Article 13 of Regulation (EU) 679/2016
Information relating to personal data collected through our WEB sites and in the most popular social networks NUDURA Portugal in its capacity as Data Controller, informs that, pursuant to art. 13 of Regulation (EU) no. 679/2016 (“GDPR”), personal data relating to commercial and marketing activities carried out in Italy and abroad will be processed in the following manner and for the following purposes:
OBJECT OF THE PROCESSING
This information notice relates to the following type of Data processing:
- Preliminary collection through our web sites and/or the most popular social networks of personal data for sending commercial and marketing communications at the request of the data subject, with the aim of developing a commercial relationship for the supply of our products
As these data are in an undefined contractual phase, they must be processed in compliance with the European Regulation on Privacy 679/2016 and in this case, for the most part, pertain to the name and surname of the data subject, personal e-mail address, personal and business telephone numbers.
E-mail address for any communication relating to the “Privacy Regulation”:email@example.com
Data Protection Officer (DPO)
Pursuant to Article 37 of Regulation (EU) 679/2016, the Data Controller, in exercise of its rights, has appointed as Data Processor Mr. Carlos Cunha, mail: firstname.lastname@example.org.
The updated list of data processors and of persons tasked with the processing is kept at the registered office of the Data Controller.
- PURPOSE AND LEGAL BASIS OF THE PROCESSING
The User’s data are collected to allow the Controller to provide its sales and marketing information, to inform the data subject, who freely requested it through our websites, of the technical characteristics of our products, as well as events and exhibitions of possible interest thereto. The data processed are guaranteed by professional secrecy on direct and indirect information. Your personal data shall be processed in compliance with the principle of lawfulness of Article 6 of Regulation (EU) 679/2016, for the following purposes:
- Marketing activities with the aim of developing a commercial relationship for the supply of our products, by sending e-mails, mail and/or telephone contacts, newsletters, commercial communications and/or advertising material on products offered by the Controller
Personal data that do not need to be stored for the purposes mentioned above will be deleted or anonymised as specified in point IX below. We would like to point out that it is necessary that you confirm your mandatory consent, as otherwise we will not be able to continue to send you commercial and marketing communications related to products and/or to report events organised by the Data Controller similar to those which you may have already used. The data collected by the Controller shall not be subject to an automated decision-making process, including the profiling of Article 22, paragraphs 1 and 4
RIGHTS OF THE DATA SUBJECT
Article 15 of Regulation (EU) 679/2016 regulates the information that the data subject may request from the Data Controller
The data subject may decide not to provide any data or to subsequently refuse to grant consent for the processing of data already provided for these purposes. In that case, the data subject will not be able to receive newsletters, commercial communications and advertising material related to the services, events and products offered by the Controller, excluding the processing of data in accordance to what was mentioned under point III, letter a;
The data subject shall have the right to request from the Data Controller, when necessary, access to the personal data or the rectification or erasure of such data or the restriction of the processing of the data that concern him/her, or to object to their processing, as well as the right to portability of the data
The data subject shall have the right to withdraw consent at any time, in case he/she has already provided it, however without prejudice to the lawfulness of the processing based on consent granted before the withdrawal (see Article 6, paragraph 1, letter a and Article 9, paragraph 2, letter a of Regulation (EU) 679/2016)
The data subject shall have the right to receive information from the Controller before any action taken by the latter aiming to a type of processing different from that for which the data were collected.
Where applicable, the data subject shall also have the rights of Articles 16-21 of the GDPR (right to be forgotten, right to object);
The data subject shall have the right to lodge a complaint with a supervisory authority.
METHODS OF PROCESSING
Your data will be processed with the operations of Article 4 paragraph 2 of Regulation (EU) 679/2016, and specifically: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Your personal data are subject to both electronic and paper processing. The processing shall be performed by persons entrusted and associates specifically tasked with regard to their functions and in conformity to the instructions they have received, always and exclusively for the achievement of the specific purposes, in scrupulous compliance with the principles of confidentiality and security required by the applicable rules and regulations.
ACCESS TO THE DATA
Your data may be accessed for the purposes specified in this information notice by employees and associates of the Controller in their capacity as persons tasked with processing and/or internal data processors and/or system administrators.
- DISCLOSURE OF THE DATA
Without express consent, the Controller may disclose your data for the purposes and in accordance with the methods specified in this information notice to Supervisory Bodies, Judicial Authorities and to all other persons to whom disclosure is required by law for the fulfilment of the aforementioned purposes. Otherwise your data will not be disseminated.
TRANSFER OF DATA
Your data shall not be transferred outside of the European Union. In any case, it shall be understood that the Controller, when this is necessary, will have the right to transfer the data within the European Union and/or to countries outside the EU and to other part-owned Companies. In that case, the Controller hereby assures you that the transfer of the data outside of the EU will be done in conformity to the provisions of the applicable legislation, by concluding, if necessary, agreements that guarantee an appropriate level of protection and/or by adopting the standard contractual clauses provided for by the European Commission.
STORAGE OF THE DATA
The Data Controller will use the data for the time strictly necessary for the achievement of the purposes and in accordance with the methods specified in this information notice, for 12 months, following which they will be destroyed.
All the personal data that has been provided will be stored and processed in compliance with the principles of lawfulness, fairness, pertinence and proportionality, with paper-based, or computer-based and telematic archiving methods. We would like to point out that the IT systems used for the management of the information collected have been configured from the start in such a way as to minimise the use of the personal data.
MODALITIES OF EXERCISING RIGHTS
We would like to point out that all Data Subjects may at any time exercise their rights with regard to Privacy by sending an e-mail to the address: email@example.com
PROVISION OF CONSENT and AUTHORISATION
Articles 4, 6, 7 of Regulation (EU) 679/2016
The data subject, whose data have been freely entered in the popup window, by ticking the prepared field declares that he/she has read the information provided pursuant to article 13 of Regulation (EU) 679/2016 and that he/she acknowledges, specifically, that the processing will concern the “personal data” of article 4 paragraph 1 of said Regulation, that is to say “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” therefore he/she provides his/her free and specific consent, supported by informed and unequivocal will, with which he/she authorises the processing, also with IT and/or telematic tools, of the personal data for the purposes and in accordance with the methods provided in this information notice, referred to in Point I.
The aforementioned consent is extended to all the subjects of the Controller’s organisation identified as the “Persons in charge”, while the Data Subject is granted the right to object thereto at any time, pursuant to Article 21 of Regulation (EU) 679/2016.