EU Regulation 2016/679 (GDPR)
EU Regulation 2016/679 (GDPR)
EUROSSOLA Srl, with registered office in Piazza G. Matteotti, 36, 28845, Domodossola, VB, Tax Code and VAT number 01203830037, in the person of the legal representative pro tempore, hereinafter also only "EUROSSOLA" or "the Data Controller" or "the Controller", in its capacity as data controller of the processing of personal data pursuant to EU Regulation no. 2016/679 - General Data Protection Regulation (hereinafter "GDPR") and Legislative Decree n. 196/2003 and s.m.i., recognizes the importance personal data protection and considers its protection one of the main objectives of its business.
By "Processing personal data" we mean any operation or set of operations, performed with or without the aid of automated processes and applied to personal data or sets of personal data, such as collection, registration, organization, structuring, storage, adaptation or modification, extraction, consultation, use, communication by transmission, diffusion or any other form of making available, comparison or interconnection, limitation, cancellation or destruction.
EUROSSOLA informs you that your personal data will be processed using manual, IT and / or telematic tools and will be based on the principles of lawfulness, correctness, transparency, purpose and retention limits, data minimization, accuracy, integrity and confidentiality. Your personal data will, therefore, be treated with logics strictly related to the purposes indicated below related to the consultation and use of the Site, in compliance with the provisions of the GDPR and the applicable national legislation regarding personal data protection and, in any case, so as to guarantee the security and confidentiality of data.
Pursuant to the applicable legislation, the data controller of the Site is EUROSSOLA Srl, with its registered office in Piazza G. Matteotti, 36, 28845, Domodossola, VB, Tax Number and VAT number 01203830037, in the person of the legal representative pro tempore.
The processing operations connected to the web services of the Site take place at the datacenter of Ehiweb.it based in Bologna, and also at other offices of the Controller and through its devices.
For any information concerning the personal data processing of EUROSSOLA, including the list of Data Processors, please write to the e-mail address: firstname.lastname@example.org
2. Personal data subject to processing
"Personal data" means any information relating to an identified or identifiable natural person, with particular reference to identifiers such as name, identification number, location data, an online identifier or one or more factors specific of the physical, physiological, mental, economic, cultural or social identity of that natural person. Personal data collected by the Site are as follows:
A) Browsing data
Computer systems of the Site collect some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with you, but because of its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the devices used by users who connect to the Site, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to your operating system and computer system. These data are used to obtain anonymous statistical information on the use of the Site and to check its correct functioning; to allow - given the architecture of the systems used - the correct delivery of various features requested by you, for reasons of security and assessment of liability in cases of computer crimes against the Website or third parties.
B) Data provided on a voluntary basis
Except as specified above regarding the navigation data necessary to process computer and electronic protocols, the provision of personal data by users of the Site is free and voluntary, even though necessary to perform specific requests: in these cases, therefore, failure to provide the data could compromise or make it impossible to perform the service. In particular, through the Website you have the possibility to voluntarily provide personal data, for example, name, surname, company name, address, telephone number, e-mail address, bank and payment references, health status data, etc., to contact, always optionally and voluntarily, EUROSSOLA through the "Contacts" form or to book services through the "Reservations" form, or to submit a spontaneous job application or any other type of communication to the addresses indicated on the Site. The personal and contact information thus provided by the users of the Site are used for the sole purpose of performing the service or provision requested with consequent acquisition of your e-mail address, necessary to respond to your requests and of any other personal data supplied by you and / or communicated through the Site and the services connected to it. EUROSSOLA will process the above said data in compliance with the the GDPR and the applicable national legislation on personal data protection, assuming that they refer to you or to third parties expressly authorized by you on appropriate legal basis that legitimizes the processing of the data in question. In such cases, you will be considered as an independent data controller, and must assume all the inherent legal obligations and responsibilities. In this regard, you grant the widest indemnity with respect to any dispute, claim, request for compensation from unlawfuly processing, etc. that could be advanced against EUROSSOLA from third parties whose personal data have been processed through your use of the Site in violation of current legistlation.
C) Sharing content via social networks
If you decide to share some content via social networks, in particular via Facebook, Twitter, Instagram, the Site may access certain information of your account if you have activated the sharing of your account data with third-party applications. You can disable the sharing of your account data with third-party applications by accessing the settings of the same. For more information on the logics and methods of processing data collected by social networks, we invite you to read the privacy statement provided by the social networks in question:
D) Cookies and related technologies
3. Purpose, legal basis and mandatory or optional nature of processing, consequences of refusal
The collection and processing of personal data by EUROSSOLA are performed in compliance with the principles of lawfulness, correctness and transparency and in such a way as to guarantee adequate security, including protection from unauthorised or unlawful processing, and from accidental loss, destruction or damage, through appropriate technical and organisational measures.
Personal data are processed, mainly with automated and electronic tools, for the time strictly necessary to achieve the purposes for which they were collected, unless it is necessary to store data for compliance with legal obligations and / or for the time needed in consideration of statutory requirements, even after processing has been carried out.
The processing connected to the website services are handled by EUROSSOLA staff, for this purpose authorized to process personal data, as well as by third parties as Data Processors specifically appointed and instructed by EUROSSOLA as Data Controller and in relation to specific activities performed, or by autonomous "Controllers", authorized to access it in accordance with legal provisions, rules and regulations.
No data deriving from the website service will be communicated or diffused, if not in an anonymous and aggregated form.
