(i) when interacting with the website https://www.elsamec.it (the “Site”) operated by Elsamec s.r.l. Via Pompeiana, 27263900 FERMO Marche – Italy.
(ii) when registering for one of our courses or other Elsamec s.r.l. services, either online on our site or offline at Elsamec s.r.l, even when contacting for assistance services, specific questions or requests;
(iii) when we communicate our marketing activities with you.
For specific processing activities, we need your consent. Continuing his shows us that he accepts the treatment activity in question.
We collect and process personal data in compliance with the laws and regulations on data protection, including, by way of example, the laws promulgated by the European Union on the protection of individuals with regard to the processing of personal data, as well as the free circulation of such data, and all laws promulgated in Member States, as well as the decrees and guidelines of the data protection authorities, from time to time, and the Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 (General Regulation on data protection of the “GDPR”), which integrates the national provisions provides for a date from 25 May 2018 (the “Data Protection Laws”).
WHO CONTROLS THE TREATMENT OF MY PERSONAL DATA? WHO IS RESPONSIBLE?
The data controller of the personal data that is collected is: Elsamec s.r.l. in the person of the Legal Representative in compliance with the legislation on the protection of personal data in the European Union.
The Data Processor can be contacted through our Privacy Office at firstname.lastname@example.org
WHAT PERSONAL DATA ARE TREATED?
Automatic collection of information on this Site
The processing of your personal data, when you visit and consult the Site, is limited to the so-called navigation data, that is to say to the data whose transmission to the Site is implicit in the functioning of the systems in charge of the management of the Site itself and in the typical communication protocols of the Internet. Navigation data, for example, are the IP addresses of the devices it uses to connect to the Site and other parameters relating to its device and its operating system.
In principle, the navigation data, such as those specified above, for example the number of visits and the time of navigation on the Site, are collected by us and processed exclusively for statistical purposes and in aggregate form for the purpose of measuring and enhancing the operation of the Site. By their very nature, navigation data can lead to the identification of users if they are associated with data held by third parties. However, we do not collect navigation data in order to associate them with identified users, except where the aforementioned data could be used in order to assess any liability in the event of crimes committed against the Site or through the Site, to the extent permitted by law.
Information that voluntarily provides us:
We collect and process:
personal data it provides when it interacts with the functionalities of the Website or uploads user generated content to the Website This personal data may include:
name and surname, e-mail address, telephone number
personal data that you provide when you join / enroll in our training activities (through our Website or at our offices), for example when you sign up for our newsletters or mailing lists or participate in promotions and other initiatives, etc. This personal data may include:
name and surname, e-mail address, telephone number
chronology of the services used
personal data that you provide when interacting with our staff, for example when sending a request for information, send us feedback, contact our secretariat for assistance. This personal data may include:
name and surname, e-mail address, telephone number
chronology of the services used
information on the reasons why you contacted us
communications content related to its interaction with our staff.
WHAT ARE THE PURPOSES OF THE TREATMENT OF MY PERSONAL DATA?
We collect and process your personal data for the following purposes:
for the operation and management of the Site
for direct marketing purposes by Elsamec s.r.l.
to allow participation in promotions and other initiatives, such as open days and cultural events
to send (with your consent, also via e-mail or other electronic means of communication such as SMS, MMS, fax, instant messaging applications) advertising and information material on our services, on special initiatives concerning prices and promotions and on initiatives such as events and activities organized by Elsamec srlo to which Elsamec srl participates;
to comply with our obligations under EU laws, regulations and regulations and to evaluate and defend a legal right.
WHAT ARE THE LEGAL BASES FOR THE TREATMENT OF MY PERSONAL DATA, AS DESCRIBED IN THIS DOCUMENT?
