PRIVACY POLICY – Information document Article 13 EU Regulation 2016/679 – GDPR – Information on the processing of personal data collected from the data subject
In compliance with the provisions of EU Regulation 2016/679 (European Regulation on the protection of personal data) we provide you with the necessary information regarding the processing of personal data provided. This information does not apply to other websites that may be accessible via links on the owner’s domain websites, and the owner is not in any way responsible for third-party websites. This information is provided in accordance with Article 13 of EU Regulation 2016/679 (European Regulation on the protection of personal data) and is also inspired by the provisions of Directive 2002/58/EC, as updated by Directive 2009/136/EC, regarding Cookies, as well as by the provisions of the Decision of the Italian Data Protection Authority of 08.05.2014 regarding cookies.
Data Controller, pursuant to Articles 4 and 24 of EU Regulation 2016/679, is A.T. TOP TAGLIO S.R.L.with registered office at Piazza IV Novembre n°4 – 20124 Milan, Italy and operational office at Via Dei Ierr, 1 – 22032 Albese con Cassano (CO), Italy in the person of the Sole Director.
Contact details: Tel. +39 031 426506, mail:privacy@toptaglio.com.
Personal data that can be processed: “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person (C26, C27, C30).
PURPOSE OF PROCESSING | BASE FOR PROCESSING | DATA RETENTION PERIOD |
Purpose A)
– Website navigation; |
Legitimate interest
Art. 6, letter f) and Recital 47: processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child, taking into consideration the reasonable expectations of data subjects based on their relationship with the data controller. |
Until the end of the browsing session |
Purpose B)
Filling out data collection contact forms; |
Pre-contractual
Art. 6, letter b) GDPR processing is necessary for the performance of pre-contractual measures taken at the request of the data subject, such as responding to information requests. |
1 year for contacts |
Purpose C)
-Processing necessary to send a quote as requested by the data subject by filling out the appropriate form on the website. |
Pre-contractual
Art. 6, letter b) GDPR processing is necessary for the performance of pre-contractual measures taken at the request of the data subject, specifically providing feedback on the requested quote. |
1 year |
Purpose D)
– Processing necessary to fulfill the emergency request made by the customer by filling out the appropriate form on the website. |
Contract
Art. 6, letter b) GDPR: processing is necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the request of the data subject. Legal obligation Art. 6, letter c) GDPR: processing is necessary for compliance with a legal obligation to which the data controller is subject. |
10 years or different legal obligation
Art. 2220 Italian Civil Code |
Purpose E)
Commercial/promotional information activities via email/newsletter/postal mail and operator phone calls. The data controller uses systems for sending newsletters and promotional communications with reports to compare and potentially improve communication results. Through reports, the data controller can, for example, know: the number of readers, openings, unique “clickers,” and clicks; the devices and operating systems used to read the communication; details of individual user activity; details of sent emails, delivered and undelivered, forwarded emails; All of this data is used to compare and potentially improve communication results. |
Consent
Art. 6, letter a): the data subject has given consent to the processing of their personal data for one or more specific purposes. |
Until opposition / Withdrawal of consent |
Recipients or categories of recipients of the data
Personal data provided will be communicated to recipients, who will process the data as data processors (Art. 28 of EU Regulation 2016/679) and/or as natural persons acting under the authority of the Data Controller and the Data Processor (Art. 29 of EU Regulation 2016/679), for the purposes listed above.
To fulfill existing contracts or related purposes, your data will be processed by companies contractually linked to A.T. TOPTAGLIO S.R.L., and in particular, may be disclosed to third parties in the following categories:
- entities providing services for the management of the information system used by A.T. TOP TAGLIO S.R.L. and the telecommunications networks;
- freelancers, firms, or companies providing assistance and consultancy services;
- platform managers for the services listed above (website hosting, etc.);
- competent authorities for compliance with legal obligations and/or orders from public bodies, upon request;
The entities in the above-mentioned categories perform the function of Data Processor or operate in total autonomy as separate Data Controllers.
Transfer of data to a third country and/or an international organization
Personal data provided will not be transferred outside the European Union.
Rights of data subjects
Data subjects have the right to obtain from the Data Controller, in the cases provided for, access to personal data and the rectification or erasure of the same or the restriction of processing concerning them or to object to processing (Articles 15 et seq. of EU Regulation 679/2016). To exercise these rights, you may contact the Data Controller – email privacy@toptaglio.com.
To stop receiving automated direct marketing communications (email), it is sufficient to write an email to privacy@toptaglio.com at any time with the subject “unsubscribe from automated.”
To stop receiving traditional direct marketing communications (operator phone calls), it is sufficient to write an email to privacy@toptaglio.com at any time with the subject “unsubscribe from traditional.”
You have the right to withdraw your consent at any time without prejudice to the lawfulness of the processing based on consent before the withdrawal. Data subjects who believe that the processing of their personal data violates the provisions of the Regulation have the right to lodge a complaint with the Italian Data Protection Authority (https://www.garanteprivacy.it/ ), as provided for in Article 77 of the Regulation itself, or to bring legal proceedings (Article 79 of the Regulation).
In the cases provided for, you have the right to data portability, and in such cases, the Data Controller will provide you with your personal data in a structured, commonly used, and machine-readable format, automatically generated.
You may object at any time to the processing of data based on legitimate interest.
Nature of data provision
The user is free to provide personal data. The provision of data is optional or necessary depending on the specific purpose for which the data is processed. Failure to provide data marked with the symbol* or label (required) will result in the inability to obtain what is requested or to use the services of the data controller. The provision of data for purposes B), C), and D) is necessary to receive a response to your request through the contact forms.
The provision of data for purpose E) is optional; in its absence, your data will not be processed for that purpose. Refusing to provide data will not affect the usability of the purposes mentioned in points B), C), and D).
Privacy Policy Amendment
The data controller reserves the right to change, update, add, or remove parts of this privacy policy at its discretion and at any time. To facilitate such verification, the policy will contain the indication of the update date.
Update Date: 03/09/2019