Privacy Policy
MARKETING INFORMATION AND CONSENT MANAGEMENT
Pursuant to and for the purposes of Arts. 13 and 14 of EU Regulation 2016/679 regarding the protection of natural persons with reference to the processing of personal data, Sinergest S.r.l., as data controller, informs You that we hold, process and store the personal data listed below in relation to the activities we carry out in Italy such as the design, development and maintenance of software and the design and provision of organizational consultancy services and for the implementation of management systems.
We respect Your privacy and therefore not only properly protect Your personal data, but in accordance with the aforementioned Regulation, we conduct processing and storage according to the principles of fairness, lawfulness, transparency and the protection of Your confidentiality and rights. The following describes how we collect, process and possibly share Your personal data. Such processing complies with the principles of fairness, lawfulness, transparency and the protection of Your confidentiality and rights.
DATA CONTROLLER
The Data Controller to whom You may apply to assert Your rights is the Company Sinergest S.r.l., in the person of its legal representative pro tempore, with registered office at Via Pesciatina 91/A, 55012, Capannori (LU) – VAT No. 01828190460 – REA LU 222938.
TYPES OF DATA PROCESSED AND PURPOSES OF PROCESSING
The processing operations may concern:
- identity data (first name and last name)
- contact data (telephone, e-mail)
All these personal data will be collected by Sinergest S.r.l. directly from You on the occasion of events and business meetings (conferences, courses, webinars, contact forms on websites and landing pages, etc.) or from our website, where You may enter Your data to obtain information about our products and services.
The processing of Your personal data is necessary to pursue purposes related to either a pre-contractual negotiation or a contractual relationship or legal obligations or marketing activities related to the dissemination of our products and services.
By way of example but not limited to, some purposes related to marketing activities are more specifically identified as follows:
- communications of information about our products or services following specific requests from You;
- responses to Your requests to enable You and/or to allow You to evaluate the product and/or consultancy activity for the purpose of purchasing goods and/or services;
- communications of information regarding the use of products/equipment and for Your possible participation in courses and/or events on product use;
- communications regarding product innovation;
- communication and invitation to training/information events and webinars;
- communications to make known new technologies related to our products; monitoring of any interaction You have with us in relation to the aforementioned cases.
Your data will in any case not be subject to automated decision-making or profiling.
We specify, in order to demonstrate how we protect Your personal data according to the principles of fairness, lawfulness, transparency and the protection of Your confidentiality and rights, that for any additional purpose not strictly related to those listed, we will provide You with a further and new privacy notice that will include the new purposes before proceeding with the processing of Your personal data.
NATURE OF THE PROVISION, CONSEQUENCES OF ANY REFUSAL AND LEGAL BASIS FOR PROCESSING
The processing of Your personal data, the purposes of which were already listed in the previous paragraph, is generally based on our legitimate interest and, in any case, on Your consent which allows the processing of Your data for marketing purposes.
With regard to marketing purposes, the legal basis, in addition to resting on Sinergest S.r.l.’s legitimate interest — which lies in our intention to improve our products and organizational consultancy services — is constituted by Your consent, which You may therefore grant or not grant for the processing of Your data for the indicated marketing purposes by ticking the relevant box with the relative option, as provided at the end of this notice. It is understood, however, that in the absence of consent we will not be able to process Your data for marketing purposes and therefore all related marketing activities that require Your consent will be prohibited to us.
PROCESSING METHODS
We have implemented appropriate technical and organizational measures also pursuant to Arts. 5 and 32 of the Privacy Regulation to protect Your personal data from data breaches, i.e., from unlawful access and/or losses due to accidental behavior and/or destruction, etc.
The number of people with access to Your personal data is limited. Specifically, the data may be collected, stored and processed for the above purposes by our employees who have been duly authorized and instructed for this purpose.
The data may also be disclosed, to the strictly necessary extent, to parties designated by us who intervene in the marketing process (e.g., organization of events, courses, conferences, webinars, etc.) or who we have appointed for maintenance and assistance activities concerning our web presence and/or the software products we use for this purpose (HubSpot; for more information on data processing see https://legal.hubspot.com/privacy-policy).
LOCATION OF PROCESSING
The data are processed and stored at the Company’s premises by authorized employees acting under the instructions given by the Data Controller. They may possibly be processed at the premises where professionals and/or companies linked to the Data Controller by a co-controller relationship and/or external responsibility operate, if any, specifically appointed for this purpose, or by the software products we use for this purpose (HubSpot; for more information on data processing see https://legal.hubspot.com/privacy-policy).
RETENTION PERIOD
The Data Controller retains and processes Your personal data for the time necessary to fulfill the indicated purposes or, by way of example, for the performance of a concluded contract, for participation in an event, as better specified above in relation to the purposes.
