Privacy policy
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Last updated: 19 September 2026.
Data controller
Rigenera Solution SRL [VAT number to be completed]
Via Provinciale Selice 55/A, 40026 Imola (BO), Italy
Email: info@rigenerasolution.com
Phone: +39 393 876 7079
No Data Protection Officer (DPO) has been appointed: the conditions set out in Article 37 of the GDPR do not apply.
1. What data we collect
1.1 Data you send us
The site has two forms. Neither asks for more than what its purpose requires.
- Contact form (main page, in French, English and Italian): full name, email address, message text and, optionally, company and country.
- Event registration form for 16 October 2026 (page /event/, in Italian): first name, last name, email address, company, role, two multiple-choice answers (whether your company already has a sustainability report and which area interests you) and, optionally, a note on topics to explore.
1.2 Data collected automatically
- Web server logs. Like any site, the server records the IP address, date and time, requested page, outcome and browser type. They keep the site running and protect it from abuse; they are kept for a short time and are not used to identify anyone.
- Where the request came from. When you land on the site we store, in the browser’s temporary
memory (see section 7), the time of arrival, the referring site, the landing page and two true/false flags
saying whether the click came from a Google Ads or Meta ad. We do not store the advertising click
identifier (
gclid,fbclidand the like), even though it would be passed to us: we want to know whether a campaign brings contacts, not who you are. This information is attached to a request only if and when you decide to send one; otherwise it disappears when you close the tab.
1.3 What we do not do
- No profiling, no automated decision-making.
- No cookies, ours or third parties’. No advertising pixels, no analytics tools.
- No sale or transfer of data to third parties for marketing purposes.
- The site’s fonts and images are served from our own domain: your browser does not contact Google Fonts or any other external delivery network. The only exception is the links you open yourself, for instance the one to Google Maps on the event page.
2. Why we process them and on what legal basis
- To answer your contact request and, if a collaboration follows, to handle the next
steps.
Legal basis: pre-contractual measures taken at your request (Art. 6(1)(b) GDPR). - To manage your participation in the event: record the confirmation, send you the email with
practical details, organise the room and the light lunch, contact you in case of changes.
Legal basis: pre-contractual measures taken at your request (Art. 6(1)(b) GDPR). The two multiple-choice answers and the optional note are used to tailor the talks to the participants. - To protect the forms from automated submissions.
Legal basis: legitimate interest in not receiving spam and keeping the service working (Art. 6(1)(f)). - To understand where contacts come from and whether any advertising campaigns pay off, in
aggregate form and without advertising identifiers.
Legal basis: legitimate interest in measuring the effectiveness of our own promotional activity (Art. 6(1)(f)). You can object at any time by writing to info@rigenerasolution.com. - To comply with legal, tax and accounting obligations when the contact becomes an
engagement.
Legal basis: legal obligation (Art. 6(1)(c)).
Providing data is optional, but without the fields marked with an asterisk it is materially impossible to reply to you or register you.
3. How a request travels
It is worth spelling out, because this is where the data leaves the site.
- The form sends the data to the server hosting the site, in the European Union, operated by Revont as data processor.
- The request is delivered by email to the mailbox of Rigenera Solution’s commercial contact, through the email provider of the rigenerasolution.com domain. For the contact form the server stores nothing: the data simply passes through.
- For the event registration, in addition to the email, the registration is added to a list of participants kept on the server: it is the register used to organise the day. It is accessible only to Rigenera Solution staff, with username and password, over HTTPS.
- Again for the event, you receive from info@rigenerasolution.com a confirmation email with the date, venue, programme and a calendar file. It is the only automatic email the site sends: no newsletter, no unsolicited reminders.
4. Who we share the data with
- Infrastructure provider (hosting, form transmission and storage of the participant list): Revont, with servers in the European Union, appointed as data processor under Art. 28 GDPR.
- Email provider of the rigenerasolution.com domain, for sending and storing emails.
- The event venue (Oliveto Sul Lago Country House), limited to the number of participants and any needs for the light lunch; it does not receive the list of names unless organisational needs require it, and in that case only first name, last name and company.
- Advisors and professionals (accountant, lawyer if needed) when the contact becomes an engagement, within the limits of legal obligations.
Data is not transferred outside the European Union, is not disclosed and is not shared with anyone else.
5. How long we keep them
- Contact requests with no follow-up: the email stays archived for as long as is useful to assess a possible later contact, and in any case no longer than 24 months.
- Event registrations: the participant list and registration emails are deleted within 12 months of the event. If a commercial contact arises after the meeting, your data follows the contact-request rule from then on.
- Requests that become an engagement: for the duration of the relationship and then for the statutory periods — ten years for tax and accounting records.
- Server logs: a few days, unless needed to document abuse.
- Referral data in the browser: until the tab is closed.
6. Your rights
You can ask us at any time to access your data, to correct it, to erase it, to restrict its processing, to receive it in a machine-readable format (portability) and to object to processing based on legitimate interest (Arts. 15-22 GDPR). If you registered for the event and can no longer attend, just write to us: we remove your name from the list.
Write to info@rigenerasolution.com: we reply within one month. If you believe the processing infringes the Regulation you can lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of the country where you live (Art. 77 GDPR).
7. Cookies and browser memory
The site uses no cookies, ours or third parties’, which is why there is no banner to accept. It
stores a single value in the browser’s sessionStorage — a memory that, unlike cookies, is
never sent automatically and is cleared when you close the tab.
| Name | Contents | Duration |
|---|---|---|
rs-state |
An encrypted text, readable only by our server, containing: the result of the anti-bot check, a random technical identifier of the visit, the time you arrived, the referring site, the landing page and two true/false flags on whether you came from a Google Ads or Meta ad. | Until the tab is closed |
It serves two purposes. The first is to keep the forms safe from automated submissions: when you arrive, the browser solves a small computation in the background — you do not have to click anything — and the result, signed by our server, lets the form go through immediately when you press “send”, with no puzzles and no external services. This part is strictly necessary for the forms to work.
The second is to know where a request comes from: the referral data has to be read on arrival, because by the time you send the form it would no longer exist. This part is not strictly necessary for the service you are asking for, which is why we have reduced it to a minimum: no identifiers, nothing after the question mark in the referring address, no data leaving your device except inside a form you send yourself. If you would rather not leave even that, you can browse in a private window or delete the value from the browser’s developer tools (Application → Session Storage): the forms keep working, the anti-bot check is simply repeated when you send.
8. Security
The site is reachable only over HTTPS. The forms are protected by an anti-bot check that requires no puzzle solving and uses no third-party services. Requests are also checked server-side: field length, validity of the email address, allowed values for the multiple-choice answers. The participant list can only be downloaded with restricted credentials.
9. Changes
If the way we process data changes, we update this page and change the date at the top. Previous versions are available on request.