Pursuant to Article 13 of the General Data Protection Regulation – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter “GDPR”), we provide you with information regarding the processing of your personal data provided within the scope of your relationship with RIBES NEST S.c.a.r.l. (hereinafter “RIBES Nest” or the “Company”).
Data Controller |
| The data controller is RIBES Nest S.C.A.R.L, with registered office in Via San Fermo 3, Padua, who can be contacted via the website www.ribesnest.it, “Contacts” section, or at the certified e-mail address (PEC) ribesnest@legalmail.it, in the person of its legal representative Mauro Fanin. |
Purpose |
Legal basis for processing |
| Managing the archiving and storage of data, sending information and communications, including electronic ones, requested by you through the Company’s website, and sending documents relating to the relationship with the Company. | (Art. 6, paragraph 1, letter c), GDPR) Processing necessary for compliance with a legal obligation to which the Controller is subject; (Art. 6, paragraph 1, letter f), GDPR) Processing necessary for the purposes of the legitimate interests pursued by the Controller related to the organizational and administrative management of its organization. |
Purpose |
Legal basis for processing |
| Promotional and marketing activities through the provision of material and information on new projects and other services of interest to you related to your activity and the activities of RIBES Nest, including by sending specific material in paper and/or electronic form, via newsletter (e-mail, SMS, MMS, instant messaging); sending information and news regarding the company and its activities via newsletter (e-mail, SMS, MMS, instant messaging); invitations to events organized or sponsored by the company; conducting market research and/or customer satisfaction surveys. | (Art. 6, paragraph 1, letter a), GDPR) Consent of the data subject |
Recipients of personal data
For the pursuit of the purposes indicated above, your personal data may be communicated to:
– public and private entities responsible for fulfilling obligations under current regulations, such as banking, financial or credit institutions, law firms or accounting firms.
– The data may also be communicated, in whole or in part, to any persons in charge of processing or data processors, in accordance with the instructions provided by the Controller.
– The data will also be processed using electronic and computer equipment.
– Third parties other than the Controller, such as:
Third parties or categories |
Purpose |
| IT companies | Management, maintenance, and updating of systems and software used by the Controller |
| Providers of networks, electronic communication services, and IT and telematic services for data archiving, storage, and management. Cloud services may involve data processing in non-EU countries that guarantee suitable privacy rights. | Hosting, housing, Cloud, SaaS, and other remote IT services essential for the delivery of the Controller’s activities; archiving and storage services for electronic documents in accordance with regulations. |
| Consultants, professionals, law firms, arbitrators, insurance companies, experts, brokers | Judicial, extrajudicial, and insurance activities in case of claims; organizational, administrative, financial, and accounting management. |
Personal data and documents |
Retention period or criteria for determining it |
| Personal details and documents relating to the relationship with the Company | For the duration necessary to pursue the purposes of the processing and also subsequently, within the limits permitted by law, for administrative and accounting purposes, as well as to assert or protect the rights of the Controller, where necessary. |
Right |
Description |
| Right to withdraw consent (Art. 13, paragraph 2, letter c) | You have the right to withdraw consent for processing for which it is required, without affecting the lawfulness of processing based on consent before its withdrawal. |
| Right of access to data (Art. 15) | You may request: a) the purposes of the processing; b) the categories of personal data concerned; c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations; d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; f) the right to lodge a complaint with a supervisory authority; g) where the personal data are not collected from the data subject, any available information as to their source; h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. You have the right to request a copy of the personal data undergoing processing. |
| Right to rectification (Art. 16) | You have the right to obtain the rectification of inaccurate personal data concerning you and to have incomplete personal data completed. |
| Right to erasure / Right to be forgotten (Art. 17) | You have the right to obtain from the Controller the erasure of personal data concerning you if the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed. |
| Right to restriction of processing (Art. 18) | You have the right to obtain from the Controller restriction of processing when you have contested the accuracy of the personal data (for a period enabling the Controller to verify the accuracy of such personal data) or if the processing is unlawful but you oppose the erasure of the personal data and request the restriction of their use instead, or if you require them for the establishment, exercise, or defense of legal claims, while the Controller no longer needs them. |
| Right to data portability (Art. 20) | You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller if the processing: (i) is based on consent, (ii) on a contract, and (iii) if the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority and provided that such transmission does not adversely affect the rights of others. |
| Right to object (Art. 21) | You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data if the processing is carried out for the pursuit of a legitimate interest of the Controller or if the processing is carried out for direct marketing purposes. |
| Right to lodge a complaint with a Supervisory Authority (Art. 77) | You have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data relating to you infringes the GDPR. |
The exercise of the rights listed above is subject to the limits, rules, and procedures provided by the GDPR, which the Data Subject must be aware of and implement. Furthermore, in accordance with Article 12, paragraph 3, the Controller shall provide the data subject with information on action taken without undue delay and, in any event, within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The Controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.
Changes and updates This information notice may be subject to changes and/or additions, also as a consequence of the applicability of the GDPR and any future regulatory changes and/or updates. The updated information notice is available on the Controller’s website.