Information notice pursuant to Art. 13 of the Regulation (EU) 2016/679 (“GDPR”)
Information to be provided where personal data are collected from the data subject
According to Regulation (EU) 2016/679 (General Data Protection Regulation) we provide you with the due information concerning the processing of the collected personal data.
This notice is provided pursuant to art. 13 of the Regulation (EU) 2016/679 (General Data Protection Regulation) and according to the provisions of the Directive 2002/58/CE, as amended by Directive 2009/136/CE on Cookies, as well as according to the Provision of the Data Protection Authority dated 08.05.2014 on cookies.
DATA CONTROLLER, pursuant to art. 4 and 24 of the Regulation (EU) 2016/679, is Citterio Line Spa, having its head office in via Dante Alighieri, 21 – 20838 Renate (MB) – Italia, as represented by the pro-tempore legal representative.
|PURPOSES OF THE
|LAWFULNESS OF THE PROCESSING||DATA RETENTION PERIOD|
|a) Browsing on this website: the data collected during the navigation will be processed to obtain anonymous statistical information on the use of the site and to check its correct functioning.||Legitimate interest |
Valued on the basis of reasonable expectations given by the data subject who surfs the current website.
|Only for the related session, after which the data are deleted.|
|b) To contact you in order to satisfy your request for information||Legitimate interest | Data subject request: the reasonable expectation of the data subject to be contacted on the basis of the request made is presumed.||1 year|
|c) Subscription to the newsletter by filling-in the relevant form||User’s consent||Subscription duration |
Until users’ objection (opt-out) | unsubscription from the mailing list
|d) Organizational, administrative, financial and accounting activities and clients / users management||Performance of a contract and
compliance with a legal obligation
|10 years or different legal obligation|
PERSONAL DATA RECIPIENTS
Your personal data may be communicated to employees or collaborators in charge of processing activities under the authority of the Controller (art. 29 Reg. UE 2016/679) or to other recipients, appointed pursuant to art. 28 of the Regulation EU 2016/679, which shall process your data as processors and/or persons acting under the authority of the Controller and the Processor. Precisely, in order to comply with contractual obligations or related purposes, your data may be processed by companies contractually involved with the Controller and in particular to third parties belonging to the following categories: - service providers for the management of the information system and the telecommunications networks (including e-mail, newsletter and website management service) of the Controller; - professionals, firms or consultancy companies; - competent authorities for the fulfilment of obligations of law and/or regulations of public bodies, upon request.
The above mentioned subjects will act as data processors or may carry out their processing activities as independent data controllers. The list of data processors is constantly updated and available at Controller’s headquarters and contacts.
DATA TRANSFER TO A THIRD COUNTRY AND/OR INTERNATIONAL ORGANISATION
Personal data may be transferred to a third Country within or outside the European Union, subject to the limits and conditions set forth by art. 44 and subsequent articles of the Regulation EU 2016/679, namely:
- to third countries or international organisations on the basis of an adequacy decision of the Commission (art. 45 Regulation EU 2016/679);
- to third countries or international organisations that have provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies for data subjects are available (art. 46 Regulation EU 2016/679);
- to third countries or international organisations on the basis of derogations for specific situations (art. 49 Regulation EU 2016/679).
NATURE OF DATA PROVISION
Except for what specified for navigation data which are necessary in order to allow navigation of the website, users are free to provide their personal data and their refusal may result in the impossibility of obtaining the information or services requested and provided through this website.
DATA SUBJECT’S RIGHTS
You may exercise your rights pursuant to articles 15, 16, 17, 18, 19, 20, 21, 22 of the Regulation EU 2016/679 by writing to the Controller’s contacts: email@example.com.
You have the right, at any time, to request the Controller to access your personal data and receive the information concerning their processing. You have the right to rectify, erase your personal data or limit their processing.
Where appropriate, you have the right to object, at any time, to the processing of your data, including profiling, and you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of your personal data for such marketing, which includes profiling to the extent that it is related to such direct marketing.
You have the right to the portability of your personal data; in such case the Controller shall provide you with your personal data in a structured, commonly used and machine-readable format.
Without prejudice to any other administrative or judicial remedy, if you consider that the processing of your personal data infringes the Regulation (EU) 2016/679, you have the right to lodge a complaint with the Data Protection Authority.
Updating date: 13/12/18