Penta di Fisciano (SA) - Italy +39 089 963379 administration@corisa.it

Privacy Policy

Legal Information

This notice explains how CO.RI.S.A. processes the personal data of people who visit www.corisa.it, under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

The Italian version of this notice is the authoritative one.

Data controller

CO.RI.S.A. – Consorzio di Ricerca Sistemi ad Agenti
Piazza Vittorio Emanuele II, 10 – 84084 Penta di Fisciano (SA), Italy
VAT and tax number: 02911500789
Email: administration@corisa.it
Certified email (PEC): corisa@gigapec.it
Phone: +39 089 963379

Data Protection Officer

The role of Data Protection Officer is held by the Director of the Consortium, who can be reached at the controller's addresses: administration@corisa.it, or by certified email at corisa@gigapec.it.

What data we process

Browsing data

This is a static site: it requires no registration and contains no data collection forms. Our hosting provider records the technical data needed to deliver the pages and keep the service secure, including your IP address, the date and time of the request, the address of the page requested and your browser type.

We use no analytics, profiling or user-tracking tools.

Data you send us by email

If you write to administration@corisa.it — including to apply to a public call — we process the information in your message and any attachments: your name, your email address, your CV and anything else you choose to send us. Sending it is entirely voluntary.

Cookies and local storage

This site does not use cookies.

To work correctly it stores two technical items in your browser's local storage:

  • userLangChoice (localStorage) — records the language you chose, so the site does not send you back to the other version on every visit;
  • langChecked (sessionStorage) — stops the language check repeating during the same browsing session.

Neither contains identifying data, and neither is sent to a server: they stay in your browser and you can delete them at any time from its settings. They are strictly necessary to provide the service you asked for and do not require consent.

The site loads no third-party resources: fonts, stylesheets and scripts are served directly by corisa.it. Simply visiting the site therefore does not disclose your IP address to any third party.

Purposes and legal bases

  • Replying to emails you send us — our legitimate interest in responding to enquiries addressed to us (Art. 6(1)(f)); where the enquiry concerns a contractual or pre-contractual relationship, the performance of pre-contractual measures (Art. 6(1)(b)).
  • Handling applications to public calls — taking steps at your request prior to entering a contract (Art. 6(1)(b)) and complying with the obligations attached to selection procedures (Art. 6(1)(c)).
  • Serving the site and keeping it secure — our legitimate interest in keeping the service available and protected from abuse (Art. 6(1)(f)).
  • Remembering your language choice — necessary to provide the service you expressly requested.

Who receives the data

We use two providers, both appointed as data processors under Article 28 of the GDPR:

  • Cloudflare, Inc. — website hosting. Processes the browsing data described above.
  • Aruba S.p.A. (Italy) — email, including certified email (PEC). Processes the messages you send us.

We do not sell or otherwise disclose personal data to third parties, and we do not use it for marketing.

Transfers outside the European Economic Area

Email is handled by Aruba S.p.A., an Italian company with infrastructure in the European Union: the messages you send us do not involve a transfer outside the European Economic Area.

Our hosting provider, by contrast, operates a globally distributed network, so processing browsing data may involve a transfer outside the EEA. Any such transfer is covered by the safeguards in Chapter V of the GDPR, in particular the Standard Contractual Clauses adopted by the European Commission.

How long we keep data

We keep personal data only for as long as the purpose it was collected for requires:

  • correspondence, for as long as it takes to deal with the matter and then for any period required by law;
  • public-call documentation, for the duration of the procedure and for the periods set by the applicable rules;
  • technical logs, for the limited period set by our hosting provider's policies.

Your rights

In relation to your data you may exercise the rights in Articles 15-22 of the GDPR:

  • access your data and obtain a copy of it;
  • have it corrected if it is inaccurate or incomplete;
  • have it erased;
  • restrict how it is processed;
  • receive it in a structured, commonly used format (portability);
  • object to processing based on our legitimate interest.

To exercise any of these, write to administration@corisa.it. We will reply within the time limits set by the Regulation.

If you believe the processing of your data breaches the Regulation, you have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the Member State where you live.

Automated decision-making

We carry out no automated decision-making and no profiling.

Changes to this notice

We may update this notice to reflect changes to the site or to applicable law. The version published on this page is always the one in force; the date it was last updated is shown below.

Last updated: 15 July 2026