POLICY FOR PROCESSING OF PERSONAL DATA
Pursuant to and by the effect of Article 13 of the European Regulation 2016/679 concerning the protection of individuals with regard to the processing of personal data (GENERAL DATA PROTECTION REGULATION – GDPR).
As required by the General Data Protection Regulation of the European Union (GDPR 2016/679, Article 13), before proceeding with processing, the interested party (User of the website www.tradyconsulting.com) is informed that personal data collected through the website are subject to processing by the Company through IT and/or telematic tools, for the purposes indicated in this policy.
1. Data Controller
The Data Controller for personal data is Trady S.r.l. with registered office in Via Parenzo, 24 00198, Roma, Italia; Partita IVA (Tax ID): 15119911004.
2. Information Processing
The personal data subject to processing is collected directly by Trady S.r.l. or by third parties expressly authorized by the Data Controller, or communicated by the Company to such third parties for the pursuit of the purposes described below.
3. Legal Basis and Purpose of Processing
The personal data provided by the User when browsing the website www.tradyconsulting.com are processed by the Data Controller in accordance with the current regulations for the protection of personal data.
The processing of your personal data by Trady S.r.l. is aimed at pursuing the following purpose:
sending communications, following your request, of information regarding Trady's activities.
The legal basis of the processing is identified in the consent to the processing of data.
4. Nature of Processing
In relation to the purposes referenced in point 1) of the previous section, providing your personal data and consent to its processing is mandatory. Failure to provide consent will make it impossible for Trady to allow the Company to send information regarding Trady's activities.
5. Personal Data Processing
The Data Controller processes the personal data provided by the User when browsing the website www.tradyconsulting.com, in the event of any request of information made available by Trady. Examples of personal data are name, last name, telephone number and email address.
6. Methods of Processing and Storing Data
The processing of personal data is performed by the Data Controller in compliance with the provisions of the current legislation on Privacy. The Data Controller processes personal data using IT and/or telematic tools and with organizational and logical procedures strictly related to the purposes indicated in this policy, as well as adopting the appropriate security measures to prevent access, disclosure, unauthorized modification or destruction of personal data, its loss and its illicit and incorrect use. The Company also undertakes to process the data according to the principles of correctness, lawfulness and transparency, to collect the data to the extent necessary and exact for processing and to allow its use only by personnel for authorized purposes. The management and storage of personal data acquired will take place in archives or on servers located within the European Union owned by the Data Controller and/or by third-party companies appointed as External Data Processor for processing.
In relation to the purpose for which data is collected, personal data will be kept for the time strictly necessary to achieve that purpose and, in any case, in accordance with the current relevant regulations.
In any case, the Company will take care to avoid the use of data indefinitely by proceeding, on a regular basis, to verify appropriately the effective permanence of the interest of the User to which they refer.
7. Data Processors and Recipients
The data collected will not be disseminated in any way, but will be treated within the limits and for the purposes described by the employees of the Company on the basis of appropriate operating instructions. Some data processing may also be performed by third parties, appointed as External Data Processors for processing, of which the Data Controller relies on or could be used in the management of the contractual relationship, the provision of services offered and organizational needs of its activities. In particular, the data could be communicated to:
Persons, public and private, that can access the data by virtue of the provision of law, regulation or community legislation, within the limits set by these rules;
Persons who need access to data for purposes related to the contractual relationship existing between the parties, within the limits strictly necessary for the performance of auxiliary tasks (such as, for example, banks and lenders, technical service providers, hosting providers, IT companies, communication agencies, mail carriers and shipping companies);
Consultants, within the limits necessary for carrying out their professional duties.
8. Transfer of Data Abroad
The management and storage of personal data will be carried out on servers of the Data Controller and/or third-party companies duly appointed as External Data Processors located within the European Union.
Your personal data may be transferred abroad, in accordance with the provisions of current legislation, even in countries outside the European Union.
The transfer to countries outside the EU, in addition to cases in which this is guaranteed by an Adequacy Decisions by the Commission, is carried out in such a way as to provide appropriate and opportune guarantees pursuant to Articles 46, 47 or 49 of the Regulation.
9. Rights of the Data Subject
As the data subject, you may exercise, at any time, the rights provided to you in Articles 15, 16, 17, 18, 20 and 21 of the GDPR which, in particular, confer the rights to:
Obtain from the Data Controller, pursuant to Article 15, confirmation of the existence or not of personal data being processed and, in this case, obtain access to the data and information such as: (i) the purposes of the processing; (ii) the categories of personal data; (iii) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients located in Third Countries or International Organizations; (iv) when possible, the retention period of the personal data provided or, if not possible, the criteria used to determine this period;
Obtain from the Data Controller, pursuant to Article 16, the correction of inaccurate personal data without undue delay; taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, by providing an additional declaration;
Obtain from the Data Controller, pursuant to Article 17, the deletion of their personal data without undue delay. The Data Controller has the obligation to cancel, without undue delay, personal data if there is one of the reasons indicated in paragraph 1 of Article 17;
Obtain from the Data Controller, pursuant to Article 18, restriction of processing when one of the hypotheses governed by paragraph 1 of Article 18 occurs;
Obtain from the Data Controller, pursuant to Article 20, the portability of data or to receive in a structured, commonly used and machine-readable format, their personal data provided to a Data Controller. The data subject also has the right to transmit such data to another Data Controller without impediments by the first Data Controller to whom it has provided them, if the conditions indicated in Article 20 paragraph 1 are met. Finally, the data subject has the right to obtain the direct transmission of personal data from one Data Controller to another, if technically feasible;
Object to, in whole or in part, pursuant to Article 21, the processing of their personal data.
To exercise these rights, the User can send their requests to email@example.com or send a request to the legal office of the Company.
It should also be noted that the Data Subject has the right to revoke the consent at any time without prejudice to the lawfulness of the processing based on the consent given prior to the revocation, without prejudice to the consequences indicated above regarding a refusal to provide such personal data. The data subject also has the right to lodge a complaint with a Control Authority.
You can make requests regarding these rights by sending an email to firstname.lastname@example.org.
Trady S.r.l. will respond to requests made by the interested party within one month, except in cases of particular complexity, for which it may take up to a maximum of three months. In any case, the Data Controller will provide the interested party with the reason for the delayed response within one month of the request. The outcome of the request will be provided in writing or in electronic format. In case of request for rectification, cancellation and limitation of processing, the Data Controller will communicate the results of the requests received by the data subject to each of the recipients of their data, unless this proves impossible or involves a disproportionate effort.
The Company specifies that a contribution may be requested from the data subject if the applications manifest to be unfounded, excessive or repetitive; in this regard, the Data Controller will provide a register to track the requests for intervention.
10. Changes to this Policy
The Data Controller