Date of update: 11 May 2018
This policy has been written specially for visitors to the website www.cersaie.it
Specific summary information will be provided or displayed on the website pages dedicated to providing specific services on demand and complete with data collection forms.
Please note that to provide a complete service our website may contain links to other websites not managed by Edi.Cer. S.p.A.
Edi.Cer. S.p.A. is not responsible for errors, content, cookies, publication of unlawful content, advertising, banners or files that do not comply with applicable regulations and the Personal Data Protection Code on the part of sites not managed by the Data Controller.
As the Data Controller for your personal data pursuant to articles 13-14 of European Regulation 2016/679, Edi.Cer. S.p.A. hereby informs you that the aforementioned Regulation protects the rights of data subjects with regard to the processing of their personal data and that said data will be processed in accordance with principles of fairness, lawfulness and transparency and in such a way as to respect your confidentiality and rights.
The information and personal data submitted by you or otherwise acquired during use of the website will be processed in accordance with the provisions of the aforementioned regulation and the privacy obligations contained therein.
a) Navigation data
During normal operation, the computer systems and software procedures used for the functioning of this website acquire personal data through the use of Internet communication protocols.
Although such information is not acquired for the purpose of being associated with identified data subjects, by its nature it may enable users to be identified as a result of processing and association with data in the possession of third parties. This category includes IP addresses or domain names used by users who connect to the website, addresses in URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used for submitting the request to the server, the size of the file obtained, etc.
These data are used for the sole purpose of obtaining anonymous and aggregated statistical information on the use of the website and to check that it is used correctly, and reside permanently on third-party servers (the hosting provider). The data may be used for verifying responsibility in the event of hypothetical computer crimes that cause damage to the website.
Personal data submitted voluntarily by the user: the optional, explicit and voluntary sending of e-mail to the addresses indicated on this website and the filling out of the forms on the site will result in the acquisition of the sender’s personal data (for example, first name, last name and e-mail address). Specific summary information is provided on pages containing forms. Please note that to compare and potentially improve the results of the communications, the Data Controller will use systems for sending out newsletters and promotional communications with reports. The reports allow the Data Controller to ascertain for example: number of readers, number of times opened, number of unique “clickers” and number of clicks; the devices (e.g. iPhone, Blackberry, Nokia, etc.) and operating systems (e.g. Windows, Apple, Linux, Android, etc.) used to read the communication; details of individual users’ activities; the number of outstanding users who have not yet confirmed their subscriptions; details of emails sent by date/hour/minute; details of delivered and undelivered emails out of those sent; list of people who have unsubscribed from the newsletter; users who have opened an email or clicked on a single link; users with problems viewing the message; link tracking (i.e. the number of clicks on the message links); click tracking (which links have been clicked on and by whom). All these data are used for the purposes of comparing and if possible improving the results of communications.
Purposes of data processing: your data collected during navigation will be used for the following purposes:
1. performance of operations closely related to and necessary for the management of relations with users or visitors to the website;
2. collection, storage and processing of your data for:
- statistical analyses, including those in an anonymous and/or aggregate form;
- statistical analyses for verifying the quality of the services provided by the website;
- improving the browsing experience by providing services and sending advertising messages in line with the preferences expressed during navigation;
- sharing of website content or the use of third party software.
The processing of data for the purposes indicated in point 1 is obligatory. Failure to communicate, or incorrect communication, of any of the information may limit and/or prevent full use of the features and services present on the site.
Provision of the data indicated in purpose 2 is optional and refusal to grant permission for your data to be processed will not affect the features and services present on the website. You may grant consent either by continuing to navigate on the website or by clicking on the x or OK on the cookie warning.
Processing methods: your personal data are processed using electronic means and using cookies for the time strictly required to fulfil the purposes for which said data were collected. All processing is performed in accordance with the methods indicated in arts. 6, 32 of the GDPR and adopting the adequate security measures indicated.
Web service related processing is performed on the external provider’s premises and is stored at the sites where the physical servers are located.
Communication: your data are processed by persons duly authorised to perform data processing.
Your data may be disclosed to third parties such as:
- External provider
- Companies that perform routine and non-routine website maintenance
- Third-party companies that provide third-party services
- Promos Srl in its capacity as data supervisor for website management and data collection.
Public disclosure: your personal data will not be publicly disclosed.
Period of retention: please note that in accordance with the principles of lawfulness, purpose limitation and data minimisation, pursuant to art. 5 of the GDPR, your personal data will be retained no longer than the period of time necessary to perform the services provided.
Data Controller and Data Supervisor: the Data Controller is Edi.Cer S.p.A., with registered offices in Viale Monte Santo 40 - 41049 Sassuolo (MO), Italy. The Data Supervisor is Promos S.r.l. viale Mercanzia 127 Blocco 2B Galleria B - Centergross – Bologna.
You have the right to obtain from the Data Controller the erasure (“right to be forgotten”), restriction, information, rectification, portability and objection to processing of your personal data, and in general you may exercise all the rights established by arts. 15, 16, 17, 18, 19, 20, 21 and 22 of the GDPR by writing to the Data Supervisor’s offices or sending an email to email@example.com.
If you have any queries about this Privacy Notice, please contact EDI.CER. S.p.A. or Promos S.r.l. by sending an e-mail to firstname.lastname@example.org.
1. The data subject is entitled to receive confirmation of the existence of personal data regarding him or her, even if such data have not yet been recorded, and to be sent these data in an intelligible form.
2. The data subject has the right to obtain the following information:
the origin of personal data;
the purpose and methods of processing;
the rationale followed in the case of processing carried out with the aid of electronic equipment;
the identification details of the data controller, data supervisors and designated representative pursuant to article 5, subsection 2;
the parties or categories of parties to whom the personal data may be disclosed in their capacity as designated representatives in the state territory, as data processors or as appointees.
3. The data subject is also entitled to request:
that the data be updated, corrected or, if in his/her interest, supplemented;
that unlawfully processed data be erased, transformed into an anonymous form or blocked; this includes data that do not need to be stored for the purposes for which the data were collected or subsequently processed;
a declaration that the parties to whom said personal data have been communicated or disclosed have been informed about the operations indicated in subsections a) and e) and their contents, unless this operation should prove impossible or requires the use of resources that are manifestly disproportionate to the rights that are being protected.
4. The data subject has the right to totally or partially oppose:
the processing of his/her personal data for valid reasons, even if such data are relevant to the purpose of collection;
the processing of his/her personal data for the purposes of sending out advertising or direct sales material or for the conducting of market surveys or commercial communications.