TRANSFER OF DATA ABROAD
The parties involved are or will be, by 2022, within the European Union and therefore Your data will not be disclosed to non-EU countries or international organizations. (For more information on data processing through the HubSpot platform please refer to the notice at https://legal.hubspot.com/privacy-policy).
Your personal data processed by Sinergest S.r.l. as Data Controller will not be disclosed for any reason nor used for purposes other than those previously described.
DATA SUBJECT’S RIGHTS
With regard to personal data, You may exercise, as a data subject, the rights referred to in Arts. 15 et seq. of Regulation (EU) No. 679/2016, specifically:
- access Your data (in full and also obtaining a copy) and know whether the Data Controller holds and/or processes personal data relating to You. On such occasion You also have the right, among other things, to obtain access to Your personal data and information relating to the purposes of processing, the categories of personal data in question, the recipients or categories of recipients to whom the personal data have been or will be disclosed;
- verify, update and obtain rectification of inaccurate data or the completion of incomplete personal data without undue delay;
- obtain the deletion or removal of Your personal data;
- obtain restriction of processing;
- receive Your data in a structured, commonly used and machine-readable format, or request transmission to another controller without impediment (right to portability);
- object to the processing of data;
- withdraw Your consent at any time.
It should also be noted that the limitation or deletion of personal data or the lack of consent to the processing of personal data affects or may affect the execution of all the marketing purposes already stated.
If you therefore have questions about how we process the personal data concerning You, you may contact us at the following e-mail address privacy@sinergest.com or send us a registered letter with return receipt to Sinergest S.r.l., Via Pesciatina 91 A – 55012 Capannori – Lucca, kindly indicating on the envelope “For the attention of Privacy Manager”.
If you have objections or complaints regarding the way we process Your personal data, while you of course have the right to lodge a complaint with the supervisory authority for the protection of Your data, we kindly ask You to contact us first so that we can verify and resolve with You any problem or concern.
CANDIDATE PRIVACY NOTICE
Pursuant to and for the purposes of Arts. 13 and 14 of EU Regulation No. 679/2016 regarding the protection of natural persons with regard to the processing of personal data.
DATA CONTROLLER, DATA PROCESSOR AND PRIVACY COMMUNICATIONS
The Data Controller is Sinergest S.r.l. Via Pesciatina 91A – Lunata 55012 Capannori (LU) – T. +39 0583 378530 – F. +39 0583 1770139 – VAT No. 01828190460 (privacy@sinergest.com).
PURPOSES OF PROCESSING
The personal, identification and curriculum data collected from the data subject or from third parties that the Data Controller may use for selection procedures are processed and used for pre-contractual purposes and, more precisely, to verify the prerequisites for hiring and/or initiating a collaboration.
In the case of targeted recruitments, it is specified that the Data Controller will process, within the collection of your personal data, only the information concerning membership of a protected category, without collecting any special categories of data relating to health.
PROCESSING METHODS
Data processing is carried out by electronic, telematic and paper-based means.
NATURE OF THE PROVISION AND CONSENT
Providing the data is optional and is left to the candidate’s choice. Failure to provide the data will make it impossible to verify the prerequisites for hiring and/or initiating the collaboration and, therefore, to establish a relationship with the Data Controller.
DISCLOSURE AND DISTRIBUTION
The collected data will not be disseminated. The data may be disclosed to third parties identified and appointed pursuant to Art. 28 of Reg. 2016/679, specifically designated as data processors.
RETENTION PERIOD
The data will be retained by the Data Controller for no longer than two years from their collection, except in the event of the establishment of an employment or collaboration relationship.
DATA SUBJECT’S RIGHTS
At any time You may exercise Your rights against the Data Controller by contacting privacy@sinergest.com, for example to request confirmation of the existence of data, their purposes, updating, deletion, or to exercise Your right of objection, file a complaint, etc.
Among the rights recognized to You by the GDPR are the following:
– Art. 15 right of access;
– Art. 16 right to rectification;
– Art. 17 right to erasure (“right to be forgotten”);
– Art. 18 right to restriction of processing;
– Art. 20 right to data portability;
– Art. 21 right to object;
– Art. 22 right to object to automated decision-making (including profiling);
– The data subject also has the right to lodge a complaint with a supervisory authority pursuant to Art. 77 of Regulation 679/2016.
Introduction
Knowing how to protect privacy is crucial to offering real business prospects to those who use Internet technology and fundamental to allowing a mutual relationship of trust to grow.
This privacy notice has been prepared by Sinergest S.r.l. to emphasize its commitment to protecting the right to privacy of all those who choose Sinergest products/services or who contribute to their creation, and it governs in detail the processing of personal data that the organization carries out as a corporate entity.
Sinergest S.r.l. commits to protecting the privacy of customers and suppliers and declares itself responsible for the security of the processed data.
