GDPR
Privacy Policy
Privacy statement pursuant to Art. 13 of EU Regulation 2016/679 (“GDPR”) and Cookie Policy
Last updated: August 2026
This information is provided by Lio Holding, based in Via Alessandro Manzoni 21, 20121 Milan, tax code and VAT number 14372030966 (hereinafter the “Company”), and is addressed to those who access the website https://www.lioholding.com/ (hereinafter “Interested parties” and “Site”). Other websites that can be reached through links on the Site are not the subject of this information. If the interested parties access these other sites through such links, the related processing of the data will be carried out in complete autonomy by the respective owners. Therefore, the Company assumes no responsibility for the aforementioned processing.
Processing of browsing data
The computer systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data of the Interested party whose transmission is implicit in the use of Internet communication protocols. This information is not directly associated with identified users, but by its very nature could, through processing and association with data held by third parties, allow such users to be identified. This category of data includes IP addresses or domain names of the computers used by users who connect to the Site, URI (Uniform Resource Identifier) addresses of the requested resources, information regarding access, information regarding location, the method used in submitting the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (success, error, etc.), information regarding the user’s visit including the clickstream data of the URL — within and from the Site — the duration of the visit on certain pages and the interaction on those pages, and other parameters relating to the operating system and the user’s IT environment.
The data collected during the Interested party’s browsing on the Site are processed to manage the Site, to verify its correct functioning, and to resolve any anomalies, functioning problems and/or abuses, as well as to ensure that the content of the Site is presented in the most effective way for the interested party and their devices.
The data could also be used to ascertain responsibility in the event of hypothetical computer crimes against the Site or third parties, and may be presented to the Judicial Authority, should this be explicitly requested.
Except for this last eventuality, the data is currently kept for a maximum period of five months.
Processing methods
Data processing is performed with the aid of IT tools, in the ways necessary to pursue the purposes for which the data were collected.
The data of interested parties will be processed by computerized and electronic means and stored with appropriate security measures in accordance with the provisions of current legislation, in order to reduce the risks of destruction or loss (even accidental) of data, unauthorized access, or processing that is not permitted or not in accordance with the purposes of the collection.
Communication and dissemination of data
Our company does not make the data subject's personal data publicly available.
In carrying out the data processing activities described in this statement, the Company also makes use of the collaboration of specialized third parties who may become aware of the data — including, for example, IT services companies (e.g. data hosting, systems protection services), telematic and archiving services — to which technical or organizational tasks or services are entrusted, and which act as processors on behalf of the Company or as autonomous data controllers.
Data processors designated by the Company, as well as authorized employees and collaborators, will be given appropriate instructions, with particular regard to security measures, in order to guarantee the confidentiality and security of the data. In any case, only those personal data necessary for the performance of their specific functions will be disclosed to them.
The data processors, where appointed, contractually undertake to guarantee compliance with the regulations in force regarding the protection of personal data and the adoption of all the security measures necessary for the adequate protection of such data.
Cookies
A cookie is a small text file that is sent to the browser and saved on the user’s terminal when the latter visits a website.
Cookies can be divided into:
- session cookies (temporary cookies that remain in the cookie folder of the user’s browser until the browsing session ends);
- persistent cookies (cookies that remain in the browser’s cookie folder for a longer time, depending on the duration of each cookie).
According to their purpose, cookies can also be distinguished as follows:
- technical cookies (used for the sole purpose of transmitting a communication over an electronic communication network, or as strictly necessary for the provider of an information society service explicitly requested by the user in order to provide that service);
- analytical cookies (cookies used for statistical analysis of the use of the site and to monitor its correct functioning);
- profiling cookies (aimed at creating profiles related to the user and used in order to send advertising messages in line with the preferences shown by the user in the context of web browsing).
Finally, it is possible to distinguish between so-called “first-party” cookies — received from the site that the user is visiting — and so-called “third-party” cookies, i.e. cookies received from sites or web servers other than the site that the user is visiting.
The Site uses the cookies “visid_incap” and “incap_ses” as first-party cookies to increase system security and performance.
Other processing carried out through the Site
Without prejudice to the foregoing, the optional, explicit and voluntary sending of messages to the addresses shown on the Site entails the subsequent acquisition of the data provided, which is necessary in order to respond to requests.
Specific information regarding the data provided may be given with reference to specific services offered on the Site.
Rights of data subjects
The interested party has the right, at any time, to obtain access to their data; to request its correction if inaccurate, or its integration if incomplete; to request its erasure or the right to be forgotten (for example, when the personal data is no longer necessary with respect to the purposes for which it was collected — erasure cannot be carried out where the processing is necessary to fulfill a legal obligation or is necessary for the establishment, exercise or defense of a right in court); to request the restriction of processing; and to data portability (in particular, upon request of the interested party, the Company will deliver to the data subject the data concerning them processed by automated means, in a structured, commonly used and machine-readable format. However, this right is limited to the data processed by the Company for the conclusion or performance of a contract with the interested party, or on the basis of their consent. Where technically feasible, and if the interested party so requests, the Company will transmit the data directly to another Data Controller). The interested party also has the right to object to the processing of said data, as well as to lodge a complaint with the Data Protection Authority if they consider that the processing of their data by the Company violates the applicable legislation in this regard.
Data Controller
Our Company Lio Holding is the Data Controller in accordance with art. 4 (7) of the GDPR. The Owner can also be contacted via email, by sending a communication to the dedicated mailbox: info@lioholding.com.