INFORMATION PURSUANT TO THE PROVISIONS OF ART. 13-14 OF REGULATION (EU) 2016/679 (GDPR) CONCERNING THE PROTECTION OF PERSONAL DATA PROCESSING.
The company hereby communicates that, for the establishment and management of the commercial relationship, it is the controller of your data, defined as “personal data”; pursuant to the legislation in question, we thus issue this information concerning the processing of your personal data.
1. PURPOSES OF THE PROCESSING, LEGAL BASIS AND TIME OF STORAGE
Data processing is construed as all operations concerned with: collecting, recording, organising, storing, consulting, processing, altering, selecting, retrieving, aligning, using, combining, blocking, disclosing, disseminating, erasing and destroying personal data or the combination of two or more of the foregoing operations. Processing is conducted based on the existence of legitimate interest in that there is a pertinent and appropriate relationship between the data subject and the controller (=> contractual and/or commercial relationship). The data collected – also via the company Website – is subject to processing carried out in compliance with principles of fairness, lawfulness, transparency and protection of your privacy and your rights, pursuant to the provisions of articles 5 and 6 of Regulation (EU) 2016/679 (GDPR).
Collection and processing of personal data are carried out to: manage commercial, administrative, accounting and legal relationships with our company, comply with pre-contractual and contractual obligations or requirements connected with the associated legislative obligations and/or in relation to requests received from law enforcement agencies, the courts of law and/or the dedicated supervisory bodies; exclusively internal aims of management of master data, databases, statistics, or aims connected to legal obligations and anyway in compliance with the conditions set down and for the purposes of meeting all the obligations set down in statutory legislation.
The personal data will be processed for the entire duration of the commercial relationship and thereafter up to the ordinary term of prescription, which is normally equal to 10 years in the case of activities that call for the management of accounting/tax aspects; in the absence of this activity, as long it is deemed that the requirements for useful and legitimate storage are present, also to be able to provide a response if you need to recover your data.
2. METHOD OF PROCESSING
Processing of data for the purposes illustrated takes place using automated methods on electronic or magnetic media, or non-automated methods on paper, by specifically appointed and trained personnel; in all cases data processing is carried out in compliance with the requirements of confidentiality and security enshrined in law, set down in the consequent regulations, and in internal codes of practice.
3. PLACE OF PROCESSING
The data is normally processed and filed at the registered office in CENATE SOTTO (BG), Via De Gasperi 6/8 and/or the plant in CORLO DI FORMIGINE (MO), Via Ferrari 27.
Data may also be processed and stored, on behalf of the Company, by professional persons and/or external firms engaged to conduct technical Activities, also in the role of Data Controllers.
4. NATURE OF DATA PROVISION
The provision of data is mandatory in order to comply fully with the services and our contractual obligations toward you and also for the correct management of our reciprocal commercial relationships; any request for erasure of data or refusal to allow processing of the data indicated in point 1 will make it impossible to proceed with our business relationship.
5. COMMUNICATION OF DATA AND SCOPE OF DISSEMINATION
The data can be disclosed to entities operating in the role of data controllers, including, in particular: entities, professional persons, companies, other organisations appointed by our company to perform processing connected to the fulfilment of our administrative, accounting and management obligations connected to the ordinary pursuit of our business on the organisational, management and economic levels; public authorities and administrations for the purposes connected to the fulfilment of legal obligations; banks, financial/lending institutions or other parties to which the transfer of data is required for execution of our company’s activities in relation to our fulfilment of the contractual obligations assumed in relation to you, including the aims of credit recovery. The data can be processed, on behalf of the controller, by parties designated as processors, both among internal personnel and the external entities defined above.
6. TRANSFER OF DATA TO OTHER COUNTRIES (NON EU COUNTRIES)
For reasons connected to management of our commercial relations, certain data may be processed and/or disclosed to other Group companies and/or other parties (customers, partners, etc.) with headquarters and/or processing operations in Third Party non-European countries. In this case the processing operations will be carried out in accordance with the pertinent requirements set down in GDPR Section V.
7. AUTOMATED DECISION-MAKING
The company does not carry out data processing connected with automated decision-making processes with or without profiling, or other types of special treatments that can result in a risk for the rights and freedoms of natural persons (GDPR art.35).
8. RIGHTS OF THE DATA SUBJECT
In relation to the personal data in question the data subject can exercise the rights provided for by Regulation (EU) 2016/679 (GDPR) in the following articles:
Article 15 – Right of access by the data subject; Article 16 – Right to rectification; Article 17 – Right to erasure (“right to be forgotten”); Article 18 – Right to restriction of processing; Article 19 – Notification obligation regarding rectification or erasure of personal data or restriction of processing; Article 20 – Right to data portability; Article 21 – Right to object; Article 22 – Automated individual decision-making, including profiling.
It is further pointed out that the data subject is entitled to submit complaints to the reference Data Protection Authority (in Italy, Garante per la Protezione dei dati personali, www.garanteprivacy.it) in the event that the requests for information made to the Data Controller fail to produce satisfactory responses.
9. DATA CONTROLLER AND DATA PROCESSOR
The data controller, which you can contact to assert the afore-mentioned rights, is SURFACES TECHNOLOGICAL ABRASIVES SPA, with registered office in Via De Gasperi 6/8 – 24069 CENATE SOTTO (BG), in the person of its pro tempore legal representative.
The data processor corresponds to the parties shown in point 5.