This notice therefore establishes the following:
- Which personal data are collected and processed in relation to the relationship with Sinergest S.r.l. as a customer and/or supplier, through the purchase of products and services.
- For the use of our website and landing pages, please refer to the specific notices published;
- Sinergest reserves the right to manage additional notices for specific cases (e.g., employees, marketing activities, etc.).
All personal data are collected and processed in compliance with Italian and EU data protection laws.
INFORMATION ON THE PROCESSING OF PERSONAL DATA (CUSTOMERS & SUPPLIERS)
Pursuant to Articles 13 and 14 of the General Regulation (EU) 2016/679 on data protection (“GDPR”)
Data subjects: customers and suppliers, including potential ones (natural persons or, in the case of legal persons, their company contacts).
This document sets out the methods and purposes of the processing of Your personal data carried out within the scope of Your customer/supplier relationship with Sinergest S.r.l., as well as any additional information required by law, including information about Your rights and how to exercise them.
Your personal data will be processed by Sinergest S.r.l., with registered office in Italy at Via Pesciatina 91/A 55012 Capannori (LU), VAT/Tax ID 01828190460, as the “data controller”, a company registered in the Lucca Companies Register, REA No. 222938 (hereinafter also the “Controller” or the “Company”), in full compliance with the provisions laid down (i) by EU Regulation 2016/679 (the “GDPR”), (ii) by Legislative Decree No. 196/2003, as last amended by Legislative Decree No. 101/2018 (the “Privacy Code”) and (iii) by the provisions of the Italian Data Protection Authority (collectively, the “Privacy Legislation”); such processing will also be based on the principles of fairness, lawfulness, transparency and protection of Your confidentiality and Your rights.
Article 4(1) of the GDPR provides that “Personal Data” means any information relating to an identified or identifiable natural person: the Data Subject.
Article 4(1) of the GDPR provides that “Special Categories of Personal Data” means any information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, as well as genetic data, biometric data intended to uniquely identify a natural person, data concerning health, or data concerning a person’s sex life or sexual orientation.
“Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (Art. 4(2) GDPR).
Pursuant to Articles 12 et seq. of the GDPR, by means of this Notice the Data Subject is informed of the appropriate information relating (i) to the Processing activities carried out by the Controller and (ii) to the Data Subject’s rights.
1. Nature and categories of data processed
For the pursuit of the purposes more specifically identified in section 2 below (“Purposes of Processing”), the Company may process Your Personal Data of a “COMMON NATURE”, including mainly: identification and registry data (e.g., first name, last name), contact data (e.g., telephone number, e-mail address, certified e-mail), data relating to duties, roles, assignments, and work experience.
During the execution of a client-software project, Sinergest may collect personal data when the organization (client, supplier) signs a contract, creates accounts on proprietary software, requests a product demo, or when it contacts the Company, directly or via web solutions.
In such cases, we may collect the following categories of information:
- Organizational identification data, relating both to the main office and any secondary offices, bank details and payment references, identification data of the legal representative, names of company contacts, e-mail address, telephone number, details relating to the assignment entrusted to us / agreement signed;
- Communications exchanged with the Company or via letters, chat service, telephone calls and social media.
- E-mail addresses. Anyone who voluntarily provides their e-mail address will receive communications from Sinergest by e-mail. We do not share the provided e-mail address with operators who are not part of Sinergest’s partner company group. It is possible to stop receiving e-mails at any time by revoking consent and sending a simple message to privacy@sinergest.com. It should also be noted that the user may have configured their e-mail application so that their data are transmitted automatically when sending an e-mail to Sinergest.
- Location, including the real-time geographic position of the computer or device used via GPS, Bluetooth, and IP address, along with crowd-sourced Wi-Fi hotspot data and transmitter locations, if the user uses location-based features and enables geolocation services on their device and computer.
- Log data. Data concerning accesses (logon and logoff to applications).
- The use of one of our software applications may involve recording the user’s IP address and the use of other technologies to collect general information about users and information on application usage, such as IP addresses. IP addresses are used for diagnosing malfunctions and administering servers. IP addresses or other data, such as user-entered information and data shared within Sinergest applications or provided in other circumstances, may also be used to determine which modules of our applications are visited and what the interests of a particular user are, in order to provide information about products and services that match their preferences.
- As a rule, Sinergest aggregates such data only in anonymous form and does not link them to a particular user, except where the user has given their express consent. When the user uses our applications, we are informed of the user’s name and of all data recorded in the database, including the notes fields.
- Sinergest may also collect IP addresses (and other technical information such as browser type) during a Call Conference / Terminal Server session initiated by the user. Such information is collected at the time of connection to Sinergest and allows us to identify the session, provide content based on the technical capabilities of the browser used by the user and to perform quality checks. The user’s IP address will never be used to identify their personal identity without their prior consent. Sinergest will collect only information related to the use of the software products.
