CONTROLLER OF THE PROCESSING
Via Cafiero 22, 20158, Milano (MI)
e-mail address: firstname.lastname@example.org
DATA COLLECTION AND PROCESSING
Navigation data: The IT systems and software procedures which perform the functions of this website acquire, during their normal operation, some personal data the transmission of which is implicit in the use of Internet communication protocols. This is information that is not collected to be associated to identified data subjects, but that could, by their very nature, through processing and associations with data held by third parties, allow the identification of the users.
This category of data includes the IP addresses, or the domain names of computers used by users who connect to the website, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc.), and other parameters related to the user's operating system and IT environment.
These data are used for the sole purpose of obtaining anonymous statistic information on the use of the website and of checking its correct operation, and they are erased immediately after the processing.
These data could be used to ascertain responsibilities in case of hypothetical computer crimes against the website. As a rule, these data are erased immediately after the processing.
Link to third party websites: Using specific links, it is possible to connect to other third-party websites. The controller of the website declines any responsibility concerning the management of personal data by third-party websites and in relation to the management of authentication credentials supplied by third party subjects.
PERSONAL DATA PROCESSED
|PURPOSE OF THE PROCESSING||LEGAL BASIS OF THE PROCESSING||DATA RETENTION PERIOD|
|Technical administration and operation management of the internet website||Performance of the contract to which the data subject is party||For the entire duration of the navigation|
|Fulfilment of obligations provided for by the regulations and by the applicable National and supranational laws (tax obligations, administrative obligations, etc.)||The need to fulfil obligations of the law to which the processor is subject||Duration provided for by the law (10 years for administrative-accounting fulfilments)|
|SIf necessary, to ascertain, exercise or defend the rights of the Processor in a judicial or extra-judicial venue||Legitimate interest (judicial and/or extra-judicial safeguard)||For the entire duration of the judicial and/or extra-judicial proceedings and/or enforcement actions, until the end of the time limits allowed for the exercise of any impugnment actions.|
|Upon expiry of the above stated retention periods, the Data will be destroyed, erased, or made anonymous consistently with the technical erasure and backup procedures and with the accountability requirements of the processor.|
DATA PROVISION COMPULSORINESS
The navigation data are necessary to start IT and computer protocols, therefore the non-provision of the data would not allow this internet website to operate.
SUBJECTS AUTHORIZED FOR THE PROCESSING
The data may be processed by the employees of the company functions assigned to the pursuance of the above indicated purposes, who have been explicitly authorized for the processing and who have received adequate operational instructions in accordance with the articles 29 of the GDPR and 2 quaterdecies of the Legislative Decree 196/2003, as amended and adjusted by the Legislative Decree 101/2018.
RECIPIENTS OF THE DATA
The data may be communicated to subjects operating in their capacity as controllers of the processing, among which, by way of example, supervisory and control authorities and bodies, and in general to public or private subjects entitled to request the data.
The data may be processed, on behalf of the controller, by trusted subjects appointed as processors (in compliance with art. 28 of the GDPR), to whom adequate operational instructions are given. These subjects, by way of example, can be companies providing the service of management and/or maintenance of the Company's internet website. The complete and constantly updated list of processors will be made available to the data subject, on request, by contacting the e-mail address email@example.com.
TRANSFER OF PERSONAL DATA TO COUNTRIES THAT ARE NOT MEMBERS OF THE EUROPEAN UNION
The personal data collected through the website will not be transferred to third party Countries and / or to international Organizations outside the European Union.
The Data may be processed by data Processors who have their offices also in Countries that are not members of the European Union, whose data protection level has been considered adequate by the European Commission in compliance with art. 45 of the GDPR.
The transfer of your personal data may be carried out also following the signature of Standard Contractual Clauses as provided for by art. 46, par. 2 lett. c) of the GDPR.
RIGHTS OF THE DATA SUBJECT – COMPLAINT WITH A SUPERVISORY AUTHORITY
By contacting the Company via e-mail at the address firstname.lastname@example.org, the data subjects may request the access to the data that concern them, their rectification, integration or erasure as well as the restriction of processing in the cases provided for by art. 18 of the GDPR as well as the opposition to the processing in the cases of legitimate interest of the controller.
Any rectifications or erasures or limitations of the processing made on request of the data subject – unless this proves impossible or involves disproportionate effort – will be communicated by the Company to each recipient to whom the personal data have been disclosed. The Company shall inform the data subject about those recipients if the data subject requests it.
The exercising of rights is not subject to any lien and it is free of charge.
Moreover, in the cases in which the processing is based on consent or on a contract, and carried out by computerized means, the data subject shall have the right to receive his/her personal data in a structured, commonly used and machine-readable format and the right to transmit these, if this is technically feasible, to another controller without hindrance.
The data subjects have the right to lodge a complaint with the competent supervisory authority, by following the procedures and indications published on the official website of the Authority on www.garanteprivacy.it.