Privacy policy
INFORMATION PURSUANT TO Art. 13 of Legislative Decree No. 196/2003 and EU REGULATION 2016/679 ON THE PROTECTION OF NATURAL PERSONS WITH REGARD TO THE PROCESSING OF PERSONAL DATA.
CIVAS dei fratelli Crippa S.R.L., with registered office in 20844 – TRIUGGIO (MB), Viale Rimembranze, 9, represented by the pro-tempore Legal Representative, in its capacity as Data Controller pursuant to Legislative Decree No. 196/2003 and subsequent amendments – Personal Data Protection Code (“Privacy Code”) – and EU Regulation 679/2016 applicable from May 24, 2018 – General Data Protection Regulation (“GDPR”) (hereinafter collectively referred to as “Applicable Law”) acknowledges the importance of protecting personal data and considers its safeguarding as one of the main objectives of its business activities.
In compliance with the Applicable Law, the Company provides the following information regarding the processing of personal data provided. This notice is issued pursuant to Art. 13 of the Applicable Law and is recommended to be read carefully as it contains important information on the protection of personal data and the security measures adopted to ensure confidentiality in full compliance with the Applicable Law.
The Company informs that the processing of personal data will be based on the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, integrity, and confidentiality. Personal data will therefore be processed in accordance with the legislative provisions of the Applicable Law and the confidentiality obligations provided therein.
PERSONAL DATA SUBJECT TO PROCESSING
“Personal Data” means any information relating to an identified or identifiable natural person, with particular reference to an identifier such as name, identification number, location data, online identifier, or one or more factors specific to their physical, physiological, economic, cultural, or social identity.
“Processing” means any operation or set of operations carried out with or without the aid of automated processes and applicable to personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or any other form of making available, alignment or combination, restriction, erasure, or destruction.
PLACE OF DATA PROCESSING
Data processing takes place at the Data Controller’s registered office, at operational sites, and at identified third parties.
TYPES OF DATA PROCESSED
The processing concerns personal and identification data voluntarily provided by the data subject (for example but not limited to: name, surname, address, tax code, landline and mobile phone number, email address, bank details, family composition, etc.).
PURPOSES, LEGAL BASIS AND MANDATORY OR OPTIONAL NATURE OF PROCESSING
Personal data voluntarily provided will be processed by the Data Controller for the following purposes:
A. Administrative-accounting purposes.
For the purposes of the application of personal data protection provisions, processing for administrative-accounting purposes concerns activities related to organizational, administrative, financial, and accounting management, regardless of the type of data processed. In particular, these include internal organizational activities, fulfillment of contractual and pre-contractual obligations, management of employment relationships in all phases, bookkeeping, and compliance with fiscal, labor, social security, health, hygiene, and workplace safety regulations.
B. Informative purposes.
The use of email contact information provided by the client in the context of the sale of a product or service for the direct sale of the Company’s own products or services is permitted for the purpose of sending informative communications. The data subject may object at any time to processing, easily and free of charge (Art. 130, paragraph 4 of Legislative Decree No. 196/03).
To unsubscribe from the mailing list, it is sufficient to send an email at any time to civas@civas.it
with the subject “unsubscribe mailing list.”
METHODS OF PROCESSING – DATA STORAGE
Processing will be carried out in both automated and manual forms, using methods and tools designed to ensure maximum security and confidentiality, by persons appointed as responsible and authorized for processing under applicable law. Data will be retained only for the period necessary for the purposes for which it was collected and subsequently processed, and in any case for the duration of the contractual or commercial relationship.
SCOPE OF DISCLOSURE
Personal data will not be disclosed without explicit consent of the data subject, after adequate information. Data may be communicated to companies contractually linked to the Data Controller and, if necessary, to entities within and outside the European Union, in accordance with and within the limits of Articles 42, 43, and 44 of Legislative Decree No. 196/2003. Data may be communicated to third parties in the following categories:
– Entities providing services for the management of the information system used by the Data Controller and telecommunication networks, including maintenance of technological infrastructure (including email);
– Entities collaborating with the Data Controller to conduct training courses, such as teachers, inter-professional associations, etc.;
– Freelancers, firms, or companies providing assistance or consultancy;
– Entities performing control, audit, and certification activities;
– Authorities competent for compliance with legal obligations or public authorities, upon request;
Identification data processed for company security procedures are not subject to disclosure, except in cases of explicit requests by competent judicial and investigative authorities.
Entities in the above categories act either as Data Processors or as independent Data Controllers. A list of Data Processors is constantly updated and available upon request at the Data Controller’s office.
Any further disclosure or dissemination will occur only with the explicit consent of the data subject. Additionally, during ordinary processing activities, personal and identification data may be accessed by persons explicitly designated as responsible and/or authorized for processing, in accordance with their respective roles.
NATURE OF DATA PROVISION AND REFUSAL
Provision of data necessary to fulfill obligations arising from contracts in force and required by laws, regulations, EU legislation, or authorities empowered by law is mandatory. Failure to provide such data will make it impossible to establish or continue the relationship, to the extent necessary for its execution. Provision of data for marketing communications is optional; the data subject may object at any time by exercising the rights under the Applicable Law as described herein.
Failure or incorrect provision of mandatory information may result in:
– The Data Controller’s inability to ensure compliance with obligations imposed by fiscal, administrative, and civil law;
– Possible non-alignment of processing results with obligations imposed by fiscal or administrative regulations.
RIGHTS OF ACCESS AND OTHER RIGHTS
The data subject may exercise rights at any time with respect to the Data Controller under the Applicable Law, including obtaining confirmation of the existence of their data, knowing its content and origin, verifying its accuracy, requesting integration, updating, or correction.
Under the conditions provided by the Applicable Law, the data subject may request deletion, restriction of processing, data portability, and may object for legitimate reasons to processing.
Triuggio (MB), 24/05/2018
Clothing industry
Office opening hours
Monday to Friday:
8:00 AM – 12:30 PM / 2:00 PM – 5:30 PM