- Use of software for remote assistance. Sinergest provides the possibility of using programs that allow a remote desktop connection to the customer’s computer (e.g., TeamViewer). Such programs allow file transfer to and from the customer’s PC. Upon downloading and starting the software, the user’s PC ID for access is generated; Sinergest accesses it using its own password. The program can enable a video conference. At the end of the support session the customer closes the program (which remains in the download area) and thus terminates the connection.
1.1 CONSENT
- In certain circumstances and in accordance with the applicable legal requirements, express consent will be requested for the processing of information collected or voluntarily provided by the customer/supplier.
2. Purposes of processing
The Processing of Your Personal Data is aimed at managing Your contractual/pre-contractual relationship with the Company and the consequent fulfillment of legal and tax obligations, as well as being intended for effective management of financial and commercial relationships.
Processing may also be aimed at pursuing any other legitimate interest of the Data Controller (e.g., for the exercise and/or defense of a right in judicial, administrative proceedings or in arbitration and conciliation procedures; to ensure the security of access to the Controller’s premises, etc.) and, in any case, at fulfilling legal obligations to which the Controller is subject, in particular civil, fiscal and accounting obligations, as well as implementing provisions issued by the tax administration or by authorities or supervisory bodies lawfully empowered to do so.
The Company carries out direct marketing activities by sending communications via e-mail; in any event, should such services be activated in the future, the Company will request specific and explicit consent before starting any Processing activity. In these cases, the legal basis for processing will be the consent of the Data Subject and refusal to give consent will not have any consequences, in particular for the proper performance of the contract. Furthermore, any consent given for processing for marketing purposes may be revoked at any time without prejudice to the lawfulness of processing carried out prior to the revocation.
The Company may nevertheless send e-mails pursuant to Article 130(4) of Legislative Decree 196/2003 – Privacy Code as amended – to promote products or services similar to those provided within the contractual relationship (so-called soft spam), provided that the data subject does not object to such use, initially or on the occasion of subsequent communications (Marketing purposes on similar products/services).
3. Legal basis
The processing of Personal Data for the purposes referred to in section 2 (“Purposes of Processing”) does not require the Data Subject’s consent because such processing is necessary to execute pre-contractual measures / the contractual relationship between the Company and You (i.e., the Customer/Supplier of Sinergest S.r.l. for whom You are the contact) and to allow mutual fulfillment of the obligations arising therefrom, as well as to enable the Company to comply with legal obligations and/or to pursue the Company’s legitimate interest in carrying out its business activities.
4. Processing methods
In accordance with Article 5 of the GDPR, the Personal Data subject to Processing are:
- processed lawfully, fairly and in a transparent manner with respect to the Data Subject;
- collected and recorded for specified, explicit and legitimate purposes and subsequently processed in a manner compatible with those purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- accurate and, where necessary, kept up to date;
- processed in a way that ensures an appropriate level of security;
- kept in a form that permits identification of the Data Subject for no longer than is necessary for the purposes for which the data are processed.
Personal Data will be processed by the Controller using automated, electronic, IT or telematic tools, and non-automated means on paper. Specific security measures are observed to prevent data loss, unlawful or incorrect use, and unauthorized access.
Automated decision-making processes pursuant to Art. 22 of the GDPR will not be used.
5. Provision of personal data
In general, the provision of Personal Data is necessary for the negotiation, establishment, management and performance of the customer/supplier contractual relationship with the Company.
Refusal to provide Personal Data, in fact, results in the Controller being objectively unable to carry out the contractual relationship and/or to properly perform all obligations required by law and/or by the contract.
6. Retention period of personal data
Personal Data are kept for the time strictly necessary to achieve the purposes for which they were collected and processed on the basis of the purposes set out in section 2 (“Purposes of Processing”) of this information document. As a general principle, therefore, Personal Data will be retained for the period of time necessary for the performance of the contract.
However, it is understood that once the contractual (or pre-contractual) relationship with the Company and, with it, the related purposes of Processing have ended, the Controller will still be obliged or entitled to retain Personal Data, in whole or in part, for certain purposes, as expressly required by specific contractual provisions (e.g., obligations of a continuing nature) or for legal obligations, in particular fiscal and tax obligations, and for the possible assertion and/or defense, including in court, of the Company’s rights (e.g., in case of possible disputes raised by the Data Subject regarding the contract signed with the Company).
7. Disclosure of personal data
Personal Data will be accessible, within the scope of their respective functions, to the Controller’s employees and collaborators (e.g., staff) duly designated for the performance of specific tasks and/or functions as authorized persons, to external collaborators and to service providers for the Controller, appointed as processors, to whom specific written instructions have been given, to the extent strictly necessary for the pursuit of the purposes referred to in section 2 (“Purposes of Processing”) of this information document.
