Skip to main content

Privacy Policy

Last updated: 17 July 2026

This privacy notice explains how the personal data of people who visit the website or contact Community is processed. It applies solely to this website and not to external websites accessible via links.

Data controller and contact details

The data controller is Community Società Benefit S.r.l., with its registered office at Via Gabrio Serbelloni, 4, 20122 Milan (MI), Italy. For enquiries regarding data protection, please write to mattia.necchio@community.it or call +39 02 89404231.

Personal data processed

  • Browsing and security data: IP address, date and time of the request, URL visited, result of the request, browser and device information, technical logs and data necessary to prevent misuse and ensure the security of the website.
  • Data provided voluntarily: personal details, contact information and the content of messages sent to the email addresses published on the website, including job applications and requests for information.
  • Information regarding cookies and similar technologies: consent preferences, online identifiers and statistical or marketing data, only where required and following consent. The latest details are available in the Cookie Policy.

Purposes and legal bases

  • To provide the website, keep it secure, prevent fraud and resolve technical issues, based on the controller's legitimate interests under Article 6(1)(f) of the GDPR.
  • To respond to enquiries, assess applications and carry out pre-contractual activities requested by the data subject, in accordance with Article 6(1)(b) of the GDPR.
  • To comply with legal obligations and respond to competent authorities under Article 6(1)(c) of the GDPR.
  • We use cookies or technologies not required for measurement, personalisation or marketing purposes, where applicable, on the basis of consent pursuant to Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time via the cookie settings.

Recipients and processors

Data may be processed by authorised staff and by suppliers who provide hosting, maintenance, security, email, consent management and digital services. These parties act as data processors or independent data controllers, depending on the service provided. Data is not sold.

Transfers outside the European Economic Area

Some technology providers listed in the Cookie Policy may process data in countries outside the European Economic Area. In such cases, the transfer takes place on the basis of an adequacy decision or appropriate safeguards provided for in Articles 45 and 46 of the GDPR, including, where applicable, standard contractual clauses.

Retention periods

Data is retained only for as long as is necessary for the purposes for which it was collected. Technical logs are retained for the period necessary for the security, diagnosis and protection of the website; enquiries and applications are retained for as long as necessary to process them and comply with legal obligations; preferences and data associated with cookies are retained in accordance with the durations set out in the Cookie Policy. Data may be retained for a longer period where necessary to establish, exercise or defend a legal claim.

Data subject rights

In the cases provided for by the GDPR, the data subject may request access to, rectification of, erasure of, restriction of processing and data portability, or may object to the processing. Where processing is based on consent, this may be withdrawn at any time without affecting the lawfulness of the processing carried out prior to such withdrawal. Requests may be sent to the data controller’s contact details set out above.

Complaints to the supervisory authority

The data subject has the right to lodge a complaint with the Data Protection Authority or the competent supervisory authority in their Member State.

Automated decision-making, security and updates

The website does not use fully automated decision-making processes that produce legal effects or have similarly significant consequences. Technical and organisational measures appropriate to the risk are in place to protect data. This policy may be updated when the services or applicable obligations change; the date shown at the top indicates the most recent version.