Web data and processing methods

The data processing related to this site’s web services is only handled by the technical personnel of the department responsible for/authorised to perform such processing. No data from the web service is disclosed or disseminated. Personal data provided by users who request information is only used to carry out the service requested, and is only disclosed to third parties if necessary to provide said service.

Data and processing methods

Personal data is processed by automated systems for the time strictly necessary to achieve the purposes for which it was collected. Specific security measures are taken in order to prevent a loss of data, its illegal or improper use, and unauthorised access to data.

Browsing data

During the ordinary course of operations, and only for the duration of the connection, the IT systems and software procedures for running this website acquire some personal data, whose transmission is implied in the use of the communication protocols of the Internet (browsing data). It concerns information that is not collected to be linked to identified data subjects, but by their own very nature could, through the processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of computers used by users who connect to the website, URI addresses (Uniform Resource Identifier) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.) and other parameters related to the operating system and the user’s IT environment. This data is processed for the following purposes:

  • to comply with the prescriptions of domestic and European laws and provisions issued by Supervisory and Control Authorities, including in relation to the obligations to monitor the operational and credit risks at the Banking Group level; the processing of your Personal Data to comply with the regulatory provisions is mandatory and your consent is not required;
  • to pursue a legitimate interest of Fideuram, companies within the Bank’s Group or third parties where such interests do not conflict with the interests or fundamental rights and freedoms of the data subjects (Article 6.1 point f of Regulation (EU) 2016/679), namely

    • to ascertain liability in the event of hypothetical computer crimes against the website, and for investigations should any disputes arise;
    • to obtain anonymous statistical information on the use of the website and to ensure that it is functioning correctly, as well as for measuring and improving the services offered and the website itself;
    • to pursue any and additional legitimate interests. In the latter case, the Data Controller may process your Personal Data only after having informed you and having ascertained that achieving its legitimate interests or those of third parties does not compromise your rights and fundamental freedoms;
and your consent is not required. The browsing data collected on the website and the app will remain on the servers for 12 months. Likewise the Personal Data may be processed for a longer time, in cases an act occurs that interrupts and/or suspends the provision that justifies the extension of the data retention.

Data provided voluntarily by the user

The optional, explicit and voluntary sending of emails to the addresses indicated on this website subsequently involves obtaining the sender’s address, required in order to reply to requests, as well as obtaining any other personal data within the message.

The use of personal data to send advertising material, commercial information, or the sale of products or services by the Bank may only occur if the sender has given prior consent by ticking the appropriate box.

Specific summary information will be progressively reported or displayed on the website’s pages, which provide particular services on request.