The data collected and processed may therefore be disclosed exclusively for the purposes specified above to:
- Banks/financial institutions for the management of collections and payments;
- Corporate consultants and freelance professionals, even in association with each other, who collaborate with the Controller (e.g., accountants, statutory auditors and administrative, tax and contractual consultants);
- Insurance companies;
- Public authorities in order to comply with regulatory obligations.
Sinergest limits the volume of personal data disclosed to the aforementioned third-party providers to the minimum necessary to provide the service on behalf of Sinergest, and such third parties are not authorized to use the personal data communicated to them except for the purposes strictly limited to the execution or performance of the service or transaction entrusted to them.
Sinergest may collect and possibly share personal data and other information in its possession to carry out investigations, prevent or take legal action against illegal activities, suspected fraud, situations that pose a potential risk to the physical safety of any person, violations of terms of use on Sinergest products and services or in other cases provided by law. Sinergest therefore reserves the right to disclose personal data or other collected information when necessary to respond to a subpoena, order or decree or when necessary to appear in court. Sinergest also reserves the right to assert or exercise its legal rights, or to defend itself in legal proceedings.
The obligation to protect the privacy and confidentiality of users’ data extends to all our employees.
As stated above, we may disclose user information to trusted third parties for the purposes set forth in this Privacy Notice. We require all third parties to adopt adequate technical and operational security measures to protect personal data, consistent with Irish and EU data protection laws. It is Sinergest’s established practice to ask such providers and business partners to handle data and information collected in ways that are compatible with the Sinergest Privacy Notice.
The list of data processors appointed by the Controller is available upon request by the Data Subject (privacy@sinergest.com).
8. Dissemination of personal data
The Data Subject’s Personal Data are not subject to dissemination. Sinergest may publicize the existence of the contractual relationship with customers and suppliers; for this purpose a specific authorization will be requested.
9. Transfer of personal data abroad
Your Personal Data may be transferred outside the European Union for the use of Google and Microsoft services.
10. Protection of minors’ privacy
Sinergest does not intentionally and knowingly collect personal data of minors under the age of 13. If it becomes aware that it has collected personal data belonging to minors under 13 years of age, it will immediately delete them from its servers.
11. Rights of the Data Subject
As Data Subjects, identifiable natural persons to whom the processed data refer may exercise the rights recognized by the Privacy Legislation and, in particular:
- right of access, that is the right to obtain from the Company confirmation as to whether or not processing of personal data concerning them is being carried out and, where that is the case, to obtain access to the data (Art. 15 GDPR) – In particular, the Data Subject has the right to obtain indication of (i) the origin of the personal data; (ii) the purposes and methods of processing; (iii) the logic applied in case of processing carried out with the aid of electronic tools; (iv) the identification details of the Controller, the processors (Art. 4(8) GDPR) and the data protection officer (DPO) appointed by the Controller pursuant to Art. 37 of the GDPR; (v) the recipients or categories of recipients to whom the Personal Data may be disclosed or who may become aware of them as processors or (possible) appointees or (possible) representatives designated within the territory of the State;
- right to rectification, that is the right to obtain the rectification of inaccurate data and/or the completion of incomplete personal data (Art. 16 GDPR);
- right to erasure, that is the right to obtain the deletion, anonymization or blocking of data processed in violation of the law, including data that do not need to be kept for the purposes for which they were collected or subsequently processed in certain circumstances provided by law (Art. 17 GDPR);
- right to obtain confirmation that the operations referred to in letters b) and c) have been communicated, also with regard to their content, to those to whom the data have been disclosed or disseminated, unless this proves impossible or involves the use of means manifestly disproportionate to the protected right;
- right to restriction of processing, that is the right to object to processing or to obtain the restriction of processing of Personal Data under the law (Art. 18 GDPR);
- right to be informed of rectifications and erasures and of restrictions on the processing of Personal Data (Art. 19 GDPR);
- right to portability, that is the right to receive Personal Data in a structured, commonly used and machine-readable format and the right to transmit the data to another controller – this right to “portability” applies only to Personal Data provided by the Data Subject and may be subject to certain restrictions as provided by the Privacy Legislation (Art. 20 GDPR);
- right to object, that is the right to object to processing of data where there are legitimate grounds, including with reference to data processing for marketing and profiling purposes, if provided (Art. 21 GDPR);
- right to withdraw consent previously given, at any time, without prejudice to the lawfulness of processing based on consent given before the withdrawal (Art. 7 GDPR);
- right to compensation, that is the right to obtain full and effective compensation from the Controller and/or the Processor for damage suffered, material or immaterial (financial loss, identity theft, discrimination, etc.), if caused by the processing of the Data Subject’s personal data in violation of the Regulation and the Controller and/or the Processor are unable to demonstrate that the harmful event is not attributable to them (Art. 82 GDPR);
- right to lodge a complaint with the Data Protection Authority (Piazza Venezia, 11 – 00187 Rome RM – PEC: protocollo@pec.gpdp.it) in case of unlawful processing (Art. 77 GDPR)
- subject to the limits set out in Legislative Decree No. 101/2018, Art. 2-undecies (Limitations to the rights of the Data Subject) and Art. 2-duodecies (Limitations for reasons of justice).
