Privacy Policy

Information notice pursuant to Articles 13-14 of Reg. (EU) 2016/679 (GDPR)

This privacy policy (the “Privacy Policy”) describes the processing of personal data carried out through the website www.mosaicgroupengineering.it (the “Website”) by the Joint Controllers identified below.

The Joint Controllers may process the user’s personal data when the user visits the Website and uses its services and features. If the user provides personal data of third parties, the user must ensure that such disclosure and the subsequent processing for the stated purposes comply with applicable law.

This Privacy Policy is an integral part of the Website and is provided, pursuant to Articles 13 and 14 of Reg. (EU) 2016/679, to those who interact with the Website’s web services (e.g. through the contact form). Processing is based on the principles of lawfulness, fairness, transparency and protection of the data subject’s privacy and rights.

1. Joint Controllers

“MOSAIC” is not a separate legal entity but the name of a project jointly developed by several engineering and architecture firms/companies cooperating with one another. The Joint Controllers of the data collected through the Website are the following:

  • DI EMIDIO PROGETTI Srl — Registered office: Rome, Via Napoleone III no. 6, VAT 02010370449, e-mail: giustino@studiodiemidio.it;
  • DOING INGEGNERIA Srl — Registered office: Ascoli Piceno, Via della Stazione no. 9, Villa Sant’Antonio, VAT 02391710445, e-mail: giustino@studiodiemidio.it;
  • STUDIO TECNICO ING. MASSIMO LIVIO MARAVALLE — Registered office: San Benedetto del Tronto (AP), Via Marechiaro n. 1, VAT 01805540448, e-mail: massimomaravalle@gmail.com;
  • STUDIO ASSOCIATO EUROPROGETTI — Registered office: Via Pontida no. 6, 63074 San Benedetto del Tronto (AP), VAT 0200690446, e-mail: info@europrogetti-engineering.it

The Joint Controllers act in joint controllership pursuant to Article 26 GDPR, jointly determining the purposes and means of the processing of data collected through the Website. The essential content of the joint-controllership arrangement is made available to data subjects, who may request a copy at info@mosaicgroupengineering.it. Regardless of the terms of the arrangement, the data subject may exercise their rights in respect of and against each of the Joint Controllers (Article 26(3) GDPR).

2. Categories of data, purposes and legal bases

2.1 Browsing data

The IT systems and software procedures used to operate the Website acquire, during normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols (e.g. IP addresses, browser/device type, operating system, request times, pages visited). Such data are used solely to obtain anonymous statistical information on the use of the Website and to ensure its correct operation and security. Legal basis: the Controller’s legitimate interest (Article 6(1)(f) GDPR).

2.2 Data provided through the contact form

Through the contact form the following personal data may be collected: first and last name, e-mail address and any further information voluntarily entered in the message. As a rule, special categories of data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) are neither requested nor processed; users are asked not to include such data in the free text.

Data are processed solely to handle contact requests and respond to messages sent, and to perform pre-contractual measures taken at the data subject’s request. Legal basis: Article 6(1)(b) GDPR. Providing the data is optional but necessary to receive a reply: without it the request cannot be processed. Data are not used for marketing purposes.

2.3 Cookies and analytics tools

The Website uses technical cookies and, subject to the user’s consent, third-party analytics cookies (Google Analytics – GA4). The types of cookies, their purposes, durations and the ways to manage consent are described in detail in the Website’s Cookie Policy. Legal basis for analytics cookies: the data subject’s consent (Article 6(1)(a) GDPR).

3. Processing methods

Processing is carried out using electronic and IT tools and, where necessary, on paper, in compliance with the principles of lawfulness, fairness, transparency, data minimisation and integrity/confidentiality set out in the GDPR. Appropriate technical and organisational measures are adopted to protect the data against unauthorised access, loss, destruction or disclosure.

4. Recipients and categories of recipients

Personal data may be accessed by employees and collaborators of the Joint Controllers authorised to process them (e.g. administrative, commercial, legal, technical staff, system administrators), acting under the direct authority of the Joint Controllers. Data may also be processed by third parties providing services functional to the operation of the Website (e.g. hosting provider, website maintenance provider, e-mail service providers) and, limited to data collected through analytics cookies, by Google as provider of the Google Analytics service; such parties are appointed as Processors pursuant to Article 28 GDPR. An up-to-date list of Processors is available at the Joint Controllers’ offices and may be requested at info@mosaicgroupengineering.it. Data are not disseminated.

5. Transfers to third countries

Data processed to handle contact requests are kept within the European Union. The Website also uses Google Analytics (GA4), provided by Google, activated only with the user’s prior consent: this tool may involve the transfer of data (e.g. IP address, identifiers contained in cookies) to the United States. The transfer takes place on the basis of the European Commission’s adequacy decision regarding the EU-U.S. Data Privacy Framework (to which Google adheres) and/or Standard Contractual Clauses, as adequate safeguards under Chapter V GDPR. Details of the cookies and their providers are set out in the Cookie Policy.

6. Retention period

  • Contact-form data for handling requests: retained for the time needed to deal with the request and, where there is no follow-up, no longer than 12 months from receipt, save for legal obligations or the need to defend a legal claim.
  • Browsing data: retained for the time strictly necessary for security and statistical purposes, subject to any legal obligations.
  • Data collected through analytics cookies: retained for the durations set out in the Cookie Policy (for Google Analytics cookies, up to approximately 13 months), subject to withdrawal of consent.


7. Rights of the data subject

The data subject may exercise at any time, within the limits and conditions set out in Articles 15-22 GDPR, the following rights:

  • right of access (Article 15);
  • right to rectification (Article 16);
  • right to erasure (“right to be forgotten”, Article 17);
  • right to restriction of processing (Article 18);
  • right to data portability (Article 20), where applicable;
  • right to object to processing (Article 21), with regard to processing based on legitimate interest;
  • right to withdraw consent given for analytics cookies, at any time, without affecting the lawfulness of processing based on consent given before withdrawal.


The data subject also has the right to lodge a complaint with the supervisory authority (Italian Data Protection Authority – Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome – www.garanteprivacy.it).

8. Exercising rights

To exercise the rights under section 8, the data subject may send a request to: info@mosaicgroupengineering.it. Consent to analytics cookies may be withdrawn at any time through the preference-management button on the Website (see Cookie Policy).

9. Updates

This Privacy Policy may be amended or updated, with changes published on this page together with the last-update date

Last updated: 04.06.2026

Menu