Privacy Policy

Information provided pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter referred to as the “GDPR”)

Introduction

The Company considers personal data to be an asset of significant value that must be protected through the adoption of procedures and practices designed to safeguard it. Transparency towards data subjects is therefore a primary objective, pursued through effective communication tools aimed at providing stakeholders with essential information on the processing of their personal data.
This Privacy Policy is therefore intended to provide data subjects with all the information required under the applicable data protection legislation, as well as appropriate assurances of reliability to stakeholders.

General Information

Data subjects, as defined in Article 4(1) of the GDPR, are hereby informed of the following general provisions, which apply to all areas of processing:

  • all personal data are processed in accordance with the applicable data protection legislation, namely Regulation (EU) 2016/679 and Italian Legislative Decree No. 196/2003, as subsequently amended and supplemented by Italian Legislative Decree No. 101/2018;
  • all personal data are processed lawfully, fairly and transparently in relation to the data subject, in compliance with the general principles laid down in Article 5 of the GDPR;
  • appropriate security measures are implemented to prevent the loss of personal data, unlawful or improper use, and unauthorised access, in accordance with Article 32 of the GDPR.

Data controller
The Company, acting through its legal representative, is the Data Controller and may be contacted using the details below for any privacy-related enquiries or to exercise the rights set out below:

DATA CONTROLLER
Name: Valcolatte Spa
Email: info@valcolatte.it

DATA PROTECTION OFFICER
Name: Galli Data Service Srl
Email: dpo@gallidataservice.com

Rights of Data Subjects

  • the right to obtain confirmation as to whether personal data concerning them are being processed and to access such data (Article 15, “Right of Access”);
  • the right to obtain the rectification or completion of inaccurate or incomplete personal data (Article 16, “Right to Rectification”);
  • the right to obtain the erasure of personal data where there are legitimate grounds for doing so (Article 17, “Right to Erasure”);
  • the right to obtain restriction of processing (Article 18, “Right to Restriction of Processing”);
  • the right to receive personal data concerning them in a structured format (Article 20, “Right to Data Portability”);
  • the right to object to processing and to automated decision-making, including profiling (Articles 21 and 22);
  • the right to withdraw consent previously given;
  • the right, where no response is received, to lodge a complaint with the Italian Data Protection Authority.

The following specific information is provided in relation to:

  • the processing of data connected with the operation of this website;
  • the processing of data relating to the Data Controller’s customers and suppliers;
  • the processing of data for video surveillance purposes.

 

1) DATA PROCESSING CONNECTED WITH THE OPERATION OF THIS WEBSITE

1.1 Browsing data
The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This information is not collected for the purpose of being associated with identified data subjects. However, by its very nature, it could enable users to be identified through processing and association with data held by third parties.
This category of data includes the IP addresses or domain names of the computers used by users accessing the website, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response provided by the server (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.

Purposes and Legal Basis of Processing
(Article 13(1)(c) of the GDPR)
These data are used solely to obtain anonymous statistical information on the use of the website and to verify that it is operating correctly.
The data may also be used to establish liability in the event of suspected cybercrimes committed against the website, on the basis of the legitimate interests pursued by the Data Controller.
Disclosure of data
(Article 13(1)(e) and (f) of the GDPR)
The data may be processed exclusively by internal personnel who have been duly authorised and instructed to process them, in accordance with Article 29 of the GDPR, or by any parties responsible for maintaining the web platform, who shall in such cases be appointed as external data processors. The data shall not be disclosed to any other parties, disseminated or transferred to countries outside the European Union, unless the requirements set out in Chapter V of the GDPR have first been complied with. Only in the event of an investigation may the data be made available to the competent authorities.
Data Retention Period
(Article 13(2)(a) of the GDPR)
The data are generally retained for short periods, except where longer retention periods are required in connection with investigative activities.
Provision of Data
(Article 13(2)(f) of the GDPR)
The data are not provided by the data subject but are collected automatically by the website’s technological systems.

 

1.2 Cookies

The use of cookies is governed by the applicable legal requirements, including:

  • the “Guidelines on Cookies and Other Tracking Tools” of 10 June 2021, published in Italian Official Gazette No. 163 of 9 July 2021;
  • Guidelines 05/2020 on consent under Regulation (EU) 2016/679, adopted by the European Data Protection Board;
  • cross-border agreements concerning data transfers outside the European Union, entered into pursuant to Chapter V of the GDPR.

