Privacy poliy

Art. 13 Regulation (EU) 2016/679 of the European Parliament and of the European Council

Gibertini S.r.l., with registered office at via F. Santi 21, Paderno Dugnano, Milan, VAT number 12075300967 (hereinafter referred to as the “Company” or the “Data Controller”), as the data controller, provides the following privacy notice pursuant to Art. 13 of Regulation (EU) 2016/679 (hereinafter “GDPR”) to the data subjects (hereinafter the “Data Subjects”).
The Company, as the data controller, is committed to protecting the privacy and rights of the Data Subjects and, in accordance with the principles established by the aforementioned regulations, the processing of the provided data will be based on principles of correctness, lawfulness, and transparency.



1. SOURCE AND CATEGORIES OF DATA

The personal data that the Data Controller may acquire will generally be provided directly by the Data Subjects. Such data may include, by way of example, identification data, contact data, and personal data (e.g., name, surname, email, etc.).



2. PURPOSE OF PROCESSING
The personal data of the Data Subjects will be processed by the Company for the following purposes:



a) to contact the Data Subjects following their request through the completion of the appropriate form on the Company’s website;
b) to comply with national and foreign laws and regulations or to execute an order from the judiciary or other authorities to which the Data Controller is subject;

c) to exercise the rights of the Data Controller, particularly the right to defense in legal proceedings.



The provision of data for the purposes referred to in points a), b), and c) is optional. However, failure to provide the data and/or any explicit refusal to process it will result in the Data Controller being unable to perform the activities indicated herein. The processing for the purpose referred to in point a) above is lawful as it is carried out under the explicit and informed consent of the Data Subjects. The processing for the purposes referred to in points b) and c) above is lawful as it is carried out to comply with laws and regulations and to exercise the rights of the Data Controller. Data Subjects may also withdraw their consent at any time with the same ease with which it was given.



3. METHOD OF PROCESSING

The data processing is carried out electronically and/or on paper by recording, processing, storing, and transmitting the data, including with the aid of IT tools.
The tools and media used in the performance of processing activities are suitable to ensure the security and confidentiality of the data.
In the performance of processing activities, the Company undertakes to:

  • ensure the accuracy and updating of the processed data and promptly record any corrections and/or additions requested by the Data Subjects;

  • adopt security measures appropriate to ensure adequate protection of the data in consideration of the potential impacts that processing may have on the fundamental rights and freedoms of the Data Subjects;

  • notify Data Subjects of any personal data breaches within the times and in the cases provided for by the applicable regulations;

  • ensure the compliance of processing operations with the applicable legal provisions.

The same methods and procedures are also used when the data are communicated for the aforementioned purposes to the subjects indicated in point 4 of this notice, who in turn are committed to processing them using only methods and procedures strictly necessary for the specific purposes indicated in this notice and in compliance with the regulations.



4. COMMUNICATION AND DISCLOSURE OF DATA

Without prejudice to communications made in compliance with legal obligations, the personal data of the Data Subjects may be known, in addition to the Data Controller, by:

  • employees and collaborators of the Data Controller as persons authorized to process the data (“Appointees”);

  • national and foreign companies belonging to the same group as the Data Controller;

  • business partners of the Data Controller responsible for managing points of sale;

  • service providers of data entry and digital archiving;

  • marketing companies;

  • administrative/accounting consultants;

  • authorities in general, administrations, public entities, and bodies, both national and foreign;

  • exclusively for the purposes mentioned above according to any consents given by the Data Subjects. Personal data are not subject to dissemination.


 

5. TRANSFERS OUTSIDE THE EUROPEAN UNION
Personal data will be stored and processed within the European Union.
In the event of any processing of personal data outside the European Union, it will only take place after the adoption of appropriate safeguards as required by the applicable regulations.



6. DATA RETENTION POLICY

The Company retains personal data in its systems in a form that allows the identification of the data subjects according to the following criteria:


  • for a period not exceeding the achievement of the purposes for which they are processed unless otherwise provided by legal or contractual obligations;

  • to comply with specific legal or contractual obligations;

  • where applicable and legitimate, until any deletion request by the Data Subjects.


 

7. RIGHTS OF DATA SUBJECTS
Data Subjects may exercise their rights recognized by the applicable regulations, and in particular by Articles 15 to 22 of the GDPR, such as: the right of access, the right to deletion, the right to object to processing, the right to restrict processing, the right to lodge a complaint with a supervisory authority.


For the exercise of the rights provided by the GDPR, Data Subjects may:

  • send their requests to the Data Controller by writing an email to the following address: gibertini@gibertini.it
  • or alternatively, contact the Data Controller at the following address:
    Gibertini S.r.l
    Via Ferdinando Santi 21
    20037 Paderno Dugnano (MI)
    indicating “Privacy” in the subject line..