Skip to main content

Privacy Policy

Last updated: July 20, 2026

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) to users who visit the website www.ly-co.it and use the services available on it.

1. Data controller

Ly-Co S.r.l. a socio unico
Viale Primo Maggio, 31 – 43047 Pellegrino Parmense (PR), Italy
VAT no. IT02512030343
Email: info@ly-co.it – Phone +39 0524 1960670

The Controller has not appointed a Data Protection Officer (DPO), as it is not required to do so by law.

2. Types of data processed

a) Browsing data

During their normal operation, the computer systems and software used to run this website collect certain data whose transmission is implicit in the use of Internet communication protocols (e.g. IP addresses, time of the request, pages visited, browser information). This information is not collected in order to be associated with identified individuals, but by its nature it could allow users to be identified. This data is used solely to obtain anonymous statistical information on the use of the website and to check that it is working properly and securely.

b) Data voluntarily provided by the user

Through the contact form on the “Contact” page, users may provide the following data: name, email address, phone number, company and message content. The optional and voluntary sending of messages to the Controller’s email addresses or phone numbers involves the collection of the sender’s contact details, which are needed to reply, as well as any other personal data included in the message.

c) Cookies

For information about cookies, please see our Cookie Policy.

3. Purposes and legal bases of processing

  • Responding to contact and quote requests – legal basis: performance of pre-contractual measures taken at the data subject’s request (Art. 6(1)(b) GDPR);
  • Compliance with legal obligations (accounting, tax, etc.) – legal basis: legal obligation (Art. 6(1)(c) GDPR);
  • Ensuring the security and proper functioning of the website – legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR);
  • Establishing, exercising or defending legal claims, where necessary – legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).

Providing the data marked as mandatory in the contact form is necessary to process the request; failure to provide it will make it impossible to respond. Providing any other data is optional.

4. Processing methods and recipients

Data is processed using electronic and telematic tools, with logic strictly related to the purposes stated above and in a way that ensures the security and confidentiality of the data, in accordance with the measures set out in Art. 32 GDPR. No automated decision-making or profiling is carried out.

Data may be processed by:

  • the Controller’s internal staff, authorized and instructed pursuant to Art. 29 GDPR;
  • technical service providers (e.g. website hosting and maintenance providers), appointed as data processors pursuant to Art. 28 GDPR;
  • consultants and professionals, where necessary to meet legal obligations;
  • competent authorities, in the cases provided for by law.

Personal data is not disclosed to the public.

5. Transfers of data to third countries

Data collected through the website is stored on servers located in the European Union. The “Location” page includes an embedded Google Maps map provided by Google Ireland Ltd: interacting with this service may involve the transfer of data to third countries (USA), based on the safeguards provided for in Art. 44 et seq. GDPR (EU-US Data Privacy Framework adequacy decision and/or standard contractual clauses). More information is available in our Cookie Policy.

6. Retention period

  • Contact form data: for the time needed to handle the request and in any case no longer than 24 months from the last contact, unless the request leads to a contractual relationship;
  • Browsing data: generally for short periods, unless needed to investigate crimes or for security purposes;
  • Data processed to meet legal obligations: for the periods required by applicable law (e.g. 10 years for accounting records).

7. Rights of the data subject

Pursuant to Articles 15-22 GDPR, data subjects have the right to:

  • access their personal data and information about its processing (Art. 15);
  • obtain the rectification of inaccurate data or the completion of incomplete data (Art. 16);
  • obtain the erasure of their data, where applicable (Art. 17);
  • obtain the restriction of processing (Art. 18);
  • receive their data in a structured, commonly used and machine-readable format – data portability (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw any consent given at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Requests may be sent to the Controller by writing to info@ly-co.it. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) if they believe the processing violates applicable law.

8. Minors

The website and the services offered by the Controller are not intended for children under 14, and the Controller does not knowingly collect personal data relating to minors.

9. Changes to this notice

The Controller reserves the right to change or update this notice, including as a result of changes in the law or in the services offered. Users are invited to check this page regularly; the last updated date shown at the top applies.

This is an English translation provided for convenience. In case of discrepancies, the Italian version prevails.