DATA PROTECTION AND CONFIDENTIALITY POLICY – PRIVACY POLICY

Information provided pursuant to Article 13 of EU Regulation 2016/679 (hereinafter “GDPR”)

AMADA Group companies consider the protection of individuals with regard to the processing of personal data to be a fundamental right. Transparency towards data subjects therefore represents a primary objective, pursued through effective communication tools aimed at providing stakeholders with basic information regarding the processing of their data.

1) GENERAL INFORMATION

Data subjects are hereby informed of the following general aspects, applicable to all areas of data processing:

  • all personal data are processed in compliance with the applicable privacy legislation currently in force (EU Regulation 2016/679 and Italian Legislative Decree 196/2003, as amended and supplemented by Italian Legislative Decree 101/2018);
  • all data relating to individuals and entities with whom we interact are processed lawfully, fairly and transparently, in compliance with the general principles set out in Article 5 of the GDPR;
  • specific security measures are implemented to prevent data loss, unlawful or improper use and unauthorised access, pursuant to Article 32 of the GDPR;
  • the company is part of an international group whose operational synergies may involve intercompany data flows; any transfer outside the EU takes place in compliance with the requirements set out in Chapter V of EU Regulation 2016/679, with specific reference to Article 46(2)(c), “standard data protection clauses adopted by the Commission”.

Data Controller, Data Protection Officer and Contact Details

  • the Data Controller is the Group company with which you have a contractual relationship, represented by its legal representative pro tempore;
  • AMADA ITALIA SRL – Via Amada I., 1/3 – 29010 Pontenure (PC) – Tel. +39 0523 872111 – Fax +39 0523 872101 – Email: marketing@amada.it
  • AMADA MACHINERY EUROPE GmbH – Italian Branch – Via Amada I., 1/3 – 29010 Pontenure (PC) – Tel. +39 0523 872311 – Fax +39 0523 872399 – Email: marketing-it@amada-machinery.com
  • AMADA has appointed a Data Protection Officer, who may be contacted for any information concerning privacy matters or to exercise the rights listed below (DPO contact details: Dr Gregorio Galli – Strada della Viggioletta, 8 – 29121 Piacenza; Tel. 0523 497066 – Email: dpo@gallidataservice.com).

Rights of Data Subjects

  • the right to request confirmation as to whether personal data concerning them are being processed and to access such data (Article 15 – “Right of access”);
  • the right to obtain the rectification/completion of inaccurate or incomplete data (Article 16 – “Right to rectification”);
  • the right to obtain, where justified grounds exist, the erasure of data (Article 17 – “Right to erasure”);
  • the right to obtain restriction of processing (Article 18 – “Right to restriction of processing”);
  • the right to receive personal data concerning them in a structured format (Article 20 – “Right to data portability”);
  • the right to object to processing and to automated decision-making processes, including profiling (Articles 21 and 22);
  • the right to withdraw consent previously given;
  • the right, in the event of failure to receive a response, to lodge a complaint with the Italian Data Protection Authority.

2) PROCESSING OF DATA RELATED TO THE OPERATION OF THIS WEBSITE

2.1 Browsing Data

The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected for the purpose of being associated with identified data subjects; however, by its very nature, it could allow users to be identified through processing and association with data held by third parties. This category of data includes the IP addresses or domain names of the computers used by users connecting to the website, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response provided by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment.

Purpose and Legal Basis of Processing (GDPR – Article 13(1)(c))

These data are used solely for the purpose of obtaining statistical information on the use of the website and checking its proper operation. The data may also be used to establish liability in the event of possible cybercrimes against the website (legitimate interests of the Data Controller).

Scope of Disclosure (GDPR – Article 13(1)(e),(f))

The data may be processed exclusively by internal personnel who have been duly authorised and instructed to process them (GDPR – Article 29), or by any parties responsible for maintaining the web platform (appointed, in such cases, as external Data Processors). The data will not be disclosed to other parties, disseminated or transferred to countries outside the EU. Only in the event of an investigation may they be made available to the competent authorities.

Data Retention Period (GDPR – Article 13(2)(a))

Data are normally retained for short periods of time, except where longer retention is required in connection with investigation activities.

Provision of Data (GDPR – Article 13(2)(f))

The data are not provided by the data subject but are automatically acquired by the website’s technological systems.

