Privacy

Home / Privacy

GENERAL PRIVACY POLICY STATEMENT (articles 13 & 14, EU Reg. n° 2016/679 and Italian legislation in force)

ZORZINI S.P.A.Whose registered office is at Via delle Industrie 55, Lauzacco (UD) – Pavia di Udine, Post Code 33050, Tax and VAT n° 00158020305,contact e-mail info@zorzinispa.com, hereinafter, also the “Body”, in its capacity as the Personal Data Controller, according and pursuant to articles 13 and 14 of EU Reg. n° 2016/679 and the Italian legislation in force, hereby notifies you that your personal data will be processed in the ways and for the purposes indicated below:

 

1. Subject, purpose, and legal basis for processing

Processing 01For its business, the Body processes personal data on their Clientsin accordance with the legal basis referred to in articles 6 and 9 EU Reg. n° 2016/679.  Information related to personal data is involved, including sensitive data, provided on an obligatory and/or optional basis, when accessing / using the services offered by the Body.

The processing must be deemed to be admissible, inasmuch as it is necessary and essential in terms of personal data● Provided in order to be able to receive communications and/or notifications related to the Body’s activities and/or the services it offers (art.6, para.1, lett. a) EU Reg. n° 2016/679) without which it is impossible to be contacted again / made aware of events / initiatives / promotions. ● Provided on an obligatory basis, as a requirement for concluding the contract for the service offered (art.6, para.1, lett. b) EU Reg. n° 2016/679) without which it is impossible to access the services covered by the contract. ● Provided on an obligatory basis for fulfilling legal obligations (to which the data controller is subject) of an administrative / accounting / managerial nature, and necessary and/or accessory to providing the services offered (art.6, para.1, lett. c) EU Reg. n° 2016/679) without which it would not be possible to access the services covered by the contract. ● Provided on an optional basis, in order to make use of additional services, for the purpose of executing the contract (art.6, para.1, lett. b) EU Reg. n° 2016/679) without which it would be impossible to make use of any accessory services required.

On the other hand processing of sensitive data(e.g. Health / genetic / biological; trade union membership; racial or ethnic origin; political opinion; religious convictions; sexual orientation) is generally forbidden, excepting where one of the following cases applies: ● If the person concerned has explicitly given their consent to processing of said data for one or more specific purpose(s) (art. 9 para. 2 lett. a) EU Reg. n° 2016/679). ● If the data have clearly been made public by the person concerned (art.9, para.2, lett. e) EU Reg. n° 2016/679). ● If said data are acquired for the purpose of ascertaining / exercising / defending a legal right in a lawsuit or where the Judicial Authorities exercise their jurisdictional functions (art. 9 para. 2 lett. f) EU Reg. n° 2016/679).


Processing 02
For its functions as employer, the Body processes personal data related to their employees / collaborators / interns, or apprentices.


Processing 03
For its business, the Body processes personal data related to their suppliers.This information relates to common and/or sensitive personal data provided on an obligatory and/or optional basis, when signing / executing contracts, in accordance to articles 6 and 9 of EU Reg. n° 2016/679.

Such processing is to be deemed admissible because it is essential for managing the relationship in terms of the personal data● provided on an obligatory basis, on conclusion of the contract in fulfilment of legal and/or contractual obligations (to which the data controller is subject), of an administrative / accounting / tax nature (art.6, par.1, lett. b) -c) EU Reg. n° 2016/679) without which it is impossible to finalise/implement the contract. ● Provided on an obligatory basis, in fulfilment of contractual / legal obligations during the relationship, in order to fulfil a legal obligation to which the Data Controller is subject (e.g. fulfilment of health and safety protection obligations, fulfilment of the obligations to protect personal data) (art.6, para.1, lett. c) EU Reg. n° 2016/679). ● Acquired for the purpose of safeguarding a legitimate interest of the Data Controller, such as that of safeguarding its own assets or those of another legal person with which the Body collaborates (art.6, para.1, lett. f) EU Reg. n° 2016/679).

Meanwhile, processing must be deemed to be admissible when it involves sensitive data(e.g. health / genetic / biological; trade union membership; racial or ethnic origin; political opinion; religious convictions; sexual orientation) in cases when the same are: ● Clearly made public by the person concerned (art.9, para.2, lett. e) EU Reg. n° 2016/679). ● Acquired for the purpose of ascertaining / exercising / defending a legal right in a lawsuit or where the Judicial Authorities exercise their jurisdictional functions (art. 9, para. 2 lett. f) EU Reg. n° 2016/679).


