DISCLOSURE ON PERSONAL DATA PROCESSING
(last updated on May 25th, 2018)
This disclosure is provided pursuant to Art. 13, paragraph 1, and Art. 14, paragraph 1, of the EU General Data Protection Regulation (GDPR) n. 679/2016 and of the Art. 13 of the Legislative Decree n. 196/2003 – Italian Personal Data Protection Code, to those who interact exclusively with this website and any third-level domains linked to it.
This disclosure is also provided for those who already have regular credentials and access through the website the IMIT Control System SRL’s secure area.
This information does not pertain third parties’ sites consulted through the links available on the site.
This document contains all the necessary information to make the data subject aware of the rules for the processing and management of data collected through this site.
The data controller is IMIT Control System SRL., PI IT02223920063, Via Varallo Pombia, 19 - 28053 Castelletto Ticino (NO), email firstname.lastname@example.org and PEC email@example.com
LEGAL BASIS FOR DATA PROCESSING
The legal basis for processing the personal data of the data subject is his/her consent.
The data subject declares to have read the disclosure on the processing of his/her/her personal data and gives his consent to its processing.
The legal basis for processing some of the may also be the contractual obligation or the legal obligation for which the data controller is responsible.
While browsing the site, data of different nature may be collected, some of which will be acquired automatically, while others only with the consent of the data subject. Specifically, the data collected through the website are as follows:
IP address (internet protocol) Date and time of the visit Browser information The physical address of the device from which the connection is made (c.d. MAC Address) The addresses of requested resources Cookies
The acquisition of technical data is implicit in the operation of the website itself and never entails the identification of the data subject.
Cookies: Cookies are small files that the site, or a third party site, sends to the interested party's terminal where they are stored before being re-transmitted to the same sites when necessary. This site uses the following types of cookies:
The website does not use profiling cookies, but only technical cookies.
Technical cookies are anonymous cookies whose acquisition is necessary to allow the user to browse the site and use all its features. Their presence also allows faster and improved browsing and use of the website, as they intervene, for example, to facilitate specific procedures when making purchases online, when logging in to areas with secure access or when a website automatically recognises a language preference. Specifically, the technical cookies used are:
Functionality or preference cookies: they allow to memorise the function choices preselected by the data subject, for example, those about language or geographical area. Browsing cookies: they guarantee the normal navigation and use of a website (allowing, for example, to make a purchase or to log in to secure areas using authentication credentials). Technical cookies can be automatically cancelled by the browser using the specific modalities provided by the same.
first name and surname email address object and text of the message
Personal data are recorded on the website only if the data subject knowingly and voluntarily enters them before a service is provided through the contact form on the "contact" page or other electronic instruments.
PURPOSE OF DATA PROCESSING
The data collected is used for the following purposes:
allow the data subject to request information; allow the data subject to receive written or oral information; contact the person requesting information; allow the person in possession of credentials to be able to access the secure area; perform statistical analysis anonymously; defend the rights of the data controller.
NATURE OF DATA PROVISION
The provision of personal data is optional. Failure to provide the requested personal data will not allow the data subject to use the services provided through the site, with the exclusion of browsing.
PERSONAL DATA RETENTION PERIOD
The personal data of the data subject will be kept for the time necessary to provide the requested service and/or for the fulfilment of the contract stipulated with the data subject and/or to fulfil legal obligations.
LOCATION OF DATA PROCESSING
The personal data of the data subject are processed at the data controller's premises but could be transferred for the security of the same data also to different subjects, appointed data controllers based in Italy or within the European Union. The data subject can contact the data controller to obtain all the information related to this transfer and to the subjects responsible for it.
DATA PROCESSING PROCEDURES
Data processing is carried out both on paper and with the aid of electronic devices. The data provided and the data provided that refers to third parties will be:
processed lawfully and fairly; collected and recorded for specific, explicit and legitimate purposes and used in further processing operations compatible with those purposes; correct or, in any case, corresponding to the information provided to us; relevant, complete and not excessive in relation to the purposes for which they are collected or subsequently processed; kept in a form that allows the identification of the data subject for a period not exceeding the one necessary for the purposes for which they were collected or subsequently processed
Specific and adequate technical and organisational security measures are adopted pursuant to Art. 32 of the European Regulation to minimise the risk of destruction, loss of data, illicit or incorrect use, unauthorised access or processing not permitted or not consistent with the purposes for which they were collected.
DATA COMMUNICATION AND DISSEMINATION
The data provided by the data subject will be communicated exclusively to qualified third parties appropriately appointed as data controllers or data processors, or to subjects to whom the communication of data is due under the provisions of law or regulation and only whenever necessary for the performance of the services requested or for legal obligations, with a guarantee of protection of the rights of the data subject and in compliance with the European Regulations and the Privacy Code. Particularly, our data may be communicated to:
- subjects, bodies or Authorities to whom it is mandatory to communicate your personal data in accordance with the provisions of law or regulation;
- persons, companies or professional offices providing assistance and advice to the data controller in accounting, administrative, and tax matters.
The complete list of data processors can be obtained by sending a request to the Data Controller at the email: firstname.lastname@example.org.
Your personal data will not be disseminated.
TRANSFER OF DATA ABROAD
The personal data of the data subject will not be transferred abroad, and the data controller has no intention to transfer them.
However, the use of Google Maps plugins and Google Analytics services by the data subject will result in the sharing of some data collected by Google. For the transfer of such data, it will not be necessary the consent of the data subject as established by the Italian and European Authorities (Decision No. 1250/2016 - Privacy Shield).
RIGHTS OF DATA SUBJECTS
The subjects to whom the personal data refer have at any time the right to:
withdraw their consent to the processing of their personal data; obtain confirmation of the existence or otherwise of such data and to know its content and origin, verify its accuracy or request its integration or updating, rectification or cancellation. Obtain confirmation of the existence of their personal data and their communication in an intelligible form. The data subject has the right to obtain information on:
the origin of their personal data; the purposes and methods of data processing; the logic applied in case of processing carried out with the aid of electronic devices; the identification details of the data controller, of the data processors and of the designated representatives; subjects or categories of subjects to whom the personal data may be communicated, or who can learn about them in their capacity as appointed representatives of the State, as designated managers or as persons in charge; the updating, rectification or, when relevant, integration of the data; deletion, transformation into anonymous form or the blocking of data unlawfully processed, including those for which no retention is required in relation to the purposes for which the data was collected or subsequently processed; the attestation that the operations referred to in points (a) and (b) have been made known, including in terms of their content, to those to whom the data was communicated or disseminated, unless such fulfilment is impossible or involves the use of means that are clearly disproportionate in relation to the right being protected; in cases of consent-based processing, the receipt of the data provided, in a structured and readable form by a data processor and in a format commonly available on electronic devices. The data subject has the right to oppose, in whole or in part:
to the processing of his/her personal data for legitimate reasons, even if pertinent to the purpose of their collection; to the processing of personal data for the purpose of sending advertising materials, for direct sales, or for carrying out market research or commercial communication activities.
Requests should be sent to the Data Controller by email at email@example.com and PEC firstname.lastname@example.org or, by mail, to IMIT Control System SRL., Via Varallo Pombia, 19 - 28053 Castelletto Ticino (NO).
The data subject is always entitled to file a complaint with the Authority for the protection of personal data (http://www.garanteprivacy.it/home/diritti/come-agire-per-tutelare-i-nostri-dati-personali).