Users may view detailed information on the types of cookies used and set their preferences through the dedicated banner. General information on cookies and similar technologies is provided below.

Definition of cookies

Cookies are small pieces of text, consisting of letters and/or numbers, that enable a web server to store information on the client device, through the browser, so that it can be reused during the same visit to the website, in the case of session cookies, or at a later time, even several days afterwards, in the case of persistent cookies. Depending on the user’s preferences, cookies are stored by the browser on the specific device being used, such as a computer, tablet or smartphone. Similar technologies, including web beacons, transparent GIFs and all forms of local storage introduced by HTML5, may be used to collect information about user behaviour and the use of services. Throughout this Privacy Policy, the term “cookies” is used to include cookies and all similar technologies.

Types of first-party cookies and managing preferences

CATEGORY PURPOSE MANAGING PREFERENCES
Essential browsing or session cookies To enable normal browsing and use of the website The main web browsers allow users to:

  • block all or selected categories of cookies by default;
  • view a detailed list of the cookies in use;
  • remove all or selected cookies installed on the device.

For information on how to configure individual browsers, please refer to the relevant section. Please note that blocking or deleting cookies may affect the website’s functionality and ease of navigation.

Analytics cookies To collect information on visitor numbers and the pages viewed
Functionality cookies To enable browsing based on a range of selected criteria
Profiling cookies To create user profiles in order to deliver advertising messages tailored to the user’s preferences

 

Managing preferences in major web browsers

Users can choose whether or not to accept cookies through their browser settings. Please note that most web browsers are configured to accept cookies automatically by default. These settings can be changed and tailored to individual websites and web applications. Most major browsers also allow users to apply different settings to first-party and third-party cookies. Cookie settings can usually be found under the “Preferences”, “Tools” or “Options” menu. Links to the cookie management guides for the main web browsers are provided below:

Microsoft Edge
https://support.microsoft.com/it-it/microsoft-edge/eliminare-i-cookie-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09

Internet Explorer
http://support.microsoft.com/kb/278835

Chrome:
http://support.google.com/chrome/bin/answer.py?hl=en-GB&answer=95647

Safari:
https://www.apple.com/legal/privacy/it/cookies/#:~:text=Se%20vuoi%20disabilitare%20i%20cookie,produttore%20come%20disabilitare%20i%20cookie

Firefox:
http://support.mozilla.org/en-US/kb/Enabling%20and%20disabling%20cookies

Opera:
https://help.opera.com/en/latest/web-preferences/

Further information

 

1.3 Integration with Online Platforms and Social Media

The website may include social media buttons, widgets, plug-ins, links and cookies designed to facilitate interaction with social media platforms and the sharing of content. Any personal data entered by users on social media channels are processed in accordance with the relevant platform’s terms and privacy settings, as accepted by users when registering with that platform. For reference, links to some of the main social media platforms are provided below, where users can manage their privacy settings and cookie preferences:

– Facebook (privacy information): https://www.facebook.com/help/cookies/

– Facebook (settings): the Privacy section of the user’s account

– Instagarm (privacy information) https://www.instagram.com/legal/privacy

– Linkedin (cookie policy): https://www.linkedin.com/legal/cookie-policy

– Linkedin (settings): https://www.linkedin.com/settings

Newsletter subscription

The newsletter provides regular, detailed updates on relevant industry developments, events and initiatives, the products and services offered, and any promotional offers.

Purposes and legal basis of processing
(Article 13(1)(c) of the GDPR)
The only personal data requested is the user’s email address, which is used solely to send the newsletter. Subscription requires the user’s specific, freely given and informed consent, pursuant to Article 6(1)(a) of the GDPR. Consent is recorded by means of a dedicated checkbox, in accordance with Article 7(1) of the GDPR.
Disclosure of data
(Article 13(1)(e) and (f) of the GDPR)
The data are processed exclusively by staff who have been duly authorised and instructed to process them, in accordance with Article 29 of the GDPR. The data may also be accessed, solely for website maintenance purposes, by the company providing the technology platform and by any providers of specific technologies used to deliver the newsletter service. The data shall not be disseminated or transferred to countries outside the European Union.
Data retention period
(Article 13(2)(a) of the GDPR)
The data are retained until the user unsubscribes. Users may unsubscribe at any time by clicking the link provided at the bottom of each newsletter.
Provision of data
(Article 13(2)(f) of the GDPR)
Failure to provide an email address and the required consent will make it impossible to subscribe to the newsletter service.

