PRIVACY POLICY
INFORMATION ON THE PROCESSING OF PERSONAL DATA Art. 13 EU Regulation No. 679/2016 (General Data Protection Regulation – GDPR)
Dear User, the personal data provided by you are subject to processing in accordance with EU Regulation 679/2016 – GDPR (hereinafter, the “Regulation”) and national legislation on the protection of personal data.
This information notice has been prepared on the basis of the principle of transparency in order to contain all the elements required by Articles 13 and 14 of the Regulation and is divided into individual sections, each of which deals with a specific topic, in order to make reading quicker, easier and more intuitive.
DATA CONTROLLER
The data controller is GLOBTRAIN GMBH, with registered office at Naumannstraße 4 – 10829 Berlin, VAT No. DE358130735.
PURPOSES OF PROCESSING
The Data Controller may process your personal data for purposes related exclusively to the management of the services offered and, in particular, for the following purposes.
A. Processing of information requests:
Processed data: name, surname, email address, telephone number.
Legal basis and lawfulness of processing: pre-contractual legal basis pursuant to Article 6(b) of the Regulation – the Processing of your Personal Data will be conducted by the Data Controller in order to respond to your request for information and will be legally based on the pre-contractual relationship that will be created between you and the Data Controller.
B. Execution of contractual documentation:
Processed data: personal data, e-mail address, telephone number, bank data.
Legal basis and lawfulness of processing: contractual legal basis pursuant to Article 6(b) of the Regulation – The Processing of your Personal Data will be conducted by the Data Controller in order to follow up the signing of the individual contractual document and will be legally based on the contractual relationship that will be created between you and the Data Controller.
C. Administrative and accounting obligations:
Processed data: personal and fiscal data.
Legal basis and lawfulness of processing: the legal basis legitimising the processing of Data for that purpose is Article 6(c) of the Regulation and, therefore, a legal obligation to which the Data Controller is subject.
D. Exercise and/or defence of a right in court:
Processed data: contractual data.
Legal basis and lawfulness of processing: the legal basis legitimising the processing of the Data for that purpose is Article 6 (f) of the Regulation, i.e., a legitimate interest of the controller.
E. Subscription to the newsletter service made available through the site:
Processed data: name, surname, email address, telephone number.
Legal basis and lawfulness of processing: consent of the data subject pursuant to Article 6(a) of the Regulation – the Processing of your Personal Data will be conducted by the Data Controller and will be legally based on your free, express and unambiguous consent.
F. Sending advertising/promotional communications concerning services similar to those for which it has expressed interest:
Processed data: name, surname, email address, telephone number.
Legal basis and lawfulness of processing: article 6 (f) of the Regulation and, therefore, a legitimate interest of the data controller to which in fact corresponds a speculative reasonable expectation of the data subject as to the receipt of that specific content.
G. Marketing (sending advertising/promotional material to promote services offered by the Company):
Processed data: name, surname, e-mail, telephone number, interests and preferences.
Legal basis and lawfulness of processing: consent of the data subject pursuant to Article 6(a) of the Regulation – the Processing of your Personal Data will be conducted by the Data Controller and will be legally based on your free, express and unambiguous consent.
H. Transfer of data to third parties for independent marketing purposes: Processed data: name, surname, email address, telephone number.
Legal basis and lawfulness of processing: consent of the data subject pursuant to Article 6(a) of the Regulation – the Processing of your Personal Data shall be carried out by the Data Controller and shall be legally based on your free, express and unambiguous consent. The contact methods used for direct and/or indirect marketing activities may be either automated (e-mail) or traditional (telephone calls with operator). In any case, you may object to the processing and/or revoke your consent, even partially, e.g. by consenting only to traditional contact methods.
TREATMENT MODALITIES
Your data will be processed with logic related to the above-mentioned purposes and, in any case, in such a way as to guarantee the security and confidentiality of the data.
Personal data transmitted by you by e-mail or by telephone contact to request information about the services offered by the Controller will be processed, also in electronic form, only by staff appointed for that purpose.
