Privacy Notice

Privacy Notice

This privacy notice describes the methods of processing personal data carried out by Epta S.p.A. through the MyEpta digital platform (hereinafter, the "Platform"), accessible from the https://www.myepta.com/  website.

The Platform is a digital portal for professionals (B2B) through which Epta S.p.A. makes available to customers and their authorised representatives (the “Users”) information, documentation, data and services (the “Services”) relating to industrial refrigeration products (the “Assets”) installed at the points of sale or operating sites (“Stores”) of the Epta Group’s customer organisations (the “Organisations”).

The Services may include, depending on the access privileges of users and the Services subscribed to by their Organisations, the viewing and analysis of technical and operational data relating to the Assets, including operating parameters, performance data, energy consumption, anomaly reporting and support for maintenance activities.

Access to the Services is subject to the completion of the procedures for registering the User and verifying and associating the User’s account with the relevant Organisation (hereinafter, "Account Pairing") and takes place only within the limits of the access privileges assigned to the User and the Services subscribed to by the relevant Organisation.

In the context of the use of the Platform, personal data relating to identified or identifiable persons may be processed.

Pursuant to and for the purposes of art. 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), Epta S.p.A., in its capacity as Data Controller, provides this notice in relation to the processing of Users’ personal data.

The purpose of this notice is to describe how personal data is processed, the purposes and legal bases of the processing, the applicable data retention periods, and the rights of data subjects.

  1. Data Controller

    The Data Controller of personal data is Epta S.p.A., Tax Code and VAT number IT 04160730968, with registered office in Via Mecenate, 86 - 20138 Milan, Italy, Tel. +39 02 55403211, e-mail uffamministrativi@pec.eptarefrigeration.com (hereinafter also “Epta”, “Company” or “Data Controller”).

    Epta has appointed, pursuant to art. 37–39 of the GDPR, a Data Protection Officer (DPO), who can be contacted at the following address:

    c-dpo@external.eptarefrigeration.com

  2. What types of data are processed on the Platform, for what purposes and on what legal bases

    The following types of personal data are processed on the Platform, for the following purposes and according to the legal bases indicated below:

    1. Browsing data

      In order to pursue our legitimate interest in ensuring the security of the Platform and establishing responsibility in the event of alleged cybercrime or other unlawful activities affecting the Platform, checking its correct functioning and obtaining statistical information on its use (Article 6, paragraph 1, letter f) of the GDPR), the computer systems and software procedures used to operate the Platform acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.

      This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.

      This category of data includes the IP addresses or domain names of the computers used by users who connect to the Platform, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, unsuccessful, error, etc.) and other parameters related to the user’s operating system and computer environment.

      An indicative list of information we may collect is as follows:

      • Internet Protocol (IP) address;
      • type of browser and device parameters used to connect to the website and/or Platform;
      • name of the internet service provider (ISP);
      • date and time of visit;
      • the visitor’s referring and exit web page;
      • possibly the number of clicks.

      The collection of such personal data takes place automatically while browsing the site and/or the Platform and their provision is therefore mandatory for all users and visitors of the site and/or the Platform.

    2. Data provided voluntarily by the user

      1. To execute the service contract to which you are a party and/or pre-contractual measures adopted at your request (Article 6, paragraph 1, letter b) of the GDPR):

        In relation to the registration to, and use of, the Platform, the personal data provided by the User are processed to:

        • allow registration on the Platform and the creation of a user account, which in the initial phase takes the form of a temporary technical account (so-called "Pending Technical Account"), necessary for the management of the Account Pairing request;
        • manage your access request and the Account Pairing process, i.e. the verification and association of your account with the relevant Organisation to which you belong, which includes verifying your identity, your membership of, or authorisation to act on behalf of, the Organisation, and the accuracy of the information you provide;
        • determine the scope of the User’s authorized access rights, based on the User’s role and the information available in the Data Controller’s systems (such as, by way of example, Organisation, account number, Store, Asset and Services);
        • allow, following the completion of the Account Pairing, the use of the Services within the limits of the access privileges assigned to the User and the Services subscribed to by the relevant Organisation;

        For clarity, registration initially involves the creation of a Pending Technical Account, which is used exclusively to manage the Account Pairing process. This account does not allow access to the Services or other restricted features of the Platform. Access to the Services becomes available only after the User has successfully completed the Account Pairing process, which essentially consists of matching the Pending Technical Account with a valid account number according to the instructions provided within the Platform, and is limited to the access privileges assigned to the User and the Services subscribed to by the relevant Organisation.

