In accordance with our commitment and care dedicated to the protection of personal data, we inform you about the methods, purposes, and scope of communication and dissemination of your personal data, as well as your rights, in compliance with Article 13 of the GDPR.
1. CATEGORIES OF PERSONAL DATA PROCESSED BY THE DATA CONTROLLER
To provide you with the services offered by the website, as the Data Controller, we must process some personal data necessary for the provision of services.
These data may be implicitly provided by the tools you use to access and use the services or explicitly provided by you.
We may process the following categories of user personal data:
• technical navigation data related to the IP address, device identifiers used by the user to access the website or services, browser characteristics, and access times;
• navigation data aimed at profiling, indirectly provided through the use of the service and obtained and analyzed with the user's consent;
• common identification data provided by the user (e.g., name, surname, email, phone number, etc.) when required for the use of products and services;
2. PURPOSES AND LEGAL BASES OF PROCESSING
The data and cookies you receive will be processed exclusively with methods and procedures necessary to provide you with the requested or subscribed services and for additional purposes for which you have expressed consent.
In particular, your data may be used to allow your registration on the website and access to all the services offered through the site, when requested.
Following your first registration, where requested and as a necessary condition for the provision of the requested service, you will be able to use the credentials (username/email/password) already used during the first registration.
Additionally, after your registration on the website, your data will be used to enable you to use all the services requested and offered through the site, specifically the ability to send you service notifications, technical communications, and ensure you can manage your preferences and subscriptions.
Only with your express consent may the data be used for statistical analysis, market research, promotional activities via social media, and sending commercial information about products and promotional initiatives. (Direct marketing purposes)
Also with your consent, the data may be used for profiling purposes conducted automatically by collecting information on your navigation during access and use of the service, and by applying statistical correlation algorithms, linking them with similar information from other users to identify common traits and group similar ones into interest categories. By assigning your browser to a class of interest, our systems will then be able to offer you content more aligned with your preferences and present advertising contributions that better match your needs and better target advertisers' interests, reducing the level of disturbance to your user experience.
Finally, with your explicit consent, your data may be provided to other third-party companies for statistical analysis, market research, and sending commercial information about products and promotional initiatives. (Marketing by third parties)
Market research communications or commercial information on products and promotional initiatives may be conducted through postal mail, email, telemarketing, SMS, MMS.
We inform you that some activities may be carried out by suppliers specifically appointed as Data Processors, including those based outside the European Union.
The legal bases of the aforementioned purposes are the execution of a request from you as the data subject and the consents you have expressed.
3. DISCLOSURE, COMMUNICATION, AND PARTIES WITH ACCESS TO DATA
Your personal data will not be disseminated but may be communicated when necessary for the provision of the service to third parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies), appointed, if necessary, as Data Processors for the technical or organizational tasks instrumental to providing the services.
Access to the data is also allowed to categories of staff involved in the organization for data processing (administrative, commercial, marketing, customer service, system administrators).
The updated list of Data Processors can always be requested from the Data Controller.
The right to disclose to third parties remains in place where you have given specific and optional consent.
4. TRANSFER OF DATA ABROAD
Your personal data will be processed within the European Union.
If for technical and/or operational reasons it becomes necessary to use entities located outside the European Union, or it becomes necessary to transfer some of the collected data to technical systems and cloud services managed outside the European Union, the processing will be regulated in accordance with Chapter V of the Regulation and authorized based on specific decisions of the European Union. All necessary precautions will be taken to ensure the fullest protection of personal data, based on such transfers: a) on adequacy decisions of the third-party recipient countries expressed by the European Commission; b) on adequate guarantees expressed by the third-party recipient pursuant to Article 46 of the Regulation; c) on the adoption of binding corporate rules, so-called Corporate Binding Rules.
5. DURATION OF PROCESSING AND RETENTION OF PERSONAL DATA
In accordance with Article 5.1(e) of the GDPR, we will process the data you have provided for the entire duration of the services requested and will retain them for 6 months following the completion of administrative activities, as well as for the time necessary to fulfill legal obligations and protect rights.
If you have authorized profiling, the anonymous data observed from time to time will be deleted 12 months after the start of the processing.
6. DATA SUBJECT RIGHTS
We guarantee that you can exercise your rights at any time as provided for by Article 12 of the GDPR. Specifically, you have the right to:
- know if the Controller holds and/or processes personal data relating to you and to access them in full, even by obtaining a copy (Art. 15 Right of Access);
- request the correction of inaccurate personal data or the integration of incomplete personal data (Art. 16 Right to Rectification);
- request the deletion of personal data held by the Controller if one of the grounds provided for by the GDPR exists (Art. 17 Right to Erasure);
- request the limitation of the processing of personal data to certain data, if one of the grounds provided for by the Regulation exists (Art. 18 Right to Restrict Processing);
- request and receive all your personal data processed by the Controller, in a structured, commonly used, and machine-readable format, or request their transmission to another controller without hindrance (Art. 20 Right to Data Portability);
- object in whole or in part to the processing of data for purposes of sending advertising materials and market research (so-called Consent) (Art. 21 Right to Object);
- object in whole or in part to the processing of data in an automated or semi-automated manner for profiling purposes (so-called Consent).
The exercise of these rights can be carried out by communicating with the Data Controller/Data Protection Officer whose contact details are provided in the relevant section of this notice.
Additionally, you always have the right to lodge a complaint with the Data Protection Authority, which can be contacted at garante@gpdp.it or through the website http://www.gpdp.it.
7. DATA CONTROLLER
To exercise your guaranteed rights, you can contact the following details:
EvK2CNR, Via San Bernardino, 145 Bergamo (Italy), evk2cnr@evk2cnr.org