PRIVACY POLICY PURSUANT TO ART. 13 OF EU REGULATION 2016/679
and Art. 13 of Legislative Decree no. 196/03 amended by Legislative Decree no. 101/2018
EMERITALIA SRL, in its capacity as data controller pursuant to Article 13 of EU Regulation 679/2016 - General Data Protection Regulation ("GDPR"), in compliance with the obligations dictated by the legislator to protect privacy, hereby wishes to inform you in advance, both of the use of your personal data and of your rights, communicating the following:
The "Data Controller"
EMERITALIA SRL, pursuant to Article 24 of EU Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: "EU Regulation"), is the Data Controller of personal data and in implementation of Article 13 of the EU Regulation, informs you that the personal data acquired, also with reference to existing legal relationships such as pre-contractual relationships (preventive), contractual relationships stipulated, are subject to processing in compliance with the aforementioned legislation.
In relation to the aforementioned processing, the Data Controller provides, among other things, the following information.
"Personal data" (pursuant to Article 4 number 1 of EU Regulation 2016/679) means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more features of the its physical, physiological, genetic, mental, economic, cultural or social identity;
"Processing" (pursuant to Article 4 number 2 of EU Regulation 2016/679) means any operation or set of operations, carried out with or without the aid of automated processes and applied to personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction;
This processing must be based on the principles of correctness, lawfulness, transparency, protecting your privacy and your rights.
Personal data collected
The personal data collected concerns:
- Browsing data
- Generic identification data (name or company name, i.e. name and surname of natural persons, residential address and/or correspondence, registered office, telephone, fax, e-mail, tax data);
Identity and contact details of the internal delegate Privacy for the Data Controller
Name and Surname or Company Name: Dr. Emiletti Riccardo
Domicile or registered office address: Via Monceniso 4 – 20090 Monza (MB)
Telephone contact details: 0392027658/9
Email contact details: privacy@emeritalia.it
Purpose of the processing
The purposes of the processing of personal data are as follows:
- Fulfilment of obligations provided for by laws, regulations, EU legislation, or by provisions issued by Authorities and Supervisory and Control Bodies in relation to or in any case connected to the existing and/or future legal relationship.
- Management of management and organizational processes;
- Provision of assistance and support services;
- Management of new contacts through the dedicated area of the www.emeritalia.it website
- Navigation data: the computer systems and software procedures used to operate this site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, successful, error, etc.) and other parameters related to the user's operating system and computer environment.
The following table specifies the legal basis, categories of data, categories of personal data, and the related retention period for each of the purposes identified above:
TABLE 1
Purposes of the processing for which the personal data are intended
Legal basis of the
Treatment
Categories of personal data subject to processing
Data retention period
personal
Categorie di destinatari
(*)
Purpose 1
Legal obligation
- Identification data
- Master data
Until the end of the contractual relationship and for a further period of 10 years thereafter
*
Purpose 2
Legal obligation
- Identification data
- Master data
Until the end of the contractual relationship and for a further period of 10 years thereafter
*
Purpose 3
Contract
- Identification data
- Master data
Until the end of the contractual relationship and for a further period of 10 years thereafter
*
Purpose 4
Contract
- Identification data
- Master data
Until the end of the contractual relationship and for a further period of 10 years thereafter
*
Purpose 5
Legitimate interest
- Browsing identification data
No
*
*Category di destinatari
In relation to the purposes indicated, the data may be communicated to the following subjects and/or categories of subjects indicated below, or may be communicated to companies and/or persons who provide services, including external ones, on behalf of the Data Controller. Among these, for the sake of clarity, the different types of languages are indicated, by way of example, but not limited to:
- IT service companies and software providers;
- Control and supervisory bodies.
The list of external Recipients/Processors with additional data useful for identification is available from the Data Controller.
Transfer of data to non-EU third countries
It does not transfer personal data outside the EU.
Retention period
See Table 1 in column 4 (storage period)
Rights of the data subject
The data subject, in relation to the personal data covered by this policy, has the right to exercise the rights provided for by the EU Regulation set out below:
- right of access of the data subject [art. 15 of the EU Regulation] (the possibility of being informed about the processing carried out on their Personal Data and possibly receiving a copy);
- right to rectification of their Personal Data [art. 16 of the EU Regulation] (the data subject has the right to rectification of inaccurate personal data concerning him/her);
- the right to erasure of their Personal Data without undue delay ("right to be forgotten") [art. 17 of the EU Regulation] (the data subject has, and will have, the right to erasure of their data); right to restriction of processing of their Personal Data in the cases provided for by art. 18 of the EU Regulation, including in the case of unlawful processing or contestation of the accuracy of the Personal Data by the data subject [art. 18 of the EU Regulation];
- right to data portability [art. 20 of the EU Regulation], the data subject may request his/her Personal Data in a structured format in order to transmit them to another controller, in the cases provided for by the same article;
- right to object to the processing of their Personal Data [art. 21 of the EU Regulation] (the data subject has, and will have, the right to object to the processing of their personal data);
- right not to be subjected to automated decision-making processes, [art. 22 of the EU Regulation] (the data subject has, as he or she will have, the right not to be subject to a decision based solely on automated processing).
Further information about the rights of the data subject can be obtained by asking the Data Controller for a full extract of the articles mentioned above.
The aforementioned rights can be exercised in accordance with the provisions of the Regulation by writing to the data controller and/or sending an email to: privacy@emeritalia.it in compliance with the provisions of Article 19 of the EU Regulation. Informing the recipients to whom the personal data have been disclosed, of any rectification, erasure or restriction of processing requested, where this is possible.
If the legal basis for the purpose of processing pursued is consent, the data subject has the right to revoke it at any time by sending an email to: privacy@emeritalia.it
Pursuant to art. 7 of the EU Regulation, the withdrawal of consent does not affect the lawfulness of the processing based on the consent given before the withdrawal.
Right to lodge a complaint
If the data subject believes that his or her rights have been compromised, he or she has the right to lodge a complaint with the Data Protection Authority, according to the procedures indicated by the same Authority at the following internet address www.garanteprivacy.it
Mandatory provision of personal data
We inform you that if the purposes of processing have as their legal basis a legal or contractual (or even pre-contractual) obligation, the data subject must necessarily provide the requested data.
Otherwise, it will be impossible for the Data Controller to proceed with the pursuit of the specific processing purposes.
The Company does not use any automated decision-making.
Processing methods
Personal data will be processed in paper, computerized and telematic form and entered in the relevant databases (customers, users, etc.) which may be accessed, and therefore become aware, by the employees expressly designated by the Data Controller as Data Processors and Authorized to process personal data, who may carry out consultation, use, processing, comparison and any other appropriate operation, including automated ones, in compliance with the provisions of law necessary to ensure, among other things, the confidentiality and security of the data as well as the accuracy, updating and relevance of the data with respect to the declared purposes.
Changes and updates
EMERITALIA SRL, in its capacity as Data Controller, may also make changes and/or additions to this information also as a consequence of any subsequent amendments and/or additions to the regulations. Changes will be notified and the interested party will be able to view the text of the constantly updated information on the website at the page: https://www.emeritalia.it/ in the section dedicated to the Privacy policy.
