Information pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data (hereinafter also "GDPR")

Pursuant to Article 13 of the GDPR, in accordance with the principle of transparency, the following information is provided in order to make the user (hereinafter the "Data Subject") aware of the characteristics and methods of processing the data that our organization will acquire through the compilation of the "Request Information" form on the website

  • Data controller

Dermakim S.r.l. - Administrative office: 21100 Varese - Via Bernascone,16/A

The data controller and privacy contact person can be contacted at 0332 287623 or via e-mail:

  • Types of personal data processed

The categories of personal data subject to processing are represented by common personal and contact data. The indicated data is necessary to manage the Data Subject's request and to contact them.

  • Purpose and legal basis of the processing

The personal data of individuals who have filled out the "Request Information" form are processed for the purpose of evaluating requests or suggestions received, responding to reports, or providing the requested information.

The processing of personal data requested by the Data Subject in the electronic contact form aims to make it possible to receive and manage requests received by the Controller through the Site.

Under Article 6 of the GDPR, the legal basis for processing is represented by the need to carry out pre-contractual measures adopted at the request of the Data Subject (Article 6 letter b GDPR), or, in the case of requests not related to pre-contractual relationships, by the legitimate interest of the Controller in managing an area of the Site where data of the Data Subjects and the applicants themselves are collected to receive a response to their requests (Article 6 letter f GDPR).

  • Scope of communication and dissemination of personal data for the pursuit of the purposes of processing

The personal data processed by the Controller will not be disclosed, nor will they be made known to indeterminate subjects in any possible form, including that of their availability or simple consultation.

They may, however, be communicated:

    • to authorized personnel of the organization depending on the scope of the request and for the purpose of processing it
    • to computer companies to perform maintenance related to the Site


  • Mandatory or optional nature of the provision of personal data

The provision of personal data is optional. If the Data Subject does not intend to communicate the personal data necessary based on what is required by the Form, the consequence would be the impossibility of proceeding with the request.

  • Data retention period

In accordance with Article 13, paragraph 2, letter a of the Regulation, it is informed that the data will be stored for 12 months, unless legal relationships develop from the received contacts. At the expiration, personal data will be deleted.

If legal or commercial relationships are established with the requesting contacts, the data will be kept for the time related to the contractual, legal, or commercial relationship eventually established, and therefore for 10 years starting from the termination of the contractual relationship. The data subject retains the right to request immediate deletion of personal data after receiving feedback and responses to the requests sent.

In this case, the request for deletion must be sent through communication to the following email address:

  • Automated decision-making processes

The Data Controller does not carry out treatments consisting of automated decision-making processes on the submitted data.

  • Location of data processing and transfers outside the European Union

The processing related to the services provided by the Website is carried out at the headquarters of the Data Controller. The data collected and processed through the Website are not subject to transfer to countries outside the European Union.

  • Data subject rights

By communication to be sent to the Data Controller at the following email address:, the data subject can exercise at any time the following rights under Articles 15 to 22 of the GDPR:

  • request access to personal data, rectification or deletion of the same, or limitation of the processing that concerns them or to object to their processing, in the cases provided;
  • obtain the portability of data which allows the data subject to receive the personal data provided to the Data Controller in a structured, commonly used, and machine-readable format and – under certain conditions – to transmit them to another data controller without hindrance. Only personal data concerning the data subject, which have been provided to the Data Controller and are processed electronically in the context of concluding a contract, are portable.
  • file a complaint with the Guarantor for the protection of personal data, if competent Authority, following the procedures and indications published on the official website of the Authority at;

The exercise of rights is not subject to any form constraint and is free of charge. Only in the case of a request for additional copies of data requested by the data subject, the Data Controller may charge a reasonable contribution based on administrative costs. The response will be given within the time limits set out in Article 12, paragraph 3 of the Regulation.