Privacy Policy
INFORMATION FOR THE PROCESSING OF PERSONAL DATA
SUBJECT-MATTER: Information pursuant to art. 13 of EU Regulation 2016/679 ("GDPR"), relating to the protection of the processing of personal data collected from the data subject.
a. DATA CONTROLLER
The data controller is Ilaria Ombriti, at Via Bernardino Poccetti, 8 50124 Florence (FI) email:
b. DATA PROTECTION OFFICER
Due to being exempt from the guidelines specified by art. 37 of EU reg. 2016/679, and in consideration of the indications in the WP243 guidelines, a Data Protection Officer has not been designated.
c. LAWFULNESS, PURPOSE AND OBLIGATIONS OF THE PROCESSING OF PERSONAL DATA
The processing of your personal data of which the company is already in possession or that which will be requested from you or communicated to us by you, or a third party will be carried out in execution of:
It is used for legal obligations: invoicing, records, registrations and other administrative/accounting purposes; |
|
It is used for contractual obligations: supply of goods and/or services; |
|
X |
It is used for fulfilling of a request made by the data subject; |
It is used for marketing operations: sending advertising material or telephone contacts (only with explicit consent). |
The communication of essential data required for the satisfaction of requests received by filling in the contact form. Failure to communicate personal data will result in the impossibility of fulfilling contractual obligations. Failure to communicate personal data will result in the impossibility of furnishing requests made.
d. LAWFULNESS OF DATA PROCESSING
The treatment of data is considered lawful in that:
The data subject has given consent for one or more purposes; |
|
X |
The processing is necessary for the execution of a contract of which the data subject is a party or for pre-contractual measures requested by the same; |
The processing is necessary to fulfill a legal obligation to which the data controller is subject; |
|
The processing is necessary for the protection of the vital interests of the data subject or of another individual; |
|
The processing is necessary for the performance of a task of public interest or connected to the exercise of public authority; |
|
X |
The processing is necessary for the pursuit of a legitimate interest (satisfaction of a request made by the data subject). |
e. RECIPIENTS OF PERSONAL DATA
- Personal data may be processed, as well as by authorized personnel within the company, also by the following subjects:
- tax and legal consultants;
- consultants for the maintenance/administration of computer hardware/software systems;
- subjects who can access your data by virtue of regulatory provisions;
- control bodies, also following inspections or verifications;
- transport and logistics companies (in execution of the request made);
- other suppliers or sub-suppliers (in execution of the request made or by contractual or regulatory obligation).
The names of the subjects listed above are available at any time upon request by the data subject
f. Transfer of personal data to third party countries or international organizations
The transfer of personal data outside the European Union or to international organizations is not permitted.
g. Retention period of personal data
The duration of data retention, where there are no regulatory obligations or where a request for cancellation by the data subject has not been received, is established on the basis of the existence of the purposes referred to in article “c”, the need for regular performance of the activity employment or in accordance with specific regulatory obligations.
Data Subject’s Rights
The data subject has the right to request access, rectification, and portability of his or her personal data at any time, as well as to object to the processing, withdraw consent or file a complaint with the Supervisory Authority for the processing of personal data.
h. Automated decision-making processes
Data is not processed by means of automated processes.