Contact information
Information (3) provided pursuant to art. 13 of EU Regulation no. 2016/679
[https://abrakadabraitaly.com/pages/contatti]
I. Why are you being given this information?
Because ABK Experience s.r.l. intends to process some of your personal data through the 'Contact Us' form (within the website 'https://abrakadabraitaly.com/') for the purposes and according to the methods described below, and the law requires you to be informed in advance and adequately. All of this is separate from what is contained in the Personal Data Protection Policy and the Cookies Policy.
II. Who is providing you with this information?
The data controller is (according to the law) the entity that has independently decided both these purposes and these methods, controlling the website in question, and the law requires you to know who it is and, above all, how it can be contacted.
In this case, it will be ABK Experience s.r.l. itself, a limited company with VAT number and tax code no. 04783490404, registered with the Business Register under no. RN-440772, located in via Monte Rosa, 11 - Riccione (RN), 47838 and reachable via the corporate e-mail contact 'compliance@abrakadabraitaly.com'.
III. What are the frequently mentioned purposes of processing?
The first task of the data controller is (according to the law) to declare what objectives it intends to achieve through the processing of your personal data.
The first (A) [1.A] purpose [main alternative] is to define the configuration of the recreational service you need, in light of what you have requested, so as to allow for a more efficient planning of its business activities and your maximum satisfaction. If you want to know more about the data controller because you are interested in the added value it can help create, this is the purpose for you.
The first (B) [1.B] purpose [main alternative] is to develop the recreational service you have purchased according to the necessary configuration, in light of what has been agreed with you, so as to allow for a more efficient conduct of its business activities and your maximum satisfaction. If you have already relied on the data controller, but need support because you have encountered an issue or developed a doubt, this is the purpose for you.
The second [2] purpose [ancillary] is to comply precisely with the legislation on personal data protection, by conforming to one or more pertinent legal obligations. Please read section (n. IV.c.) on your rights carefully to understand what the data controller will be required to do.
The third [3] purpose [ancillary] is to eventually protect – even if it is hoped that there will be no need – its economic interests in out-of-court and/or judicial settings [legitimate interest]. Don't worry, it's just the legislator who imposes such a clarification on us...
IV.a. Who will help pursue the purposes of processing?
The second task of the data controller is (according to the law) to declare what methods it intends to adopt for the processing of your personal data: here, in particular, who will have access to your personal data. Keep in mind that a service provider in this context is not a simple software reseller, but the entity that hosts your personal data involved in the use of the software on its servers.
Internally, with regard to the first (A) [1.A], the first (B) [1.B], the second [2] and the third [3] purposes, only the sole director (general management area) will be involved.
Externally, with regard to the first (A) [1.A] and the first (B) [1.B] purposes, the corporate website hosting service provider (A), the secretarial - commercial and technical assistance service provider, compliant, commercial and technical (B) and – possibly – the corporate instant messaging hosting service provider (C) will be involved, all authorized to operate as data processors.
Externally, with regard to the second [2] purpose, the corporate website hosting service provider (A), the secretarial - commercial and technical assistance service provider, compliant, commercial and technical (B), – possibly – the corporate instant messaging hosting service provider (C), – possibly – the corporate e-mail hosting service provider (D), – possibly – the certified corporate e-mail hosting service provider (E) and – possibly – the specifically selected lawyer(s) (F) will be involved, all authorized to operate as data processors, as well as – possibly – the specifically selected lawyer(s) (I), acting as independent data controller(s).
Externally, with regard to the third [3] purpose, – possibly – the corporate e-mail hosting service provider (A), – possibly – the secretarial - commercial and technical assistance service provider, compliant, commercial and technical (B), – possibly – the certified corporate e-mail hosting service provider (C) and – possibly – the specifically selected lawyer(s) (D) will be involved, all authorized to operate as data processors, as well as – possibly – the specifically selected lawyer(s) (I), acting as independent data controller(s).
Please note that the corporate website hosting service provider, for the pursuit of the first (A) [1.A], the first (B) [1.B] and the second [2] purposes, will – in case of detection of its operational needs – transfer its personal data to Canada (CA) and – possibly – to one or more additional non-EU member states, which can still be classified as third countries, adopting as adequate safeguards the adequacy decisions regarding the individual pertinent national legal systems on personal data protection, pursuant to art. 45, p. 1 of the GDPR and/or the standard contractual clauses for the transfer of personal data referred to in the implementing decision (European Commission) no. 2021/914, pursuant to art. 46, p. 2, l. c) of the GDPR, as declared at 'https://www.cloudflare.com/it-it/cloudflare-customer-dpa/' (section "6. Data transfers from the EEA, Switzerland, and the UK"), unfortunately not currently available in Italian.
Please also note that the secretarial - commercial and technical assistance service provider, compliant, commercial and technical, for the pursuit of the first (A) [1.A], the first (B) [1.B] and the second [2] purposes, will – in case of detection of its operational needs – transfer its personal data to Canada (CA) and – possibly – to one or more additional non-EU member states, which can still be classified as third countries, adopting as adequate safeguards the adequacy decisions regarding the individual pertinent national legal systems on personal data protection, pursuant to art. 45, p. 1 of the GDPR and/or the standard contractual clauses for the transfer of personal data referred to in the implementing decision (European Commission) no. 2021/914, pursuant to art. 46, p. 2, l. c) of the GDPR, as declared regarding its distinct hosting assistant (corporate email) at 'https://www.cloudflare.com/it-it/cloudflare-customer-dpa/' (section "6. Data transfers from the EEA, Switzerland, and the UK"), unfortunately not currently available in Italian.
