Private Notice - Customers & Suppliers
Notice regarding the processing of personal data pursuant to Article 13 of “Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/CE” (“GDPR”).
Dear Customer,
Dear Supplier,
Rattinox Srl wishes to inform you of the purposes and methods of processing the personal data concerning you, or concerning any natural persons who may act on your behalf, in accordance with the provisions of the GDPR.
Controller, purposes of processing and nature of the main data processed.
The Controller processes the personal data of natural people exclusively for the following purposes:
1.Pre-contractual and contractual purposes, relating to the establishment and management of the contractual relationship;
2.Administrative purposes, relating to the management of administrative matters connected with the existing contractual relationship;
3.Commercial communication and marketing purposes;
4.Security purposes and the protection of company assets;
5.Purposes relating to statistical processing and the monitoring of quality and customer satisfaction.
Personal data (Surname and first name; telephone numbers, e-mail address, tax data and bank details) are collected in order to organize and manage the contractual relationship, and only with your express consent for commercial communication and marketing purposes.
Main methods of data processing
The Controller minimizes the collection and processing of personal data to what is strictly necessary for the purposes pursued.
Data may be processed in paper form, in electronic form and through the use of video surveillance systems. Data may also be processed using systems that employ artificial intelligence, in compliance with applicable law.
The Controller, following an assessment of the risks and, where applicable, of the impact on the protection of personal data related to the loss of confidentiality, availability and integrity of the information processed, plans and adopts the necessary technical and organizational measures to minimize such risks. This is also intended to ensure the resilience of the processing carried out, within the broader need to guarantee the continuity of the services provided.
Legal basis for processing
The legal basis for the processing of personal data for the purposes referred to in points 1 and 2 is contractual (Article 6(1)(b) of the Regulation) and is necessary in order to establish and manage the contractual relationship and to fulfil the related legal obligations.
Refusal to consent to processing makes it impossible to establish and maintain the contractual relationship and, therefore, to provide the service.
The legal basis for the processing of personal data for commercial communication and marketing purposes, point 3, is consent (Article 6(1)(a) of the Regulation) and is optional. Refusal to consent does not affect the provision of the service.
Processing for the purposes of company security, protection of assets and statistical processing and monitoring of quality and customer satisfaction, points 4 and 5, is based on the legitimate interest of the controller (Article 6(1)(f) of the Regulation).
Disclosure or dissemination of the data processed
The Controller does not disseminate or disclose your personal data to third parties for purposes other than those indicated above.
Processing by third parties
For the processing of your data within the scope of the purposes listed above, the Controller may make use of the assistance of third parties, such as, for example:
1.Providers of administrative services, such as accountants;
2.Providers of IT technical support services;
3.Software providers;
4.Banking and insurance institutions;
5.Certification bodies;
6.Public authorities, national and EU supervisory bodies.
In such cases, the Controller appoints such parties as external data processors pursuant to Article 28 of the GDPR and ensures that they may process your personal data exclusively for carrying out the activities within their remit, strictly related to the purposes previously defined, and in compliance with adequate technical and organizational data protection measures.
Data are not disseminated or disclosed to third parties beyond the specific provisions of the law and, if requested, may be disclosed to public authorities.
Data are not transferred abroad, and no profiling or automated decision-making is carried out.
Information on and exercise of the data subject’s rights
The Controller wishes to inform you of the rights that the GDPR grants you as a data subject. Such rights are set out in Articles 15 et seq. of the GDPR and concern:
1.the data subject’s right to request access to personal data from the controller;
2.the data subject’s right to request the controller to rectify or erase such data, or to restrict its processing;
3.the data subject’s right to object to the processing thereof;
4.the data subject’s right to data portability;
5.the data subject’s right to lodge a complaint with a supervisory authority.
Retention period for personal data and reference criteria
The Controller retains the personal data processed with reference to the following criteria:
1.compliance with the requirements applicable to the duration of the existing contractual relationship;
2.compliance with administrative and tax requirements under applicable law;
3.Data processed for statistical purposes and for monitoring quality and customer satisfaction, based on the Controller’s legitimate interest, will be kept in identifiable form only for the time strictly necessary to carry out the analysis. At the end of this activity, the data will be irreversibly anonymised or aggregated, preventing any subsequent identification of the data subject and thereby falling outside the scope of privacy legislation.
Data may be retained for a longer period in relation to requests from public authorities.
Personal data, including special categories of data, may be retained for a longer period, within the limits of the statute of limitations, in relation to needs connected with the exercise of the right of defence in the event of disputes.
Data Controller
The Controller of your personal data is Rattinox Srl, P.IVA IT02349500963, with registered and operating office in Via Pietro Mascagni, 10/12, Mariano Comense cap. 22066 (CO). For any request for information regarding the processing carried out on your personal data, as well as for the exercise of your rights under Articles 15 et seq. of the GDPR, you may contact the following e-mail address: info@rattiinox.com.