CYBER 4.0 – PRIVACY POLICY
To get information about your personal data collected, the purposes and the parties with whom the data are shared, contact the Data Controller.
Data Controller
Cyber 4.0 Association
Via Ardito Desio 60 – 00131 Rome
Owner’s email address: privacy@cyber40.it
Types of Data Collected
The Owner does not provide a list of types of Personal Data collected.
Full details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific informational texts displayed prior to the collection of such Data.
Personal Data may be freely provided by the User or, in the case of Usage Data, automatically collected during the use of this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users who are in doubt about which Data are mandatory are encouraged to contact the Data Controller.
Any use of Cookies – or other tracking tools – by this Application or by the owners of third party services used by this Application is for the purpose of providing the Service requested by the User, in addition to the additional purposes described in this document and in the Cookie Policy.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application.
Method and place of processing of collected Data
Mode of treatment
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
The processing is carried out by means of computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes. In addition to the Data Controller, in some cases, other subjects involved in the organization of this Application (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.
Location
The Data are processed at the Holder’s operational offices and at any other location where the parties involved in the processing are located. For more information, please contact the Data Controller. The User’s Personal Data may be transferred to a country other than the country in which the User is located. To obtain more information about the location of processing, the User may refer to the section on Personal Data Processing Details.
Retention period
Unless otherwise stated in this document, Personal Data is processed and kept for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligations or based on Users’ consent.
Cookie Policy
This Application makes use of Tracking Tools. To learn more, Users may consult the Cookie Policy.
More information for users
Purpose and Legal Basis of Processing
Purpose:
The Owner processes Personal Data related to the User to execute information, training, activities necessary to ensure the User’s participation in popular and/or educational events within the scope of the subjects covered by the charter and/or projects in which Cyber 4.0 participates as an organizer or partner.
The Controller processes the User’s Personal Data only if there is at least one of the following legal bases for processing:
- the User, or the person exercising parental authority in the case of underage Interested Parties, has given consent for one or more specific purposes;
- processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
- processing is necessary to fulfill a legal obligation to which the Controller is subject;
- the processing is necessary for the performance of a task of public interest or the exercise of public authority vested in the Controller;
- processing is necessary for the pursuit of the legitimate interest of the Controller or third parties.
However, it is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.
Additional information on shelf life
Unless otherwise stated in this document, Personal Data is processed and kept for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligations or based on Users’ consent.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of that contract is completed.
- Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When processing is based on the User’s consent, the Controller may retain Personal Data longer until that consent is revoked. In addition, the Controller may be required to retain Personal Data for a longer period to fulfill a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, at the expiration of this period the right of access, deletion, rectification and the right to Data portability can no longer be exercised.
Rights of the User based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights with respect to the Data processed by the Data Controller.
In particular, to the extent provided by law, the User has the right to:
- Revoke consent at any time. The User may revoke the previously expressed consent to the processing of his/her Personal Data.
- Object to the processing of their Data. You may object to the processing of your Data when it is done pursuant to a legal basis other than consent.
- Access to your Data. You have the right to obtain information about the Data processed by the Data Controller, certain aspects of the processing and to receive a copy of the Data processed.
- verify and request correction. Users may verify the accuracy of their Data and request that it be updated or corrected.
- obtain restriction of processing. The User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
- Obtain the deletion or removal of their Personal Data. The User may request the deletion of their Data from the Data Controller.
- Receive their Data or have their Data transferred to another owner. You have the right to receive your Data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transferred unimpeded to another data controller.
- propose complaint. The User may bring a complaint to the relevant data protection supervisory authority or take legal action.
Users have the right to obtain information regarding the legal basis for the transfer of Data abroad including to any international organization governed by international law or formed by two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect their Data.
Details of the right to object
When Personal Data are processed in the public interest, in the exercise of public powers vested in the Data Controller or in pursuit of a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users are reminded that, should their Data be processed for direct marketing purposes, they may object to the processing at any time, free of charge and without providing any reasons. If Users object to processing for direct marketing purposes, the Personal Data are no longer processed for such purposes. To find out whether the Data Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.
How to exercise rights
Any requests to exercise the User’s rights may be addressed to the Controller through the contact details provided in this document. The request is free of charge and the Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectification, deletion or restriction of processing will be communicated by the Controller to each of the recipients, if any, to whom the Personal Data has been transmitted, unless this proves impossible or involves a disproportionate effort. The Data Controller shall notify the User of such recipients if the User so requests.
More information about the treatment
Litigation defense
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages of its possible establishment for the defense against abuse in the use of this Application or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.
Specific disclosures
Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual disclosures regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Owner will re-collect the User’s consent, if necessary.
Last updated: January 27, 2026
