Via S. Giuseppe, 2 – 36050 Cartigliano (VI)

0424 592526

 

Customer policy

Home / Customer policy

Policy pursuant to Art. 13 of the general data protection regulation no. 2016/679 (GDPR) of the European Union

Cartigliano, 30 October 2018

Dear Customer,
Pursuant to Art. 13 of Regulation EU no. 2016/679, in relation to the personal data that will come into the possession of Officine di Cartigliano S.p.A. as a result of the contractual relations with you, we would kindly ask you to read the following.

General principles

Officine di Cartigliano S.p.A. will process your personal data in accordance with principles of lawfulness, fairness and transparency, restriction of purpose, data minimisation, accuracy, restriction of storage, integrity and confidentiality, accountability of the Controller.

The controller

The controller is Officine di Cartigliano S.p.A. – with registered office in 36050 CARTIGLIANO(VI), Via San Giuseppe, 2 – VAT number 00167890243 – tax code 00167890243 R.E.A. VI-80062 – amministrazione@cert.cartigliano.com – tel. 0424 592526 – fax 0424 590515

The processors

In addition to the Controller, other internal and external processors of OFFICINE DI CARTIGLIANO S.P.A. might process your personal data.
In order to satisfy legal obligations or for reasons strictly functional to fulfilment of the obligations deriving from the working relationship, your data may be communicated to:

  • data processing centres and/or service companies outside our organisation, but strictly related to it for operational purposes;
  • to credit and/or financial companies, to transport and/or delivery service companies; to parties responsible for management of correspondence, to hosting providers and technical consultants and to any party involved in providing and supporting the service we offer to our customers;
  • to tax consultants, to the company legal affairs office, to debt recovery agencies;
  • to public and private entities, also following inspections or audits or for fulfilment of obligations imposed by law or obligatory regulations, EU regulations or secondary regulations (such as: the Revenue Administration, Revenue Police units, the judicial authorities, the Italian Exchange Office, the Employment Office, local healthcare authorities, other agencies);
  • to parties who might access your data according to law or secondary or EU regulations.

A precise list of processors and their assignments is kept at the company head office.

Types of data processed

The data we may process in our activities, for which you must promptly notify any rectifications, supplements and/or updates, is:

  • surname and first name/company name
  • complete address/registered office
  • Tax code and/or VAT number
  • company and/or personal telephone number
  • company and/or personal mobile telephone number
  • company and/or personal fax number
  • company and/or personal e-mail address

Processing methods

The personal data is processed on paper, electronically and/or using telematic means. It is managed internally in full compliance with Italian Legislative Decree no. 196/03, as revised by Italian Legislative Decree no. 101/2018. The Controller adopts appropriate security measures to prevent unauthorised access, theft, alteration, loss or destruction of the personal data.

Purposes of processing

The personal data is processed to allow Officine di Cartigliano S.p.A. to supply its services. The data may be used to contact you, if required by the contractual relationship.
The personal data will be processed for direct marketing purposes only after you have given your specific consent.
The personal data will also be processed to satisfy legal requirements, such as tax and accounting obligations.
In certain cases, of which you will be informed, failure to provide your personal data could make it impossible for Officine di Cartigliano S.p.A. to supply the service requested.

Legal basis of processing

Officine di Cartigliano S.p.A. will process your personal data in all the following cases:

  • where necessary to fulfil its contractual obligations
  • where necessary to satisfy legal requirements
  • when you have given your consent

Data storage

Your personal data will be stored for the validity period of the contract and subsequently for the time for which Officine di Cartigliano S.p.A. is subject to the obligation of keeping the data for taxation purposes or for other purposes imposed by law, and also for the limitation period for any legal actions. The limit imposed by Officine di Cartigliano S.p.A. is 10 years, after which the data will be erased.

Disclosure of data and profiling

Your personal data will not be disclosed or subject to any automated decision-making process, including profiling. Your data will not be transmitted to third countries.

Rights of the data subject

As the data subject, you may exercise the following rights at any time:

  • obtain confirmation that your personal data exists in the Officine di Cartigliano S.p.A. archives
  • learn the origin of the data and the purposes and methods of processing
  • obtain rectification or erasure of the data
  • object to its processing
  • withdraw consent, if processing is based on consent
  • request restriction of processing
  • obtain data portability
  • file a complaint

You may exercise these rights by sending written notice via PEC (certified public e-mail address) to amministrazione@cert.cartigliano.com or via registered letter with acknowledgement of receipt to Officine di Cartigliano S.p.A. in 36050 CARTIGLIANO (VI), Via San Giuseppe, 2

Supervisory authority:

If you deem this necessary, you may contact the Personal Data Protection Authority to protect your rights, using the following contacts:
Personal Data Protection Authority
Piazza Montecitorio no. 121
00186 Rome
For general information, send an e-mail to protocollo@pec.gpdp.it

Glossary

Personal data: any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Data subject:
Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller