Privacy policy

INFORMATION ON THE PROCESSING OF PERSONAL DATA (Articles 13 and 14 of EU Regulation 2016/679)

Pursuant to Articles 13 and 14 of the EU Regulation 2016/679 (hereinafter referred to as GDPR) on the protection of personal data, we inform you that the personal data collected, with reference to the contractual relationship established or to simple requests for information, will be processed in compliance with the above-mentioned regulation and we provide you with the following information:

PERSONAL DATA COLLECTED
The personal data collected, with your free and express consent, are related exclusively to - identification data (e.g. first name, surname, address, telephone, fax, e-mail, etc...). - fiscal data (if required by law - e.g. tax code, VAT number, etc...).
- data related to the purchase of a product (cost, shipping address, etc.).

DATA CONTROLLER AND PERSONAL DATA PROCESSOR (13.1 a, b)

Data controller: DAMIANI SRL A SOCIO UNICO, Via Marsili, 4 - 40124 Bologna (BO), info@damianieditore.com - 051 4380747
The Data Protection Officer (Art. 37 GDPR) has not been appointed.


The data subject may contact the data controller at any time to exercise the rights set out in Article 13.2 letters b, c, d. The list of any external data processors can be requested from the data controller at any time. This information is provided only for this site and not for any other websites consulted by the user through links contained therein. This policy may be subject to change due to the introduction of new regulations in this regard, the user is therefore invited to periodically check this page. If the user is under 16 years of age, in accordance with Art. 8, c.1 EU Regulation 2016/679, he or she must legitimise his or her consent through the authorisation of his or her parents or legal guardian.

PURPOSES AND METHODS OF PERSONAL DATA PROCESSING (13.1 c) The purposes of personal data processing are as follows: 1) fulfilment of legal obligations connected with the contractual relationship
2) organisational management of the contractual relationship
3) fulfilling the request received by us;
4) Administrative management related to the processing of an order;
5) Sending commercial material via newsletters.

Personal data will be processed in paper, computerised and telematic form, and entered into the relevant databases that can only be accessed by the data controller and its appointees. With regard to data processed in electronic form, it is emphasised that all appropriate security measures have been taken to protect the rights, freedoms and legitimate interests of the data subject as per Article 22.3 of the GDPR. The legal basis for the processing is Art. 6.1 letter b) of the GDPR (execution of a request or contract) with regard to purposes 1 to 4, or consent for purpose 5.

ADDRESSEES OF PERSONAL DATA (13.1 e, f)
Without prejudice to communication to third parties carried out in execution of legal obligations or deriving from regulations or other Community legislation, or at the request of judicial offices or other third parties to whom the right is granted by the aforementioned provisions, the data may be communicated to the following categories of third-party recipients -banks and credit institutions, for handling payments;
-insurance companies;
-collection companies, factoring companies, leasing companies, insurance companies or credit assignment companies, credit consortia (for the sole purpose of credit protection and better management of our rights concerning the individual business relationship);
- commercial information companies;
- consultants;
- professionals and professional firms (lawyers, accountants, auditors, etc.);
- parties that provide maintenance and/or IT assistance services in relation to the Controller's systems, databases and IT services;
- shippers, carriers and couriers;
- other suppliers and sub-suppliers (in the case of customer or supplier data), or customers (in the case of supplier or sub-supplier data);
- other companies, entities and/or natural persons carrying out activities that are instrumental, supportive or functional to the performance of the contracts or services requested;
- public bodies.
The data controller has appointed as external data controllers all categories of third-party recipients to whom the communication of data was obligatory, unless they take on the role of autonomous data controller under current legislation. Personal data will in no way be disseminated and will not be processed by automated decision-making processes (such as profiling). The data controller also informs that it does not intend to transfer the data to a third country outside the EU or to an international organisation outside the EU.

PERIOD OF STORAGE OF PERSONAL DATA (13.2 a)
At the end of the performance, provision of the service or response, personal data will be retained solely for historical or statistical purposes, in accordance with the law, regulations, EU legislation and codes of ethics and good conduct signed in accordance with Article 40 of the GDPR, for a period as per current legislation (usually 10 years), or, if not subject to any law, for a period not exceeding five years. Beyond that period, the personal data will be kept anonymously, or will be destroyed.

RIGHTS OF INTERESTED PARTIES (13.2 b)
In relation to the aforementioned processing operations, the data subject has the right to request access to his or her personal data and the rectification or deletion thereof or the restriction of the processing concerning him or her, or to object to its processing, as well as the right to data portability.

RIGHT TO WITHDRAW CONSENT (13.2 c)
If the processing is based on consent, the controller shall inform the data subject that he/she has the right to withdraw it at any time without prejudice to the lawfulness of the processing based on the consent given before the withdrawal.

RIGHT TO PROPOSE COMPLAINT (13.2 d)
The holder shall inform the data subject of his right to lodge a complaint with a supervisory authority, in which case he must request information from the latter using one of the systems indicated above to contact him. To exercise his rights, the data subject must send a communication to the Controller using one of the above methods.

MANDATORY OR OPTIONAL NATURE OF DATA SUBMISSION (13.2 e)
The provision of data and the related processing are compulsory in relation to the purposes relating to tax obligations; it follows that any refusal to provide the data for such purposes may result in the impossibility for the data controller to carry out the same professional relationships and legal obligations. The provision of data and its processing is optional in other cases, without any consequences.

EXISTENCE OF AN AUTOMATED DECISION-MAKING PROCESS (13.2 f)
The data controller informs the data subject that there is no automated decision-making process on this site, therefore, in particular, there is no profiling system.