PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
(Pursuant to Articles 13 and 14 of EU Regulation 2016/679 – GDPR)
We wish to inform you that EU Regulation 2016/679 (the “General Data Protection Regulation” or “GDPR”) provides for the protection of natural persons with regard to the processing of personal data. In compliance with this legislation, the processing of your data will be based on the principles of fairness, lawfulness, transparency and the protection of your privacy and your rights.
- Data Controller
The Data Controller is Smartkiosk Italy Srl, with its registered office at Via A. Modigliani 32 – 56010 Vicopisano (PI), VAT No./Tax Code 02157160504, in the person of its current legal representative.
Contact details: Email: amministrazione@smartkiosk.eu | Certified email (PEC):legal@pec.smartkiosk.eu | Telephone: 0587 294486 - Types of Data Processed
The Data Controller processes personal data relating to identification, contact details and tax information (for example: first name, surname, company name, address, telephone number, email address, bank and payment details) concerning the data subject or internal contacts/employees, as provided when establishing a pre-contractual or contractual relationship. - Purposes and Legal Basis for Processing
Your personal data is processed without your express consent for the following purposes:
a) Performance of the contract or pre-contractual measures: for the management of quotations, the entry of personal details, the fulfilment of contractual obligations and the provision of the requested services/products. (Legal basis: Article 6(1)(b) of the GDPR).
b) Compliance with legal obligations: to comply with civil, fiscal, accounting, tax or social security obligations laid down by national or EU legislation. (Legal basis: Article 6(1)(c) of the GDPR).
c) Pursuit of a legitimate interest of the Data Controller: for the protection of rights and the management of judicial or extrajudicial disputes; for the verification of economic and financial reliability; for internal organisational communications. (Legal basis: Article 6(1)(f) of the GDPR). - Methods of Processing
The processing of personal data is carried out by means of the operations set out in Article 4(2) of the GDPR, namely: collection, recording, organisation, storage, consultation, processing, modification, selection, retrieval, comparison, use, interconnection, blocking, disclosure, erasure and destruction of data. The data is processed both on paper and electronically and/or automatically, with appropriate security measures in place to ensure the confidentiality and integrity of the data. - Data Retention Period
The Data Controller will process personal data for as long as is necessary to fulfil the purposes set out above and, in any event, for no longer than 10 years from the termination of the contractual relationship, in accordance with statutory obligations regarding the retention of accounting records and civil law documents (Article 2220 of the Italian Civil Code). - Scope of Disclosure and Access to Data
Your data may be made accessible or disclosed for the purposes described above to:
- Employees and staff of the Data Controller, in their capacity as authorised data processors who have received specific training.
- Third-party companies or other entities carrying out outsourced activities on behalf of the Data Controller (e.g. professional firms specialising in employment, tax or legal consultancy, credit institutions, shipping and logistics companies, IT maintenance companies), duly appointed as External Data Processors pursuant to Article 28 of the GDPR.
- Judicial authorities, supervisory bodies and public authorities pursuant to specific legal obligations.
Your data will not be disclosed to unspecified parties.
- Transfer of Data Abroad
Personal data is stored on servers located within the European Union. It is understood that the Data Controller, should it become necessary, shall have the right to move the servers outside the EU. In such a case, the Data Controller hereby guarantees that the transfer will take place in accordance with the applicable legal provisions (e.g. Standard Contractual Clauses approved by the European Commission). - Rights of the Data Subject
At any time, you may exercise, in accordance with Articles 15–22 of the GDPR, the right to:
- Request access to your personal data and obtain a copy of it.
- Have inaccurate data rectified or incomplete data completed.
- Request the erasure of your data (right to be forgotten) where the conditions set out in Article 17 of the GDPR are met.
- Request the restriction of processing in the circumstances set out in Article 18 of the GDPR.
- Request the portability of your data in a structured, machine-readable format.
- To object to the processing at any time on grounds relating to your particular situation.
To exercise your rights, you may send a written request to the Data Controller’s contact details set out in point 1.
- Right to lodge a complaint
Any data subject who considers that the processing of their personal data infringes the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it), as provided for in Article 77 of the GDPR, or to bring the matter before the appropriate courts (Article 79 of the GDPR).
