NOUS S.R.L. – Piazzale Europa 12, 22074 Lomazzo (CO) – IT, VAT 02731320038, Tax Code 02731320038 as the data controller, informs Users in accordance with Articles 13 and 14 of EU Regulation No. 2016/679 about the methods of processing their Personal Data.

1 PURPOSE OF THE PROCESSING

The Data Controller processes common personal data (art. 6 GDPR) provided by the User when voluntarily registering on the Data Controller’s websites, subscribing to forms (contact forms) or newsletter forms, filling out forms for shipping purchased items, online requests for clarification or support requests, and sending newsletters or during navigation on the Data Controller’s site.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed prior to the collection of the data itself.

2 PURPOSES OF THE PROCESSING AND LEGAL BASIS

Your common personal data is processed:

A) without the express consent of the User (art. 6 GDPR), for the following Service Purposes:

  • Allow the User to use the Services provided by the Data Controller (art. 6 lett. b);
  • Process a contact request (art. 6 lett. b);
  • Comply with legal obligations, regulations, community legislation, or an order from an Authority (art. 6 lett. c);
  • Exercise the rights of the Data Controller, such as managing disputes arising during the retention period of the Data (art. 6 lett. f).

B) only with the specific and distinct consent of the User (art.6 lett. a, GDPR), for the following purposes:

  • Send emails and newsletters, commercial communications, and/or promotional material on products or services offered by the Data Controller;
  • Manage commercial profiling activities;
  • Manage access to their Woocommerce account (if present)
  • Manage access to the Reserved Area for file and document exchange (if present)
  • Manage data for orders and shipments of items purchased by the customer (if present)

In the course of the activities performed by the Data Controller, the personal data listed below are processed for the following purposes using the following services:

  • Contact management and sending messages
  • Uploading documents and files to the customer if present:
  • Order management and fulfillment
  • Payment management (external, see STRIPE)

This type of service allows managing a database of email contacts, phone contacts, or contacts of any other type, used to communicate with the User.

These services, if activated (at the discretion of the data controller), may also allow the collection of data regarding the date and time of message views by the User, as well as the User’s interaction with them, such as information on clicks on links embedded in the messages.

  • Mailchimp, (The Rocket Science Group LLC)
    Mailchimp is an email address management and message sending service provided by The Rocket Science Group LLC.

Personal Data collected

name, surname; email.

Location of processing

United States – Privacy Shield. Subject adhering to the Privacy Shield.

  • Interaction with social networks and external platforms
    This type of service allows for interactions with social networks or other external platforms directly from the pages of this Website. The interactions and information acquired from this Website are in any case subject to the User’s privacy settings related to each social network. This type of service may still collect data on traffic for the pages where the service is installed, even when Users do not use it. It is recommended to log out from the respective services to ensure that the data processed on this Website is not reconnected to the User’s profile.
  • “Like” button and social widgets of Facebook (Meta, Inc.)
    The “Like” button and Facebook social widgets are services for interacting with the Facebook social network, provided by Meta, Inc.

Personal Data collected

Cookies; Usage data.

Location of processing

United States – Privacy Policy. Subject adhering to the Privacy Shield.

 

  • SPAM protection
    This type of service analyzes the traffic of this Website, potentially containing Users’ Personal Data, in order to filter it from traffic parts, messages, and content recognized as SPAM.
  • Akismet (Automattic Inc.)
    Akismet is a SPAM protection service provided by Automattic Inc.
 

various types of Data as specified by the service’s privacy policy.

Place of processing

United States – Privacy Policy.

 

  • Statistics
    The services contained in this section allow the Data Controller to monitor and analyze traffic data and help track User behavior.
  • Google Analytics (Google LLC)
    Google Analytics is a web analytics service provided by Google LLC or Google Ireland Limited, depending on where this Website is used (“Google”). Google uses the Personal Data collected to track and examine the use of this Website, compile reports, and share them with other services developed by Google.

Personal Data collected

Cookies; Usage Data.

Place of processing

United States – Privacy Policy; Subject adhering to the Privacy Shield.

 

3 CONSEQUENCES OF REFUSING TO PROVIDE DATA

If the User refuses to provide the data referred to in art. 2, A), it will be impossible for the Data Controller to provide the services offered. If the User refuses to give consent for the purposes referred to in art. 2, B), their right to benefit from the services offered by the Data Controller will not be prejudiced, but they will not be able to use the services indicated in point B).

The possible use of Cookies – or other tracking tools – by this Website or by third-party service providers used by this Website, unless otherwise specified, aims to provide the service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy. Settings can be modified by accessing the respective areas in the browser.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Website and guarantees that they have the right to communicate or disseminate them, releasing the Data Controller from any liability towards third parties.

4 METHODS OF PROCESSING AND ACCESS TO DATA

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, alteration, or destruction of Personal Data.

Processing is carried out using IT and/or telematic tools, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of this Website (administrative, commercial, marketing staff, legal, system administrators), internal collaborators of the Data Controller (appointed Processors), or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) duly appointed, if necessary, as Data Processors by the Data Controller may also have access to the Data. The updated list of Data Processors can always be requested from the Data Controller via email at info@nous.energy

5 RETENTION PERIOD

Data are processed and stored for the time required by the purposes for which they were collected, therefore:

  • Personal Data collected for purposes related to the execution of a contract (art. 6, lett. b, GDPR) between the Data Controller and the User will be retained until the execution of such contract is completed and to comply with legal obligations requiring longer retention (art. 2220 c.c.);
  • Personal Data collected for purposes related to the legitimate interest of the Data Controller (art. 6, lett. f, GDPR) will be retained until that interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Data Controller by contacting them as per the following art. 10.
  • When processing is based on the User’s consent (art. 6, lett. a, GDPR), the Data Controller may retain Personal Data longer until such consent is revoked (opt-out or by specific request as per the following art. 10). Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an Authority.

