Table of Contents
Personal data that may be processed: “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (C26, C27, C30)
Specific privacy policies
Specific policies may be published on the pages of the Website in relation to particular services or processing of the data provided.
Controller, pursuant to Articles 4 and 24 of Reg. (EU) 2016/679 is Tigullio Digital SRL – WYLAB – REGISTERED OFFICE: CHIAVARI (GE) Via D. Gagliardo 7, Postcode 16043, represented by its pro-tempore legal representative, contact via email email@example.com
2 DATA PROTECTION OFFICER (DPO), pursuant to Articles 37 – 39 of Reg. (EU) 2016/679, the controller is not obliged
3 PURPOSES AND LEGAL BASIS FOR THE PROCESSING
Personal data will be processed in compliance with the conditions of lawfulness pursuant to Art. 6 f) Reg. (EU) 2016/679 (legitimate interest) for the following purposes:
– compilation of any data collection form for contact requests and sending information;
– compilation of any data collection form to submit your start-up application
– compilation of any data collection form in the newsletter and promotional communications area
Data processing is based on Article 6 (1) (f): (recital 47) taking into account the reasonable expectations of the data subject at the time and in the context of the collection of personal data, where the data subject can reasonably expect that the data be processed for that purpose.
4 RECIPIENTS OR CATEGORIES OF RECIPIENTS OF THE DATA
The personal data provided will be communicated to recipients, who will process the data as data processors (Article 28 of Reg. (EU) 2016/679) and/or as natural persons acting under the authority of the Controller and the Data Processor (Article 29 of Reg. (EU) 2016/679), for the purposes listed above in point 3, and to third parties. Specifically, the data will be communicated to:- subjects who provide services for the management of the information system and communication networks (including e-mail); – firms or companies within assistance and consultancy relationships; – authorities competent for compliance with legal obligations and/or provisions of public bodies, on request; – in the case of administrative accounting purposes, the data may be sent to commercial information companies for the evaluation of solvency and payment habits and/or subjects for debt collection purposes. The subjects belonging to the aforementioned categories perform the function of Data Processor, or operate in total autonomy as independent Controllers. The list of Data Processors is constantly updated and available by writing to firstname.lastname@example.org or by writing to the registered office
5 TRANSFER OF DATA TO A THIRD COUNTRY AND/OR AN INTERNATIONAL ORGANIZATION AND SAFEGUARDS
The personal data provided will not be transferred to countries outside the EU.
6 DATA RETENTION PERIOD OR CRITERIA FOR DETERMINING THE PERIOD
The data will be processed in an automated and manual manner, with methods and tools aimed at ensuring maximum security and confidentiality, by persons specifically appointed for this purpose. In compliance with the provisions of Article 5 (1) e) of Reg. (EU) 2016/679, the personal data collected will be stored in a form that allows the identification of the data subjects for no longer than is necessary for the purposes for which the personal data are processed. The storage of personal data provided depends on the purpose of the processing:
– for contact requests or start-up applications (maximum 1 year);
– to receive newsletters or promotional communications in general by e-mail (maximum 24 months);
the timing is determined on the basis of criteria the data subject may have information on by writing to email@example.com
7 RIGHTS OF THE DATA SUBJECTS
You may assert your rights as expressed in Regulation (EU) 2016/679, by contacting the Controller, by sending an e-mail to firstname.lastname@example.org or by writing to the Controller’s registered office indicated above. You have the right, at any time, to request from the Controller access to (art. 15), rectification (art. 16) or erasure (art. 17) of your personal data, or the restriction of processing (art. 18) or to object to their processing based on legitimate interest (art. 21). Withdrawal of consent. The processing does not have a legal basis in consent but in the legitimate interest. Where the processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
To object to the processing and to exercise all other rights please write to email@example.com
You have the right to lodge a complaint with a supervisory authority. Provision of personal data is not mandatory. You are free to provide personal data in the dedicated areas on the site. Failure to provide personal data shall however makes it impossible to use the services offered by the Data Controller. There is no automated decision-making process.
Date of update 30.10.19