POLICY
pursuant to Article 13 of EU Regulation 2016/679
Rossella S.p.A (hereinafter, the “Data Controller"),in its capacity as Data Controller, pursuant to art. 13 of EU Regulation 2016/679 (hereinafter, the "Privacy Regulation"),as amended and supplemented, collects and subsequently processes personal data relating to its Customers and Suppliers (hereinafter, the "Data Subject").
1.Types of data processed
Personal data being processed includes:
Common personal data. This information includes, but is not limited to, personal details and contact details (e-mail address and telephone number).
Special data:
2. Processing purposes and methods.
The data subject's personal data are processed as part of the Controller's normal business activities, for the following purposes:
- Proper and complete performance of the obligations of the contractual relationship entered into (hereinafter, the "Contract");
- Administrative and accounting tasks strictly related to the Contract;
- Fulfilment of specific obligations laid down by law, regulations or Community
- legislation;
- Promotional activities concerning products and services similar to those already purchased
Personal data is processed under the authority of the Data Controller by persons specifically appointed, authorised and instructed to process them, pursuant to Art. 29 of the Privacy Regulation, by means of manual, computerised or telematic tools, with logic strictly related to the purposes, and, in any case in such a way as to guarantee the confidentiality and security of personal data. Personal data may also be processed on behalf of the Data Controller by specially appointed data processors, pursuant to art. 28 of the Privacy Regulation.
3. Legal basis of the processing and nature of the provision.
With reference to the purposes referred to in paragraph 2, points 1, 2 and 3 above, provision of personal data is mandatory and constitutes a necessary requirement for the execution of the Contract and the related fiscal and administrative fulfilments. Failure to provide data will make it impossible to receive the service subject of the Contract. The legal basis for the relevant processing is the proper execution and management of the Contract.
With reference to point 4) -activities towards acquired customers-, the legal basis is the legitimate interest of the Data Controller. The customer may stop receiving these e-mail communications at any time.
4. Persons or categories of persons to whom personal data may be communicated and scope of communication.
In relation to the processing purposes indicated above and within the limits strictly pertinent to the same, the data subject’s personal data will or may be communicated to the following categories of subjects:
- Tax authorities and other public authorities, where required by law or at their request;
- Credit institutions for payment instructions or other financial activities instrumental to the performance of the Contract;
- External parties carrying out control activities, such as auditing companies, board of auditors, supervisory body;
- Companies and organisations for the management of claims and/or the protection of interests and rights;
- Subjects designated as external data controllers pursuant to Art. 28 of the Privacy Regulations, for activities connected with, instrumental to or consequent upon the performance of the Contract
The updated list of subjects appointed as external data controllers can be provided by the Data Controller upon request by the Data Subject.
5. Extra-EU data transfer
Personal data will not be transferred to non-EU countries; if, for reasons connected with the execution of the contract, or the fulfilment of legal obligations, a transfer to non-EU countries and/or organisations is necessary, such transfer will take place in compliance with the applicable legislation. Transfers will be made by means of appropriate guarantees, such as adequacy decisions, standard contractual clauses approved by the European Commission or other legal instruments.
6. Period of data retention or criteria for determining the period
The data subject’s personal data are retained by the Data Controller for the time necessary to fulfil the purposes set out in paragraph 2 (points 1 to 3),as well as for the period required by civil, tax and regulatory provisions and, in any case, no more than 10 years from the termination of the contractual relationship.
As far as promotional purposes towards already acquired customers (paragraph 2, point 4),the data subject's data will be processed until the exercise of the right to object (which can be activated at the beginning, when sending the individual communications and/or through direct contact with the data controller) and in any case no later than 24 months after collection.
At the end of the retention period, the data will be anonymised or deleted, unless they need to be retained for other purposes as provided for by law.
7. Rights of the data subject.
The articles of the Privacy Regulation give the Data Subject the right to:
- Access their Personal Data, (or a copy of such Personal Data),as well as to further information on the processing in progress;
- Correct or update their personal data processed by the Controller, where such data are incomplete or out of date;
- Delete personal data from the Data Controller's databases in the cases provided for by current legislation;
- Limit processing of personal data by the Controller;
- Obtain a structured, commonly used and machine-readable format for the personal data concerning them;
- Oppose to the processing of personal data by the Controller (e.g. promotional activities)
You may exercise your rights by writing to the following e-mail address info@rossella.it
In any case, the data subject is always entitled to lodge a complaint with the competent Supervisory Authority (Garante per la Protezione dei Dati Personali).
8. Changes to the privacy policy
The Data Controller reserves the right to modify, update, add or remove parts of this information notice, and notify the data subjects.
Information updated in MAY 2021
ROSSELLA SPA
Via IV Novembre 490
21042 - CARONNO PERTUSELLA (VA) Tel: +39 029659191
E-mail: info@rossella.it