2.2 Cookies

Cookies are small text files (letters and/or numbers) that allow a web server to store information on the client (browser) for reuse during the same visit to the website (session cookies) or subsequently, even several days later (persistent cookies). Cookies are stored, according to the user’s preferences, by the individual browser on the specific device used (computer, tablet or smartphone). Similar technologies, such as web beacons, transparent GIFs and all forms of local storage introduced with HTML5, may be used to collect information about user behaviour and the use of services. In this Privacy Policy, cookies and all similar technologies will hereinafter simply be referred to as “cookies”.

Possible Types of First-Party Cookies and Preference Management

Technical browsing or session cookies

Purpose: to ensure normal browsing and use of the website.

Through the main web browsers, users can:

  • block by default the receipt of all (or certain types of) cookies;
  • view a detailed list of the cookies used;
  • remove all or some of the cookies installed.

For information on the settings of individual browsers, please refer to the relevant section below. Please note that blocking or deleting cookies may affect the usability of the website.

Technical analytics cookies: used to collect information on the number of visitors and pages viewed.

Technical functionality cookies: used to enable browsing according to a series of criteria selected by the user.

Profiling cookies: used to create user profiles in order to send advertising messages in line with the user’s preferences.

The website may contain links to third-party websites and third-party cookies. For further information, please refer to the Privacy Policies of any linked websites.

Managing Preferences Through the Main Web Browsers

Users can decide whether or not to accept cookies using their browser settings (please note that, by default, almost all web browsers are configured to automatically accept cookies).

These settings can be changed and configured specifically for different websites and web applications.

Furthermore, the main browsers allow users to define different settings for “first-party” and “third-party” cookies.

Cookie settings can usually be found under the “Preferences”, “Tools” or “Options” menu.

Below are the links to the cookie management guides for the main web browsers:

Further Information

Purpose and Legal Basis of Processing (GDPR – Article 13(1)(c))

Identification and contact data required to activate and provide the newsletter service (name and email address) are requested.

Subscription is subject to specific, freely given and informed consent (GDPR – Article 6(1)(a)).

Scope of Disclosure (GDPR – Article 13(1)(e),(f))

The data are processed exclusively by personnel who have been duly authorised and instructed to process them (GDPR – Article 29), or by any third parties exclusively responsible for the proper provision of the service (e.g. maintenance of the web platform or mailing applications).

Data Retention Period (GDPR – Article 13(2)(a))

The data are retained for periods compatible with the purpose for which they were collected and, in any case, until the user unsubscribes.

Provision of Data (GDPR – Article 13(2)(f))

Providing the data is necessary in order to activate the service.

2.4 Careers

This page allows data subjects to submit their application for employment with AMADA.

Identification and contact details, as well as the candidate’s curriculum vitae, are requested.

Purpose and Legal Basis of Processing (GDPR – Article 13(1)(c))

The data are acquired for the proper management of personnel selection procedures, as well as for subsequent responses.

Submission of the application is subject to specific, freely given and informed consent (GDPR – Article 6(1)(a)).

In the event of employment, the candidate will receive the appropriate Privacy Notice relating to the employment relationship established.

Scope of Disclosure (GDPR – Article 13(1)(e),(f))

The data are processed exclusively by personnel who have been duly authorised and instructed to process them (GDPR – Article 29).

Data Retention Period (GDPR – Article 13(2)(a))

The data are retained for periods compatible with the purpose for which they were collected.

Provision of Data (GDPR – Article 13(2)(f))

Providing the data relating to mandatory fields is necessary in order to submit an application, while optional fields are intended to provide staff with additional information useful for facilitating the selection process.

2.5 Access to Download Areas

The website provides certain pages, currently being implemented, where content and information materials will be made available:

  • Customer Area;
  • Sales Area;
  • Technical Area.

Access data and credentials will be assigned and managed following an authorisation request.

Purpose and Legal Basis of Processing (GDPR – Article 13(1)(c))

Data required to identify the user are requested in order to allow access to the download area.

Specific, freely given and informed consent is required (GDPR – Article 6(1)(a)).