 

1.5 Contact and information requests
This page allows data subjects to request information. Identification and contact details are required.

Purposes and legal basis of processing
(Article 13(1)(c) of the GDPR)
The identification and contact details necessary to respond to requests from data subjects are collected. Submitting a request requires the data subject’s specific, freely given and informed consent, pursuant to Article 6(1)(a) of the GDPR. Consent is recorded by means of a dedicated checkbox, in accordance with Article 7(1) of the GDPR.
Disclosure of data
(Article 13(1)(e) and (f) of the GDPR)
The data are processed exclusively by staff who have been duly authorised and instructed to process them, in accordance with Article 29 of the GDPR. The data may also be accessed, solely for website maintenance purposes, by the company providing the technology platform and its authorised staff. The data shall not be disseminated or transferred to countries outside the European Union.
Data retention period
(Article 13(2)(a) of the GDPR)
The data are retained for no longer than is necessary for the purposes for which they were collected.
Provision of data
(Article 13(2)(f) of the GDPR)
The provision of the data requested in the mandatory fields is necessary in order to receive a response. The optional fields allow users to provide staff with additional information that may help facilitate contact.

 

1.6 Careers
This page allows data subjects to submit a job application. Applicants are required to provide their identification and contact details, together with their curriculum vitae.

Purposes and legal basis of processing
(Article 13(1)(c) of the GDPR)
The data are collected for the proper management of the recruitment process, the assessment of applications and any subsequent contact with applicants. Submitting an application requires the applicant’s specific, freely given and informed consent, pursuant to Article 6(1)(a) of the GDPR. Applicants who are subsequently hired will receive a separate privacy notice relating to their employment relationship.
Disclosure of data
(Article 13(1)(e) and (f) of the GDPR)
The data are processed exclusively by staff who have been duly authorised and instructed to process them, in accordance with Article 29 of the GDPR. The data may also be accessed, solely for website maintenance purposes, by the company providing the technology platform and its authorised staff. The data shall not be disseminated or transferred to countries outside the European Union.
Data retention period
(Article 13(2)(a) of the GDPR)
The data are retained for a period appropriate to the purposes for which they were collected, normally 24 months, unless the applicant requests their erasure before the end of that period.
Provision of data
(Article 13(2)(f) of the GDPR)
The provision of the data requested in the required fields, marked with an asterisk (*), is necessary in order to submit a job application. The optional fields allow applicants to provide staff with additional information that may assist with the recruitment process.

 

1.7 Voluntary provision of personal data
Where users choose to get in touch with the Company by sending messages to the addresses provided, by sending private messages to its official social media profiles or pages, where this option is available, or by completing and submitting any forms on the website, the Company will collect the sender’s details, insofar as necessary to respond, together with any other personal data contained in the communication. The sender is responsible for ensuring that the personal data provided are accurate, relevant to the request and limited to what is necessary for that purpose.

2) DATA PROCESSING RELATING TO CUSTOMER AND SUPPLIER RELATIONSHIPS

2.1 Categories of personal data processed
The Company processes identification and contact data relating to customers and suppliers, including, for example, first name, surname, company name, personal and tax details, address, telephone number, email address, and banking and payment details. It also processes the names and contact details of their designated contacts. These data are collected and used in connection with the provision of the Company’s services.

2.2 Purpose and legal basis of processing

The data are processed for the following purposes:

  • to enter into contractual or professional relationships and provide the related services;
  • to comply with the pre-contractual, contractual and tax obligations arising from existing relationships and to manage the related communications;
  • to comply with obligations imposed by law, regulations, European Union legislation or orders issued by the competent authorities;
  • to pursue the Data Controller’s legitimate interests and exercise its rights, including the establishment, exercise or defence of legal claims, the protection and recovery of amounts owed, and ordinary internal operational, administrative and accounting requirements.

Failure to provide the above data will make it impossible to establish a relationship with the Data Controller.
Pursuant to Article 6(1)(b), (c) and (f) of the GDPR, the above purposes constitute the applicable lawful bases for processing. Where personal data are to be processed for other purposes, such as marketing communications or the production of photographic or video content, the specific consent of the data subjects will be obtained.