        The following data is required to create the Pending Technical Account: name, surname, e-mail address, organisation to which you belong, country/region. Additional data may be required to complete the Account Pairing process, including the account number and information relating to the User’s role within the Organisation.

        The provision of personal data is optional but necessary for registration on the Platform and for access to the Services; otherwise, you will not be able to create your account or use the Platform.

        If the Account Pairing process is not completed, your personal data will be processed for a limited period, as indicated in the data retention section.

        The contact data provided by the User may only be used for communications strictly related to the management of registration, access requests and use of the Platform, unless the User has given specific consent for marketing and information purposes.

      2. To comply with the legal obligations to which Epta is subject, arising under applicable tax, accounting, administrative and security laws and regulations (Article 6, paragraph 1, letter c) of the GDPR).
      3. To pursue our legitimate interest in exercising or defending a right in or out of court (Article 6, paragraph 1, letter f) of the GDPR): we may process your personal data to pursue our legitimate interest in exercising or defending a right in or out of court, including in the event of any pre-contractual liability.
      4. To pursue our legitimate interest in ensuring the successful completion of the registration process (Art. 6, para. 1, lit. f) of the GDPR): we may send you, through automated tools (such as emails), communications intended to assist you in completing the Account Pairing process, including reminders.

      For marketing and informational purposes (Article 6, paragraph 1, letter a) GDPR): Subject to your free, specific and optional consent, your personal data may be processed by Epta for the sending, through automated tools (such as e-mail, SMS, messaging applications) and/or traditional methods (such as telephone with operator and paper mail), promotional, commercial and informational communications, relating to the products, services, initiatives and activities of Epta, standardised according to the relevant category of User, without this entailing automated decision-making processes or profiling of any kind pursuant to art. 22 GDPR. The provision of consent is optional; failure to provide it or subsequent revocation does not affect in any way the registration on the Platform or the use of the related services. You may revoke your consent at any time, even partially, only for automated communication methods, by contacting the Data Controller at the addresses indicated in paragraph 5 below.

  3. Communication to third parties and disclosure of personal data

    Your personal data may be accessed by employees and authorised personnel of the Data Controller who have been duly authorised to process such data and who act under its instructions. Personal data may also be disclosed to third-party service providers, including providers of IT and application support services, communication services, data processing services, hosting and cloud infrastructure services, cybersecurity services, web analytics services and Platform management services, as well as to companies within the Epta Group involved in the provision of the products and Services accessible through the Platform and in the management of the related commercial, support and maintenance activities. Such recipients process personal data in accordance with their respective roles and responsibilities under applicable data protection legislation. Personal data may be processed by providers of technological and infrastructure services, including cloud service providers and digital identity management providers, to the extent necessary for the operation and security of the Platform.

    Personal data may also be disclosed to law enforcement authorities, courts, or other competent public authorities where required by applicable law or pursuant to a binding judicial, administrative or regulatory order, as well as to our legal advisers where necessary for the establishment, exercise or defence of legal claims.

    Any transfer of your personal data to countries outside the European Union or the European Economic Area (the “Third Countries”) will take place only where the destination country has been recognised by the European Commission as ensuring an adequate level of protection for personal data or, where no such adequacy decision exists, where appropriate safeguards are in place to ensure a level of protection substantially equivalent to that guaranteed within the European Union, including through the execution of the Standard Contractual Clauses approved by the European Commission. In all cases, appropriate measures will be implemented to ensure that data subjects can effectively exercise their rights and benefit from adequate safeguards in relation to the processing of their personal data. Such transfers may also occur in connection with the use of cloud services and authentication systems supporting the operation of the Platform.

