INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA

This information notice is provided pursuant to Article 13 of EU Regulation 2016/679 (GDPR) and Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, to users interacting with the website of MOLLIFICIO ADRIESE DI CECOLIN ERIKA & C. SAS, accessible electronically at:
[www.mollificioadriese.com](https://www.mollificioadriese.com), corresponding to the website’s home page.
This notice describes the management methods of the Company’s official website only; it does not apply to any external websites that users may access through links.
Further information may be provided within the various access channels, divided according to the topics addressed. Additional notices may be included on the Website in relation to specific services.

Data Controller:

MOLLIFICIO ADRIESE DI CECOLIN ERIKA & C. SAS
VIALE DEL LAVORO 25/27/29 – 45010 VILLADOSE (RO)

 contact details: privacy@mollificioadriese.com

 

 

Purpose of processing Legal basis for processing Data retention period
General administrative and accounting activities, as well as compliance with legal obligations, regulations, and applicable national and supranational legislation. Need to comply with legal obligations. For the duration of the contractual relationship and, after its termination, for the ordinary limitation period of 10 years.
Any request for contact, including the provision of information requested by you; Performance of a contract to which the data subject is a party or implementation of pre-contractual measures taken at the data subject’s request (Article 6(1)(b) of the Regulation). For the time necessary to provide a response.
Where necessary, to establish, exercise or defend the Controller’s rights in legal proceedings. Legitimate interest. For the entire duration thereof, until the time limits for bringing appeals have expired.
Direct marketing

Sending—by automated means of contact (such as SMS, MMS and email) and traditional means (such as telephone calls with an operator)—promotional and commercial communications relating to the services/products offered, notifications of corporate events or participation in webinars, as well as market research and statistical analysis.

Consent (optional and revocable at any time). Please note that the Controller collects a single consent for the Marketing purposes described herein, pursuant to the Italian Data Protection Authority’s General Provision “Guidelines on promotional activities and combating spam” of 4 July 2013. If you wish to object to the processing of your data for Marketing purposes carried out through the means indicated herein, and/or withdraw your consent, you may do so at any time by contacting the Controller using the contact details indicated in this notice, without affecting the lawfulness of processing based on consent before its withdrawal. Until consent is withdrawn.
Once the retention periods indicated above have expired, the Data will be destroyed, deleted or anonymised, in accordance with technical deletion and backup procedures.

 

Types of Data Processed and Collection Methods

Browsing data – log files

It is possible to access the Website without being required to provide any personal data. During their normal operation, the IT systems and software applications used to operate this website collect certain data (the transmission of which is implicit in the use of Internet communication protocols) that are not associated with directly identifiable users. The data collected include the IP addresses of users connecting to the website, the addresses in URI/URL (Uniform Resource Identifier/Locator) notation of the requested resources, the time of the request, the numerical code indicating the status of the response provided by the server (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.
This information does not provide the user’s personal data and is not collected in order to be associated with identified data subjects. Rather, it consists of technical/IT data collected and used in an aggregated and anonymous manner in order to verify the proper functioning of the Website and monitor its security; improve service quality and provide statistics on the use of the Website; and ascertain liability in the event of alleged cybercrimes against the website.

Data voluntarily provided by the user

The optional, explicit and voluntary sending of messages to contact addresses, as well as the completion and submission of forms on the Controller’s website, entails the acquisition of the sender’s contact details and of all personal data included in the communications, necessary to respond to requests submitted and/or provide the requested service. However, we ensure that such processing will be carried out in accordance with the principles of fairness, lawfulness and transparency, and with the protection of confidentiality, as set out in the GDPR. In any event, before a specific service is activated, appropriate information will be provided and, where necessary, consent to the processing of personal data will be obtained. Such consent may subsequently be withdrawn at any time, resulting in the inability to use the relevant service.
Failure to provide consent or withdrawal thereof does not entail any consequence, except for the inability to use the Website and/or receive the requested service or obtain more detailed information on the Company’s activities.
In any event, the processing of personal data may be carried out, where necessary, to pursue a legitimate interest of the Controller or on the basis of a legal obligation. In particular, obtaining consent for the processing referred to in the previous paragraph relating to browsing and log data is not necessary, as the data are processed on the basis of a legitimate interest (Recital 47 of the GDPR).

Provision of Data

Apart from what is specified for browsing data, the provision of personal data by the data subject for certain purposes described in the previous paragraph is optional. Failure to provide such data may make it impossible to use certain services provided by the website.

Methods of Data Processing

Personal data are processed using automated tools for the time strictly necessary to achieve the purposes for which they are collected, in compliance with the principles of lawfulness, purpose limitation and data minimisation pursuant to Article 5 of the GDPR, and in accordance with the mandatory retention periods prescribed by law. Specific security measures are implemented to prevent data loss, unlawful or improper use, and unauthorised access.

Disclosure and/or Dissemination of Data

Your data subject to processing will not be disclosed, but may be communicated to companies contractually linked to the Company, in accordance with and within the limits of the GDPR. Personal data are stored on servers located within the European Union. It is understood, however, that should it become necessary, the Controller may transfer servers outside the EU. In such cases, the Controller shall ensure that the transfer of data outside the EU is carried out in compliance with applicable legal provisions, following the execution of the standard contractual clauses adopted by the European Commission, and the user will be informed.
The data may be communicated to third parties belonging to the following categories:

– entities providing services for the management of the information system used by the Company and telecommunications networks (including email);
– professional firms or companies in the context of assistance and consultancy relationships;
– competent authorities, in order to comply with legal obligations and/or provisions of public bodies, upon request;
– companies providing marketing platform management services;
– companies providing website and information system maintenance services.

The entities belonging to the above categories act as Data Processors or operate in full autonomy as separate Data Controllers. The list of Data Processors is constantly updated and available at the Company’s registered office. Any further communication or disclosure will take place only with your explicit consent.

Possible Existence of Automated Decision-Making

The Controller informs the data subject that this website does not use an automated decision-making process and, in particular, does not use any profiling system.

Minors
This Website and the Controller’s Services are not intended for persons under 16 years of age, and the Controller does not knowingly collect personal information relating to minors. Should information concerning minors be inadvertently collected, the Controller will promptly delete it upon request by users.

Data Subject Rights

Data subjects have the right to receive information from the Company concerning the processing of their personal information by sending an email to: privacy@mollificioadriese.com

  • Right of access: we are transparent about the data we collect and how we use it. You may contact us at any time by sending an email to access the information we hold.
  • Right to rectification: you have the right to obtain the correction of any inaccurate or incomplete information and to request that it be updated and/or amended.
  • Right to erasure: send us a request for the deletion of all data relating to you, and we will process your request within 30 days.
  • Right to restriction: you have the right to request that the Data Controller restrict the processing of your data.
  • Right to data portability: if you request it, we will export your data so that it can be transferred to third parties in a structured, commonly used and machine-readable format.
  • Right to object: you may unsubscribe at any time from all specific uses we make of your data (newsletters, automated emails, etc.).
  • Right to lodge a complaint: if you believe that your rights have not been respected, you may lodge a complaint with the competent authority in accordance with the instructions published on the website
    www.garanteprivacy.it or by email at urp@gpdp.it