1. Scope and principles
This notice is provided under Articles 12, 13 and, where applicable, 14 GDPR and Italian data-protection law. It covers vitamini.life, information/commercial enquiries and prospective B2B relationships. Separate notices will be issued before e-commerce, newsletters, competitions, loyalty, apps, research or child-facing features.
2. Controller and DPO
Piazza Trivulziana 4/A, 20126 Milan (MI), Italy
VAT IT04398760274 · REA MI 2679515 · SDI 3ZJY534 · LEI 815600299308A5DAE574
Certified e-mail (PEC): unitedsafety@pec.it · Tel. +39 02 5656 8416
Privacy: privacy@uese.eu · DPO: dpo@uese.it
3. Data processed
Technical logs required by the deployed infrastructure; contact/correspondence data voluntarily sent; B2B/professional information. Special-category data are not requested, particularly health information about children. Data may come from the individual, their organisation or legitimate public/professional B2B sources.
4. Purposes and legal bases
Website security/operation rely on legitimate interests and, where applicable, legal obligations; replies and pre-contractual steps rely on Article 6(1)(b) or legitimate interests for B2B; legal defence/compliance on Articles 6(1)(c)/(f). Future electronic marketing or profiling will rely on consent where required. No significant solely automated decisions or advertising profiling are currently active.
5. Children
The website is primarily for adults and is not designed to collect personal data directly from children. Future child-facing features will require dedicated notices, age assurance and parental authorisation where required. UESE does not intend to profile children for personalised advertising.
6. Recipients
Authorised staff and providers for hosting, e-mail, security, maintenance, compliance and professional advice may process data; processors are appointed under Article 28 GDPR where appropriate. Data may be disclosed to authorities/advisers when legally necessary and are not sold to advertisers.
7. International transfers
UESE favours EEA infrastructure. Third-country transfers will use adequacy decisions, Standard Contractual Clauses or another mechanism under Articles 44–49 GDPR with supplementary safeguards where needed.
8. Retention
Technical logs are retained only as needed for security; unprogressed enquiries normally up to 24 months; B2B relationships according to legal/defence periods; future marketing consent until withdrawal or the period in the relevant notice.
9. Security and DPIA
UESE applies risk-based organisational and technical safeguards. New high-risk profiling or systematic child-data processing will be assessed in advance and, where required, subject to a DPIA under Article 35 GDPR.
10. Rights and complaints
Individuals may exercise access, rectification, erasure, restriction, portability, objection and consent-withdrawal rights via privacy@uese.eu or the DPO and may complain to the Italian Data Protection Authority or the competent EU supervisory authority.
11. Updates and precedence
The notice may change with the project, providers, features or law. Specific notices prevail for the relevant processing. The Italian version is UESE’s reference text, without prejudice to mandatory local rights.
