Informative notice, as per European Regulation 2016/679 (“GDPR”), Article 13 Data Controller (GDPR Art. 13a and 15b).
The Data Controller is GAFITEX SRL (hereinafter also referred to as the “Data Controller”), in the person of the acting legal representative, with registered office VIA CAVRIANA 14, GUIDIZZOLO (MN), ITALY. Personal data is collected by the Data Controller by recording and archiving in paper and electronic databases. The data is processed according to the principles of correctness, lawfulness, transparency, limitations of purpose and conservation, data minimization, accuracy, integrity, confidentiality and accountability.
Data Protection Officer
The designated Data Protection Officer is the point of contact for parties wishing to receive information on the processing of their data and/or the supervisory authority, and can be contacted at the e-mail address of firstname.lastname@example.org.
Gafitex Srl, in the person of its acting legal representative, with registered office in VIA CAVRIANA 14, GUIDIZZOLO (MN) ITALY, acting as the Data Controller and contactable via the e-mail address of email@example.com, collects and/or receives information concerning the Data Subject such as:
Example of the types of data
Name, surname, physical address, nationality, province and municipality of residence, landline and mobile telephone, fax, VAT number, e-mail address
Bank details / PayPal profile
IBAN and bank details (not credit card number)
Telematic traffic data
Logs, originating IP address
The data controller, even without express consent, may use the contact details communicated by the Data Subject for the purposes of other direct product sales, limited to cases of similar products, unless the Data Subject explicitly objects. Purpose of the data processing and legal basis
The data collected and processed will be used exclusively for the purposes of:
- Fulfilling a customer or company contract
- Communication to third parties for reasons of fiscal and administrative management.
The processing of collected personal data, including any data that is sensitive (“special categories of personal data”) or relates to any criminal conviction or crime (“judicial data”), for which consent must be according to this notice, takes place for the management purposes identified above. All the data is processed, therefore, exclusively for obligations relating to the activities of the Data Controller, whose legal basis is based in consent (e.g. for the processing of “special categories of personal data” or for marketing or profiling purposes),
in the need to fulfil a contract of which the Data Subject is a party or pre-contractual measures taken at the Data Subject’s request, in fulfilling legal obligations to which the Data Controller is subject,
in the legitimate interest of Data Subject, in carrying out a task of public interest or connected to the exercise of public powers of which the Data Controller is invested, or in safeguarding the legal interests of the Data Subject or of another natural person.
Nature of the data collection
The provision of personal data and its subsequent processing by the Data Controller, for the aforementioned purposes, are necessary for the establishment, continuation and proper management of the relationship between the Data Controller and the Data Subject or are required by law, regulations or European Community legislation. Any refusal to provide the requested personal data may lead to the impossibility, in whole or in part, to fulfil or manage the established or potential relationship. The provision of personal data and its subsequent processing by the Data Controller for the purposes referred to in points A, B and C is optional, and failure to such whole or partial data shall not entail any consequences.
Data processing methods
The data will be processed by the persons in charge of processing with manual, IT and telematic tools within the scope and for the purposes specified above, and, in any case, always respecting the security and confidentiality of such data, in compliance with the law and the provisions of the Guarantor for the Protection of Personal Data.
Categories of subjects to whom the data may be communicated:
The processing of personal data will be carried out by expressly designated and specifically trained appointees. Such parties shall process the data in accordance with the instructions received from the Data Controller, according to operational instructions specific to their roles.
The data may also be processed by third parties (outsourced), appointed as external data processors and used, from time to time by the company, for the provision of services relating to the indicated purposes, and for greater protection of the data. In all cases, such parties will process the data in accordance with the instructions received from the Data Controller, according to operational instructions provided to them in relation to the appointed roles and limited to what is necessary and instrumental for the execution of specific operations related to the requested services and exclusively for the achievement of the purposes indicated in this notice.
The data shall not be subjected to general disclosure.
Duration of the processing and data retention
The data collected will be kept for a period of time not exceeding that necessary for the purposes for which they were collected, for contractual or pre-contractual fulfilment, and for legal and/or regulatory obligations (without prejudice to statutory limitations, in the respect of rights and compliance with associated obligations). In particular, the criteria used to determine the retention period are established by specific laws governing the activity of the Data Controller (e.g. by tax legislation regarding the processing of administrative and accounting data or by specific provisions of the Guarantor for the Protection of Personal Data that regulate the processing activity and the purposes pursued by the Data Controller). The personal data may, in any case, be kept up to the maximum time permitted by Italian Law.
Rights of the Data Subject:
The Data Subject has the right to:
- Request the cancellation, transformation into an anonymous form, or limitation of processing of the data collected in violation of the law;
- Request the updating, correction and integration of any data;
- Obtain certification that such requests have been brought to the attention of those to whom the data are communicated;
- Oppose, for legitimate reasons, the processing of the data or any automated decision-making processes (including profiling);
- Request the limitation of the processing or the portability of the data towards another data controller.
For such purposes, requests should be sent via e-mail to firstname.lastname@example.org (specifying “Privacy” in the subject line) or via registered letter with return receipt to GAFITEX SRL. The Data Subject is reminded of the right to lodge a complaint with the Guarantor for the Protection of Personal Data for the exercise of such rights or for any other matter relating to the processing
of the personal data. The Data Subject has the right, at any time, to withdraw consent to the
processing of personal data provided for the purposes indicated above, without prejudice to the lawfulness of the processing based on the consent given before such withdrawal of consent.
Having read the information, I consent to the processing of my personal data and, expressly, to the processing of any sensitive data (“special categories of personal data”) and/or data relating to criminal convictions or crimes (“judicial data”) for the fulfilment of the aforementioned e-commerce purposes.