    Further information can be requested by writing to compliance@eptarefrigeration.com

  4. Duration of processing and storage of personal data

    The Data Controller retains personal data for as long as necessary to fulfil the purposes for which it was collected, and in particular:

    • for the purposes referred to in point 2.1 above, for a maximum period of six months, unless further retention is necessary to establish responsibility in the event of alleged cybercrime affecting the website and/or the Platform, or to comply with requests from judicial authorities or law enforcement authorities;
    • for the purposes referred to in point 2.2 a), above: (i) in the event that the registration process is successfully completed and the User’s account has been correctly associated with the relevant Organisation (Account Pairing), personal data will be retained for the duration of the contractual relationship relating to the Services and until the User requests deletion of the account. In any case, the account and its data will be automatically deleted in the event of inactivity for 2 consecutive years, meaning that the User has not accessed the Platform during that period; (ii) in the event that the registration process is not completed, or the process of verifying and associating the account with the relevant Organisation (Account Pairing) is not completed, the personal data will be retained for the period strictly necessary to manage the Account Pairing request and, in any case: (x) for a period not exceeding 48 hours from the creation of the Pending Technical Account, if the User does not complete the Account Pairing request within that period; (y) for a maximum period of 15 days from the creation of the Pending Technical Account, if within 48 hours of the creation of the Pending Technical Account, the User has contacted Epta to receive assistance in the Account Pairing process and Epta has verified that the User is authorised to operate within the Platform on the basis of a valid account number, for the sole purpose of allowing the completion of the Account Pairing process. If the periods referred to in points (x) and (y) expire without the Account Pairing process being successfully completed, the Pending Technical Account and the associated personal data will be automatically deleted.
    • for the purposes referred to in points 2.2. b) and 2.2. c), for 10 years, to comply with retention obligations under accounting and tax laws and regulations and with the applicable limitation periods for contractual claims;
    • for the purposes referred to in point 2.2 d) above), for 3 years from the date on which you last provided your consent for marketing and informational communications; as the expiry of this period approaches, you will be asked whether you wish to continue receiving such communications and, if so, the retention period referred to above will be renewed. Otherwise, the personal data will be deleted upon expiry of the retention period.

    The retention times of the data collected through cookies are available in the Cookie Policy: https://www.myepta.com/cookie-policy

  5. Rights of the data subjects (Articles 15 to 22 of the Regulation)

    Finally, we inform you that, at any time, free of charge and without formalities, you may exercise the rights provided for under Articles 15 to 22 of the GDPR. In particular, you have the right to obtain confirmation as to whether or not personal data concerning you is being processed and, where that is the case, to access such data and receive a copy thereof, together with the information required by Article 15 of the GDPR (right of access); to obtain the rectification of inaccurate personal data concerning you and the completion of incomplete personal data (right to rectification); to obtain the erasure of your personal data where one of the conditions set out in Article 17 of the GDPR applies (right to erasure or “right to be forgotten”); to obtain the restriction of processing in the cases provided for by Article 18 of the GDPR (right to restriction of processing); to be informed of any rectification, erasure or restriction of processing carried out in accordance with Article 19 of the GDPR; to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit such data to another controller, where the conditions set out in Article 20 of the GDPR apply (right to data portability); and to object, at any time and on grounds relating to your particular situation, to the processing of your personal data based on the Data Controller’s legitimate interests (right to object).

    Regarding processing for marketing purposes, you have the right to object at any time to the processing of your personal data for such purposes and to withdraw any consent previously given, in whole or in part, including with regard only to automated means of communication. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

    Requests to exercise your rights, as indicated above, can be submitted by post to the address Epta S.p.A., Via Mecenate, 86 - 20138 Milan, Italy, or by e-mail to compliance@eptarefrigeration.com

    You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali): www.garanteprivacy.it.

  6. Use of Cookies

    For further information about the use of cookies and the related processing of personal data, please refer to our Cookie Policy: https://www.myepta.com/cookie-policy

  7. Changes

    This Privacy Policy may be subject to changes or updates in accordance with regulatory and technological developments. In the event of material changes to the Privacy Policy, we will send you the new version of the Privacy Policy by e-mail.

Last updated: July 22, 2026