PURSUANT TO ART. 13-14 OF THE REGULATION (EU) 2016/679
We inform you, pursuant to Art. 13-14 of the Regulation (EU) 2016/679 on the protection of personal data (“GDPR”) that your personal data could be processed according to the current legislative and contractual provisions.
In relation to the above, we inform you that:
The Data Controller, that is whoever determines the purposes and means of the processing of personal data, is the IMA Group company with which your company has a contractual relationship (hereinafter “Company” or “Data Controller”).
The updated list of the IMA Group companies is available at the following website: https://ima.it/it/il-gruppo-ima/societa-del-gruppo-ima/.
You can request all the details regarding the Data Controller identification data by sending an email to: privacy@ima.it.
The IMA Group companies have appointed a data protection officer (“DPO”) who can be contacted to obtain clarifications on the processing of your personal data.
In particular, the Italian companies of the IMA Group has appointed the following DPO:
Alberto Bertuzzo
Pirola Pennuto Zei & Associati
Via delle Lame 109
40122 Bologna (Italy)
Tel.:+39 051 526711
E-mail: dataprotectionit@ima.it
other European companies of the IMA Group has appointed the following DPO:
Christian Schwinge
schwinge GmbH
Am Kochenhof 12
70192 Stuttgart
GERMANY
Phone: +49 (0) 711 / 258560-0
E-mail: dataprotectioneu@ima.it.
For purposes described in paragraph 3 below, the Company collects and processes “contact” personal data (name, surname, email address, telephone number, position and company) of the Contact Personnel within its suppliers (“Personal Data”).
Moreover, during the qualification procedures of its suppliers, the Company may gain knowledge of identification Personal Data and data related to the position covered by the Contact Personnel within the supplier for purposes connected to the operational management of the commercial relationship.
Data update
At any time, you can verify that the Personal Data processed for the purposes as per this information are correct and, should they be changed, you can request the update of this data, by sending an email to privacy@ima.it or by registered post to the Company’s headquarters.
The collection and the processing of your Personal Data is carried out without your consent.
Indeed, your Personal Data are processed pursuant to Art. 6 para. 1 letters b), c) and f) of the GDPR for the following purposes:
The processing of your personal data for the purposes mentioned above has its legal basis on:
We hereby remind you that you can object to the processing at any time by contacting the Company as per in paragraph 8 below, except in the event that the Company demonstrates the existence of prevailing, compelling, legitimate grounds for the exercise or the defence of a right, pursuant to Art. 21 of GDPR.
In general, the provision of Personal Data and their processing is obligatory; indeed should you refuse to supply your data (or your desire to request their erasure), means that is impossible for the Company to enter into and proceed with the contractual relationships.
The processing by the Company of your Personal Data shall be based on principles of correctness, lawfulness, transparency and protection of your privacy and your rights, in accordance with the principles expressed by the GDPR.
Your Personal Data may be processed by paper-based or IT instruments and it shall include – in compliance with the limits and conditions laid down by the privacy legislation – all the operation or set of operations necessary for the processing at issue, including communication to subjects as per para. 6 below. The processing of Personal Data shall be carried out in compliance with confidentiality and security rules provided by European regulations, by law, and other national provisions.
Processing of your Personal Data is achieved by means of the operations described in Art. 4 no. 2 GDPR, that are: collection, recording, organisation, structuring, updating, storage, adaptation or alteration, retrieval and analysis, consultation, use, disclosure by transmission, comparison, alignment, restriction, erasure or destruction.
The Company guarantees the logical and physical security of the Personal Data and, in general, the confidentiality of the Personal Data processed, implementing all the appropriate technical and organisational measures required to avoid the loss of Personal Data, the unlawful use or, in any event, the incorrect use of the same, and unauthorized access by third parties.
Your Personal Data shall not be disclosed, but the Company could, for the purposes described in Art. 3 above, communicate them to:
The third parties as above to which the Company shall communicate your Personal Data shall process them in their role as Data Processors, expressly appointed by the Company pursuant to Art. 28 of the GDPR or as autonomous data controller.
The Personal Data collected by the Company shall not be disseminated, without prejudice to the communications provided by laws.
It is understood that, in the event of any extraordinary corporate transaction (e.g. sale or lease of a company, merger, etc.) concerning the Company, the Personal Data may be transferred or communicated to third parties purchasers/lessee or others, entitled by the Company.
Your Personal Data shall be stored for the period of time strictly necessary for the purposes of the data processing indicated in para. 3 above and, in any event, for no longer than 10 years from the termination of the contractual relationship and, anyway, no later than the terms established by law for the prescription of the rights.
With regard to the Personal Data processed for the purpose indicated in para. 3 lett f), the storage period is 2 years from the termination of the audits activities.
At the end of the aforementioned periods Personal Data shall be erased.
With reference to your Personal Data you can exercise, at any time, the rights pursuant to the GDPR as indicated below:
The Company, moreover, informs you that it is possible to lodge a complaint pursuant to Art. 77with the competent supervisory authority based on your residence, workplace or place of infringement of your rights.
You may exercise your above listed rights by means of a request to be sent by email to privacy@ima.it or by registered post to the Company Headquarters.
Requests relating to the exercise of your rights shall be processed without undue delay and in any event within 30 days from the receipt of the request.
Finally, we inform you that the Company reserves the right to modify or update this information also in order to comply with new obligations imposed by laws or for technical reasons.