In compliance with the provisions of EU Regulation 2016/679 (European General Data Protection Regulation) we provide the necessary information regarding the processing of personal data carried out through this website. The information must not be considered valid for other websites that may be consulted via links on the website of the controller's domain, which is not to be considered in any way responsible for third party websites. This is an information pursuant to art. 13 of the 2016/679 EU Regulation and is also inspired by the provisions of Directive 2002/58 / EC, as updated by Directive 2009/136 / EC, on Cookies as well as to the provisions of the Italian Data Protection Authority dated 08.05.2014 regarding cookies.
DATA CONTROLLER is FONDITAL S.p.A., with registered office in Vobarno (BS) - Via Cerreto, 40, in the person of the legal representative pro-tempore, (hereinafter, the "Controller" or “Data Controller”). You may at any time contact the Data Controller at the following addresses: paper mail: FONDITAL S.p.A. Via Cerreto, 40, Vobarno (BS); email: email@example.com; contact area http://www.fondital.com/it/it/contacts.
The Controller may appoint other subjects, internal to the company, duly authorized and instructed to perform processing operations under the authority of the Data Controller, pursuant to Article 29 of EU Reg. 2016/679. Processing operations may also be carried out on behalf of the Data Controller by external parties duly appointed as Data Processors in compliance to art. 28 of the EU Reg. 2016/679. A complete and updated list of the Data Processors is available at the registered office of the Owner, to the contacts indicated above.
Personal data: any information on a identified or identifiable natural person (“data subject”). A person is condsidered identifiable if can be identified, directly or unidirectly, through a specific reference like a name, identification number, geographical position, online identification or any specific characteristic element of his physical, physiological, genetic, psychic, economical, cultural or social identity (as an example, first name, last name, birth date, address, email address, telephone number etc).
Navigation data: IT systems and software procedures dedicated to operate this website acquire, during their regular functioning, some personal data which transmission is implicit in the use of communication protocols on the interrnet. Those information are not acquired to be associated to identified data subjects, but, by their very nature, said information may allow to identify the users through processing and association to data posessed by third parties. In this data category there are IP adresses and domain names of the computers used by the users to connect to the website, Uniform Resource Identifier adresses of the requested resources, time of the request, the methods used to submit the request to the server, dimensions of the file obtained as a reply, code numbers indicating the state of the server’s reply (fruition, error etc) and other parameters related to the Operating system and the computer environment of the user. The data are used solely to extract anonymous statistical information on the use of the website to monitor its normal functioning and get cancelled right after the processing.
The personal data of the user can be treated with additional methods and aims to related to maintenance of the website
Data deliberately provided by the user
The optional and deliberate submission of personal data (ex. Through emails to the email addresses listed on this website or by filling a registration form or a form to request catalogues, price lists and data sheets existing on this website) entails the acquisition and processing by the Data Controller of the deliberately provided users data including first and last name, address, telephone number, email address and any potential further data provided to receive access credentials to specific areas of the website (ex. Occupation) such as Sign in area, downoload area, events area. Moreover, specific summary information will be provided on this website concerning the user’s data processing (ex. “work with us” applications).
3.AIM AND LEGAL BASIS OF THE PROCESSING
The personal data deliberately provided, will be processed according to the conditions of lawfullness established ex art. 6 paragraph 1 letter F, UE Regulation 2016/679 (legitimate interest of the Controller, considering the legitimate expectations of the Data Subject at the time and in the context of the collection of personal data, as the Data Subjects can expect that a data processing can take place) for the following aim:
The processing of data will be in compliance with the conditions of law pursuant to art. 6, paragraph 1, letter a) EU Reg. 2016/679 (consent of the interested party) for the following purposes:
The processing of data will be in compliance with the conditions of law pursuant to art. 6 lett. b) and c) EU Reg. 2016/679 (contractual and legal obligations) for the following purposes:
4.DATA ADDRESSEES OR CATEGORIES OF DATA ADDRESSEES
The personal data provided may be disclosed to: - a company belonging to the Fondital Group; - service providers for the management of the information system used by the controller and the telecommunications networks (including e-mail, the web platform, the website, the sending of newsletters); agencies, studios or companies in the context of assistance and consultancy partnerships for the purposes described above; service providers in relation to the user’s orders via e-commerce area; competent authorities for compliance with legal obligations and / or provisions of public bodies, upon request. The subjects belonging to the aforesaid categories perform the function of Data Processors, or operate in complete autonomy as separate Data Controllers. The list of Data Processors is constantly updated and available at the Controller's office and through the contacts listed above.
