Privacy Policy*
Dear User,
with this document, drawn up in accordance with Art. 13 of EU Regulation no. 679/2016 (hereinafter also referred to as the "Regulation") Isotta Fraschini Motori S.p.A. informs you, as the data subject for the processing of personal data, of the following.
1. Data Controller
The data controller for the processing of the personal data requested from you (such as name, surname, email, password and identity document) is Isotta Fraschini Motori S.p.A., VAT number 04776160725, with registered office in Viale F. de Blasio, Z.I. - 70123 Bari (BA), (hereinafter also referred to as the "Controller"), PEC XXXXXXX@XXXXXXXXXXXXXXX.XX, tel. +39 XXX XXXXXXX fax +39 XXX XXXXXXX.
2. Purpose and legal basis of the personal data processing
Your personal data will be processed, with the support of computer and/or paper, solely for the following purposes and on the following legal basis:
- purpose of managing the reserved area of the site of reports to the Supervisory Body: through management of the area of the site reserved for whistle-blowing reports and the data of registered users; processing carried out on the basis of the express consent of the data subject;
- purpose of compliance audit and reports to the Supervisory Body: by carrying out the activities related to the application by the Controller of Legislative Decree 231/2001 and the requirements thereof; processing carried out on the basis of the legitimate interest of the Controller.
It should also be noted that your data will be communicated and processed within Isotta Fraschini Motori S.p.A. by personnel duly appointed and instructed by the Controller.
3. Recipients of personal data
Your personal data may be transmitted, in close relation to and where compatible with the purposes set out above, to the following categories of persons:
- Supervisory Body and support staff;
- service providers;
- any other parties, to whom current legislation provides for the obligation of disclosure.
The contact data of the external data processors who carry out activities in the interest of the Controller, can be requested by you at the following PEC address XXXXXXX@XXXXXXXXXXXXXXX.XX.
4. Transfer of personal data to a third country or an international organisation
The Controller does not intend to transfer your personal data to countries outside the European Union.
5. Period of retention of personal data
Your data will be stored:
- for the purpose of managing the reserved area, for 24 months from the last update or report made by you;
- for the purpose of managing reports to the Supervisory Body, for 10 years from the date of first filing of the report.
In any case, the terms of limitation in force will be respected to enforce the rights and obligations relating to your relationship with the Controller or any other contractual or legal obligations which the Controller is required to comply with.
6. Rights of the data subject
We inform you that, as the data subject, you have the right to obtain from the Controller:
Right of access:
(Article 15 of the Regulation)
|
confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, the right to obtain, among other things, access to your personal data and information regarding the purposes of the processing, the categories of personal data concerned and the recipients or categories of recipient to whom the personal data have been or will be disclosed.
|
Right to rectification:
(Article 16 of the Regulation)
|
(i) rectification without undue delay of inaccurate personal data concerning you and (ii) completion of your personal data, where incomplete.
|
Right to erasure ("right to be forgotten"):
(Article 17 of the Regulation)
|
erasure of personal data concerning you without undue delay (the Data Controller has the obligation to erase personal data without undue delay in the cases set out in Article 17 of the Regulation).
|
Right to restriction of processing:
(Article 18 of the Regulation)
|
restriction of processing in the cases set out in Article 18 of the Regulation.
|
Right to data portability:
(Article 20 of the Regulation)
|
receipt in a structured, commonly used and machine-readable format of personal data concerning you; the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, in the cases set out in Article 20 of the Regulation.
|
Right to object for processing carried out under Article 6(1)(e) or (f):
(Article 21 of the Regulation)
|
objection, at any time, on grounds relating to your particular situation, to the processing of personal data relating to you under Article 6(1)(e) or (f), including profiling on the basis of such provisions.
|
You will be able to exercise your rights at any time, as well as to withdraw the consent given during registration by means of a formal request sent to the PEC address XXXXXXX@XXXXXXXXXXXXXXX.XX accompanied by an identity document.
You also have the right to lodge a complaint with the Data Protection Authority if you believe that the processing of your personal data breaches the provisions of EU Regulation no. 679/2016.
7. Nature of consent for data processing and consequence of refusal to give consent
The data relating to registration on the site for reports to the Supervisory Body are optional and are processed on the basis of the consent of users; failure to provide such data will make it impossible for users to complete the registration activities.
The data relating to reports made to the site for reports to the Supervisory Body and collected by the site are needed for the correct handling of the reports.
For the Privacy Guidelines adopted by the Data Controller and/or further clarifications please contact the Data Controller at the following address: PEC XXXXXXX@XXXXXXXXXXXXXXX.XX..
The Data Controller plans to appoint a Data Protection Officer (DPO) who can be contacted at the following PEC address: XXXXXXX@XXXXXXXXXXXXXXX.XX.