PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA pursuant to Article 13 of Regulation (EU) 2016/679, General Data Protection Regulation (“GDPR”).
Version – November 2025
Scope, Data Controller, and Definitions
Scope of this privacy policy
Dear Customer, this privacy policy is provided for the website “www.arenamilano.it” owned and operated by Arena Milano Management S.r.l., with registered office in Milan, Via Fabio Filzi n. 29 (nel seguito, “Arena Milano”, the “Controller” or the “Company”), in its capacity as Data Controller.
Pursuant to Article 13 of Regulation (EU) 2016/679 on the protection of personal data (“GDPR”), we inform you that your personal data will be processed using both electronic and paper-based tools. This privacy policy, drafted in accordance with the principle of transparency and containing all the elements required by the GDPR, is divided into specific sections, each addressing a particular topic, in order to make it easy to read and understand.
Please note that this website does not contain information, functions, or services directly intended for users under the age of 16. Minors must not provide information or personal data without the consent of those having parental responsibility over them. Arena Milano therefore invites all users under 16 not to communicate any personal data without prior authorization from a parent or guardian.
For the definition of the terms used in this privacy policy, please refer to Definitions.
Data Controller
Unless otherwise specified in this privacy policy, the Data Controller of your personal data is Arena Milano with registered office in Via Fabio Filzi, n. 29 – 20124 – Milan, Italy, e-mail: privacy@arenamilano.it.
Processing for Website Functionality and IT Security Purposes
Collection of General Data and Information
The Arena Milano website collects a range of general data and information whenever a data subject or an automated system accesses it. These data and information are stored in the server’s log files. The following may be recorded: (1) the types and versions of the browser used; (2) the operating system used by the accessing system; (3) the website from which the accessing system reaches our website (so-called referrer); (4) the sub-websites accessed through the system on our website; (5) the date and time of website access; (6) an IP (Internet Protocol) address; (7) the Internet service provider of the accessing system; and (8) other similar data and information used to prevent danger in case of attacks on our IT systems.
Arena Milano does not use these general data and information to draw conclusions about the data subject. Instead, this information is necessary to: (1) correctly deliver the content of our website; (2) optimize our website content and related advertising; (3) ensure the long-term functionality of our IT systems and website technology; and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyberattack. These anonymized data and information are therefore evaluated by Arena Milano statistically and with the aim of increasing data protection and security within our company, ultimately ensuring an optimal level of protection for the personal data we process. The anonymous data in the server log files are stored separately from all personal data provided by a data subject.
Data Storage When Visiting the Website
When you visit our website, the IP address assigned to the data subject by the Internet service provider (ISP), along with the date and time of access, is stored. The retention of these data occurs as it is the only means to prevent misuse of our services and, if necessary, to enable the detection and resolution of offenses that have been committed. For this purpose, the storage of these data is necessary to protect the Data Controller. In principle, these data will not be transferred to third parties unless there is a legal obligation to do so or the disclosure is necessary for criminal prosecution.
Marketing and profiling
Please note that, subject to your consent, Arena Milano may process your personal data to send you advertising materials and discounts relating to its own products and/or services or those of third parties (data processing for marketing purposes) via the following contact channels: e-mail, SMS, push notifications, or other automated and non-automated systems.
Furthermore, subject to your consent, Arena Milano may process the personal data you have provided for profiling purposes, that is, for the analysis of your purchasing preferences and behavior, in order to send you advertising materials from Arena Milano or from third parties that are of your specific interest (data processing for profiling purposes).
With regard to the processing of your data for marketing and profiling purposes, please note that providing your data is entirely optional, and such processing is based on your consent, which is voluntary and may be withdrawn at any time. Failure to provide such data will have no impact on your ability to use the services offered by Arena Milano through the website, including the ability to make purchases thereon, and will entail only the following consequences
lack of consent to the processing of data for marketing purposes will result in the inability to receive advertising materials relating to products and/or services of Arena Milano and/or third parties;
lack of consent to the processing of your personal data for profiling purposes will result in the inability of Arena Milano to develop your commercial profile, through the analysis of your preferences and habits (also with the aim of ensuring greater customer satisfaction and the continuous improvement of the services offered), as well as in the impossibility of sending you advertising materials relating to products and/or services of Arena Milano and/or third parties that may be of specific interest to you.
You may, in any case, withdraw your consent, if previously given for marketing and/or profiling purposes, at any time by writing to the following e-mail address privacy@arenamilano.it.
It is understood that any subsequent withdrawal of consent shall not affect the lawfulness of the processing carried out prior to such withdrawal.
Newsletter
If you wish to be informed about upcoming major events, access exclusive pre-sales, or take advantage of special promotions and discounts, you may subscribe to the newsletter service, even without necessarily registering on the website as described under Marketing.
Please note that through the newsletter we may also provide you with personalized information about our products and services, subject to your consent to profiling activities. In all such cases, we process your personal data solely on the basis of your consent, as defined in Article 130 of the Italian Privacy Code (Legislative Decree No. 196 of 30 June 2003).
From the moment you subscribe to our newsletter, we analyze and record whether you open it. In such cases, we process your personal data on the basis of the consent you provide pursuant to 130 of the Italian Privacy Code, in order to tailor the service to your needs and to improve the effectiveness of our marketing campaigns.
