INFORMATION ON THE PROCESSING OF PERSONAL DATA
PURSUANT TO ART. 13 GDPR (EU Reg. 2016/679)
La Galvanina S.p.A., owner of the site www.galvanina.com (hereinafter also the “Site”), intends to give information on how the Site is managed in relation to the processing and protection of the personal data of the data subjects (hereinafter also “Data Subjects”) who browse the Site.
This document represents an information pursuant to the provisions of art. 13 of the European Regulation of 27 April 2016 n. 679 (hereinafter “GDPR” or “Regulation”) and is valid only and exclusively for the Site owned by the Company and not for other sites that can be consulted by the user through links that may be activated through the Site.
This information may undergo changes following the introduction of new rules or revision of the same, or following changes to the Site, so we invite users to periodically visit this section.
This information does not exclude that further information on the processing of personal data is also given to the Data Subjects in different ways, for example by sending specific information following the activation or request, through the Site, of a specific service.
1. Data Controller and Contact Information
The Data Controller is La Galvanina S.p.A. (hereinafter also the “Data Controller”), located in Via della Torretta No. 2 – 47923 Rimini (RN) Italy, VAT NUMBER 00142010404.
For the purpose of exercising the rights provided by the Regulation and for any request relating to your personal data, you can contact the Data Controller, sending a communication to the email address email@example.com or a registered letter with return receipt to the above address.
2. Purpose and legal basis of the data processing
The purposes for which the processings of personal data are carried out are the following:
- Information request – Contact form
When the Data Subject contacts us through the “contacts” section on the Site, we collect information, including Personal Data (including name and surname, e-mail address, telephone number, company to which he belongs, role, location data). The processing of this data is carried out in order to respond to the specific requests of the Data Subject.
For this purpose, the processing of Personal Data is carried out, depending on the case: a) as necessary for the execution of a contract of which the Data Subject is party or in order to take steps at the request of the data subject prior to entering into a contract (pursuant to of art.6.1, letter B, GDPR); b) or, as necessary for the for the purposes of the legitimate interests pursued by La Galvanina S.p.A. (pursuant to article 6.1, letter F, GDPR), considering the reasonable expectations of the Data Subject in consideration of the relationship with the Data Controller, as indicated in recital no. 47 of the GDPR.
- Direct Marketing
When filling out the forms on the Site, the Data Subject may be given the opportunity to consent to the processing of personal data also for marketing purposes. For this purpose, consent is expressed by the Data Subject by clicking on the box “I give my consent to the processing of my personal data for marketing purposes by La Galvanina S.p.A.”.
In this case, the data will be processed in order to update the Data Subject on the promotional and marketing initiatives promoted by La Galvanina regarding new products or novelties on existing products and / or on promotional events organized by La Galvanina SpA, both through automated tools – for example, fax, e-mail, sms, mms, calls without operator, newsletters, etc. – that through traditional contact methods (paper mail and / or direct calls via operator).
In this case, the legal basis of the processing is that referred to in art. 6.1, lett. A, GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes”.
At any time the Data Subject has the possibility to choose not to receive any more commercial communications from the Data Controller by following the instructions contained in the e-mail received or by sending an e-mail to firstname.lastname@example.org.
Pursuant to art. 21 of the European Regulation 2016/679, we inform you that the Data Subject has the right to object at any time to the processing of personal data concerning him / her for direct marketing purposes (including sending newsletters). This right can be exercised by contacting the Data Controller in the manner referred to in point 1) above.
We inform the Data Subjects that pursuant to art. 130, paragraph 4, of Legislative Decree 196/2003 and subsequent amendments (relating to the so-called “soft spam”), without having to acquire your express consent, we can use the e-mail address that you provided to us in the context of a previous purchase, for the purpose of direct sale and / or promotion of our products similar to those you have already purchased, provided that you do not object to such use by writing to the data controller or by clicking on the appropriate link to object to the receiving communications considered unwanted, made available within the promotional emails sent by our Company. The Data Subject may object to the processing by contacting the Data Controller at the addresses referred to in point 1) or by clicking on the appropriate link to oppose the receipt of communications considered unwanted, present in all promotional emails sent by La Galvanina SpA.