Scope of Disclosure (GDPR – Article 13(1)(e),(f))

The data are processed exclusively by personnel who have been duly authorised and instructed to process them (GDPR – Article 29), or by any parties responsible for maintaining the web platform (appointed, in such cases, as external Data Processors).

Data Retention Period (GDPR – Article 13(2)(a))

The data are retained for periods compatible with the purpose for which they were collected and, in any case, until the user requests their deletion.

Provision of Data (GDPR – Article 13(2)(f))

Failure to provide the data will make it impossible to access the download area.

2.6 Customer Satisfaction

This page allows data subjects to express their level of satisfaction regarding products/services, comparisons with potential competitors and the organisation of events.

Purpose and Legal Basis of Processing (GDPR – Article 13(1)(c))

The data are collected for the purpose of improving the services provided by AMADA.

Submission of the questionnaire is subject to specific, freely given and informed consent (GDPR – Article 6(1)(a)).

Scope of Disclosure (GDPR – Article 13(1)(e),(f))

The data are processed exclusively by personnel who have been duly authorised and instructed to process them (GDPR – Article 29).

Data Retention Period (GDPR – Article 13(2)(a))

The data are retained for periods compatible with the purpose for which they were collected.

Provision of Data (GDPR – Article 13(2)(f))

Providing the data relating to mandatory fields is necessary in order to submit feedback.

2.7 Request for Information / Quotation

The relevant pages allow data subjects to request information or quotations from the appropriate staff members. AMADA provides competent contacts and consultants who may be contacted at any time and for any requirement.

Purpose and Legal Basis of Processing (GDPR – Article 13(1)(c))

Identification and contact data necessary to respond to requests from data subjects are requested.

Submission of the request is subject to specific, freely given and informed consent (GDPR – Article 6(1)(a)).

Scope of Disclosure (GDPR – Article 13(1)(e),(f))

The data are processed exclusively by personnel who have been duly authorised and instructed to process them (GDPR – Article 29).

Data Retention Period (GDPR – Article 13(2)(a))

The data are retained for periods compatible with the purpose for which they were collected.

Provision of Data (GDPR – Article 13(2)(f))

Providing the data relating to mandatory fields is necessary in order to receive a response, while optional fields are intended to provide staff with additional information useful for assessing the request.

2.8 Data Voluntarily Provided by the User

The optional, explicit and voluntary sending of emails and/or ordinary mail to the addresses indicated on this website entails the subsequent acquisition of the sender’s address, which is necessary in order to respond to requests, as well as any other personal data included in the communication.

The disclaimer included in outgoing emails used for any response will contain all the references necessary to consult this Privacy Policy and will also highlight the professional nature of any communication transmitted through any company email address.

2.9 Google Fonts (Hosted Locally)

This website uses so-called Google Fonts, provided by Google, to ensure the uniform display of fonts.

Google Fonts are installed locally on the Data Controller’s server; therefore, while browsing the website, no connection is made to Google servers and no personal data (e.g. IP address) are transmitted to third parties.

For further general information on Google Fonts, please refer to the Google Fonts FAQ and Google Privacy Policy.

3) PROCESSING OF CUSTOMER / SUPPLIER DATA

AMADA may process personal identification data relating to customers/suppliers (for example, first name, surname, company name, personal/tax details, address, telephone number, email address, banking and payment details) and their operational contacts (first name, surname and contact details), acquired and used as part of the contractual management (administrative and operational) of products/services sold or purchased.

Purpose and Legal Basis of Processing

The data are processed in order to:

  • establish contractual/professional relationships;
  • fulfil pre-contractual, contractual and tax obligations arising from existing relationships, as well as manage the necessary related communications (with particular reference to service and after-sales activities);
  • comply with obligations established by law, regulations, EU legislation or orders issued by an Authority (with particular reference to participation in tenders/contracts, joint liability obligations and safety procedures relating to work carried out at premises);
  • pursue a legitimate interest and exercise a right of the Data Controller (for example, the right of defence in legal proceedings, the protection of creditor positions, and ordinary internal operational, management and accounting requirements).
  • Pursuant to Article 6(b), (c) and (f), the above purposes represent appropriate legal bases for the lawfulness of processing.

Should processing be carried out for purposes other than those indicated above, specific consent will be requested from the data subjects.

