EU REGULATION 2016/679 (GDPR)
Subject: Privacy statement pursuant to art. 13 of EU Regulation 2016/679 (General Data Protection Regulation - GDPR) and art. 13 of Legislative Decree 196/2003 as supplemented and amended by Legislative Decree 101/2018 and subsequent amendments thereto.
Pursuant to art. 13 of Legislative Decree 196/2003 (hereinafter “Privacy Code”) and art. 13 of EU Regulation 2016/679 (hereinafter “GDPR 2016/679”) containing provision for the protection of personal data of individuals and other subjects, we wish to inform you that the personal data you supplied will be processed in accordance with the aforementioned regulations.
Zoe s.r.l.s., with registered office in 40134 – Bologna, Via Dal Lino no. 27, phone no. 334.9890342, PEC: email@example.com, in the person of its legal representative ad interim and single member, Mr Ianassi Mauro, is the Data Controller.
Data Protection Officer (DPO)
Zoe s.r.l.s. is not required to appoint a Data Protection Officer.
Purposes of data processing
The data is processed with the sole purpose to ensure the proper and complete performance of the Contracts for the supply of telematic services, web services, graphics and logo design and other web services offered by Zoe S.r.l.s., as increased over time with the progress of technology, entered into by a client by signing the order form and signing the General Terms and Conditions of Contract (GTC) for acceptance.
Data processing and storage modalities
Data processing is performed in manual and/or telematic and/or computerised and/or analog form, in accordance with the security provisions set out in art. 32 of GDPR 2016/679 and Annex B of Legislative Decree 196/2003 (arts 33-36 of the Code), by persons appointed to this end, and in keeping with the requirements provided for in art. 29 of GDPR 2016/ 679. In particular, it should be noted that data processing is carried out in keeping with the principles of legitimacy and data minimisation pursuant to art. 5 of the GDPR, and on the basis of the explicit consent given previously and the consent implied when signing a Contract for the supply of telematic services, web services, graphics and logo design and other web services offered by Zoe S.r.l.s., as increased over time with the progress of technology, entered into by a client by signing the order form and by signing the General Terms and Conditions of Contract for acceptance.
Data processing is performed by the Data Controllers(s), the employees and the external collaborators of ZOE s.r.l.s., in their position as data processors, and/or by external contractors. Personal data may be processed by means of paper files and/or computer files (also by means of portable devices) and are processed by methods strictly limited to what is necessary in relation to the purposes described above.
By visiting site https://www.zoewebsolutions.it, users give their consent to the processing of the data supplied by browsing, limited to the data supplied (e.g., IP address), even in the absence of a contractual relationship. The personal data of the data subject are also processed by Zoe s.r.l.s. whenever a user sends in a contact request via website https://www.zoewebsolutions.it and/or through a separate e-mail and/or some other form of communication (fax, phone), this activity by a data subject being construed as their implicit consent to the processing of the data supplied pursuant to this privacy statement.
Scope of dissemination and subjects to whom the data may be communicated
We also inform you that the provision of personal data is strictly necessary to the performance of the activities specified above. The subjects to whom the data may be communicated include: the employees responsible for processing the data, external collaborators, for the purposes as per point 3, in the event of litigation, subjects operating in the judiciary sector, banks, for the purposes described above, subjects who process the data to meet legal requirements and, in general, all those subjects who must have access to the data for the aforementioned purposes. The data collected will not be disseminated under any circumstances and will not be shared without the prior consent of the data subject, other than in the cases mentioned above. For taxation and fiscal purposes, Zoe s.r.l.s. is authorised to disclose the personal data of a data subject to the company’s CPA for the fulfilment of fiscal, accounting and taxation requirements, and/or in order to comply with legal obligations pursuant to the applicable regulations.
The client/data subject knows that their personal data is held in paper and electronic files (also by means of portable devices) and is stored in servers operated by telematic service companies (OVH s.r.l., ICAAN –the latter, limited to the registration of the domain name) having a contractual relationship with Zoe s.r.l.s., and the data will be retained after the expiration/termination of their contracts for a time period of at least ten years, or longer, as necessary to meet the obligations provided for by the law or by applicable regulations, as well as to fulfil fiscal/taxation requirements. Hence, upon signing an order form and the GTC, clients also give their consent to the storage of the data, possibly in computer files, for a longer period than is strictly necessary to achieve the purposes specified in point 3.
Refusal to provide personal data and withdrawal of consent.
The refusal to supply personal data in the circumstances envisaged in point 3, and/or the revocation of consent to the processing of personal data, makes it impossible for Zoe s.r.l.s. to perform the Contract signed by a client/person concerned and to pursue the purposes as per point 3 above, with the liability for all the legal and GCT consequences of early termination falling on the client/the person concerned.
Sharing and transfer of personal data to foreign countries
Personal data cannot be shared and can be transferred to EU countries for the purposes stated in point 3. The data will not be communicated to countries outside the EU other than for the purpose of domain registration.
Special categories of personal data
Pursuant to arts. 26 and 27 of Legislative Decree 196/2003 and arts. 9 and 10 of EU Regulation 2016/679, a client/person concerned is informed that Zoe s.r.l.s. abstains from processing sensitive data belonging to “special categories”, that is, data revealing the “racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and well as genetic data, biometric data allowing the unique identification of a natural person, data on a person’s health or sexual life or sexual orientation”.
Automated decision-making processes, including profiling
Zoe s.r.l.s. does not make use of any automated individual decision-making, including profiling, as per article 22(1) and (4) of EU Regulation 679/2016.
Rights of the data subject arts 15 to 22
Pursuant to art. 7 of Legislative Decree 196/2003 and articles 15 to 22 of EU Regulation 2016/679, a client/data subject may exercise at any time the following rights:
a) right to request confirmation as to the existence of personal data of the data subject;
b) right to obtain information on the purposes of the data processing, the categories of personal data processed, the addressees or categories of addressees to whom the data has been or will be communications, and, whenever possible, the retention period;
c) right to rectification and erasure;
d) right to restriction of processing;
e) right to data portability, i.e., the right to receive from the Controller their personal data in a structured, commonly used and machine-readable format, and the right to transmit such data to another Controller without any impediment;
f) right to object at any time to the processing of their data , also for purposes of direct marketing;
g) right to object to automated individual decision-making concerning natural persons, including profiling.
h) right to obtain access to their personal data from the controller and right to rectification and/or erasure, right to restriction of processing of their data, or to object to the processing thereof, and right to portability of the data;
i) right to withdraw their consent at any time, limited to conditions whereby the processing is based on the data subject’s consent, for one or more specific purposes, and in the case of ordinary personal data (e.g., date and place of birth, or place of residence), or special data categories (e.g.,
personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health status or sex life). The withdrawal of consent shall not affect the lawfulness of processing based on consent given before the withdrawal thereof;
j) Right to lodge a complaint with a supervisory authority (the Personal Data Protection Authority – www.garanteprivacy.it) and/or with jurisdictional authorities.
The data subject can exercise his/her rights by sending a written request via certified e-mail (PEC) to Zoe S.r.l.s. at firstname.lastname@example.org.