We will collect and process your personal data for the purposes described in the “What are the purposes of the processing of my personal data?” On one of the following legal bases:
the processing of your personal data is necessary for the stipulation of a contract or to carry out the procedure that precedes the stipulation of a contract, at your request (article 6.1. (b) of the GDPR, in force since 25 May 2018);
the processing is necessary for purposes related to our legitimate interests or those of our associated partners in ATS if these interests do not conflict with your interests or fundamental rights and freedoms (article 6.1. (f) of the GDPR, in force since 25 May 2018) . The legitimate interests we pursue include, in particular, our interest in managing and maintaining the contractual relationship with you, in responding to your specific requests, in asking for your feedback to improve our site and our services, or in pursuing other general activities of marketing by Elsamec srl
When your specific consent is necessary for the processing of personal data, as described in this document, your personal data will be processed by virtue of this consent (article 6.1. (A) of PILR, of the GDPR, in force since 25 May 2018) ;
HOW LONG WILL MY PERSONAL DATA BE TREATED?
Personal data is not stored beyond the time necessary to achieve the specific data processing purposes described here, except where longer or shorter storage periods are provided for under the laws in force.
ARE MY PERSONAL DATA SAFE?
We are committed to protecting the security and confidentiality of your personal data. We adopt – and require each service provider and / or third party responsible for the processing of personal data on our behalf – to adopt, as per our instructions – technical and organizational measures aimed at preventing the loss and destruction, even accidental, of data, unauthorized access and illicit or abusive use of data. Furthermore, IT systems and software programs are configured so that personal and identification data are used only when necessary to achieve the specific processing purposes from time to time provided.
We use a wide range of advanced security technologies and procedures to help protect personal data against the risks described above.
However, it should be noted that no electronic transmission or storage of information is 100% secure. Therefore, despite the security measures we have put in place to protect your personal data, we cannot or will guarantee that there will be no cases of loss, misuse or alteration of the data.
In case of violation of personal data, the Data Controller, in accordance with Article 33, notifies the competent control authority pursuant to Article 55 of the GDPR without undue delay and, where possible, within 72 hours of the when it became known, unless it is unlikely that the breach of personal data poses a risk to the rights and freedoms of individuals. If notification to the supervisory authority is not made within 72 hours, it is accompanied by the reasons for the delay.
When the violation of personal data is likely to present a high risk for the rights and freedoms of natural persons, the data controller, in accordance with the art. 34, notifies the interested party without undue delay.
WHERE DO MY PERSONAL DATA GO TO FINIREI? WHO ARE THE ADDRESSEES, WHERE ARE THE DATA TRANSFER AND FOR WHAT AIMS?
The personal data collected through our website are stored on the servers managed internally by Elsamec s.r.l.
Your personal data will be accessible, in our organization, to specially appointed and trained internal and external personnel who need to access it in relation to the functions performed and the processing purposes specified in this document. We make sure that these people are required to meet all the security and confidentiality requirements of the case.
Your personal data may also be shared with institutions, authorities, public bodies, insurance companies, professionals, independent consultants, even in associated form, business partners, companies, or other legitimate recipients, where permitted by applicable laws and regulations, for example in case of judicial proceedings, instances of courts and competent authorities or other legal obligations, to protect and defend our rights, our property and the Site.
Personal data will not be disclosed to third parties for their marketing purposes.
The recipients mentioned above may be located in countries other than the country in which the personal data were originally collected – bearing in mind that your personal data will, in principle, be transferred only within the European Economic Area or in other countries of which the European Commission recognizes the ability to guarantee an adequate level of protection of personal data.
Am I obliged to provide my personal data? What are the consequences if I refuse to provide them?
Except in relation to navigation data, providing your personal data may be a necessary requirement to stipulate or execute a contract (course or other services registration), as well as for the performance of certain services, such as registration for our newsletters, promotions and other initiatives communicated through the Site or other channels, response to, and management of, requests for information, questions, communications or feedback. In the circumstances mentioned above, the refusal to provide us with your personal data would prevent us from fulfilling the contract or providing the services or information requested, as specified above.
