INFORMATION ON THE PROCESSING OF PERSONAL DATA

ex art. 13 del Regolamento (UE) 679/2016 (General Data Protection Regulation - GDPR)

Pursuant to Arts. 13 and 14 of Regulation 2016/679/UE (hereinafter referred to as “GDPR”) INEO SRL, with registered office in Rome, at via Paolo di Dono 149, 00142, in the person of the pro tempore legal representative dott. Salvatore Mafodda, available at the e-mail address privacy@ineo.it, as “Data Controller” (hereinafter referred to as “Data Controller”) he informs you that in the provision of services and in the context of legal relations relating to his activity, he recognises and respects the right to the protection of personal data, as a fundamental right of the person.

In the current regulatory environment, the ability to maintain control of your information becomes essential and requires a constant and conscious effort to ensure adequate levels of protection of personal data.

È In this regard, it is useful to remember that Regulation (EU) 679/2016 (General Data Protection Regulation - GDPR) defines «personal data» as any information concerning an identified or identifiable natural person («data subject»).

By «processing», according to the GDPR itself, we mean, instead, any operation or set of operations, carried out with or without the aid of automated processes and applied to personal data or sets of personal data, such as the collection, registration, organisation, structuring, preservation, adaptation or modification, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, comparison or interconnection, limitation, cancellation or destruction.

The following information describes the methods and purposes of the processing of personal data of users who access and use the websites www.ineo.it (hereinafter briefly “Site”).

The information is provided only for the Site and not even for third-party websites that may be accessible through hyperlinks (links) contained in the Site.

1. Data Controller and Data Protection Officer

Data controller, pursuant to art. 4 of the GDPR, is INEO SRL, based in Rome, at Via Paolo di Dono 149, 00142, in the person of the pro tempore legal representative dott. Salvatore Mafodda, e-mail address privacy@ineo.it tel. 06.95222271

The Personal Data Protection Officer (DPO) of INEO can be contacted at the following e-mail address dpo@ineo.it by writing to: Data Protection Officer - Ineo S.r.l., via Paolo di Dono 149, 00142 - Rome.

2. Nature of the data provision

To use the services offered through the Site, the user may be required to provide the personal data necessary to ensure the use.

in particular, for the purpose of filling in the forms on the Site, the provision of data marked with an asterisk is necessary for the management and feedback to communications forwarded by the user.

In any case, please note that the user is free to provide the requested data, in the sense that he is not legally obliged to provide them: failure to provide the data indicated as necessary, however, makes it impossible for the Data Controller to render the requested service.

3. Types of data processed and purpose of processing

The processing operations are carried out with reference and limited to the personal data necessary for the use of the Site and its functionalities.

The types of data subject to processing shall include, in particular:

  • navigation data: during the user’s navigation on the Site, the computer systems responsible for its operation automatically acquire certain information whose transmission is implicit in the use of Internet communication protocols. This data category includes the IP addresses or domain names of computers and terminals used by users, addresses in URI/URL notation (Uniform Resource Identifier/Locator) of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (good end, error, etc.) and other parameters related to the user’s operating system and IT environment.

    These data are processed for purposes related to the provision of the services offered through the Site, including the guarantee of proper functioning of the same. The legal basis of the processing is, therefore, constituted by the execution of a contract of which the interested party is a party, pursuant to art. 6, par. 1, lit. b) of Regulation (EU) 679/2016 (GDPR).

    In particular, navigation data are processed for the purpose of:
  • ensure the correct functionality of the Site and the usability of its services;
  • obtain aggregated and anonymised statistical information relating to the use of the Site (such as, for example, the most visited pages, the number of visitors by time or day, geographical areas of origin, etc.).
    For more information on the collection, use and retention time of navigation data, please refer to the cookie policy
    cookie policy
    .
  • data provided voluntarily by the user, ie personal data (identification and/ or contact) provided by users during the use of the website, by filling in the contact forms in the individual sections, where it is required to indicate name, surname and contact details and, optionally, further information such as the indication of your job role and your company and, in particular:
  • name, surname, e-mail address and other personal data, if any, contained in e-mails sent to the addresses indicated on the Site and/or its attachments, in order to carry out the processing activities necessary to respond to your requests;
  • name, surname, and e-mail address provided by filling in the form “contact us” and the registration form for the newsletter service, in order to send periodic information notices, insights into privacy and information security services, as well as more generally for promotional communications of training initiatives and Ineo services;

4. Processing methods, purposes, legal basis and nature of the data processed

Your data are collected and recorded lawfully and correctly for the purposes indicated above in compliance with the principles and requirements of art. 5 c 1 of the GDPR.

