Privacy Notice
Information on the processing of personal data of customers and suppliers under Article 13 of Regulation (EU) 2016/679 (GDPR).
Information on the processing of personal data of customers and suppliers under Article 13 of Regulation (EU) 2016/679 (GDPR).
Contact details of the Data Controller
The Data Controller is E-project Srl, whose company details are provided in the heading of this notice.
Contact details of the Data Protection Officer
The Data Controller has appointed a Data Protection Officer (DPO), who can be contacted regarding the processing of personal data and the exercise of rights under the European Regulation at: DPO@e-projectsrl.it.
Scope, purposes and legal basis of processing
The Data Controller processes identifying, non-sensitive personal data relating to individuals, provided in connection with the contractual relationship and necessary for its performance, including, for example, first name, surname, company name, address, telephone number and email address.
- Pre-contractual negotiations and activities necessary to enter into and perform the contract, including an assessment of the ongoing relationship and the associated risks.
- Compliance with legal, regulatory and EU obligations or orders issued by authorities, including administrative, accounting and tax activities.
- The legitimate interests of the Data Controller, in connection with its relationship with the data subject, for internal statistical and commercial purposes and for purposes relating to banking, credit, insurance and the protection of creditor rights, subject to a balance between those interests and fundamental rights.
Providing personal data is optional. However, failure to provide data, or the provision of incomplete or inaccurate data, may make it impossible to enter into the contract.
How personal data is processed
Processing includes the operations referred to in Article 4(2) of the GDPR, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure and destruction.
Data is processed both on paper and using non-automated electronic and/or digital tools, in ways closely related to the stated purposes and with measures designed to ensure its security, integrity and confidentiality.
Access and disclosure
Personal data will not be made publicly available, but may be accessed by or disclosed, to the extent necessary, to:
- employees and other personnel of the Data Controller who are authorised to process personal data, and/or system administrators;
- companies linked through control or association within the meaning of Article 2359 of the Italian Civil Code;
- third-party companies and other parties contractually linked to the Data Controller, such as banks, insurance companies, consultants, business information providers, carriers, freight forwarders and professional firms, including those acting as Data Processors;
- supervisory bodies, judicial authorities and other parties to whom disclosure is required by law.
Data transfers
Personal data is managed and stored within the European Union, on servers located in Italy belonging to the Data Controller and/or third-party companies entrusted with these activities and duly appointed as Data Processors.
Data retention period
The personal data collected is processed throughout the contractual relationship and, in any event, for no longer than 10 years after its termination, in compliance with applicable legal obligations.
Data subject rights
Data subjects may exercise the following rights at any time by contacting the Data Controller:
- access to their personal data;
- rectification, completion and updating of their personal data;
- erasure of personal data or restriction of processing, or objection to processing, where applicable;
- data portability, where applicable;
- withdrawal of consent, where applicable, without affecting the lawfulness of processing carried out before withdrawal;
- lodging a complaint with the Italian Data Protection Authority.