Scope of Disclosure

The data may be processed by duly authorised and instructed internal personnel or by external parties whose activities are necessary for the proper fulfilment of contractual obligations between the parties and who have duly undertaken confidentiality and data-protection obligations (accounting/tax consultants, credit institutions, etc.).

The data may also be disclosed to public bodies and organisations in order to comply with legal obligations (e.g. registration on portals and registers).

Finally, as specified above, intercompany data flows may occur. Any transfer outside the EU takes place in compliance with the requirements set out in Chapter V of EU Regulation 2016/679, with specific reference to Article 46(2)(c), “standard data protection clauses adopted by the Commission”.

4) INFORMATION ON DATA PROCESSING FOR VIDEO SURVEILLANCE PURPOSES

To supplement the information provided to data subjects by means of the signs displayed in areas where video surveillance systems are in operation, please note that:

  • the processing of personal data through video surveillance systems is carried out in compliance with the applicable privacy legislation currently in force (EU Regulation 2016/679 “GDPR”; Italian Legislative Decree 196/2003, as amended and supplemented by Italian Legislative Decree 101/2018; General Measures issued by the Italian Data Protection Authority, expressly recognised by Article 22(4) of Legislative Decree 101/2018);
  • images are recorded by AMADA Italia Srl, represented by its legal representative pro tempore, acting as Data Controller;
  • the system is installed for SECURITY purposes and the use of cameras is intended to protect property, individuals and assets against possible intrusion, fire, theft, robbery or acts of vandalism, as well as for the possible defence of the Data Controller’s rights in legal proceedings (collection of evidence);
  • access to or passage by data subjects through the aforementioned entrances, premises and relevant areas necessarily involves the recording of images that may concern them;
  • the images captured may be recorded and retained for the period strictly necessary to achieve the purpose indicated above and, in any case, for no longer than the periods provided for by law (never exceeding 7 days), except where a longer period may be necessary in order to comply with specific requests from judicial authorities or law-enforcement authorities in connection with ongoing investigations. At the end of the applicable retention period, the recorded images are deleted from the relevant electronic, IT or magnetic storage media;
  • the images may be processed exclusively by formally authorised and instructed personnel or by external companies which, acting as Data Processors, assist with system maintenance and surveillance activities. They are not disclosed or disseminated outside the Data Controller’s organisation in any way, except in compliance with orders issued by judicial or law-enforcement authorities or, in the event of unlawful acts, for use in any related legal proceedings;
  • the images will be processed using tools and methods suitable for ensuring an adequate level of security and confidentiality, with particular reference to the measures indicated in Article 32 of the GDPR and the General Measure of 08/04/2010;
  • data subjects have the right to contact the Data Controller regarding any request for access to video-recorded data concerning them, pursuant to Articles 15 et seq. of the GDPR. In particular, where the person concerned is identifiable, they have the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them exist and to receive such data in an intelligible form; to obtain information regarding their processing (origin of the data, purposes and methods of processing, identification details of the Data Controller and, where appointed, the Data Processors, etc.); to obtain the erasure or blocking of data processed unlawfully; and to object, on legitimate grounds, to the processing itself;
  • any recording of employees and use of recorded images is carried out in compliance with the applicable employment legislation (Article 4 of Italian Law 300/70, “Workers’ Statute”, as amended by Article 23 of Italian Legislative Decree 151/2015, the “latest implementing decree of the Jobs Act”).

CONTACT DETAILS OF THE DATA CONTROLLER AND DATA PROTECTION OFFICER

The Data Controller is the undersigned Organisation, represented by its legal representative pro tempore:

AMADA Italia Srl
Tel.: 0523 872111

AMADA Machinery Europe GmbH – Italian Branch
Tel.: 0523 872311

Pursuant to Articles 37–39 of the GDPR, the Data Controller has appointed a Data Protection Officer, who may be contacted for any information concerning privacy matters or to exercise privacy rights:

Galli Data Service Srl
Tel.: 0523 497066
Email: dpo@gallidataservice.com

5) POLICY UPDATES

Please note that this Privacy Policy may be periodically reviewed, including in relation to developments in the applicable legislation and case law.

In the event of significant changes, appropriate notice will be provided on the website’s home page for a reasonable period of time.

Data subjects are nevertheless encouraged to consult this Privacy Policy periodically.