Personal data will be processed by INEO for the duration of the assignment and also subsequently to assert or protect their rights or for administrative purposes and/ or to implement obligations arising from the regulatory and regulatory framework pro applicable time limits and in compliance with the specific legal obligations on data retention.

Specific security measures shall be taken to minimise the risk of destruction or loss, including accidental loss, of the data subject to processing, unauthorised access, processing not allowed or not in compliance with the purposes indicated in this statement.In compliance with current legislation on the protection of personal data of the Data Subject will be stored, collected and processed by the Company for the following purposes:

  • fulfillment of contractual obligations, execution and/or conclusion of the contract with the Customer and/or management of any pre-contractual measures [par.3 point 1 and 2];
  • fulfilment of any legal obligations, tax and tax provisions arising from the performance of business activities and obligations related to administrative and accounting activities [par. 3 point 1 and 2];
  • sending newsletters and communications with direct marketing purposes through email, sms, mms, push notifications, paper mail, telephone with operator, in relation to products and services provided [par. 3, point 2].

The legal bases of the processing for the purposes a) and b) indicated above are Articles 6.1.b. and 6.1.c) of the Regulation. The provision of Data for the aforementioned purposes is optional, but any failure to provide the Data and the refusal to provide them would make it impossible for the Company to perform and/ or conclude the contract and provide the services required by the same.The legal basis for the processing of personal data for the purpose b) is art. 6.1.a) of the GDPR as the processing is based on consent; please note that the Data Controller may collect a single consent for the marketing purposes described here.

The provision of consent to the use of data for marketing purposes is optional and, if the data subject wishes to object to the processing of data for marketing purposes carried out by the means indicated herein, as well as revoke the consent given, may at any time do so without any consequence (except for the fact that you will no longer receive marketing communications) by following the indications in the section of the “Rights of the Data Subject” of this Policy.

Finally, please note that for the processing carried out for the purpose of sending direct advertising material or its direct sale or for the performance of its own market research or commercial communications in relation to products or services similar to those used by the Customer, The Data Controller may use e-mail addresses or personal data in accordance with and to the extent permitted by art. 130, paragraph 4 of the Code and the general provisions of the Guarantor Authority for the protection of personal data, even in the absence of explicit consent.The legal basis for the processing of data for this purpose is art. 6, paragraph 1, lett. f) of the GDPR, without prejudice to the possibility of opposing such processing at any time, following the indications present in the section of the “Rights of the Data Subject” of this Policy.

5. Period of retention of data

The data subject to processing will be kept for a period of time not exceeding that necessary to achieve the purposes for which they were collected or subsequently processed and, in particular:

  • the data provided by sending e-mails or filling in the contact forms on the site will be kept for the time necessary to provide feedback;
  • the data provided for the purpose of subscribing to the newsletter service will be processed until the data subject exercises his right of objection pursuant to 21 GDPR;
  • the data processed in order to find a request for information on initiatives, training courses and webinars of the Academy made available on the Site will be kept for a maximum period of 12 months from their provision.

The Data Controller will, after the expiration of the retention periods in accordance with the criteria indicated, take measures to delete or anonymize the data that should not be kept for specific regulatory obligations.

6. Target groups

Within the limits of what is provided for each specific feature and/or for each specific service, the personal data processed by the Data Controller will not be disseminated, that is, it will not be disclosed to indeterminate subjects, in any possible form, including making them available or simply consulting them.

Instead, they may be made accessible to workers and/or collaborators who work for and under the responsibility of the Data Controller, in their capacity as designated and/or authorised to process personal data and/or System Administrators, and/or to third-party companies or other entities that carry out outsourcing activities on behalf of the Data Controller, to this end appointed External Data Processors pursuant to art. 28 GDPR.

The updated list of subjects appointed Data Processors pursuant to art. 28 GDPR may be requested from the Data Controller.

In no case will personal data be disclosed, disseminated, transferred or otherwise transferred to third parties for illicit purposes and, in any case, without making appropriate information to the data subjects and obtaining their consent, where required by law.

This is without prejudice to any communication of data at the request of the judicial or public security authorities, in the manner and in the cases provided for by law.

