COOKIE POLICY
SNATT LOGISTICA S.p.A., (Tax Code and VAT No.: 02060420359) (hereinafter “SNATT”), in the person of its pro tempore legal representative, with registered office in Campegine (RE), Via Kennedy, 12/b , , in its capacity as Data Controller pursuant to Articles 4(7) and 24 of EU Regulation No. 2016/679 (GDPR), sets out below its cookie policy (the “Policy”) applicable solely to this website (the “Website”).
Legal framework of reference.
1.1. The Policy is based on the following EU and/or national regulatory provisions (first and/or second level): (i) Directive No. 2002/58/EC of 12 July 2012 (the so-called ePrivacy Directive), as amended by Directive No. 2009/136/EC; (ii) Article 122 of the amended Legislative Decree No. 196/2003 (Privacy Code), which transposed the ePrivacy Directive into national law; (iii) GDPR: Articles 4(11), 7, 12, 13, 25 and 95 (in addition, in particular, to Recitals 30, 32 and 173); (iv) Guidelines No. 5/2020 adopted on 4 May 2020 by the EDPB, replacing the Guidelines of 10 April 2018 signed by WP Art. 29; (v) Provision No. 231 of 10 June 2021 [web doc. No. 9677876] signed by the Data Protection Authority (Privacy Guarantor); (vi) Recommendation No. 2/2001 of the WP Art. 29; (vii) Opinion No. 2/2010 of the WP Art. 29; (viii) Opinion No. 4/2012 of the WP Art. 29; (ix) Guidelines No. 8/2020 of the EDPB; (viii) Measures No. 224 of 9 June 2022 [web doc. No. 9782890],
No. 243 of 7 July 2022 [web doc. No. 9806053], No. 254 of 21 July 2022 [web doc. no. 9808698], no. 329 of 4 June 2025 [web doc. no. 10152755] and no. 327 of 4 June 2025 [web doc. no. 10152729] signed by the Data Protection Authority.- Cookies and other tracking tools: definition and classification.
2.1. Cookies[1] are, as a rule, strings of text that a website (“publisher” or “first party”) visited by the user or a different website (“third party”) places and stores, directly (in the case of the first-party website) or indirectly (through the latter, in the case of the third-party website), on a terminal device available to the user. In this regard, the Data Protection Authority has specified that the information encoded in cookies may include both personal data pursuant to Article 4(1) of the GDPR (e.g. IP address, username; email address; unique identifier) and non-personal data pursuant to Article 3(1) of EU Regulation No. 1807/2018 (e.g. language; type of device used).
Alongside (or in addition to) these, there may be (and therefore be used) ‘other tracking tools’, which can be divided into ‘active’ (which have almost the same characteristics as cookies) and ‘passive’ (e.g. fingerprinting).
2.2. Beyond the intrinsic characteristics described above, cookies (and other tracking tools) may have different characteristics in terms of duration (and therefore be considered ‘session’[2] or “persistent”[3] , depending on their duration), from a subjective point of view (depending on whether the publisher acts independently or on behalf of a “third party”) and, finally (but in particular), based on the purpose of the processing pursued, so that they can be divided into two different (macro) categories:
- “technical”, used for the sole purpose of “carrying out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for the provider of an information society service explicitly requested by the contractor or user to provide that service” (Article 122(1) of the Privacy Code).
In this regard, the Privacy Guarantor has highlighted, in Provision no. 231 of 10 June 2021 (in line with the previous Provision on the subject of 2014), that “analytics cookies“[4] may well be included within the scope of cookies (or other tracking tools) of a “technical” nature (and, therefore, may be used without the prior consent of the data subject), under certain conditions, aimed at precluding the possibility that their use could lead to the direct identification of the data subject (single out)[5] .
- “profiling”/”marketing” cookies (so-called non-technical cookies), used to trace specific actions or recurring behavioural patterns in the use of the features offered (patterns) back to specific, identified or identifiable subjects, in order to group the different profiles into homogeneous clusters of varying sizes, so that the Data Controller can, , among other things, to tailor the provision of the service in an increasingly personalised manner beyond what is strictly necessary for the provision of the service, as well as to send targeted advertising messages (i.e., in line with the preferences expressed by the user when browsing the web).
[1] See Recital 30) of the GDPR (“Natural persons may be associated with online identifiers generated by the devices, applications, tools and protocols they use, such as IP addresses, temporary markers (cookies) or other identifiers, such as radio frequency identification tags. Such identifiers may leave traces which, in particular when combined with unique identifiers and other information received from servers, may be used to create profiles of natural persons and identify them”), and Article 122(1) and (2) of the Privacy Code (“1. The storage of information in the terminal equipment of a contractor or user or access to information already stored is permitted only on condition that the contractor or user has given their consent after being informed in a simplified manner. This does not prohibit the technical storage or access to information already stored if it is for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for the provider of an information society service explicitly requested by the contractor or user to provide that service. For the purposes of determining the simplified methods referred to in the first sentence, the Garante shall also take into account the proposals made by the most representative national consumer and economic associations involved, also with a view to ensuring the use of methods that guarantee the effective awareness of the contractor or user. 2. For the purposes of expressing the consent referred to in paragraph 1, specific configurations of computer programs or devices that are easy and clear to use for the contractor or user may be used…”); see also page 15) of Provision No. 231 of 10 June 2021 signed by the Privacy Authority: “…to date, there is still no universally accepted system of semantic coding of cookies and other tracking tools that allows for an objective distinction to be made, for example, between technical cookies and analytics or profiling cookies, other than on the basis of the information provided by the controller itself in its privacy policy […] the hope is that a general coding system will be agreed upon in the near future’.
