Privacy policy and cookie policy
This document provides information on how Pomilio Blumm processes personal data sent by users who consult this website or use forms to send messages and information requests.
This document provides information on how Pomilio Blumm processes personal data sent by users who consult this website or use forms to send messages and information requests.
By this document, and pursuant to Articles 13 to 22 of EU Reg. 679/2016, the Data Controller wishes to inform how it processes the personal data of its Clients and Suppliers.
The types of data processed are:
Essential purposes for managing pre-contractual and contractual phases (including, by way of example, data communication to electronic communication service providers, e.g. Domain Name Registrars)
The data centers used by the Controller are located in the European Union.
Clients and Suppliers are informed that:
EU Regulation 679/16, in Articles 13 through 22, grants data subjects various rights, including rectification, erasure, or restriction of processing carried out by the Data Controller.
These rights remain enforceable against the Data Controller following the termination of contractual relationships for any reason.
Rights may be exercised by contacting the Data Controller directly, specifying the affected data and the reason for the update, correction, erasure, restriction, or portability request.
Requests must be sent to the Data Controller's registered address along with a valid ID of the applicant.
If exercised via an agent, the request must include a power of attorney granting authority to request and receive responses, along with the representative's ID.
Within 30 days of receiving the request, the Controller will notify the applicant of its approval or refusal (providing detailed grounds for any rejection).
Data subjects may always assert their rights under EU Reg. 679/2016 by contacting the Data Protection Authority or ordinary judicial authorities.
Clients/Suppliers acknowledge this notice and note that mandatory data processing for regulatory and contractual fulfillment, specifically regarding:
Do not require explicit consent, as they are performed under statutory legal bases and/or contractual necessity.
Pursuant to Articles 13 to 22 of EU Reg. 679/2016, the Data Controller provides information on the processing of personal data belonging to candidates submitting resumes spontaneously or in response to job postings.
The types of data processed include details standard to European resume formats.
Data is processed to evaluate candidate suitability for potential employment opportunities.
N.B. Resumes are not evaluated using automated decision-making processes; all recruitment decisions are made exclusively by humans.
Personal data contained in resumes is stored within the European Union.
Personal data in resumes is not disclosed publicly. It is shared exclusively with authorized public authorities, as well as legal, accounting, and HR consultants for relevant assessments.
Resumes are saved on network resources controlled by the Data Controller, accessible solely to HR staff tasked with candidate evaluation and interviews.
The Controller's technical infrastructure is secured via firewalls, antivirus, and antispam controls; data is backed up, and personnel are instructed to handle personal data strictly within assigned job duties using company tools.
Upon expiration of the retention period defined in Section 3, resumes will be deleted unless longer retention is mandated by law.
EU Regulation 679/16 (Articles 13-22) guarantees data subjects rights to request data access, correction, deletion, or processing restrictions from the Data Controller.
Rights may be exercised by contacting the Data Controller directly, detailing the exact data concerned and the reason for modification, update, erasure, blocking, or data portability.
Requests must be addressed to the Data Controller's registered address along with a copy of the applicant's identity document.
If acting via a proxy, the request must include a power of attorney granting explicit authority to receive information, alongside the representative's ID copy.
The Controller will respond within 30 days of receipt, stating whether the request is accepted or rejected (providing detailed justifications in case of refusal).
Data subjects retain the right to lodge a complaint with the Data Protection Authority or the competent courts under EU Reg. 679/2016.
Candidates acknowledge this privacy notice and note that processing required to assess candidacy for potential employment does not require consent, as it relies on legal grounds (Legislative Decree 196/03 Art. 111-bis - Information in case of receiving CVs) and/or legitimate interest.
This privacy policy applies whenever browsing content on Pomilio Blumm S.r.l. domains allows the collection of information that directly or indirectly identifies a natural person.
Processing carried out by third parties (access providers, hosting providers, social network operators, analytics services) is governed by their respective privacy policies, which users are encouraged to review:
The Data Controller is Pomilio Blumm S.r.l. - Lungomare Papa Giovanni XXIII n. 22 - contact@pomilio.com – phone +39 085 421 2032
The Data Protection Officer can be reached at: DPO c/o Pomilio Blumm S.r.l. - Lungomare Papa Giovanni XXIII n. 22 – dpo@pomilio.com
This website can be browsed anonymously and, in this mode, does not process personal data.
Traffic logs generated automatically by systems (IP, user agent, timestamp, pages visited) and data from website usage analytics systems are used solely to ensure proper system operations, carry out maintenance and upgrades, protect the Controller's legal rights, and meet legal obligations.
The Controller uses the Matomo analytics platform, which does not collect personal data or export information outside the European Union, to fulfill statutory obligations (e.g., international localization rules) and protect the Controller's legal rights.
Matomo operates via cookies and tracking pixels on company websites. The anonymous traffic data mentioned in item A above may be shared with analytics providers who return aggregated reports to the Controller.