At the end of each retention period, Personal Data will be deleted. Therefore, upon the expiration of that term, the rights of access, deletion, rectification, and the right to data portability can no longer be exercised.

6 DATA SECURITY

The Data Controller has adopted a wide range of security measures to protect User Data against the risk of loss, abuse, or alteration. In particular: it has adopted appropriate technical-organizational measures as per art. 32 GDPR, uses secure data transmission protocols known as SSL or HTTPS. Additional security policies have been adopted such as HSTS, Firewall, Malware Detection, and Anti-DDoS systems.

7 TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION

The Data Controller generally does not transfer Personal Data outside the European Union. The servers used for managing and storing Personal Data are located in Europe. However, some activities carried out (e.g., periodic backups) may be managed by companies established outside the EU (point 2 of the table below), which are still able to offer guarantees in line with Privacy Shield agreements.

1

Server IP Location
Netherlands – Noord-Holland – Amsterdam – Siteground Hosting Eood
GDPR
2
ASN
Netherlands AS32475 SINGLEHOP-LLC – SingleHop LLC, US (registered Jul 21, 2005)
SingleHop LLC has adhered to the EU-U.S. Privacy Shield Framework, thus providing technical and organizational measures in line with GDPR.

 
The Data Controller, as specified in the previous article 4, may utilize the services offered by Mailchimp – Rocket Science Group LLC, a web platform that provides marketing automation services and related email marketing services. The use of services provided by MailChimp involves the transfer of Data outside the European Union, specifically according to the methods and countries indicated in the Company’s Privacy Policy. The security of Personal Data entrusted to MailChimp is not compromised by the extra-EU transfer as the provider in question has adhered to the Privacy Shield, as indicated in the table:

MailChimp – The Rocket Science Group LLC d/b/a
Meghan Farmer, Data Protection Officer The Rocket Science Group LLC Georgia, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, Georgia 30308 dpo@mailchimp.com Phone: (404) 806-5843
MailChimp adheres to the EU-U.S. Privacy Shield Framework, thus offering technical and organizational measures in line with GDPR.

Personal Data is also shared with extra-EU providers according to the methods and purposes set out in the previous article 2 (subjects adhering to the Privacy Shield as indicated in their respective Privacy Policies).

8 USER DATA ANALYSIS AND FORECASTING (“PROFILING”)

The Data Controller may process usage data collected through this Website to create or update/user profiles. This type of processing allows the Data Controller to evaluate choices, preferences, and behaviors of the User. By way of example and not limitation, User preferences may be inferred by monitoring interactions with the articles contained in the “Blog” section and assessed in order to provide service offers more aligned with the User’s interests.
User profiles can also be created using automated tools, such as algorithms, which may also be provided by third parties. To obtain further information on profiling activities, the User may contact the Data Controller at the email address indicated in article 4 of this Privacy Policy.

The User has the right to oppose this profiling activity at any time. To find out what profiling processes are carried out by the Data Controller, the User can request this through the contact methods mentioned in the subsequent article 10, also referring to the section of this document related to User rights.

Users are never subject to automated decisions made based on the profiling activities listed in this article.

9 USER RIGHTS

In particular, the User has the right to:
• Withdraw consent at any time. The User can withdraw consent for the processing of their Personal Data previously expressed.
• Object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are provided in the section below.
• Access their Data. The User has the right to obtain information about the Data processed by the Data Controller, about certain aspects of the processing, and to receive a copy of the Data processed.
• Verify and request rectification. The User can verify the accuracy of their Data and request its update or correction.
• Obtain restriction of processing. When certain conditions are met, the User can request the restriction of processing their Data. In this case, the Data Controller will not process the Data for any other purpose than their conservation.
• Obtain deletion or removal of their Personal Data. When certain conditions are met, the User can request the deletion of their Data by the Data Controller.
• Receive their Data or have them transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to obtain its transfer without hindrance to another controller. This provision is applicable when the Data is processed using automated tools and the processing is based on the User’s consent, on a contract to which the User is a party, or on related contractual measures.
• Lodge a complaint. The User can lodge a complaint with the competent data protection supervisory authority or take legal action in case of non-compliance with their rights by the Data Controller.

10 HOW TO EXERCISE RIGHTS

Users can exercise their rights at any time by sending the relevant request according to the following contact methods:
• By registered mail to NOUS S.R.L. Piazzale Europa 12, 22074 Lomazzo (CO) – IT, VAT 02731320038, Tax Code 02731320038
• By email to info@nous.energy

11 MINORS

This Site and the Services of the Data Controller are not intended for minors under the age of 18, and the Data Controller does not intentionally collect personal information relating to minors. In the event that information about minors is unintentionally recorded, the Data Controller will promptly delete it at the request of users.

12 CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to make changes to this Privacy Policy at any time by informing Users on this page and, if possible, on this Website as well as, where technically and legally feasible, sending a notification to Users through one of the contact details held by the Data Controller. Please therefore consult this page regularly, referring to the date of the last modification indicated at the bottom.