Processing 04
For its business, the Body processes personal data related to itswebsitevisitorsorpersonal data of visitors to its social media pages(LinkedIn). These are data provided optionally by users, and obtained by browsing and using the various contents / services and associated with preferences / interests, processed in accordance with and pursuant to articles 6 and 9 of EU Reg. n° 2016/679.

Such processing must be deemed admissible inasmuch as it is essential for using the contents and in relation to thepersonal data● when the person concerned has consented to their personal data being processed for one or more specific purposes (art. 6 para. 1 lett. a) EU Reg. n° 2016/679).

On the other hand, processing must be deemed to admissible when related to sensitive data● if the person concerned has explicitly given their consent to processing of said data for one or more specific purpose(s) (art. 9 par. 2 lett. a) EU Reg. n° 2016/679). ● Clearly made public by the person involved (art.9, para.2, lett. e) EU Reg. n° 2016/679). ● Acquired for the purpose of ascertaining / exercising / defending a legal right in a lawsuit or where the Judicial Authorities exercise their jurisdictional functions (art. 9, para. 2 lett. f) EU Reg. n° 2016/679).

 

2. Processing means

Personal data will be processed in hard-copy and digital formats. Processing of the data will be marked by the principles of correctness, legality, and transparency, and can also be done using automated means for storing, managing, and transmitting it, using tools able to guarantee security and confidentiality, by using adequate procedures that avoid the risk of loss, unauthorised access, illegal use, and dissemination.

 

3. Communication of data

The data may be known to Entities tasked with Processing and/or Data Processors (such as supervisors of the computer system [system administrators]; companies and/or professional practices that provide assistance and consultancy on accounting, administrative, fiscal, legal, tax, and financial matters (accountants, labour consultants, attorneys, etc.); persons working in the legal sector, counter parties and related lawyers, boards of arbitrators, and, in general, all public entities (INPS, INAIL, INL, etc.) and private entities (funds, social-security and assistance funds, trade union organisations, etc.) to whom communication is necessary for correct execution of the contract.  An updated list of Data Processors is kept at the Data Controller’s registered office.

 

4. Data preservation period

The Data will be processed and kept for the time required for the purpose for which it was collected and/or is used.  Personal data are kept for service purposes or, in any case, for the prescription time laid down by law, or for a longer period of time if this is necessary to safeguard the Body’s rights and to allow them to demonstrate fulfilment of their obligations.  Subsequently, the data is rendered anonymous and processed for aggregate, anonymous statistical analysis.

Therefore, on expiry of the preservation period, the right to access, erase, correct, and transfer the Data may no longer be exercised.

 

5. Transferring data

Personal data stored in hard-copy / electronic format by the Data Controller may also be communicated to outside professionals for tax compliance and accounting and labour-related formalities.  The Data Controller reserves the right to keep the data using cloud services, and commits to selecting suppliers for this service from among those who provide adequate guarantees, as provided for by art 46 of EU Reg. n° 2016/679.

 

6. Rights of the interested party

Everyone has the right to ask the Data Controller for access to data related to them, correction or erasure of the same, the completion of incomplete data, and limitation of processing; to receive the data in a structured format, commonly used and legible using an automatic device; to revoke any consent they may have granted to processing the data at any time, and to fully or partly oppose the use of the data; to file a complaint with the Authorities, and to exercise the other rights granted to them in terms of articles 15 to 22 of EU Regulation n° 2016/679. We wish to state that, if the data is processed for direct marketing purposes, each person may oppose such processing, without providing any motivation.

 

7. How to exercise rights

Each person may exercise their rights at any time by contacting the Data Controller at their registered office or by sending an e-mail to the address: info@zorzinispa.com, or by lodging a complaint with the supervisory Authority.

 

8. Changes and updates

The Data Controller reserves the right to make changes to this privacy statement.  For all updates you are requested to see the company notice boards, and other channels made available. Further information on processing of personal data can be requested from the Data Controller at any time, using the contact details indicated.

 

Lauzacco-Pavia di Udine, 17 April 2019

Zorzini S.p.A.

Art. 7 Diritto di accesso ai dati personali ed altri diritti