Privacy Policy
Privacy Policy
1. Identity and Contact Details of the Data Controller
In compliance with the principle of transparency established by Art. 12 of Regulation (EU) 2016/679 (hereinafter 'GDPR'), please be advised that the Data Controller is Home Gallery, a legal entity under Italian law with its registered office at Via A. Gianelli 103-105 r, Genova (GE), Tax Code/VAT No. 01800540997. Any request regarding data protection may be formally addressed to the certified email address homegallery@pec.it or to the dedicated mailbox quinto@immobiliarehomegallery.it.
2. Purposes and Legal Bases of Processing
The processing of personal data is guided by the principles of lawfulness, fairness, and transparency (Art. 5 GDPR) and is based on the following legal grounds (Art. 6 GDPR):
- Contractual Performance (Art. 6.1.b): Processing is a conditio sine qua non for the establishment and execution of the real estate brokerage relationship, the management of appointments, and the fulfillment of pre-contractual obligations.
- Compliance with Legal Obligations (Art. 6.1.c): Processing is mandated by mandatory regulations, including anti-money laundering legislation (Legislative Decree 231/2007) and tax and accounting obligations.
- Legitimate Interest (Art. 6.1.f): For the protection of corporate assets, fraud prevention, and the exercise of the right of defense in legal proceedings.
- Consent (Art. 6.1.a): Exclusively for direct marketing activities and non-essential profiling, subject to free, specific, informed, and unambiguous consent, which can be revoked at any time.
3. Categories of Data Subject to Processing
The Data Controller acquires and processes, within the limits of the data minimization principle (Art. 5.1.c GDPR):
- Common Data: Personal details, telephone and electronic contact information, necessary for the identification of the contracting party.
- Economic and Financial Data: Information strictly necessary for the assessment of real estate capacity or requirements.
- Browsing Data: IP addresses, URIs, and technical parameters automatically acquired by internet communication protocols (see Cookie Policy).
4. Processing Methods and Data Retention Period
Data processing is carried out using IT and electronic tools suitable for ensuring security (Art. 32 GDPR) and confidentiality. Data will be stored for the period strictly necessary to achieve the purposes (storage limitation principle), and specifically:
- For the duration of the contractual relationship and, subsequently, for the ten-year ordinary statute of limitations (Art. 2946 of the Italian Civil Code) for civil and tax purposes.
- For 24 months for marketing purposes, unless consent is renewed.
4-bis. Data Retention Table
| Category | Purpose | Legal basis | Duration |
|---|---|---|---|
| Contact details | Request management/pre-contractual | Art. 6.1.b GDPR | Up to 24 months from the last interaction |
| Contractual data | Execution of the relationship and legal compliance | Art. 6.1.b/6.1.c GDPR | 10 years (statute of limitations/taxes) |
| Access logs | Security, anti-fraud | Art. 6.1.f GDPR | 12 months (unless otherwise required) |
| Marketing | Commercial communications | Art. 6.1.a GDPR | 24 months (consent renewal) |
5. Scope of Communication and Dissemination
Data will not be disseminated. It may be communicated to third parties, appointed where necessary as Data Processors pursuant to Art. 28 of the GDPR (e.g., IT service providers, legal and tax consultants) or to Public Authorities in the exercise of their legitimate functions.
6. Exercise of Data Subject Rights
The Data Subject may exercise the rights established by articles 15-22 of the GDPR (Access, Rectification, Erasure/Right to be Forgotten, Restriction, Portability, Objection) at any time by submitting a formal request to the Data Controller. This is without prejudice to the right to lodge a complaint with the Data Protection Authority (Art. 77 GDPR) if the Data Subject considers that the processing violates current legislation.
7. Nature of Data Provision
Providing data for contractual purposes is mandatory; failure to do so will make it impossible to proceed with the brokerage relationship. Providing data for marketing purposes is optional, and withholding consent will not affect the use of the main services.
8. Data Transfer Outside the EU
Personal data is stored on servers located within the European Union. Should it become necessary for technical and operational reasons to use entities located outside the European Economic Area (EEA), the transfer will take place in accordance with Chapter V of the GDPR, following the signing of Standard Contractual Clauses (SCC) or the verification of European Commission Adequacy Decisions.
9. Revision Clause
The Data Controller reserves the right to modify this privacy policy at any time by notifying Users on this page. Please therefore consult this page regularly, referring to the date of the last modification indicated at the bottom.
10. Security Architecture and Data Segregation (Janus II)
Data processing follows a multi-layered security model. Personal data collected via the public interface (SAMI) is transmitted to the management system (Janus II) exclusively through an encrypted channel. The process includes:
- Ingestion: Acquisition via secure HTTPS (TLS) channel.
- Access Control: Every read and modification is subject to strong cryptographic authentication, with private keys residing locally on company devices, and role-based authorizations verified by the server.
- Selective Encryption: Documents and credentials stored in the Vault area are end-to-end encrypted (AES-256) with keys not held by the server; remaining operational data resides on restricted-access infrastructure and is protected by access controls and server-side attestation logs.
11. Data Not Obtained from the Data Subject (Art. 14 GDPR)
If personal data is not obtained directly from the data subject, the Controller shall inform the data subject, within a reasonable period and in any case no later than one month (or at the first point of contact), regarding: the sources from which the data originates, the categories of data being processed, the purposes and legal bases, the recipients, as well as the rights recognized by the GDPR.
12. Personal Data Breaches
The Data Controller adopts incident management procedures in compliance with Articles 33–34 of the GDPR. In the event of a personal data breach, where the breach poses a risk to the rights and freedoms of individuals, the Supervisory Authority will be notified within 72 hours and, if the risk is high, communication will be sent to the data subjects. The process includes: containment, forensic analysis, impact assessment, corrective measures, and recording the event in the incident log.
13. DPO and Security Reporting Channel
For matters relating to the protection of personal data, the data subject may contact the Data Controller at the address quinto@immobiliarehomegallery.it or via the PEC (certified email) address homegallery@pec.it. If a Data Protection Officer (DPO) has been appointed, their contact details are published on this page. A dedicated channel is available for reporting vulnerabilities or security incidents.