Personal data breach.
The Data Controller is required to:
- notify any security breach that accidentally or unlawfully leads to the destruction, loss, alteration, unauthorized disclosure or access to personal data transmitted, stored or otherwise processed to the Data Protection Authority without undue delay and, where possible, within 72 hours from the moment it became aware of it, unless it is unlikely that the breach poses a risk to the rights and freedoms of natural persons. If this time limit is not met, the breach notification must be accompanied by reasons for the delay. For the minimum content of the notification, refer to the provisions of Art. 33 of the GDPR;
- communicate the personal data breach to the Data Subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons, except in cases provided for in Art. 34 of the GDPR.
12. Data Controller
The Data Controller is Sinergest S.r.l., with registered office in Italy, VAT No. 01828190460, contactable at the following details:
– Tel.: +39 0583 378530;
– E-mail: privacy@sinergest.com;
– P.E.C.: info@pec.sinergest.com;
– Postal address: SINERGEST S.r.l., Via Pesciatina 91/A 55012 Capannori (LU).
13. Communications and exercise of the Data Subject’s rights
To exercise the rights referred to in section 11 (“Rights of the Data Subject”), You may submit a written request, without formality, to the Controller by sending a communication to the following e-mail address: privacy@sinergest.com
14. Changes to the privacy notice
Our Privacy Notice is subject to periodic reviews and may be amended in light of changes in management; any changes will be communicated to the user via a notice on our website.
Last Update 23/02/2023
Privacy Policy of the Website [www.sinergest.com](http://www.sinergest.com)
Information on the processing of personal data
Welcome to www.sinergest.com. By means of this notice, Sinergest S.r.l., in its capacity as Data Controller, informs You that, pursuant to and for the purposes of Art. 13 of EU Regulation 679/2016 (General Data Protection Regulation, hereinafter GDPR), the data acquired and/or provided by You will be processed in accordance with applicable national and European legislation on the processing of personal data and always respecting the principles of transparency, lawfulness, fairness and the protection of Your confidentiality and rights.
Data Controller
Pursuant to Arts. 4 and 24 of the GDPR, the Data Controller is:
Sinergest S.r.l. with registered office at Via Pesciatina, 91/A – 55012 Capannori (LU), Italy
Email address: privacy@sinergest.com
Tel. +39 0583 378530 – Fax. +39 0583 1770139
Types of data collected and purposes of processing
Specifically, the personal data processed through the website are as follows:
- a) data provided directly by You via the “CONTACTS” section (name, e-mail address, company, telephone and any other data You voluntarily provide in the “message” field). Such data are used exclusively to carry out Your requests.
- b) data sent optionally, explicitly and voluntarily to the e-mail address indicated on the site. In this case the sender’s e-mail address is acquired (necessary to reply to the request), as well as any other personal data included in the message. Such data are used exclusively for the purpose of responding to Your requests.
- c) any personal and “special” data contained in CVs that may be submitted to the addresses indicated on the site or via the “WORK WITH US” area (name, surname, e-mail and any other data You voluntarily provide in the “message” field). In this case, the Data Controller – in accordance with the measures and guidelines of the Authority – will provide information on the processing of data contained in CVs at the first useful contact with the candidate.
- d) browsing data. The IT systems and software procedures used to operate this website acquire, during their normal operation, personal data whose transmission is implicit in the use of Internet communication protocols. These are, however, information that are not collected to be associated with identified data subjects, but which by their nature could, through processing and association with data held by third parties, allow the identification of users. This category of data includes the IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of requested resources, the browser, the time of the request and other parameters relating to the operating system and the IT environment of the user. Such data are used solely to obtain anonymous statistical information on the use of the site and to check its correct functioning and are deleted immediately after processing. (see https://www.sinergest.com/cookie-privacy-policy/).