[2] Cookies designed to collect and store data while a user accesses a website, and disappear once the user has closed the relevant browsing session.
[3] Cookies designed to last for a predetermined period of time (e.g. minute, month, year).
[4] Analytical cookies are usually used to evaluate the effectiveness of an information society service provided by a publisher, to design a website or, finally, to help measure its traffic (i.e. the number of visitors, possibly broken down by geographical area and time of connection).
[5] See Provision No. 231 of 10.6.2021 signed by the Privacy Guarantor, pp. 13/14: “The structure of the analytics cookie must therefore allow for the possibility that it may refer not only to one but to several devices, so as to create reasonable uncertainty about the digital identity of the person receiving it. As a rule, this effect is achieved by masking appropriate portions of the IP address within the cookie. Taking into account the representation of 32-bit IP version 4 (IPv4) addresses, which are usually represented and used as a sequence of four decimal numbers between 0 and 255 separated by a dot, one of the measures that can be implemented in order to benefit from the exemption is to mask at least the fourth component of the address, an option that introduces an uncertainty in the attribution of the cookie to a specific data subject equal to 1/256 (approximately 0.4%). Similar procedures should be adopted with regard to IP version 6 (IPv6) addresses, which have a different structure and an enormously larger addressing space (consisting of binary numbers represented with 128 bits). The Data Protection Authority also emphasises the need for the use of analytics cookies to be limited solely to the production of aggregate statistics and for them to be used in relation to a single website or a single mobile application, so as not to allow the tracking of the browsing of persons who use different applications or browse different websites. It is therefore understood that third parties providing web measurement services to publishers must not combine the data, even if minimised, with other processing (e.g. customer files or statistics on visits to other sites) or transmit it to other third parties, as this would lead to an unacceptable increase in the risk of user identification. except in cases where the statistics they produce with the minimised data concern multiple domains, websites or apps attributable to the same publisher or business group. However, even in the absence of the prescribed minimisation measures, it is possible to consider lawful the use of statistical analyses relating to multiple domains, websites or apps attributable to the same data controller is considered lawful, provided that the data controller carries out the statistical processing itself and that such analyses do not result in an activity that, going beyond the boundaries of a mere statistical count, actually takes on the characteristics of processing aimed at making commercial decisions.
- Cookies installed on the Website.
3.1. The following types of cookies have been installed (or may be installed, subject to the user’s specific consent) on the Website:
Name
Type
Function
First/Third party
Duration[1]
_GA
_GA_FMYSDEBQP7
Analytical
Records a unique ID used to generate statistical data on how visitors use the site. If consent is given, it allows for the personalisation of advertisements.
First party[2]
10/2026
10/2026
_GLC_AU
Marketing
Used by Google AdSense to verify the effectiveness of advertising on all websites that use their services.
First party
12/2025
_IUB_CS-13404889
_IUB_CS-34040271
_IUB_CS-51372451
_IUB_CS-81047119
_IUB_CS-S4164087
_IUB_CS-S4164087
Technical
Tracks cookie preferences.
Third party (iubenda)[3]
9/2026
4/2026
8/2026
5/2026
6/2026
9/2026
_IUB_PREVIOUS_PREFERENCE_ID
Technical
Tracks cookie preferences.
First party
9/2026
WP_WPML_CURRENT_LANGUAGE
Technical
Tracks language preference.
Part One
9/2026
- Impostazioni del browser
4.1. SNATT highlights the possibility for the user to delete and block the operation of the cookies described in Article 3 above at any time by using the appropriate settings within the browser used: in this regard, SNATT adds that, if the user decides to disable the technical cookies referred to in Article 2.2. point i), the quality and speed of the services and features offered and made available on the Website may deteriorate.
Information on how to manage cookies with some of the most popular browsers can be found by visiting the following web pages:
https://support.google.com/chrome/answer/95647?hl=it
https://support.mozilla.org/it/kb/Gestione%20dei%20cookie?redirectlocale=enUS&redirectslug=Cookies
https://support.microsoft.com/it-it/help/17442
https://support.apple.com/it-it/guide/safari/sfri11471/mac
https://support.apple.com/it-it/HT201265
https://help.opera.com/en/latest/security-and-privacy/#clearBrowsingData
For more information about Google’s policy on the use of personal information, please visit the following link:
Rights of the data subject.