3. Types of personal data processed
Data provided by the user
As part of the various purposes described above will be collected and processed common personal data, which means that they do not belong to particular categories, such as for example: the name and surname of the Data Subject, the contact details (e-mail address and number by phone) or location (e.g. Country), the company to which the Data Subject belongs, his/her role, the activity carried out.
Data that we automatically collect
The computer systems and software procedures used to operate the Site acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature it could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers and terminals used by users, the addresses in URI / URL (Uniform Resource Identifier / Locator) notation of the requested resources, the time of the request, the method used in the submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user’s computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the Site or other users, only upon request from the supervisory bodies in charge.
La Galvanina could use the information collected through the Site to understand and analyze the usage trends of its Visitors and Users (statistical purposes), to improve the Site and its services, as well as to develop new products, services, features and functionality. For this purpose, we inform you that any data collected through the Site are used by La Galvanina only in anonymous or aggregate form.
4. Processing methods and Security of personal data
The personal data collected are processed, exclusively by authorized subjects, with automated and non-automated tools, with methods suitable for guaranteeing the security and confidentiality of the data and for the time necessary to achieve the purposes for which they were collected.
In order to protect the information that is sent to us, both during transmission and once received, we follow generally accepted industry standards. We maintain adequate administrative, technical and physical safeguards to protect personal data from accidental or illegal destruction, accidental loss, unauthorized alteration, disclosure or unauthorized access, improper use and any other illegal form of processing of personal data in our possession. This includes, for example, firewalls, password protection and other access controls and authentication. We use SSL technology to encrypt data during transmission over the public Internet and we also use application-level security features to make personal data anonymous.
If you believe that your personal data have been compromised or unlawfully processed through the Site, please contact us immediately in the manner referred to in point 1) above.
If we become aware of a violation of the security systems, which involves personal data, we will inform the authorities and if necessary the Data Subjects of the occurrence of the violation in accordance with the applicable law.
5. Recipients or categories of recipients of personal data
The personal data of which the Data Controller will come into possession are not subject to disclosure.
The personal data collected may be communicated to the other companies of the La Galvanina Group, located in the EU and Extra EU. They also may be known by Authorized Subjects (e.g. La Galvanina employees) and by the Data Processors appointed by the Data Controller pursuant to art. 28 GDPR (e.g. third-party companies that carry out data processing on behalf of the Data
The updated list of Data Processors is kept at La Galvanina and can be consulted at the request of the Data Subject.
6. Transfer of personal data to third countries
If necessary to achieve the purposes referred to in this Notice, the personal data collected through the Site may be transferred by the Data Controller to countries not belonging to the European Union. La Galvanina S.p.A. ensures that this transfer will take place:
– towards companies belonging to the La Galvanina Group and which adopt the same procedures regarding the processing of personal data, also through the adoption of binding corporate rules or corporate binding rules approved by the competent supervisory authority;
– to non-EU countries that the European Commission has deemed to guarantee an adequate level of protection (Art. 45 GDPR) or after stipulating standard contractual clauses approved by the European Commission; – after verification of the Privacy Shield Certification (on this point see: http://www.privacyshield.gov/welcome).
Any exceptions to the above will only take place in compliance with art. 49 GDPR.
7. Data retention period
Information request – Contact form: personal data relating to requests for information from users will be kept for the time necessary to provide the answer to the Data Subject and in any case no later than 3 months from the request.
Direct Marketing: in the event that the Data Subject has consented to the sending of informative and promotional material or commercial communications regarding new products or updates (e.g. newsletter), the data will be kept for a period not exceeding 24 months from the release of specific consent for marketing purposes.
