This information notice is provided pursuant to Article 13, Regulation (EU) 2016/679 (hereinafter, the “Regulation” or “GDPR”) to those who browse the website below:
www.tethis-lab.com
(the “Web Site“)
The policy describes how the Web Site is managed with reference to the processing of personal data referable to the users browsing it. It should also be noted that this policy concerns only the Web Site, to the exclusion of any Internet site to which the visitor may be redirected through links that may be available within the Web Site.
1. The data controller
Tethis S.p.A., with registered office in Milan, via Francesco Olgiati 5, e-mail address privacy@tethis-lab.com in the person of its legal representative pro tempore is the data controller (hereinafter, the “Company” or the “Controller“).
2. How to contact the data protection officer
The Controller has appointed a Data Protection Officer (“Data Protection Officer” or “DPO“) who can be contacted by sending an e-mail to dpo@tethis-lab.com.
3. What is personal data and which data we process
“Personal data” means any information capable of identifying, directly or indirectly, a natural person (“Data”) and, in this case, the user who is browsing the Web Site (hereinafter, the “User”).
When the User visits the Web Site, the Company may collect Data either indirectly (e.g., IP address and the URL of their device in order to monitor their use of the Web Site), or directly (e.g., if they voluntarily enter Data within forms specifically set up on the Web Site). This includes:
| Category | Details |
|---|---|
| Personal details | First and last name |
| Contact information | e-mail address, phone number |
| Information on the organization the User belongs to | Business name, address, website |
| Device and navigation information | Information about the browser or device used to access the Web Site and browsing data on the Web Site as described in the section on cookies |
| Information requests | Any information shared by the User as part of sending inquiries through the contact form or through the Controller’s contact information available on the Web Site. |
In any case, the Controller undertakes to collect only information that is adequate, relevant and limited to what is strictly necessary to achieve the purposes pursued by the same from time to time, and that this does not result in a limitation or other violation of the rights and freedoms of the User as data subject.
Within the Web Site, there are social media widgets (i.e., LinkedIn), and links to external sites, such as the whistleblowing platform, please note that the processing activities performed on such web pages are governed by their respective privacy policies. For information regarding these processings, please read the relevant privacy policies.
4. Purpose of processing
a. Web Site management and security
The Controller collects and processes Data for the purpose of enabling the use of the Web Site, controlling its proper functioning, and ensuring its security.
The legal basis for processing is Article 6(1)(f) GDPR, i.e. the legitimate interest of the Controller to enable navigation on the Web Site and the proper management thereof.
b. Handling of information requests
By filling out the appropriate form available on the Web Site, or through channels outlined therein, is possible to contact the Controller to request information regarding the Company (e.g., current projects, services offered, partnerships, etc.).
Such processing is carried out in order to comply with a User’s request and, therefore, is based on the condition of lawfulness in Article 6(1)(b) GDPR.
The provision of Data is optional; however, depending on the case, failure to complete the contact form or to provide sufficient information will result in the impossibility for the Company of following up on the request.
c. Exercise and/or defense of rights in court
The Controller may process Data to assert and defend its rights in court directly or through third parties (e.g., lawyers).
Where necessary, processing will be based on the lawful basis pursuant to Article 6(1)(f) GDPR i.e. the legitimate interest of the Company in the protection of its rights.
5. Cookie
Cookies are packages of information sent by a web server (e.g., the Web Site) to the User’s Internet browser, automatically stored by the User on the computer and automatically sent back to the server each time the User accesses the site.
The Web Site does not use proprietary cookies, however, it incorporates and gives the possibility to view directly from its pages videos and multimedia content (so-called “embedded contents”) located on third party platforms. In this regard, the Web Site uses players made available by Vimeo (and/or other providers if applicable indicated in the table below) in relation to which, if activated, technical cookies may be installed in order to allow the User to play the multimedia content.
Below is some more detailed information (i.e., name, domain, duration, and type) about the cookies that Company uses on the Web Site.
| Name | Domain | Purpose | Duration | First or third party |
|---|---|---|---|---|
| __cf_bm | .vimeo.com | Distinguishing between humans and bots | 30 minutes | Third party (Vimeo) |
| _cfuvid | .vimeo.com | Cloudflare cookie used to enforce rate limiting rules | Session | Third party (Vimeo) |
Use of Google Analytics for Statistical Analysis
The Web Site uses Google Analytics, a web analytics service provided by Google Ireland Limited (for users residing within the European Economic Area) and/or Google LLC (hereinafter collectively referred to as “Google”), acting as data processors or autonomous data controllers depending on the active features.
-
Data Collected and Purposes: Google Analytics collects data regarding the user’s interaction with the Web Site (e.g., appropriately anonymized IP address, pages visited, date and time of visit, duration of stay, type of browser, and device used). This information is processed solely for aggregate and anonymous statistical analysis in order to monitor the proper functioning of the Web Site, improve its content, and optimize the user browsing experience.
-
Location of Processing and Data Transfers: Data generated by the service is stored on Google’s servers. In the event of any personal data transfers outside the European Economic Area (e.g., to Google LLC in the United States), such transfers take place on the basis of appropriate legal safeguards adopted by Google (such as Standard Contractual Clauses approved by the European Commission or equivalent mechanisms under the GDPR).