Purposes and legal basis
The personal data provided will be processed in compliance with the conditions of lawfulness pursuant to Art. 6 of the GDPR for the following purposes:
- to execute Your requests and respond to inquiries submitted via the “CONTACTS” or “WORK WITH US” sections or to the e-mail address indicated on the site. The processing of data collected and stored following the completion of forms or the sending of e-mails is based on the legitimate interest of the Data Controller (Art. 6, letter f) GDPR) to be more efficient, to provide information about the services offered, and to improve and develop new products and services;
- to implement all pre-contractual measures adopted at the request of the data subject as well as all operational and management needs related thereto. The legal basis in this case is the need to execute the contract to which the data subject is a party or to carry out pre-contractual measures (Art. 6, letter b) GDPR);
- to comply with legal obligations to which the Data Controller is subject. In this latter case, the legal basis is the need to fulfill legal obligations that require the Controller to collect and/or further process certain types of personal data (Art. 6, letter c) GDPR);
- the processing of data contained in received CVs is lawful as it is necessary to carry out pre-contractual measures (Art. 6, letter b) GDPR) requested by the data subject. The processing of “special” data is lawful on the basis of the Supervisory Authority’s authorization no. 1/2016, whose effectiveness was extended pursuant to Art. 21 of Legislative Decree 101/2018.
Processing requiring Your explicit consent
With Your prior consent, Your personal data may be processed by the Data Controller for commercial and promotional purposes. If You provide Your consent, You may receive commercial communications via automated contact methods (for example, e-mail).
Processing methods
The Data Controller performs the processing necessary in compliance with national privacy legislation and the GDPR. Data processing is and will be carried out both using paper supports and through electronic and IT tools, but in any case by using tools and procedures suitable to guarantee security and confidentiality, with organizational arrangements and logic strictly related to the indicated purposes.
The Data Controller will process personal data in accordance with applicable security provisions in order to minimize risks of destruction and loss, even accidental, of data; unauthorized access; processing not permitted or not in accordance with the purposes of data collection and unlawful or incorrect use of data.
Nature of provision
Provision of the data required to complete the forms on the site is mandatory in order to send the request and/or use the service and failure to provide them would make it impossible to submit the request and obtain the desired service. The provision of additional data is purely optional.
Data retention
Data are and/or will be processed for the time strictly necessary to fulfill Your requests or – in general – to achieve the purpose for which they were collected. They will also be retained for the duration of the commercial/contractual relationship and thereafter for compliance with legal obligations and/or for administrative, commercial and tax purposes.
Data collected for marketing purposes will be retained for a maximum period of 24 months from the date of last contact. In any case, You may always request the cessation of processing or deletion of the data.
Disclosure and dissemination
We inform You that Your data will not be disseminated, disclosed or made known to unspecified parties in any way, including by making them available.
For purposes related to commercial/contractual needs concerning existing relationships, the data may be disclosed and/or made available to the following subjects:
- persons authorized to process data within Sinergest S.r.l., always according to the instructions given by the Data Controller;
- subjects entitled to access the data by virtue of legal or regulatory provisions or EU legislation, within the limits and for the purposes provided by such rules;
- other service provider companies, as independent controllers or external processors, duly appointed (For more information contact privacy@sinergest.com);
- banks, credit institutions and debt collection companies.
Data transfer
We inform You that Your personal data will not be transferred abroad to non-EU countries that do not ensure adequate levels of personal data protection. If this were necessary to provide You with services or to conclude a contract, the Data Controller ensures that the transfer of Your personal data to such countries will take place only after entering into specific contracts in accordance with applicable law and regulations.
Social Media
Sinergest S.r.l. uses social media for communication purposes related to its services.
Third-party sites accessible via this website are not covered by this notice. To consult the Privacy Policies of these social media platforms, we invite You to visit the following pages:
FACEBOOK: https://it-it.facebook.com/privacy/explanation
LINKEDIN: https://www.linkedin.com/legal/privacy-policy?_l=it_IT
YOUTUBE: https://policies.google.com/privacy?hl=it
TWITTER: https://gdpr.twitter.com/it.html
Data Subject’s rights
Pursuant to Arts. 15 et seq. of EU Reg. 2016/679, You may exercise the following rights:
- to know whether the Data Controller holds and/or processes personal data relating to You and to access them in full and obtain a copy (Art. 15 Right of access);
- to rectify inaccurate personal data or have incomplete personal data completed (Art. 16 Right to rectification);
- to obtain the erasure of personal data held by the Controller if one of the grounds provided by the GDPR applies (Art. 17 Right to erasure);
- to request that the Controller restrict processing to certain personal data if one of the grounds provided by the GDPR applies (Art. 18 Right to restriction of processing);
- to request and receive all Your personal data processed by the Controller in a structured, commonly used and machine-readable format or to request transmission to another Controller without impediment (Art. 20 Right to portability);
- to object to processing (Art. 21 Right to object);
- to lodge a complaint with the competent supervisory authority (for Italy, the Data Protection Authority, https://www.garanteprivacy.it/) if You believe that the processing of Your personal data is contrary to applicable law).