7. Transfer abroad

In no case will personal data be disclosed, disseminated, transferred or otherwise transferred to third parties for illicit purposes and, in any case, without making appropriate information to the data subjects and obtaining their consent, where required by law. This is without prejudice to any communication of data at the request of the judicial or public security authorities, in the manner and in the cases provided for by law. Personal data will not be transferred abroad, to countries or international organizations not belonging to the European Union that do not guarantee an adequate level of protection, recognized, pursuant to art. 45 GDPR, based on an adequacy decision of the EU Commission. In the event that it is necessary for the provision of the services of the Site, the transfer of personal data to non-EU countries or international organizations, for which the Commission has not taken any adequacy decision pursuant to art. 45 GDPR, will take place only in the presence of adequate guarantees provided by the country or the recipient organization, pursuant to art. 46 GDPR and provided that the data subjects have actionable rights and effective means of redress. In the absence of a decision of adequacy of the Commission, pursuant to art. 45 GDPR, or adequate guarantees, pursuant to art. 46 GDPR, including binding corporate rules, the cross-border transfer will take place only if one of the conditions indicated in art. 49 GDPR.

8. Rights of the Data Subject

The data subject is granted the right to access his or her personal data, to request its rectification, updating and cancellation or limitation, if incomplete, erroneous or collected in violation of the law, as well as to object to processing for legitimate reasons or to obtain its portability.

The interested party, in particular, pursuant to Articles. 15-22 of Regulation (EU) 679/2016, has the right to obtain confirmation of the existence or not of personal data concerning him, even if not yet recorded, and their communication in an intelligible form.

You also have the right to obtain information on:

  • the purposes and methods of processing;
  • the logic applied in the case of treatment carried out with the help of electronic tools;
  • the identification details of the Data Controller, of the Data Controller and of the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of it as authorised data subjects.

The data subject has the right to obtain:

  • the updating, correction or integration of their data;
  • the deletion, transformation into anonymous form or blocking of data processed in violation of the law, including those whose storage is not necessary in relation to the purposes of the processing;
  • the limitation of processing, when one of the hypotheses referred to in Article 18 GDPR applies;
  • proof that the transactions referred to in letters a), b) and c) have been brought to the attention of those to whom the data have been communicated or disseminated, except where such compliance proves impossible or involves the use of means manifestly disproportionate to the protected right;
  • the transmission of data concerning him, provided to the Data Controller and processed on the basis of the consent expressed by the data subject for one or more specific purposes, in a structured format, commonly used and machine-readable. Pursuant to art. 20 of the GDPR, the interested party also has the right to transmit such data to another Data Controller without impediments and, if technically feasible, to obtain the direct transmission of personal data from one Data Controller to the other.
  • if the processing is based on consent, withdraw your consent at any time (pursuant to Article 7, paragraph 3 of the GDPR).

The interested party has the right to object, in whole or in part:

  • for legitimate reasons, to the processing of personal data concerning him, even if pertinent to the purpose of the collection;
  • to automated decision-making processes that significantly affect your person.

Without prejudice to any other administrative or judicial appeal, the interested party has the right to lodge a complaint and / or report to a supervisory authority, particularly in the Member State in which he usually resides, works or in the place where the alleged violation has occurred.

9. Exercise of rights

The above rights are exercised with a request addressed to the Data Controller, directly or through an authorized person, orally or by sending an e-mail message to the e-mail privacy@ineo.it.

The interested party also has the right to contact the Data Protection Officer (D.P.O.) in charge, at the following e-mail address dpo@ineo.it.

The request is formulated freely and without formalities by the interested party, who has the right to receive appropriate feedback within a reasonable time, depending on the circumstances of the case.

The interested party may make use, for the exercise of his rights, of non-profit bodies, organizations or associations, whose statutory objectives are of public interest and which are active in the field of protection of the rights and freedoms of the interested parties with regard to the protection of personal data, giving, for this purpose, a suitable mandate. The interested party can also be assisted by a trusted person.

To find out about your rights, lodge a complaint and always be updated on the legislation on the protection of individuals with regard to the processing of personal data, the interested party can contact the Guarantor Authority for the protection of personal data, by consulting the website at address http://www.garanteprivacy.it/

10. Final provisions

The Owner reserves the right to modify and / or update this Information.

Best regards

The Data Controller

INEO S.R.L.

Information updated in December 2023

INEO Logo White

Via Paolo di Dono, 149 Roma

INEO O Icon

Our staffs always ready to respond to your needs.
Call us at 0695222271, write us at info@ineo.it ore use our dedicated page.

@ Ineo S.r.l.
P. IVA 11010851001