5.1.In relazione ai dati personali dell’utente, SNATT informa che il relativo soggetto interessato ex art. 4 n. 1) del GDPR possiede la facoltà di esercitare i seguenti diritti eventualmente soggetti alle limitazioni previste dagli artt. 2 undecies e 2 duodecies del CodiceCodice Privacy: diritto di accesso ex art. 15 del GDPR: diritto di ottenere la conferma che sia o meno in corso un trattamento di dati personali che riguardano l’interessato, oltre che le informazioni di cui all’art. 15 del GDPR (es. finalità di trattamento, periodo di conservazione); diritto di rettifica ex art. 16 del GDPR: diritto di correggere, aggiornare o integrare i dati personali; diritto alla cancellazione ex art. 17 del GDPR: diritto di ottenere la cancellazione o distruzione o anonimizzazione dei dati personali, laddove tuttavia ricorrano i presupposti elencati nel medesimo articolo; diritto di limitazione del trattamento ex art. 18 del GDPR: diritto con connotazione marcatamente cautelare, teso ad ottenere la limitazione del trattamento laddove sussistano le ipotesi disciplinate dallo stesso art. 18; diritto alla portabilità dei dati ex art. 20 del GDPR: diritto di ottenere i dati personali, forniti a SNATT, in un formato strutturato, di uso comune e leggibile da un sistema automatico (e, ove richiesto, di trasmetterli, in modo diretto, ad un altro Titolare del trattamento), laddove sussistano le specifiche condizioni indicate dal medesimo articolo (es. base giuridica del consenso e/o esecuzione di un contratto; dati personali forniti dall’interessato); diritto di opposizione ex art. 21 del GDPR: diritto di ottenere la cessazione, in via permanente, di un determinato trattamento di dati personali; diritto di proporre reclamo all’Autorità di Controllo (ossia, Garante Privacy italiano) ex art. 77 del GDPR: diritto di proporre reclamo laddove si ritiene che il trattamento oggetto d’analisi violi la normativa nazionale e comunitaria sulla protezione dei dati personali.
5.2. In aggiunta ai diritti descritti al precedente art. 5.1., SNATT precisa che, in relazione ai dati personali dell’interessato, sussiste, ove possibile e conferente, la facoltà di esercitare, da un lato, il (sotto) diritto previsto dall’art. 19 del GDPR (“Il titolare del trattamento comunica a ciascuno dei destinatari cui sono stati trasmessi i dati personali le eventuali rettifiche o cancellazioni o limitazioni del trattamento effettuate a norma dell’articolo 16, dell’articolo 17, paragrafo 1, e dell’articolo 18, salvo che ciò si riveli impossibile o implichi uno sforzo sproporzionato. Il titolare del trattamento comunica all’interessato tali destinatari qualora l’interessato lo richieda”), da considerarsi connesso e collegato all’esercizio di uno o più diritti regolamentati agli artt. 16, 17 e 18 del GDPR; dall’altro lato, SNATT precisa che, in relazione ai dati personali dell’interessato, sussiste, ove possibile e conferente, la facoltà di esercitare il diritto previsto dall’art. 22 paragrafo 1) del GDPR (“L’interessato ha il diritto di non essere sottoposto a una decisione basata unicamente sul trattamento automatizzato, compresa la profilazione, che produca effetti giuridici che lo riguardano o che incida in modo analogo significativamente sulla sua persona”), fatte salve le eccezioni previste dal successivo paragrafo 2).
5.3. In ossequio all’art. 12 paragrafo 1) del GDPR, SNATT si impegna a fornire all’utente le comunicazioni di cui agli artt. da 15 a 22 e 34 del GDPR in forma concisa, trasparente, intellegibile, facilmente accessibile e con un linguaggio semplice e chiaro: tali informazioni saranno fornite per iscritto o con altri mezzi eventualmente elettronici ovvero, su richiesta dell’utente, saranno fornite oralmente purché sia comprovata, con altri mezzi, l’identità di quest’ultimo.
5.4. In ossequio all’art. 12 paragrafo 3) del GDPR, SNATT informa che si impegna a fornire all’utente le informazioni relative all’azione intrapresa riguardo ad una richiesta ai sensi degli artt. da 15 a 22 del GDPR senza ingiustificato ritardo e, comunque, al più tardi entro un mese dal ricevimento della richiesta stessa; tale termine può essere prorogato di n. 2 mesi se necessario, tenuto conto della complessità e del numero delle richieste (in tal caso, il Titolare si impegna ad informare l’utente di tale proroga e dei motivi del ritardo, entro un mese dal ricevimento della richiesta).
5.5. L’utente può esercitare, in qualsiasi momento, i sopra descritti diritti (fatta eccezione per il diritto ex art. 77 del GDPR) mediante l’utilizzo dei dati di contatto illustrati all’art. 6.
- Contact details.
6.1. SNATT can be contacted at the following address: snattlogisticaspa@legalmail.it
6.2. The Data Protection Officer (DPO) pursuant to Article 37 of the GDPR, appointed by SNATT, is Gabriele Borghi, who can be contacted at the following address: dpo@snatt.it
Campegine (RE), 10 September 2025 (date of last update).
SNATT LOGISTICA S.p.A.
(represented by its pro tempore legal representative)