Exercise of Your rights may be carried out by sending a request to the Controller’s e-mail address: privacy@sinergest.com
Updates and changes
The Data Controller reserves the right to make changes to this notice at any time and without prior notice, also taking into account changes in the laws or regulations governing this matter and protecting Your rights. Changes will apply from the date of publication on the website.
We therefore invite You to consult this section regularly to verify publication of the most up-to-date Privacy Policy of the website.
For more information on the processing of data carried out by Sinergest S.r.l. see also the company notice published at www.sinergest.com/privacy.
Appointment of the Data Processor for the processing of personal data pursuant to Art. 28 of EU Regulation 2016/679
Information pursuant to Art. 13 of Regulation (EU) 2016/679 and Art. 3.1 of the Data Protection Authority’s Provision of 8 April 2010
In compliance with Art. 13 of Regulation (EU) 2016/679 (Regulation) and Art. 3.1 of the Data Protection Authority’s Provision of 8 April 2010 (Provision), Sinergest S.r.l. (hereinafter, “Sinergest”), in its capacity as Data Controller,
INFORMS
that at its registered office in Lucca, located at Via Pesciatina, 91/A – 55012 Capannori, a composite video surveillance system is in operation, implemented by means of closed-circuit cameras. The system operates during closing hours and brief notices have been posted in all areas in accordance with the Data Protection Authority’s Provision of 8 April 2010.
Purpose of processing
The personal data of the data subjects, specifically the images acquired through recording, are collected exclusively to pursue a legitimate interest of the organization and to ensure the safety of people and assets.
Processing methods
The data are subject to electronic processing in compliance with appropriate security and data protection measures and always for the purposes described above.
In particular, in the processing of the data, the organization declares that it adheres to the following principles:
- Lawfulness of processing: the processing of data by video surveillance is carried out fairly and for specific and legitimate purposes (protection of company property and organizational and production needs). The systems have been installed and are used in compliance with Art. 4 of Law no. 300/1970;
- Necessity of processing: the organization undertakes not to use the system in an excessive or unnecessary manner;
Proportionality of processing: the data collected are strictly necessary for achieving the purposes indicated in the preceding paragraph.
Communication to third parties and disclosure of data
The data in question will not be disseminated and will not be disclosed except for the protection of a right in judicial proceedings or to the judicial police upon a specific request. The data may be accessed by authorized persons acting on behalf of the organization, who perform the functions necessary for processing the images and/or data or for system maintenance. Management is available for any explanation or clarification.
Furthermore, we inform you that the images are visible only for the aforementioned purposes and in no case may they be used to verify workers’ diligence or for disciplinary measures. Since the recordings are automatic and generalised, a person who enters the surveilled areas cannot avoid being recorded. The images and/or data collected are not cross-checked, associated or interconnected with any other personal data collection system.
Minimum information
Data subjects are properly notified by means of signs (simplified notices) placed in the areas and premises subject to video surveillance. Such signs contain all the information required by Art. 3 of the Provision. We attach the site plans showing the positioning of the systems.
Retention period for images and biometric data
The cameras operate 24 hours a day on Saturdays and Sundays, and during the week from 20:00 to 08:30, periods during which no one is present inside the offices.
The images and/or data are retained for a maximum period of 3 hours. After this period, the images and/or data are automatically deleted by over-recording.
Data Controller
The Data Controller is Sinergest S.r.l..
Designation of the Person Responsible and of the Authorized Processor
The Data Controller has appointed in writing the person(s) authorized to process data, authorized both to access the images and to operate the systems and, when indispensable for the purposes pursued, to view the images and/or make copies, in accordance with Art. 3.3.2 of the Provision. The data may be accessed by personnel appointed within the organization who perform the functions necessary for processing the images or for system maintenance. Management is available for any explanation or clarification.
Rights of the data subject
Data subjects have the right at any time to obtain confirmation of the existence or non-existence of personal data concerning them and to know their content and origin, to verify their accuracy or to request their completion or updating, or their rectification (Arts. 15 et seq. of Regulation (EU)).
Data subjects also have the right to request the rectification of inaccurate personal data, deletion, restriction of processing, data portability, as well as to lodge a complaint with the supervisory authority and to object on legitimate grounds to their processing (Arts. 17 et seq. of the Regulation).
Requests should be addressed to Sinergest S.r.l., Via Pesciatina, 91/A – 55012 Capannori, Lucca. privacy@sinergest.com
Notice pursuant to Arts. 13 and 14 of Regulation (EU) 679/2016 and of the Privacy Code as amended by Legislative Decree 101/2018.
Cookie Notice pursuant to Art. 13 of Regulation (EU) 679/2016 (GDPR) and the Privacy Code as amended by Legislative Decree 101/2018 and Guidelines on Cookies and other tracking tools – 10 June 2021