Processing of Data for Information Requests
If you have questions regarding the services offered or wish to initiate a collaboration with the Company, you may contact Arena Milano using the contact details provided in the designated section. In such cases, we will process your data pursuant to Article 6(1)(b) of the GDPR.
Communication of Personal Data
Provision of Data and Consequences of Failure to Provide
Except for data that is automatically collected to enable website navigation, some of the information requested on the website may be marked as “mandatory” – for example, indicated with an asterisk (*) – as it is necessary to access the services offered by the Company through the website. Failure to provide data marked as “mandatory” will make it impossible for the Data Controller to provide the requested service.
Failure to provide, or partial or inaccurate provision of, data marked as “optional” will not prevent access to the services offered on the website; however, it may affect the quality or the manner in which the service is delivered or the functionality to be used. In particular, the provision of data for the fulfillment of contractual obligations, compliance with legal obligations, and with reference to the legitimate interest of Arena Milano is mandatory.Your personal data will be processed exclusively by persons authorized by the Data Controller pursuant to Article 29 of the GDPR, in their capacity as data processors and/or system administrators.
Sharing of Data with Third Parties (Recipients)
Your personal data will not be published, communicated, or disclosed except to third parties whose activities are necessary and related to achieving the purposes described in this privacy policy. In accordance with applicable law, your personal data may be communicated to the competent financial offices or to other public authorities.
Finally, your personal data may be communicated to public entities or judicial authorities where required by law, upon their express request, or for the investigation and prosecution of crimes, the prevention and safeguarding against public security threats, or to allow the Data Controller to ascertain, exercise, or defend a right in judicial proceedings.
Retention of data
Please note that your personal data, processed for marketing and profiling purposes, will be retained for a defined period of time.
Specifically:
after 24 months, your personal data will no longer be processed for marketing purposes;
after 12 months, your personal data will no longer be processed for profiling purposes.
Except as indicated above, your data for the other purposes described above, as well as for compliance with legal obligations and/or the pursuit of the legitimate interest of protecting the rights of Arena Milano, will be processed and retained for the period necessary to achieve the purposes indicated above and, in any case, for the maximum period provided by applicable law regarding the limitation of rights and/or expiry of claims, and, more generally, for the exercise or defense of the rights of Arena Milano in disputes initiated by public authorities, public entities, or private parties.
Rights of the Data Subject
As a data subject, you have the right to request that the Data Controller allow you to exercise the following rights:
Right of Access
You may request confirmation as to whether or not personal data concerning you is being processed and, if so, obtain access to such data and to specific information about the processing, such as, for example, the purposes, the categories of data processed, and the existence of the other rights listed below. You may also request a copy of your data.
Right to Rectification
You have the right to request and obtain the rectification of inaccurate personal data concerning you and/or the completion of incomplete personal data.
Right to Erasure
You may obtain the erasure of your personal data without undue delay if:such data is no longer necessary for the purposes for which it was collected;
you have withdrawn your consent on which the processing was based (unless another legal basis for processing exists);
you object to the processing of your data (as indicated below) and there are no overriding legitimate grounds for the processing, or you object to the processing of your data for marketing or profiling purposes related to marketing;
your data has been unlawfully processed;
your data must be erased to comply with a legal obligation;
personal data of a child under 16 years of age has been collected in relation to the offer of information society services.
Please note that this right does not apply where the processing of data is necessary, among other things:
to comply with a legal obligation;
for the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing
You have the right to obtain restriction of processing where:
you contest the accuracy of the personal data concerning you, for the period necessary for the Controller to verify the accuracy of such data;
the processing is unlawful and you request restriction of use instead of erasure;
you need the data for the establishment, exercise, or defense of legal claims;
you have objected to the processing, as indicated below, pending the verification of whether the legitimate grounds of the Controller override yours.
Right to Data Portability
You have the right to receive the personal data concerning you, in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller in cases where the processing of your data is based on consent or relates to special categories of personal data processed on the basis of your consent, or where the processing is based on the performance of a contract and is carried out by automated means.You also have the right to have the personal data transmitted directly from one controller to another, where technically feasible. The possibility of obtaining the erasure of the data, as indicated above, remains unaffected.
Right to Object
You have the right to object at any time to processing based on the legitimate interest of the Controller, unless the Controller demonstrates compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
Claim
You also have the right to fill a complaint with the Supervisory Authority.
The above rights may be exercised by submitting a request to the Data Controller without any formal requirements. Such a request may be sent by mail or e-mail to the following addresses:
Via Fabio Filzi n. 29 - Milan (Italy);
e-mail: privacy@arenamilano.it
Contacts
All requests and inquiries regarding the processing of your personal data may be addressed to the Data Controller at the following addresses:
Arena Milano, Via Fabio Filzi n. 29 - Milan (Italy);
E-mail address: privacy@arenamilano.it;
Definitions
This privacy policy i based on the definitions set forth in article 4 of the European Data Protection Regulation (GDPR), the essential elements of which are listed below in order to facilitate the understanding of the text of the notice itself:
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Recipient: a natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether or not it is a third party. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of such data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
Personal Data: any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. Personal data may include, for example, name, contact details, user behavior, or banking information.
Data processor: a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Processing of personal data: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
This privacy notice shall take effect as of November 2025.