General privacy policy notice to data subjects
Pursuant to article 13 of EU Reg. 2016/679
In compliance with the provisions of Article 13 of European Regulation no. 2016/679 (hereinafter “GDPR”), we hereby inform the data subjects of the processing methods carried out by the Data Controller.
Personal data processed
The Controller acquires only the data necessary for the correct management of the relationships undertaken with the data subjects, with particular reference to the fulfilment of the relevant legal / contractual / professional obligations. Personal data (common data relating to visitors of the site such as – by mere way of example – visitors, suppliers, customers and candidates) are acquired directly from the data subject when the relationship is established or are voluntarily provided by the data subject to the contact details of the Data Controller (website, email boxes, traditional mail, etc.).
Purpose of processing, legal basis and retention periods.
- Collection of navigation data
Computer systems and software procedures for the operation of the Site acquire, during their normal operation, certain personal data whose transmission is implied in the use of Internet communication protocols. This data is not collected to be associated with identified data subjects, but by its very nature could make possible the identification of users through processing and association with data held by third parties.
This category of data includes the IP addresses or domain names of the computers used by the users to connect to the site, the URI (Uniform Resource Identifier) notation addresses of the required resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (success, error, etc.).
This data is used only for the purpose of obtaining anonymous statistical information on the use of the Site and for checking its proper operation.
The legal basis for the legitimate processing of personal data is the legitimate interest of the Data Controller; the data is deleted immediately after processing.
- Use of Cookies
Cookies are data created by a server and stored in text files on your computer’s hard drive and allow the website to be aware of your behaviour.
The site makes use exclusively of technical cookies, divided into:
-
- Navigation or session cookies, which guarantee normal navigation and use of the website (allowing you, for example, to keep your preferences, e.g. so that you do not have to re-enter your username and password each time you access the site);
- Analytics Cookies, used exclusively to collect information, in aggregate form, on the number of users and how they visit the site, in order to evaluate and improve its operation. For example, they make it possible to know which pages are the most and least frequented, they record the number of visitors and the time spent on the site by users. All information collected by these cookies is anonymous and not linked to your personal data;
This site does not use profiling cookies.
The site contains third-party cookies, sent from sites or web servers other than ours, on which some elements may reside (such as, for example, images, maps, sounds, specific links to pages of other domains) present on the site that the user is visiting.
You can oppose the registration of cookies on your hard disk by configuring your browser (Internet Explorer, Mozilla Firefox, Safari, etc.) to disable cookies. After this operation, however, some web page functions may not be performed correctly.
- Providing assistance to the data subject
In order to recognize the data subject for the purpose of providing assistance in relation to specific requests from user with regard to the correct management of the relationship undertaken with the Company and related fulfilments, including but not limited to: requirements prior to the signing of contracts, requirements to execute contracts, for normal internal operational, administrative and accounting requirements, to carry out the necessary communications with the data subject and respond to any requests as well as to evaluate any professional applications.
The legal basis for this processing is the need to implement measures after the conclusion of the contract in order to improve the service to the user and meet the user’s expectations. The data will be kept for ten years from the date of collection.
- Legal Obligations
To comply with obligations under applicable national and supranational laws and regulations, including sector-specific.
The legal basis for this processing is the performance of legal obligations to which the Company is subject. The data will be kept until the legal obligations for which the same is processed have been fulfilled.
- Judicial Defence and Extrajudicial Debt Collection.
The processing of data by the Data Controller may be aimed, if necessary, at ascertaining, exercising or defending the Data Controller’s rights in court or recovering a debt of the data subject.
The legal basis for this processing is the legitimate interest of the Company to defend itself in court against the data subject. In the case of litigation, the data shall be kept for the entire duration of the proceedings, until the terms of the appeal have been exhausted.
Data provision
The provision of data for the purposes referred in letters:
- a) is mandatory;
- (b) is optional; failure to provide it may result in the non-execution or partial execution of certain functions of the web pages;
- (c) is mandatory in order to ensure the performance of the Controller’s contractual obligations towards the data subject;
- d) is mandatory to allow the Controller to comply with obligations under applicable national and supranational laws and regulations, including sector-specific.
- (e) is mandatory to guarantee the legitimate interest of the Controller in defending itself in court and/or recovering a debt of the data subject.
Processing methods
The processing of data may consist in its collection, recording, storage, modification, processing, communication, cancellation, diffusion, transfer and may be carried out both on paper and with the help of electronic, computerized and digital transmission tools, in accordance with methods and instruments suitable to ensure an adequate level of security and confidentiality of the data.
Communication and dissemination scope
The data may be processed by internal staff, authorized according to the procedures provided for in the Regulations, communicated to them by means of written instructions.
The data may be communicated to external parties in order to fulfil legal obligations or obligations deriving from a contract to which the data subject is a party or for administrative, financial or commercial needs (if the fundamental rights and freedoms, dignity or legitimate interest of the data subject do not prevail). In particular, the data concerning the data subject may be communicated to independent data controllers, such as, for example, companies offering services instrumental to the purposes indicated in this document (e.g. IT service providers) and companies that carry out activities concerning market studies and statistical analyses.
The data may also be processed, on behalf of the Company, by external parties designated as external data processors, such as, for example, companies that manage the website on behalf of Acciaierie Bertoli Safau S.p.A..
Data transfer outside the European union
Some navigation data may be transferred outside the European Union (see cookie policy).
Rights of the Data Subject
In relation to the processing of personal data carried out by the Data Controller, the data subject may ask the Data Controller for access to the data concerning him/her, their deletion, correction of rectification of inaccurate data and the completion of incomplete data,
the limitation of the processing in the cases provided for in Article 18 GDPR, as well as the opposition to the processing, for reasons related to your particular situation, in cases of legitimate interest of the Controller.
Where the processing is based on consent, the data subject has the right to withdraw the consent at any time.
In the event that the processing is based on consent or contract and is carried out by automated means, the data subject has the right to receive the data in a structured, commonly used and machine-readable format and, if technically feasible, to transmit it to another data controller without impediments.
At any time, the data subject may lodge a complaint with the Privacy Authority, as well as resort to the other means of protection provided by applicable legislation.
In order to exercise his/her rights, the data subject may contact the Data Controller, ABS, – Acciaierie Bertoli Safau – with registered office in Buttrio 28 – Frazione Cargnacco – 33050 Pozzuolo del Friuli (UD), Tel +39 0432 613211 – Fax +39 0432 613209, email: [email protected].
Updated on 21/07/2020