Information notice pursuant to Art. 13 of the Regulation (EU) 2016/679 (“GDPR”)
Information when personal data are collected from the data subject
1. DATA CONTROLLER, pursuant to art. 4 and 24 of the Reg. (EU) 2016/679, is CASSINA S.P.A. – registered office Via L. Busnelli 1 Meda (MB), representend by the legal representative pro tempore.
The company has appointed the Data Protection Officer (DPO) pursuant to art.37-39 of the Reg. UE 2016/679 whose contact is: firstname.lastname@example.org
2. PURPOSES AND LAWFULNESS OF THE PROCESSING
The Personal data shall be processed in accordance to the requirements for the lawfulness of processing set forth by Art. 6 of the Regulation (EU) 2016/679 for the following purposes:
A) "Contacts - Press Office", to obtain feedback from the Data Controller and to receive the information, the material, the press releases requested and to contact the Data Controller in order to receive information on products or services thereof. Art. 6 par. 1 lett. f) as the legal basis of the processing: legitimate interest or your legitimate expectation to receive feedback to the request for information sent to the data controller.
B) (consent) subscription to the newsletter of CASSINA S.P.A., for promotional communication by e-mail (mailing list service) and for related activities – art.6 par. 1. lett. a) as legal basis for the processing.
3. RECIPIENTS OR CATEGORIES OF RECIPIENTS OF PERSONAL DATA
Personal data provided by you may be communicated to recipients, which shall process your data as Processors (art. 28 of the Reg. EU 2016/679) and/or persons acting under the authority of the Controller and the Processor (art.29 of the Reg. UE 2016/679) for the purposes pointed in point 2 ahead. Precisely, your data may be communicated to recipients part of the following categories: -Group company for administrative-accounting purposes or for process your request; internal staff of the Data Controller; - subjects providing services for the management of the information system and communication networks (including e-mail and web sites); - studies or companies in the context of assistance and consultancy relationships; - Competent authorities for compliance with legal obligations and / or provisions of public bodies, upon request; - The subjects belonging to the aforesaid categories act as data Processors or act in complete autonomy as separate data Controllers.
4. DATA TRANSFER TO A THIRD COUNTRY AND/OR INTERNATIONAL ORGANISATION
Personal data may be transferred within or outside the European Union, in favour of companies part of the Group for administrative-accounting purposes or for process your request. Personal data may be transferred outside the European Union and the transfer will be made by Data Controller to the limits and conditions set forth by art. 44 and subsequent articles of the Regulation EU 2016/679 “General Principle for transfers”.
5. DATA RETENTION PERIOD OR RELEVANT CRITERIA
The processing shall be carried out in automated and / or manual manner, with methods and tools aimed at ensuring the best security and confidentiality, by persons specifically appointed to do so.
According to the provisions set forth in art. 5 par. 1 lett. e) of the Regulation EU 2016/679, collected personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Personal Data will be retained:
- to visit the current internet website (temporary);
- request for contact - 1 year;
- subscription to the newsletter – until unsubscription and withdrawal of consent (opt-out);
6. NATURE OF UNDERWRITING AND REFUSAL
Below, for each purposes of the processing of the Personal Data are listed the nature of underwriting.
The non-submittal of personal data for purpose A) will result the impossibility to send a request to the Data Controller. The consent for registration to the data controller’s mailing list is optional and, if provided, will necessarily entail the processing of your personal data (e-mail address). Failure to provide personal data will result the impossibility to receive newsletters from CASSINA S.P.A.
7. DATA SUBJECT’S RIGHTS
You may exercise your rights as indicated in the Regulation EU 2016/679, by contacting the data Controller, sending an e-mail to email@example.com or contacting the Data Protection Officer by sending an e-mail to firstname.lastname@example.org. In particular, you have the right to: obtain confirmation that a treatment is underway and if so, to request the data Controller to access of this Data and obtain other information like: kind of Personal Data; recipients or categories of recipients of personal data; data retention period or relevant criteria; the right to ask to rectification, cancellation of your personal data or the limitation of the processing of them; the right to object the processing of your data; the right to lodge a complaint with the Data Protection Authority; if the Personal Data has not been collected by the Data Subject, all the information concerning the origin; the existence of authomated decision-making (profiling also art.22 GDPR); appropriate safeguards in case of data transfer to a third country or international organization art 44 and subsequent of GDPR; the right to obtain a copy of your Personal Data.
Upgrade date: 26th June 2018