PERSONAL DATA PROCESSING INFORMATION
Clori & C srl with registered office in Via del Filagno 6 - 22074 Lomazzo (CO), VAT no. 03430620132 (hereinafter, “Owner"), as data controller, informs you that your data will be processed in the following ways and for the following purposes in accordance with Art. 13 EU Regulation no. 2016/679 (hereinafter "GDPR"):
1. Type of information treated
The Owner processes personal, identifying data, for example, name, surname, company name, address, telephone, e-mail, bank and payment references - (hereinafter, "personal data" or even "data") communicated by you when finalising a service contract with the Owner.
2. Purpose of treatment
Your personal data is processed without your express consent in accordance with Art. 6 letter b), e) GDPR), for the following Service Purposes in order to: - finalize a service contract with the Owner;
- fulfill pre-contractual, contractual or tax obligations arising from existing relations with you;
comply with obligations laid down by law, regulation, Community legislation or orders from the Authority (e.g. regarding anti-money laundering);
exercise Owner’s rights, for example the right of defence in court;
Only with your specific and separate consent, according to Art. 7 GDPR), for the following Marketing Purposes:
contact you by e-mail, mail and/or sms and/or telephone, newsletters, commercial communications and/or advertising material about products or services offered by the Owner and carry out a survey to measure the degree of satisfaction with the quality of services;
contact you by e-mail, post and/or text message and/or telephone commercial and/or promotional communications from third parties (e.g. business partners, insurance companies).
We would like to inform you that, if you are already our customer, we may send you commercial communications relating to the Owner’s services and products similar to those you have already used, unless you opt out.
3. Treatment methods
The processing of your personal data is carried out through the operations indicated in Art. 4 no. 2) GDPR and specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, cancellation and removal of data. Your personal data is subject to both paper and electronic and/or automated processing.
The Owner will process personal data for the time necessary to fulfil the above mentioned purposes and, in any case, for no longer than 10 years from the termination of the relationship for Service Purposes, and for no longer than 2 years from the data collection for Marketing Purposes.
4. Data access
Your data may be made accessible for the purposes set out in Art. 2.A) and 2.B):
to employees and collaborators of the Data Controller, in their capacity as internal data processors and/or system administrators;
to third party companies or other subjects (for example, credit institutions, professional firms, consultants, insurance companies for the provision of insurance services, etc.) who carry out outsourcing activities on behalf of the Data Controller, in their capacity as external data processors.
5. Data communication
The Data Controller may communicate your data, without your express consent in accordance with Art. 6 letter b) and c) GDPR), for the purposes referred to in Art. 2.A) to Supervisory Bodies (such as IVASS, the Institute for the Supervision of Insurance), judicial authorities, insurance companies for the provision of insurance services, as well as to those subjects who require the communication by law for the fulfillment of these purposes. These subjects will process the data in their capacity as independent data controllers. Your data will not be disseminated.
6. Data transfer
Personal data is stored on servers located in Lomazzo, within the European Union. In any case, it is understood that the Owner, if necessary, will have the right to move the servers even outside the EU. In this case, the Data Controller assures from now on that the transfer of data outside the EU will take place in accordance with the applicable legal provisions, subject to the standard contractual clauses provided by the European Commission.
7. Nature of the provision of data and consequences of refusal to respond
The conferment of your data for the purposes referred to in Art. 2.A) is mandatory. In its absence, we will not be able to guarantee you the Services outlined in Art. 2.A).
The conferment of your data for the purposes referred to in Art. 2.B), on the other hand, is optional. You may therefore decide not to provide any data or, subsequently, not agree to the processing of data already provided: in this case, you may not receive newsletters, commercial communications and advertising material relating to the Services offered by the Owner. In any case, you will continue to be entitled to the Services referred to in Art. 2.A).
8. Rights of the interested party
In your capacity as data subject, you have rights as per Art. 15 GDPR and, specifically, the right to: obtain confirmation as to whether or not personal data concerning you exists, regardless of whether it has been recorded or not, and communication of such data in intelligible form; obtain information about: a) the source of the personal data; b) the purposes and methods of processing; c) the logic applied to the processing, if the latter is carried out with the help of electronic means; d) the identification data concerning data controller(s), data processor(s) and representative(s) designated as per Art. 3, paragraph 1, GDPR; e) the bodies or categories of bodies to whom/which the personal data may be communicated and who/which may have access to said data in their capacity as designated representative(s) in the State's territory, data processor(s) or person(s) in charge of the processing; to obtain: a) the updating, correction or, when interested, integration of the data; b) the cancellation, transformation into anonymous form, or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which the data was collected or subsequently processed; c) certification confirming that operations as per letters a) and b) have been notified, in addition to their content, to the entities to whom/which the data was communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected; to object, in whole or in part: a) for legitimate reasons, to the processing of personal data concerning you, even if pertinent to the purpose of collection; b) to the processing of personal data concerning you, where it is carried out for the purpose of sending advertising materials or direct sales or else for the performance of market or commercial communication surveys, using automated calling systems without the intervention of an operator by e-mail and/or traditional marketing methods by telephone and/or paper mail. It should be noted that the right to object of the interested party, set out in point b) above, for direct marketing purposes by automated means, extends to traditional marketing methods and that in any case the interested party may exercise the right to object even only in part. Therefore, the interested party may decide to receive only communications by traditional means or only automated communications or neither.
Where applicable, it also has rights under Articles 16-21 GDPR (Right of rectification, right to oblivion, right to limitation of processing, right to data portability, right of opposition), as well as the right to complain to the Guarantor Authority.
9. Ways of exercising rights
You may exercise your rights at any time by sending:
a registered letter with return receipt to Clori & C srl, Via del Filagno 6 - 22074 Lomazzo (CO)
an e-mail to the address clorisrl@legalmail.it
10. Owner, manager and persons in charge
The Data Controller is Clori & C srl, with registered office in Via del Filagno 6 - 22074 Lomazzo (CO)
The updated list of data processors and persons in charge of processing is kept at the Data Controller’s registered office.
- - - - -