5.DATA TRANSFER TO A THIRD COUNTRY AND / OR AN INTERNATIONAL ORGANIZATION AND GUARANTEES
Personal data provided will not be disclosed and may be transferred to countries outside the EU, in order to comply with the aforementioned purposes, within the limits and under the conditions set forth in art. 44 and following of Regulation (EU) 2016/679. Specifically, the data will only be transferred: - to third countries or international organizations for which the Commission has intervened with an adequacy assessment (Article 45 of the EU Reg. 2016/679); - towards third countries or international organizations that have provided adequate guarantees and with which the person concerned has rights to action and effective remedies (Article 46 of the EU Reg. 2016/679), including through contractual clauses and other provisions in Article 46 paragraph 3; - towards third countries international organizations on the basis of exceptions in specific situations (Article 49 of the EU Reg. 2016/679). The concerned party may obtain information about the guarantees provided by the Data Controller for the transfer of data by contacting the Data Controller to the contacts above
6.DATA STORAGE PERIOD OR CRITERIA TO DETERMINE THE PERIOD
The treatment will be carried out in an automated and manual way, with methods and instruments aimed at guaranteeing maximum security and confidentiality, by persons specifically appointed.
In compliance with the provisions of art. 5 paragraph 1 letter e) of Reg. UE 2016/679 the personal data collected will be stored in a form that allows identification of data subjects for a period of time not exceeding the achievement of the purposes for which the personal data are processed.
The retention times of the personal data provided depend on the purpose of the processing performed:
a) purposes related to the technical navigation data for the correct functioning of the website: storage only for the related session, after which the data are deleted;
b) purposes of matching the request for information / documents / contacts (12 months);
c) for administrative / accounting / financial purposes related to the supply of a good / service (10 years);
d) data collection for personnel selection (24 months);
e) direct marketing or promotional communications (24 months);
f) profiling (12 months)
7.NATURE OF THE PROVISION AND REFUSAL
The provision of your personal data for the purposes referred to in point 3 letter h) of this statement is necessary in order to fulfill contractual and legal obligations related to the supply of Fondital goods / services through the site e-commerce area web. A refusal, will make it impossible to provide the good / service requested through the e-commerce area. The provision of your personal data for the purposes referred to in paragraph 3 letters a) b) c) d) of this information is necessary in order to: browse the website, comply with your requests, evaluate your application, send business communication of your interest (if already our customer). Any refusal to provide data implies, respectively, the inability to browse the site, be contacted and / or receive information and / or documents required, receive direct marketing communications of interest. The provision of personal data and consent to processing for the purposes referred to in points 3 lett. e) f) and g) of this information (direct marketing by the Data Controller / communication to the other companies of the Fondital Group for marketing / user profiling purposes) is optional. Any refusal of consent will result, respectively, that your data will not be processed for direct marketing purposes and / or will not be disclosed to the Group companies for marketing purposes and / or will not be processed for profiling purposes.
8.RIGHTS OF THE DATA SUBJECT
You can assert your rights as expressed in articles 15, 16, 17, 18, 19, 20, 21, 22 of Regulation (EU) 2016/679, towards the data controller, to the following contacts: FONDITAL S.p.A. Via Cerreto 40, Vobarno (BS); email: firstname.lastname@example.org; contact area http://www.fondital.com/it/it/contacts. You have the right, at any time, to obtain from the Controller access to your personal data and request information on the purposes, categories of personal data processed, addressees to whom personal data will be communicated, with particular reference to recipients in third countries, the retention period of personal data or, where this is not possible, the criteria for its definition; the existence of an automated decision-making process, including profiling. You have the right to correct, delete your personal data or limit their processing. Where the processing is based on Article 6 (1) (a) or Article 9 (2) (a), you have the right to withdraw your consent at any time without prejudice to the lawfulness of the treatment based on consent lent before the revocation. You have the right to be informed of the existence of adequate safeguards related to the transfer of your data to a third country or to an international organization pursuant to Article 46 of Regulation (EU) 2016/679. You have the right to the portability of your personal data; in this case the Data Controller will provide you your personal data, in a structured format, commonly used and readable by automatic device, and the right to transmit this data to another data controller. Furthermore, you have the right to object at any time, for reasons connected with your particular situation, to the processing of your personal data in accordance with Article 6 (1) (e) of), including profiling on the basis of these provisions . If your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for these purposes, including profiling in so far as it is connected to such direct marketing. You have the right not to be subjected to a decision based solely on automated processing, including profiling, which produces legal effects or which has a similar impact on you personally. Without prejudice to any other administrative or judicial appeal, in the event that you believe that the processing of your personal data violates Regulation (EU) 2016/679, you have the right to lodge a complaint with a supervisory authority.
The Controller has the right to change, update, add or remove portions of this privacy statement at its discretion and at any time. The data subject is required to periodically check for any changes. In order to facilitate this verification, the information will contain the indication of the update date of the information. The use of the site, after the publication of the changes, will constitute acceptance of the same.
Date of update: 25th of May 2018
DATA CONTROLLER - FONDITAL S.P.A.