-
Google’s Privacy Policy: For further details on how Google processes data, please consult their official privacy policy: https://policies.google.com/privacy
Integration for the Cookie Policy & Consent Management
Third-Party Analytics Cookies (Google Analytics)
Google Analytics installs technical or analytics cookies (e.g., _ga, _ga_*) to track the user’s browsing session and generate reports on Web Site usage.
-
Cookie Retention Period: Varies from a single session up to a maximum of 2 years (unless revoked or cleared earlier by the user).
How to Revoke or Manage Consent
The installation of Google Analytics cookies occurs exclusively upon the user’s consent (collected via the cookie banner displayed upon first access to the Web Site).
Users may revoke or modify their consent at any time using the following methods:
-
Via Web Site Settings: By clicking on the “Manage Cookie Consent” link/button located in the footer of any page on the Web Site.
-
Via Browser Opt-out Add-on: By installing the official Google Analytics Opt-out Browser Add-on provided by Google for your browser: https://tools.google.com/dlpage/gaoptout
-
Via Browser Settings: By configuring your browser preferences to block or delete third-party cookies.
6. To whom we communicate the data
The Controller may disclose the Data, as an integral part of the processing activities, to third parties located in the territory of the European Economic Area (“EEA”) that offer the Controller IT, administrative services, as well as to external consultants who will carry out the processing as data processors pursuant to Article 28, GDPR. The updated list of data processors is maintained by the Controller and is available upon request.
The Controller may disclose Data to third parties located in the EEA, such as entities to which the disclosure is due under legal obligations, to Public Administrations or legal advisors. In addition, where necessary for the purposes of following up on User requests for information or collaboration, Data may be shared with project partners.
These parties will process the Data as autonomous controllers.
7. Where we transfer the data
The Web Site’s server is located in Italy.
The Data may be transferred to external companies that provide the Company with Web Site maintenance and development services and, in general, IT services, specifically appointed as data processors, as well as, where such communication is possible or required by law, communicated to other companies or Public Entities located within the EEA, which will process the Data for their own purposes as autonomous data controllers.
As a general rule, the Controller will not transfer Data to countries outside the EEA. However, in the limited exceptional circumstances where this may be necessary, such transfer will only take place in accordance with the conditions set out in the GDPR to countries for which the European Commission has provided an adequacy decision or, alternatively, will be regulated through the use of standard contractual clauses adopted by the European Commission, or on the basis of any other appropriate means permitted by the relevant legislation.
For more information about where the data has been transferred, if at all, please contact the Controller by writing to the e-mail address in Paragraph 1.
8. How long we keep the data
We process Data for as long as is strictly necessary to achieve the purposes stated in Section 4.
The retention times of the Data collected indirectly by the Controller via cookies are listed in Section 5 “Cookies”.
If the User directly provides Data to us through the Web Site, the Data will be processed by the Controller:
- i. To respond to user requests submitted via the contact form: for as long as is strictly necessary to fulfill user requests, but no longer than 1 year after the last interaction.
- ii. For the protection of our rights in court: for the duration of the litigation, and until the decisive decision is final.
- iii. For Web Site security purposes: for the time strictly necessary to fix any bugs and malfunctions of the Web Site.
After the mentioned retention periods have elapsed, the Data will be deleted, except for judicial requirements or ongoing administrative audits on the date of expiration of the retention period.
9. The user’s rights as a data subject
During the period in which the Controller processes the Data, the User, as a data subject, may at any time exercise the following rights:
- Right of access – the User has the right to obtain confirmation about the existence of a processing concerning the Data and, if applicable, the right to receive any information concerning such processing.
- Right to rectification – the User has the right to obtain rectification of Data where it is inaccurate or incomplete.
- Right to deletion – in certain circumstances, the User the right to obtain the deletion of Data held within the Controller’s archives if it is not relevant to the continuation of the contractual relationship or necessary to fulfill a legal obligation to which the Controller is subject or for the establishment, exercise or defense of a right in court.
- Right to restriction of processing – upon the occurrence of certain conditions, the User has the right to obtain restriction of processing concerning the Data.
- Right to portability – upon the occurrence of certain circumstances, the User has the right to obtain the transmission of the Data in our possession in favor of a different controller.
- Right to object – the User has the right to object, at any time for reasons related to their particular situation, to the processing of Data based on the lawful basis of legitimate interest or the performance of a task of public interest or the exercise of public authority, including profiling, unless there are legitimate grounds for the Controller to continue the processing that override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of a right in court.
The above rights may be exercised against the Controller by writing to the e-mail address in Paragraphs 1 and 2.
10. Complaints
Should the User wish to file a complaint regarding the way the Data is processed by the Controller, or regarding the handling of a proposed request, the User has the right to file a complaint directly with the Supervisory Authority in the manner described on the official website at the following link:
https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/4535524.
11. Final provisions
The Controller reserves the right to modify and/update this policy at any time.
Version updated as of: 23/07/2026