1. Purpose, legal basis of the processing for which the data are intended The processing of the personal data you provide is aimed solely at fulfilling contractual obligations and fulfilling your specific requests, as well as fulfilling regulatory obligations, in particular accounting and tax . For the purposes of the indicated processing, the owner may become aware of data defined as "sensitive" pursuant to EU Reg. 2016/679, such as those suitable for revealing racial or ethnic origin, of any other kind.
2. Processing methods In relation to the aforementioned purposes, your data are subject to computer and paper processing. The processing operations are implemented in such a way as to guarantee the logical, physical security and confidentiality of your personal data.
3. Legitimate interests pursued by the data controller or by third parties
4. Nature of personal data Your personal data, sensitive concerning the performance of the service requested by you, constitute the object of processing. During the provision of the service it may be necessary to acquire and carry out processing operations of your sensitive personal data, you are asked to express your consent in writing.
5. Mandatory or optional nature of the provision The provision of your personal and sensitive data is not compulsory, but any refusal could make it impossible or extremely difficult to provide the services you requested.
6. Scope of communication and dissemination of data Your data may be disclosed to: • all subjects to whom the right of access to such data is recognized by virtue of regulatory provisions; • to our collaborators, employees in the context of their duties; • to all those natural and / or legal persons, public and / or private when the communication is necessary or functional to the performance of our business and in the manner and for the purposes illustrated above;
7.Mode and duration of storage of personal data Depending on the purposes of the processing indicated above, the duration of the minimum treatment is 5 years (legal period)
8. Identification details of the owner, manager and of the Privacy Officer ESSE 21 SRL Via Podgora, 10, 20122, Milan, Tel. 0255180402 Italy email: firstname.lastname@example.org
9. Rights of the interested party 9.1 Art. 15 (right of access), 16 (right of rectification) of EU Reg. 2016/679 The interested party has the right to obtain from the data controller confirmation that personal data is being processed or not. concern and in this case, to obtain access to personal data and the following information: a) the purposes of the processing; b) the categories of personal data in question; c) the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if they are recipients of third countries or international organizations; d) the retention period of the personal data envisaged or, if this is not possible, the criteria used to determine this period; e) the existence of the data subject's right to ask the data controller to rectify or delete personal data or limit the processing of personal data concerning him or to oppose their processing; f) the right to lodge a complaint with a supervisory authority; h) the existence of an automated decision-making process, including profiling and, at least in such cases, significant information on the logic used, as well as the importance and expected consequences of such processing for the data subject.
9.2 Right pursuant to art. 17 of EU Reg. 2016/679 - right to cancellation ("right to be forgotten") The interested party has the right to obtain from the data controller the cancellation of personal data concerning him without undue delay and the data controller has the '' obligation to delete personal data without undue delay, if one of the following reasons exists: a) the personal data are no longer necessary with respect to the purposes for which they were collected or otherwise processed; b) the interested party revokes the consent on which the processing is based in accordance with Article 6, paragraph 1, letter a), or Article 9, paragraph 2, letter a), and if there is no other legal basis for the processing ; c) the interested party opposes the processing pursuant to Article 21, paragraph 1, and there is no legitimate overriding reason to proceed with the processing, or opposes the processing pursuant to Article 21, paragraph 2; d) the personal data have been unlawfully processed; e) personal data must be deleted to fulfill a legal obligation under the law of the Union or the Member State to which the data controller is subject; f) personal data have been collected in relation to the information society service offer referred to in Article 8, paragraph 1 of EU Reg. 2016/679
9.3 Right referred to in art. 18 Right to limitation of treatment The interested party has the right to obtain from the data controller the limitation of treatment when one of the following hypotheses occurs: a) the interested party disputes the accuracy of personal data, for the period necessary for the data controller to verify the accuracy of such personal data; b) the processing is unlawful and the interested party opposes the cancellation of personal data and requests instead that its use be limited; c) although the data controller no longer needs it for processing purposes, the personal data are necessary for the data subject to ascertain, exercise or defend a right in court; d) the interested party opposed the processing pursuant to Article 21, paragraph 1, EU Reg. 2016/679 pending verification of the possible prevalence of the legitimate reasons of the data controller with respect to those of the interested party.
9.4 Right referred to in Article 20 Right to data portability The interested party has the right to receive in a structured format, commonly used and readable by an automatic device, the personal data concerning him provided to a data controller and has the right to transmit such data to another data controller without hindrance by the data controller