2.3 Processing methods and data retention period
Personal data are processed by carrying out the operations referred to in Article 4(2) of the GDPR, including collection, recording, organisation, storage, consultation, processing, alteration, selection, retrieval, comparison, use, interconnection, restriction, disclosure, erasure and destruction. Personal data are processed in both paper and electronic form.The Data Controller will retain personal data for no longer than is necessary to fulfil the purposes for which they were collected and to comply with the applicable legal obligations. As a general rule, the retention period will correspond to the duration of the relationship with the data subject, without prejudice to any longer period required for the retention of administrative records and business correspondence.).

2.4 Processing, disclosure and data transfers
The data are processed by internal staff who have been duly authorised and instructed in accordance with Article 29 of the GDPR.
Data subjects may request details of the parties to whom their personal data may be disclosed, including any external parties acting as data processors or independent data controllers, such as consultants, technicians, banks and transport service providers. Data may also be disclosed to subsidiaries or affiliated companies.
The data will not be disseminated or transferred outside the European Union. Any transfer to a country outside the European Union will take place only in compliance with the conditions set out in Chapter V of the GDPR, so as to ensure that the level of protection afforded to data subjects is not undermined. Such transfers may be based on an adequacy decision under Article 45, appropriate safeguards under Article 46, binding corporate rules under Article 47 or the specific derogations provided for in Article 49.).
Personal data are not used in automated decision-making processes that have significant effects on the data subject.

3) DATA PROCESSING IN CONNECTION WITH VIDEO SURVEILLANCE SYSTEMS

Further to the information provided to data subjects by means of the notices displayed in areas where video surveillance systems are in operation, please note that:

  • personal data are processed through video surveillance systems in accordance with the applicable data protection legislation, including Regulation (EU) 2016/679 (the “GDPR”), Italian Legislative Decree No. 196/2003, as amended and supplemented by Italian Legislative Decree No. 101/2018, and the general measures issued by the Italian Data Protection Authority, as expressly recognised by Article 22(4) of Italian Legislative Decree No. 101/2018;
  • images are recorded by Valcolatte S.p.A., acting through its legal representative, in its capacity as Data Controller;
  • the system has been installed for security purposes. The cameras are used to protect people, premises and other assets against potential intrusions, fires, theft, robbery or acts of vandalism, and, where necessary, to establish, exercise or defend the Data Controller’s legal rights, including through the collection of evidence;
  • anyone entering or passing through the entrances, premises and surrounding areas concerned will necessarily be captured by the video surveillance system.
  • the images captured may be recorded and retained only for as long as is strictly necessary to fulfil the purpose set out above and, in any event, for no longer than the period permitted by law, which shall never exceed seven days. Images may be retained for longer only where necessary to comply with specific requests from judicial or law enforcement authorities in connection with ongoing investigations. At the end of the applicable retention period, the recorded images will be erased from the relevant electronic, digital or magnetic storage media;
  • the images may be processed exclusively by duly authorised and instructed staff or by external companies acting as data processors and providing system maintenance or security services. They will not be disclosed or disseminated outside the Data Controller’s organisation, except where required to comply with orders issued by judicial or law enforcement authorities or, in the event of unlawful conduct, for use in legal proceedings;
  • the images will be processed using systems and procedures designed to ensure an appropriate level of security and confidentiality, with particular regard to the safeguards set out in Article 32 of the GDPR and the General Measure of 8 April 2010.
  • data subjects may contact the Data Controller to request access to video recordings concerning them, in accordance with Articles 15 et seq. of the GDPR. In particular, where the data subject can be identified, they have the right to obtain confirmation from the Data Controller as to whether personal data concerning them are being processed and to receive such data in an intelligible form. They may also request information concerning the processing, including the source of the data, the purposes and methods of processing, and the identity and contact details of the Data Controller and, where appointed, the data processors. They may request the erasure or restriction of any data processed unlawfully and object to the processing on legitimate grounds;
  • any recording of employees and any use of the resulting video footage shall comply with the applicable employment legislation, including Article 4 of Italian Law No. 300/1970, the “Workers’ Statute”, as amended by Article 23 of Italian Legislative Decree No. 151/2015, the final implementing decree of the Jobs Act.

UPDATES TO THIS PRIVACY POLICY

This Privacy Policy may be reviewed and updated periodically, including to reflect changes in the applicable legislation and relevant case law.
Any significant changes will be prominently displayed on the website’s homepage for an appropriate period of time.
Data subjects are nevertheless encouraged to review this Privacy Policy regularly.