The management and storage of personal data will take place on servers of the Data Controller and/or of third-party companies appointed and duly designated as Data Processors pursuant to Article 28 of the Regulation.
Servers are currently located in the European Union and data will not be transferred outside the European Union. In any case, it is understood that, should it be necessary to transfer the location of the servers to non-EU countries, this will always be done in accordance with Articles 45 et seq. of the Regulation and in compliance with the applicable national legal provisions, stipulating, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses provided by the European Commission.
The site also incorporates plugins and/or buttons in order to enable easy sharing of content on social networks.
When you visit a page on our website that contains a plugin, your browser connects directly to the servers of the social network from where the plugin is loaded and the server can track your visit to our website and, where appropriate, associate it with your social network account, particularly if you are logged in at the time of your visit or if you have recently browsed one of the websites containing social plugins.
If you do not wish the social network to record data about your visit to our website, you must log out of your social account and delete the cookies that the social network has installed in your browser. Plugins are installed on this site with advanced privacy protection functions for Users, which do not send cookies and access the cookies on the User’s browser not when the page is opened, but only after clicking on the plugin.
The collection and use of information by social networks is governed by their respective privacy policies, to which please refer.
SUBJECTS TO WHOM YOUR DATA MAY BE DISCLOSED
Your data may be communicated to certain third parties who have been formally appointed by the data controller and who have been appointed as ‘data processors’, in accordance with the provisions of the law and the contractual relationship with the data controller, in order to allow the fulfilment of legal obligations for the management of the information system and for the protection of the legitimate interests of the data controller.
It is understood that the Processors will only be provided with the data necessary to be able to fulfil the service.
For the fulfilment of specific obligations under current legislation, your data could also be communicated to Formamentis S.p.A. Società Benefit, as Data Controller’s parent company, specifically appointed responsible for the processing of personal data pursuant to art. 28 GDPR.
A list of external Processors is available from the Data Controller.
PRESERVATION
The data collected will be kept for a period of time no longer than is necessary for the purposes for which they were collected or subsequently processed, without prejudice to the period provided for by national law for the storage of civil law data only and the fulfilment of any other legal requirements.
The data you provide for marketing purposes, on the other hand, will be stored for no longer than 2 years.
Thereafter, your data will be deleted or anonymised and processed for aggregate and anonymous statistical analysis.
RIGHTS OF THE DATA SUBJECT
As provided for in Articles 15 to 21 and 77 of the Regulation, you may at any time exercise the following rights:
A. obtain the indication:
a) the origin of the personal data, the purposes and methods of processing;
b) the logic applied in the event of processing by electronic means;
c) the identity of the data controller, data processors and the persons or categories of persons to whom the personal data may be communicated or who may become aware of them in their capacity as data processors or persons in charge of processing;
B. request from the data controller access to and rectification, updating, integration, erasure or anonymisation of personal data, as well as restriction of the processing of data concerning him/her and the portability of the data;
C. request the blocking of data processed in breach of the law, including data whose storage is not necessary in relation to the purposes for which the data were collected or subsequently processed, and obtain certification that such operations have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, unless this proves impossible or involves a manifestly disproportionate effort compared with the right protected;
D. object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her pursuant to Article 6(1)(e) or (f). The controller shall refrain from further processing the personal data unless he can demonstrate compelling legitimate grounds for processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims;
E. withdraw consent to the processing of your personal data by sending a communication by registered letter with acknowledgement of receipt or by PEC to the data controller;
F. to lodge a complaint/appeal with the Data Protection Authority pursuant to Article 77 of the Regulation.
For the exercise of its rights, it may avail itself of the services of natural persons, entities, associations or bodies, conferring, to this end, a written proxy. To know your rights, file a complaint/complaint/appeal and to be kept up-to-date on the legislation on the protection of persons with regard to the processing of personal data, you can contact the Information and Data Protection Commissioner by consulting the website https://idpc.org.mt/.
CONTACTS
These rights may be exercised by writing to the Data Controller by e-mail to the address privacy@fmtsgroup.it and/or by contacting the Data Protection Officer to the e-mail address dpo@fmtsgroup.it.