WHAT ARE MY RIGHTS IN RELATION TO THE PROCESSING OF MY PERSONAL DATA AND HOW CAN I EXERCISE THEM?
It has the right, at any time, to enforce the rights recognized under the current Data Protection Laws, including – by way of example – the right to access, rectify, restrict, cancel, oppose (ie by opposing, at any time and free of charge, to the processing of your personal data for direct marketing purposes), portability, as well as the right to withdraw consent. Furthermore, it is your right to file a complaint with the competent supervisory authority.
For any questions or requests regarding the processing of personal data by Elsamec s.r.l.e to exercise the rights recognized by the Data Protection Laws, you can contact us at email@example.com
DATE REVISED MAY 2018
APPENDIX 1 – RIGHTS OF THE INTERESTED PARTY
To the extent permitted by current legislation, it is your right to obtain confirmation from us that your personal data is being processed and, if so, to request access to such personal data, including, without limitation, the categories of personal data in question, the purposes of the processing and the recipients or categories of recipients. However, we are not obliged to take into account the rights and freedoms of other parties; so it is not an absolute right. Should you request more than one copy of the personal data being processed, we may charge you a reasonable fee based on administrative costs.
It is your right to ask us to rectify any inaccurate personal data concerning you. Furthermore, based on the purposes of the processing, it is your right to request the integration of incomplete personal data, for example by providing an additional declaration.
RIGHT TO CANCELLATION (“OBLIGATION LAW”)
It is your right to ask us to delete your personal data in certain circumstances, as specified by current legislation. When your request falls into one of these circumstances, we will delete your data with due diligence. If, for technical and organizational reasons, we are not able to delete your personal data, we will ensure that they become completely and irreversibly anonymous, so that we will no longer be in possession of such personal data concerning you.
RIGHT OF LIMITATION OF TREATMENT
In some circumstances, as specified by current legislation, it is your right to request the limitation of the processing of your personal data. In this case, your personal data will be processed, except for storage, only with your consent or for the verification, exercise or defense of a right in court or to protect the rights of another person physical or legal or for reasons of significant public interest.
RIGHT TO DATA PORTABILITY
As specified by current legislation, it is your right to receive personal data concerning you (which you provided) in structured format, commonly used and readable by computer, and to transmit such data (or have it transmitted directly by us) to another owner of the treatment, where possible from the technical point of view
RIGHT OF OPPOSITION
In certain circumstances, as specified by current legislation, it is your right to object, for reasons based on your particular situation, at any time, to the processing of your personal data by us, asking us to refrain from further processing your personal data unless we do not demonstrate the existence of legitimate and binding reasons for proceeding with the processing which prevail over your interests, rights and freedoms or for the verification, exercise or defense of a right in court – specifically in the case of processing of your personal data based on our legitimate interests or for statistical purposes.
RIGHT OF OPPOSITION TO DIRECT MARKETING
If your personal data is processed for direct marketing purposes, it is your right to oppose, at any time, the processing carried out for these purposes (including profiling, to the extent that it is related to direct marketing purposes)
RIGHT TO NOT BE SUBJECT TO DECISIONS EXCLUSIVELY BASED ON AN AUTOMATED TREATMENT
Without prejudice to the limitations of the case, it is your right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects that concern you or that have a similar impact on your person.
RIGHT TO REVOKE THE CONSENT
If you wish to access your personal data or exercise the rights mentioned above, you can make a written request, attaching an identity document to our address: privacy @ firstname.lastname@example.org.
Any communication by us in relation to your rights, as specified above, will be provided free of charge. However, in the event of manifestly unmotivated or excessive requests, specifically because of their repetitive nature, it is our right to charge an appropriate fee – in consideration of the administrative costs incurred to provide the information or communication or to take the requested action – or refuse us to respond to the request.
Should you consider that your treatment violates the laws in force, it is your right to lodge a complaint with a competent supervisory authority, the Privacy Guarantor (www.garanteprivacy.it), on which you can find a specific form.