The personal data you provide through the Site will be processed by EUROSSOLA for the following purposes:
A) purposes related to the fulfillment of a contract you are a party of or the fulfillment of pre-contractual measures you request;
B) purposes of statistical research / analysis on aggregate or anonymous data, without therefore the possibility of identifying the user, aimed at measuring the functioning of the Site, measuring traffic and evaluating usability and interest;
C) purposes related to the fulfillment of obligations required by law, by a regulation, by EU legislation or by an order of the Authority, including accounting, administrative and fiscal, to which EUROSSOLA is subject;
D) purposes necessary to establish, exercise or defend a legal right in a legal action or whenever judicial authorities exercise their judicial functions;
E) for marketing purposes, to send you via e-mail, newsletters, sms, mail and / or telephone contacts, commercial communications and / or advertising material and information on the services or products offered by EUROSSOLA.
Please note that if you are already a customer, we may send you commercial communications relating to EUROSSOLA services and products similar to those you have already received, subject to your disagreement.
The legal basis for personal data processing for the purposes referred to in point A)above is the execution of a contract of which you are a party or the execution of pre-contractual measures taken at your request.
The purpose referred to in point B) does not involve personal data processing, while the legal basis of personal data processing for the purposes referred to in point C) above is the fulfillment of a legal obligation to which the Data Controller is subject.
The legal basis for personal data processing for the purposes referred to in point D)above is the pursuit of the Data Controller’s legitimate interest.
Please note that, taking into account the processing purposes as explained above, providing your personal data for the purposes referred to in points A), B), C) and D) is mandatory. The partial, incorrect or absence of consent and/or the explicit refusal to the processing will make it impossible for the Data Controller to fulfil your requests, to process your purchase order, to comply with the assumed contractual obligations or a legal obligation to which the Data Controller is subject to or fulfil requests from relevant Authorities.
The processing of your personal data for the marketing purposes referred to in point E) above can only take place on the basis of your specific and distinct consent. The provision of data for these purposes is optional, with the consequence that you may decide not to give your consent, or to withdraw it at any time. Refusal to give consent to the data processing does not entail consequences on contractual relationships.
Performing the above mentioned purposes, the Data Controller may become aware of particular categories of personal data pursuant to the GDPR, in particular those considered suitable to reveal your health status. The processing of these categories of data can take place only if the data subject has given his or her explicit consent and in compliance with the GDPR. For such reasons, we ask you to give your explicit written consent to the processing of such data. You will have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. Therefore, the sending of such data will result in the immediate cancellation of the data by EUROSSOLA in the absence of the acquisition of your consent to their processing.
The personal data of minors under the age of 16 will not be processed by the Data Controller unless prior authorization from the holder of parental responsibility.
4. Recipients categories
Your personal data may be shared, for the purposes specified in article 3 above, with:
a) entities to perform the services offered by the Website, including, but not limited to, the sending of e-mail messages, the newsletter service and the analysis of the Website’s functioning; other external entities, each for its specific area of competence, with whom the Data Controller maintains the necessary relations carrying out its business or due to legal obligations; entities who have been specifically appointed and for the time necessary to achieve the purposes for which the data were collected, which typically act as the Data Processors of EUROSSOLA;
b) persons authorized by EUROSSOLA to process personal data that commit to maintain confidentiality or have an appropiate legal obligation of confidentiality (e.g. employees and collaborators of EUROSSOLA);
c) judicial or supervisory authorities, administrations, bodies and public bodies, in the exercise of their functions, when required by law.
In any case, your data will not be disclosed.
5. Extra-EU transfers
The Site may share some of the data collected with services located outside the European Union area. In particular with Facebook, Instagram or Twitter, via social plugins.
This type of service allows interaction with social networks, or other external platforms, directly from the pages of the Site. The interactions and information acquired from the Site are in any case subject to the user's privacy settings relating to each social network.
The transfer is authorized based on specific decisions of the European Union and the Data Protection Authority, specifically decision 1250/2016 (Privacy Shield), for which no further consent is required. The above mentioned companies guarantee their compliance to the Privacy Shield.
6. Data Storage
The management and storage of personal data takes place on servers located within the European Union owned and / or available to the Data Controller and / or third party companies.
EUROSSOLA will process your personal data for the time strictly necessary to achieve the purposes indicated in article 3 above.
Without prejudice to the foregoing, EUROSSOLA will process your personal data for the term allowed under Italian law to protect its rights and interests.
Further information regarding the storage period of personal data and the criteria used to determine this period can be requested writing to the e-mail address indicated above.
7. Your rights
In accordance with the provisions of the GDPR, you have the right to exercise the following rights:
a)right of access: to confirm whether or not personal data concerning you are being processed and, where is the case, to receive information relating, in particular, to: purposes of processing, categories of personal data processed and storage period, recipients to whom the personal data can be disclosed (Article 15, GDPR);
b)right of rectification: to obtain, without undue delay, the correction of inaccurate personal data concerning you and the integration of incomplete personal data (article 16, GDPR);
c)right to cancel: obtain, without unjustified delay, the deletion of the personal data concerning you, in the cases provided for by the GDPR (article 17, GDPR);
d)right of limitation: to obtain the processing limitation from the Data Controller, in the cases provided for by the GDPR (article 18, GDPR);
e)right to portability: to receive in a structured format, commonly used and readable by an automatic device, the personal data concerning you provided to the Controller, as well as to have them transmitted to another Controller without impediments, in the cases provided for by the GDPR (article 20, GDPR);
f)right to object: to object to the processing of personal data concerning you, unless there are legitimate reasons for the Data Controller to continue processing(article 21, GDPR);
g)the right to withdraw any consent given at any time, without prejudice to the lawfulness of the processing based on the consent given before the withdrawal;
h)right to lodge a complaint with the the Italian Data Protection Authority or another Supervisory Authority, pursuant to art. 77 of the GDPR.
You may at any time exercise your rights as indicated above by sending:
- a registered letter to: EUROSSOLA Srl, P.zza G. Matteotti 36 - 28845 Domodossola (VB);
- an e-mail to the address: email@example.com