The Controller cannot identify users accessing its sites, but third-party analytics providers may possess additional data that enables them exclusively to identify individual users.
The Controller has no access to this additional data; the third-party provider is responsible for informing users and obtaining consent where required by law.
Users are responsible for reviewing the Controller's privacy policy before deciding whether to continue browsing the website.
All communications sent to the Controller via web forms or institutional email addresses are processed to respond to inquiries, protect the Controller's legal rights, and comply with regulatory requirements (e.g., documenting response times for data subject requests).
The Controller maintains official pages and profiles across social networks, each operating under its own privacy policy. Accessing the Controller's social media profiles triggers third-party processing, which may include collecting and analyzing user personal data.
The Controller has no access to this data and receives only aggregated analytics that do not permit personal user identification or individual profiling.
While user posts containing personal data are discouraged, users may post content containing personal details on official social profiles. In such cases, the Controller performs no processing other than collecting, storing, or deleting content to protect its legal rights.
If identifying a user becomes necessary (e.g., upon registration), only essential data required to interact with the user will be collected: name, surname, and email address, plus any additional details specified prior to collection. Only an email address (which need not include a real name) is required to respond to inquiries under item 2.c.
Data specified in section 3, along with related traffic logs, is processed for the purposes and legal grounds listed in section 2 of this notice.
Personal and non-personal data collected via this website are processed electronically through connection log systems (for site delivery), automated analysis tools (for troubleshooting and statistics), and automated messaging systems (for handling email communications).
This website:
The web hosting infrastructure provides high availability, automated backups, and perimeter network protection.
Data centers hosting the website infrastructure are located in the European Union.
We use Cloudflare services to manage DNS records for the domain pomilioblumm.eu.
Cloudflare acts as a DNS service provider and may process technical data associated with domain resolution requests (e.g., DNS queries). Processing complies with Cloudflare's privacy policy, accessible at: https://www.cloudflare.com/privacypolicy/
Data processing related to analytics services complies with the privacy policies of Matomo, LinkedIn, and any active vendors.
Where applicable, Data Processing Agreements have been executed with third-party service providers.
The publishing platform is hosted on European servers provided by DigitalOcean. DigitalOcean acts as a cloud hosting and infrastructure vendor. Processing on these servers complies with applicable data protection regulations. For details, visit DigitalOcean's privacy policy: https://www.digitalocean.com/legal/privacy-policy
Email infrastructure and delivery services are managed by Google Inc. (https://support.google.com/policies/answer/9581826?hl=it)
Platform maintenance, collection of anonymous usage statistics, and email communications handling are managed by the Controller, which may engage technical sub-processors for dispatch activities.
Personal data processed is retained for the longest applicable statutory limitation period for civil and criminal claims, after which it is destroyed.
Email addresses provided voluntarily are processed for declared purposes until consent is revoked.
Data collected through this site or submitted voluntarily is not shared with third parties, except for technical necessity related to platform operation or legal and international compliance requirements.
Embedded content from social networks and statistical cookies may allow third-party platforms to collect traffic data and match it with existing user profiles. Before interacting with embedded content or granting cookie consent, users are advised to review the privacy notices of the respective platforms.
No personal data is published or disclosed by the Controller beyond what is explicitly declared herein.
Without prejudice to the fact that failure to provide consent does not prevent access to or consultation of the Website, the following processing activities do not require the data subject's consent:
The following activities do require the data subject's consent:
Specifically, newsletters are distributed through IT and electronic communication infrastructures owned by, or lawfully available to, the Controller. The Controller may also engage technology service providers, email management providers or message delivery service providers, duly authorised or appointed as data processors pursuant to Article 28 of Regulation (EU) 2016/679.
The email address used for newsletter subscriptions is neither disclosed nor communicated to third parties for their own independent promotional purposes, unless the data subject has provided specific and separate consent or another appropriate legal basis provided by law applies.
The Controller may record the information necessary to demonstrate that consent has been validly obtained, including the date and time of subscription, the email address used, the version of the Privacy Notice accepted and, where applicable, confirmation of the subscription completed through the relevant verification procedure. Such information is processed in accordance with the principles of necessity, proportionality, data minimisation and storage limitation.
The data subject may withdraw consent at any time, without any formalities and as easily as it was given, by using the unsubscribe link included in each newsletter or by contacting the Controller using the contact details provided in this Privacy Notice.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal. Following an unsubscribe request, the sending of communications will cease within the technical time strictly necessary to process the request. The Controller may retain only the information strictly necessary to document the withdrawal of consent, prevent any further unsolicited communications and protect its legal rights, in compliance with the applicable retention periods.
This is without prejudice to any exceptional circumstances in which applicable law permits communications to be sent by email without obtaining fresh consent, provided that all statutory conditions are fully met and the data subject is always given the opportunity to object to any further communications easily and free of charge.
