HOGWART - The Change Management Company

Privacy notice under Articles 13–14 GDPR (EU Regulation 2016/679)

Website visitors’ privacy notice

The data provided to Hogwart S.r.l. through the message form in the contact section of the website will be processed in compliance with current personal data protection laws, pursuant to EU Regulation 679/2016 (“GDPR”).

1. Data Controller
The Data Controller is Hogwart S.r.l., based in Milan, Viale dei Mille, 7, ZIP 20129, Tel +39 02 84179551, VAT no. 03761420961.

2. Type of Data Processed
Personal data of adult individuals are processed. "Personal data" refers to any information relating to an identified or identifiable natural person. The data processed includes:
1 - data provided by the data subject through the form, such as personal details (name, surname, email address), and any other voluntarily submitted data;
2 - data provided when submitting a job application via the website, including personal details (name, surname, gender, date of birth, nationality, postal address, phone number, email), education, work experience, IT and language skills;
3 - data shared during other interactions with the Controller (name, surname, gender, date of birth, nationality, postal address, phone number, email).

3. Purposes of Data Processing
A.1 - responding to any kind of information requests, and fulfilling legal, regulatory, or EU obligations;
A.2 - fulfilling pre-contractual, contractual, and tax obligations deriving from relationships with the data subject;
A.3 - exercising the rights of the Controller, e.g., the right to legal defense.

4. Mandatory or Optional Nature of Data Provision
Providing data for the purposes described in section 3.A is mandatory, as it is necessary for the requested services and legal obligations. Refusal to provide such data may make it impossible for Hogwart S.r.l. to provide the services or fulfill legal requirements.

5. Data Processing Methods
5.1 - Data is collected electronically during service activation, including through data cross-checking and email use.
5.2 - Data is processed through registration, consultation, communication, storage, deletion, using both electronic and manual methods, ensuring data security and confidentiality.
5.3 - Data is stored on electronic/magnetic/IT supports, kept on servers located in Italy.
5.4 - Data will be processed by employees and/or collaborators of Hogwart S.r.l. according to their roles and the Controller's instructions.

6. Data Access
Your data may be accessed for the purposes in section 3.A:
6.1 - by employees and collaborators as authorized individuals or internal data processors;
6.2 - by third-party companies or others (e.g., business partners, banks, professionals, consultants, insurance companies) acting as external processors;
6.3 - by Public Administrations within institutional roles as permitted by law or regulation.

7. Data Communication
Without the need for express consent (ex art. 24(a) (b)(d) Privacy Code and art. 6(b)(c) GDPR), the Controller may share data with supervisory bodies, judicial authorities, insurance companies, and other entities required by law. These parties will act as independent controllers. Your data will not be publicly disclosed.

8. Data Subject Rights
As per art. 7 of the Privacy Code and art. 15 GDPR, the data subject has the right to:
8.1 - obtain confirmation of the existence or not of their data and access it in an intelligible form;
8.2 - obtain information on: a) the source of the data; b) processing purposes and methods; c) logic applied if processed electronically; d) controller and processor identification; e) entities or categories to whom the data may be communicated;
8.3 - obtain: a) updating, correction, or integration of data; b) deletion, anonymization, or blocking of unlawful data; c) confirmation that the above operations have been communicated to third parties unless impossible or disproportionate;
8.4 - object, in whole or in part: a) for legitimate reasons to data processing; b) to processing for marketing purposes via automated or traditional means. Rights under articles 16-21 GDPR (rectification, erasure, restriction, portability, objection), and the right to lodge a complaint with a Supervisory Authority, are also recognized.

To exercise the above rights or request more information, the data subject may contact Hogwart S.r.l. using the contact details on the website (e.g., hogwart@hogwart.it). The Controller will respond without undue delay and at the latest within one month. This period may be extended by two months if necessary, depending on request complexity and volume, with notice given within one month.

9. Data Retention
Data processing for purposes described in section 3.A will last as long as needed for service provision and additional time as required by civil, fiscal, or tax law. After this period, data will be deleted or permanently anonymized.

10. Privacy Policy Updates
This Privacy Policy may be subject to occasional updates. In case of changes, Hogwart S.r.l. will inform the data subject by publishing the updates on the website.

11. Data Transfer Abroad
Data is not shared or transferred outside the EU. Data storage will take place on servers located within the EU. If necessary, the Controller may relocate servers within or outside the EU. In such cases, data transfers will occur in compliance with adequacy decisions by the European Commission or through adoption of Standard Contractual Clauses.

Hogwart actively collaborates on projects with partner companies