We inform you that longer retention periods than those indicated above may be determined by compliance with current legislation, by requests made by the Public Administration or by another judicial, governmental or regulatory body or by the participation of the Data Controller in judicial procedures involving the processing of data personal data provided by the Data Subject.
8. Nature of the provision of data
The provision of personal data for the purposes indicated in this Policy is optional. However, the refusal to provide the data could make it impossible for the Data Controller to provide the services requested by the user and therefore to achieve the aforementioned purposes.
It should be noted that any refusal to give specific consent for direct marketing purposes will prevent the Data Controller from carrying out said activity towards the Data Subject, unless there are hypotheses of soft spam (for which the current legislation allows the sending of commercial communications without the need for express consent to those who are already our customer), in the presence of which the Data Subject retains, however, the right to object to that data processing. The refusal to provide data or consent for marketing purposes will not prevent the requests sent through the contact form from being processed.
9. Rights recognized to the Data Subject
The Data Subject can exercise the rights that are recognized by the GDPR at any time, in the manner described in the previous point 1). In particular, it is recognized to the Data Subject:
Right of access
You can ask us whether or not we process any of your Personal Data and, in this case, you can obtain access to such Data from us in the form of a copy. When you make a request for access, we also provide you with further information, such as the purposes of the processing, the categories of personal data in question and any other information necessary for you, to exercise this right.
Right to rectification
You have the right to correct your data in the event of inaccuracy or incompleteness. Upon request, we will correct inaccurate personal data about you and, taking into account the purposes of the processing, we will complete the incomplete data.
Right to erasure
You have the right to have your personal data deleted. The erasure of your personal data can only take place in certain cases, listed in article 17 of the GDPR. This includes situations where your personal data is no longer needed in relation to the initial purposes for which it was processed, as well as situations where it was unlawfully processed. In relation to how we provide certain services, we inform you that it may take some time before the backup copies are deleted. We also inform you that La Galvanina S.p.A. within the limits of the state of the art, will provide for the erasure of your personal data, except in the case in which the conservation of the same is imposed by law.
Right to restriction of processing
You have the right to obtain the restriction of the processing of your personal data, which means that we suspend the processing of your data for a certain period of time. The circumstances that may give rise to this right (art. 18 GDPR) include situations in which the accuracy of personal data has been contested, but it takes time to verify their (in)accuracy. If you have obtained the restriction of the processing of your data, we will inform you before that restriction is lifted.
Right to object
You have the right to object to the processing of your personal data, which means that you can request us to stop processing your personal data for certain purposes (e.g. direct marketing). We inform you that this right is recognized to the Data Subject only in particular circumstances (art. 21 GDPR) and, in particular, in the event that the legal basis of the processing is constituted by the
legitimate interest of the Data Controller.
Right to data portability
The right to data portability implies that you can ask us to provide you with your personal data in a structured format, commonly used and machine-readable format and to ask us to transmit such data directly to another data controller, where this is technically feasible.
Right to withdraw consent
You have the right to withdraw consent to the processing of personal data at any time, if the processing is based on your consent (e.g. direct marketing). In any case, the revocation of consent does not affect the lawfulness of the processing based on consent before the revocation.
10. Right to lodge a complaint with the supervisory authority
The Data Subject also has the right to lodge a complaint with the supervisory authority, if he/she believes that a processing that concerns her/him violates the GDPR and / or current legislation on the processing of personal data.
We inform you that in Italy this Authority is represented by the Guarantor for the Protection of Personal Data, based in Rome. The Data Subject not residing in Italy may lodge a complaint before the designated Control Authority in his/her country of residence.
11. Inexistence of an automated decision-making process
The processings referred to in this Policy are not subject to automated decision-making processes by La Galvanina.
12. How to contact us
Please contact us in the manner described in the previous point 1) for any question, doubt or comment on this Policy, your personal data, your consent options or to exercise your rights.
The Data Controller
La Galvanina S.p.A.