Specifically, newsletters are distributed through IT and electronic communication infrastructures owned by, or lawfully available to, the Controller. The Controller may also engage technology service providers, email management providers or message delivery service providers, duly authorised or appointed as data processors pursuant to Article 28 of Regulation (EU) 2016/679.
The email address used for newsletter subscriptions is neither disclosed nor communicated to third parties for their own independent promotional purposes, unless the data subject has provided specific and separate consent or another appropriate legal basis provided by law applies.
The Controller may record the information necessary to demonstrate that consent has been validly obtained, including the date and time of subscription, the email address used, the version of the Privacy Notice accepted and, where applicable, confirmation of the subscription completed through the relevant verification procedure. Such information is processed in accordance with the principles of necessity, proportionality, data minimisation and storage limitation.
The data subject may withdraw consent at any time, without any formalities and as easily as it was given, by using the unsubscribe link included in each newsletter or by contacting the Controller using the contact details provided in this Privacy Notice.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal. Following an unsubscribe request, the sending of communications will cease within the technical time strictly necessary to process the request. The Controller may retain only the information strictly necessary to document the withdrawal of consent, prevent any further unsolicited communications and protect its legal rights, in compliance with the applicable retention periods.
This is without prejudice to any exceptional circumstances in which applicable law permits communications to be sent by email without obtaining fresh consent, provided that all statutory conditions are fully met and the data subject is always given the opportunity to object to any further communications easily and free of charge.
Data subjects have the right to request access to, rectification of, or erasure of personal data, restriction of processing, or to object to processing (Articles 15 et seq., GDPR). Requests may be submitted via:
Pursuant to law, the application must include an identity document of the applicant. If submitted via a proxy, it must include a authorization proxy, representative ID, and specify whether the response should be addressed to the principal or the proxy.
Responses will be provided within 30 working days of receipt via the same delivery method and to the address specified in the application.
The applicant or designated representative is solely responsible for verifying that the specified physical or email address is active and monitored.
Data subjects who consider that processing of their personal data via this website breaches the Regulation have the right to lodge a complaint with the Data Protection Authority (Art. 77 GDPR) or seek judicial remedies (Art. 79 GDPR).
This website can be browsed completely anonymously. Anonymous profiling cookies for aggregated analytics are deployed only upon user consent. It does not identify or render identifiable any individual to Pomilio Blumm, except as accessible to analytics service providers. Details are published in this privacy notice.
All corporate domain names are assigned to Pomilio Blumm S.r.l.
Content published on this site is protected under Italian Copyright Law (L. 633/41) and remains the exclusive intellectual property of Pomilio Blumm S.r.l. Any use must be authorized in advance.
Direct linking to pages on this site is permitted; embedding pages within third-party sites is prohibited.
The publishing platform relies primarily on standard web technologies, including JavaScript, PHP, and HTML. This approach ensures enhanced control over data processing and infrastructure security. Certain third-party features are managed via MySQL databases.
All trademarks, logos, and textual names used on this site, unless owned by third parties, are the property of Pomilio Blumm S.r.l. pursuant to Legislative Decree 30/2005 (Industrial Property Code).
Pomilio Blumm S.r.l. encourages interaction with anyone interested in its initiatives. However, before sharing content or data, users should observe the following guidelines.
Unless strictly necessary, users should refrain from posting personal data belonging to themselves or third parties. If necessary, review Pomilio Blumm S.r.l.'s Data Protection and Cookie Policy prior to posting.
Pomilio Blumm S.r.l. promotes respectful and civil communication. Offensive, obscene, or inappropriate posts are prohibited. This includes, without limitation, content damaging personal reputation/dignity, infringing intellectual or industrial property rights, or promoting illegal goods and age-restricted services.
Pomilio Blumm S.r.l. does not engage in proactive or general surveillance of user-generated content. However, upon notification of potential legal violations, it reserves the sole right to hide content and share available information with competent authorities.
All content published by Pomilio Blumm S.r.l. is its exclusive intellectual and industrial property or used under license from rights holders.
Content reuse is allowed within statutory copyright limits, subject to express permission and provided it remains strictly non-commercial.
Intellectual and industrial property rights over content posted by users on Pomilio Blumm S.r.l. official channels remain with the original authors.
Subject to moral rights and author attribution, Pomilio Blumm S.r.l. is granted a royalty-free, perpetual, worldwide, cross-platform license to reuse user-submitted content across all institutional and promotional activities.
While official profiles are generally accessible, Pomilio Blumm S.r.l. assumes no obligation to guarantee availability across all geographic regions, full functionality, or specific language versions.
Pomilio Blumm S.r.l. takes reasonable measures to publish accurate, up-to-date information, but undertakes no legal obligation to guarantee continuous updates.
Consequently, users are advised to contact Pomilio Blumm S.r.l. directly before taking actions based on published site content.