Finally, please note that the corporate instant messaging hosting service provider, for the pursuit of the first (A) [1.A], the first (B) [1.B] and the second [2] purposes, will – in case of detection of its operational needs – transfer its personal data to the United States of America (US) and – possibly – to one or more additional non-EU member states, which can still be classified as third countries, adopting as adequate safeguards the adequacy decisions regarding the individual pertinent national legal systems on personal data protection, pursuant to art. 45, p. 1 of the GDPR and/or the standard contractual clauses for the transfer of personal data referred to in the implementing decision (European Commission) no. 2021/914, pursuant to art. 46, p. 2, l. c) of the GDPR, as declared at 'https://www.whatsapp.com/legal/business-data-transfer-addendum' (section "6. Data transfers from the EEA, Switzerland, and the UK"), unfortunately not currently available in Italian.
IV.b. How long will it take to pursue the purposes of processing?
The second task of the data controller is (according to the law) to declare what methods it intends to adopt for the processing of your personal data: here, in particular, for how long it will have access to your personal data.
With regard to the first (A) [1.A] purpose, the necessary personal data will be stored until the date of completion of the definition of the recreational service's configuration, even if the outcome is negative.
With regard to the second [2] purpose, if it follows the pursuit of the first (A) [1.A] purpose, the necessary personal data will also be stored until the date of completion of the definition of the recreational service's configuration, but subsequently – in a separate and secure place, to ensure the pursuit of the third [3] purpose – for an additional 10 years from then.
With regard to the third [3] purpose, if it follows the pursuit of the first (A) [1.A] purpose, the necessary personal data will also be stored for a period of 10 years from the date of completion of the definition of the recreational service's configuration, without prejudice to what has already been specified regarding the management subsequent to such completion.
With regard to the first (B) [1.B] purpose, the necessary personal data will be stored until the date of completion of the development of the recreational service according to the necessary configuration, even if its duration is shortened by a termination of the relevant contract.
With regard to the second [2] purpose, if it follows the pursuit of the first (B) [1.B] purpose, the necessary personal data will also be stored until the date of completion of the development of the recreational service according to the necessary configuration, but subsequently – in a separate and secure place, to ensure the pursuit of the third [3] purpose – for an additional 10 years from then.
Finally, with regard to the third [3] purpose, if it follows the pursuit of the first (B) [1.B] purpose, the necessary personal data will be stored for a period of 10 years from the date of completion of the development of the recreational service according to the necessary configuration.
IV.c. What rights can you exercise before, during and after processing?
The second task of the data controller is (according to the law) to declare what methods it intends to adopt for the processing of your personal data: here, in particular, what you can ask the data controller to do.
With regard to the first (A) [1.A], the first (B) [1.B], the second [2] and the third [3] purposes, you may access your processed personal data, obtaining information on the processing similar to that found in this policy, as well as a copy of the same, rectify your processed personal data, for example if you have changed your e-mail contact, delete your processed personal data, for example if you consider the processing unlawful, restrict the processing of your processed personal data, instead of having them deleted, for example if you consider the processing unlawful: all this can be done by writing to 'compliance@abrakadabraitaly.com'.
Furthermore, with regard to the first (B) [1.B] purpose, you may obtain the portability of your processed personal data: this can also be done by writing to 'compliance@abrakadabraitaly.com'.
Furthermore, only with regard to the third [3] purpose, you may object to the processing of your processed personal data: this can also be done by writing to 'compliance@abrakadabraitaly.com'.
However, finally, with regard to the first (A) [1.A], the first (B) [1.B], the second [2] and the third [3] purposes, you may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali) at 'https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/4535524’ or with the national supervisory authority operating within the territory of the European Union Member State where you reside and/or work, in any case qualified as the competent supervisory authority: this will be very useful if at any time you consider the processing of your personal data unlawful.
IV.d. Is it mandatory to communicate your personal data to the data controller?
The second task of the data controller is (according to the law) to declare what methods it intends to adopt for the processing of your personal data: here, in particular, whether there is a pre-contractual or contractual and/or legal obligation that requires the data controller to collect your personal data.
With regard to the first (A) [1.A] purpose, there is a pre-contractual obligation, and therefore the data controller would otherwise not be able to act effectively to define the configuration of the recreational service.
Furthermore, with regard to the first (B) [1.B] purpose, there is a contractual obligation, and therefore the data controller would otherwise not be able to act effectively to develop the recreational service according to the necessary configuration.
Finally, with regard to the third [3] purpose, there is no pre-contractual or contractual and/or legal obligation, and therefore the data controller acts only to satisfy its legitimate interest linked to this purpose, ensuring all necessary guarantees.
Date: 12/01/2026
The legal representative of the data controller: Mr. Valerio MONTANARI