Information notice pursuant to Art. 13 of the Regulation (EU) 2016/679 (“GDPR”) Information when personal data are collected from the data subject
According to Regulation (EU) 2016/679 (General Data Protection Regulation) we provide you with the due information concerning the processing of the collected personal data.
Personal data that can be treated: “personal data” means any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifying element such as a name, an identification number, location data, an online identity or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (C26, C27, C30 Reg. UE 679/2016).
specific information may be find on the Site page in relation to particular services or processing of the data provided.
1. SUBJECTS OF THE PROCESSING
DATA CONTROLLER, pursuant to art. 4 and 24 of the Regulation (EU) 2016/679, is FP4F SRL – Via Erba, 14, Cusano Milanino (MI) Italy, P.IVA IT07053660960, [email protected], as represented by the pro tempore legal representative.
2. PURPOSES AND LAWFULNESS OF THE PROCESSING
Your personal data shall be processed in accordance to the requirements for the lawfulness of processing set forth by Art. 6 of the Regulation (EU) 2016/679 for the following purposes:
A) Data processing for (art.6. b):
- the visit to the website;
- Contact us Area: the personal data provided by the user during registration will be processed for purposes related to the request for forwarded information;
- fulfillment of contractual obligations, of law and administrative-accounting purposes. The processing performed for administrative-accounting purposes are those related to the performance of organizational, administrative, financial and accounting activities for the purposes of the application of the provisions regarding the protection of personal data, regardless of the nature of the data processed. In particular, these objectives pursue internal organizational activities, those functional for the fulfillment of contractual and pre-contractual obligations, information activities.
B) Data processing for (art 6 lett. b)
- prior consent and until opposition, the data subjects data will be treated for direct marketing, for promotional, commercial, communication and marketing purpose also through the subscription of newsletter/mailing list of the website airness.it. The data will be entered in the CRM of the company to compare and possibly improve the results of communications, to use systems for sending newsletters and promotional communications with reports. Thanks to the reports, the Data Controller will be able to know, for example: the number of readers, openings, unique "clickers" and clicks; the devices and operating systems used to read the communication; the detail on the activity of individual users; the details of the emails sent, e-mail delivered or not, of those forwarded. All these data are used for the purpose of comparing, and possibly improving, the results of communications.
3. DATA RETENTION PERIOD OR RELEVANT CRITERIA
The processing shall be carried out in automated and/or manual way, with methods and tools aimed at ensuring the best security and confidentiality, by persons specifically appointed to do so. According to the provisions set forth in art. 5 par. 1 lett. e) of the Regulation EU 2016/679, collected personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Data retention period depends on the purposes:
- to visit the current internet website (temporary);
- request for contact, information and appointment reservation (1 year maximum);
- staff selection (24 months maximum);
- newsletter or promotional communication by e-mail (up to the conferment of the opt-out);
- discharge of obligations laid down by agreements, by laws and administrative and accounting activities (10 years maximum unless otherwise specified by law);
The Data Subject can receive information regarding the criteria of the retention period by contacting [email protected]
4. NATURE OF UNDERWRITING AND REFUSAL
With exception of what above specified concerning navigation data, the User is free to provide personal data. The provision of personal data for purpose A) is necessary to improve the operactions and be able to use the services offered by data Controller. The non submittal of personal data may the result the impossibility to obtain the required services. The provision of personal data for purpose B) is optional. The non submittal of personal data may make it impossible to send promotional, commercial, informative communication and/or offerts related to activities, products or services offered via newsletter/mailing list and/or e-mail.
5. DATA SUBJECT’S RIGHTS
You may exercise your rights pursuant to articles 15, 16, 17, 18, 19, 20, 21, 22 of the Regulation EU 2016/679, by contacting the data Controller, or the data Processor, or the Data Protection Officer service by writing to [email protected]
You have the right to request the data Controller to access, rectify, cancel your personal data or limit their processing at any time. Furthermore, you have the right to object to the processing of your data (including automated processing, e.g. profiling) and to the portability of your data at any time. If you believe that the processing of your data violates the provisions of Regulation EU 2016/679, pursuant to art. 15 letter f) of the aforementioned Regulation EU 2016/679, you have the right to lodge a complaint with the Data Protection Authority and, with reference to art. 6 paragraph 1, letter a) and art. 9 paragraph 2, letter a), you have the right to withdraw the consent given at any time, except for prejudice to any other administrative and judicial appeal.
In case of a request of data portability, the Controller shall provide you with your personal data in a structured, commonly used and machine-readable format, subject to the provisions set forth in paragraphs 3 and 4 of art. 20 of Regulation EU 2016/679.