Dear Customer/Supplier,
In compliance with EU Regulation 2016/679 (GDPR), which establishes rules for the protection of individuals and other data subjects with regard to the processing of personal data, based on the principles of lawfulness, fairness, transparency, protection of privacy and data subjects’ rights (Article 5 of the GDPR), and pursuant to Article 13 of the GDPR, the relevant information is hereby provided, as summarized in the table below.
| DATA CONTROLLER | ALFA SISTEMI SPA with registered office at Viale Palmanova, 464 – 33100 Udine E-mail address: info@alfasistemi.net; telephone: 0432.524471 |
| DATA PROTECTION OFFICER (DPO) | PRATIKA S.R.L. (contact person dott. Alex Stellini), Via Carnia, n. 1, Rodeano Alto, Rive D'Arcano (UD) E-mail address: dpo@gruppopk.com; telephone: 0432.807545 |
| PERSONAL DATA PROCESSED | Personal data relating to natural persons processed by the Company for the purposes of entering into and performing the contractual relationship with its customers/suppliers (data of the company’s Legal Representative who signs the contract on behalf of the customer/supplier, as well as data of the customer’s/supplier’s employees/consultants involved in the activities covered by the contract). Data falling within special categories of personal data, as provided for under legislation on health and safety in the workplace, including any judicial data contained in publicly accessible databases. |
| PURPOSES OF THE PROCESSING | Establishment and performance of the contractual relationship with the customer/supplier Fulfilment of administrative and accounting obligations Compliance with obligations arising from laws, regulations, EU legislation, or orders issued by the competent Authority Assessment, exercise and/or defence of the Company’s rights in judicial proceedings Sending, by email, post and/or SMS and/or via telephone contacts, newsletters, commercial communications and/or promotional material concerning products or services offered by the Data Controller, as well as conducting customer satisfaction surveys regarding the quality of the services provided |
| DATA RETENTION PERIOD | Durata contrattuale Alla cessazione del rapporto contrattuale, per un periodo di 10 anni o quanto diversamente stabilito dalla normativa pro tempore vigente Restano fatti salvi in ogni caso periodi di conservazione maggiori o specifici previsti da normative e regolamenti applicabili nel settore, oppure utili all’eventuale difesa in For the duration of the contractual relationship Following termination of the contractual relationship, for a period of 10 years or for such other period as may be established by the legislation in force from time to time In all cases, longer or specific retention periods provided for by applicable laws and regulations in the relevant sector, or periods necessary for the potential defence of the Company’s rights in legal proceedings, shall remain unaffected In the event of judicial proceedings, for the entire duration thereof, until the expiry of the applicable time limits for bringing any appeal or other legal challenge Commercial communications: personal data are retained for a period of 2 years following termination of the contractual relationship, or until you express your objection to such processing. Once the above-mentioned retention periods have expired, the data will be destroyed, deleted or anonymised, in accordance with the applicable technical procedures for deletion and backup. |
| LEGAL BASIS FOR PROCESSING | Activities necessary for the performance of a contract or for compliance with a legal obligation to which the Data Controller is subject It is always possible to request the Data Controller to clarify the specific legal basis applicable to each processing activity Any commercial communications, in the context of an existing B2B relationship, in accordance with the guidelines issued by the competent Data Protection Authority and the GDPR, fall within the Data Controller’s legitimate interest, as “soft spam” |
| PROVISION OF PERSONAL DATA | mandatory, as it is strictly necessary to fulfil the purposes set out above. Failure to provide such data will make it impossible to carry out and achieve those purposes |
| DATA RECIPIENTS | External parties acting either as independent Data Controllers or as Data Processors appointed by the Data Controller pursuant to Article 28 of the GDPR (e.g. public bodies, public authorities, consultants and service providers of various kinds) The complete list of Data Recipients and Data Processors appointed by the Data Controller is always available at the registered office of the Data Controller. |
| PERSONS AUTHORISED TO PROCESS PERSONAL DATA | Employees of the Company’s departments responsible for pursuing the purposes set out above, who have been expressly authorised to process personal data and have received appropriate operational instructions. |
| TRANSFER OF PERSONAL DATA | Certain personal data may be disclosed to Data Recipients and Data Processors (appointed by the Data Controller) established in non-European third countries, in accordance with the principles of lawfulness, fairness, transparency and protection of confidentiality (Articles 44 et seq. of EU Regulation 2016/679 – GDPR). Where the Data Controller is required to transfer personal data to third countries, the applicable legal requirements and principles shall apply. Each transfer is assessed on a case-by-case basis, and the data subject may always request detailed information regarding such transfers. |
| DATA SUBJECT’S RIGHTS AND RIGHT TO LODGE A COMPLAINT | Right to withdraw consent (Article 7): the data subject may withdraw their consent to the processing of their personal data at any time, without prejudice to any mandatory requirements under the legislation in force at the time of the withdrawal request. Right of access (Article 15): the right to obtain from the Data Controller confirmation as to whether or not personal data concerning the data subject are being processed and, where this is the case, to obtain access to such data and to specific information relating to the processing concerned. Right to rectification (Article 16): the data subject may request the rectification of their personal data where such data are inaccurate. Right to erasure (Article 17): the data subject may request the erasure of their personal data held by the Data Controller in specific circumstances (e.g. withdrawal of consent, achievement of the purposes for which the data were collected, unlawful processing), subject to certain exceptions (e.g. where the data are necessary for compliance with legal obligations or for the establishment, exercise or defence of legal claims). Right to restriction of processing (Article 18): the data subject may obtain restriction of processing where they contest the accuracy of the data (for the period necessary for the Data Controller to verify their accuracy), where the processing is unlawful and the data subject requests restriction rather than erasure, where the Data Controller no longer needs the data but the data subject requires them for the establishment, exercise or defence of legal claims, or where the data subject has objected to the processing, pending verification of whether the legitimate grounds of the Data Controller override those of the data subject. Right to data portability (Article 20): upon request, the data subject has the right to receive the personal data concerning them that they have provided to the Data Controller, in a structured, commonly used and machine-readable format (e.g. JSON, XML or CSV), where the conditions provided for by the GDPR are met. Right to object (Article 21): the data subject has the right to object to the processing where the legal basis is the legitimate interest of the Data Controller or the performance of a task carried out in the public interest. This right is subject to limitations where the legitimate grounds of the Data Controller override those of the data subject, or where the processing is necessary for the performance of a task carried out in the public interest or for the establishment, exercise or defence of legal claims before a court. Right to lodge a complaint (Article 77): the data subject has the right to lodge a complaint with the competent supervisory authority in the Member State of their habitual residence, place of work, or in the Member State where the alleged infringement occurred. All of the above rights may be exercised by submitting a specific request to the Data Controller through the contact details provided in this privacy notice. |