Our company, as data controller (hereinafter referred to as the Controller), informs you pursuant to Article 13 of Legislative Decree no. 196 of June 30, 2003 (hereinafter, the “Privacy Code”) and Article 13 of EU Regulation no. 2016/679 (hereinafter, the “GDPR”) that your data will be processed in the manner and for the following purposes:
1. Object of the processing
The Data Controller processes the personal, identifying data (for example, name, surname, company name, address, telephone number, email address, bank and payment details – hereinafter, “personal data” or also “data”) communicated by you when entering into contracts for the Data Controller’s services.
2. Purpose of processing
Your personal data is processed without your express consent (Article 24, letters a), b), and c) of the Privacy Code and Article 6, letters b), and e) of the GDPR) for the following Service Purposes:
- conclude contracts for the Data Controller’s services;
- fulfill pre-contractual, contractual, and tax obligations arising from existing relationships with you;
- fulfill obligations established by law, regulation, EU legislation, or by an order of the Authority (such as anti-money laundering);
- exercise the Data Controller’s rights, such as the right to defense in court.
3. Processing methods
Your personal data is processed using the operations indicated in Article 4 of the Privacy Code and Article 4(2) of the GDPR , specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure, and destruction of data. Your personal data is subject to both paper-based and electronic and/or automated processing.
The Data Controller will process personal data for the time necessary to fulfill the aforementioned purposes and in any case for no longer than 10 years from the termination of the relationship for Service Purposes.
4. Access to data
Your data may be made accessible for the purposes set out in Article 2:
- to the Data Controller’s employees and collaborators, in their capacity as persons in charge and/or internal data processors and/or system administrators;
- to third-party companies or other entities (for example, credit institutions, professional firms, consultants, insurance companies for the provision of insurance services, etc.) who carry out outsourced activities on behalf of the Data Controller, in their capacity as external data processors.
5. Data Disclosure.
Without the need for express consent ( pursuant to Article 24, letters a), b), and d) of the Privacy Code and Article 6, letters b) and c) of the GDPR ), the Data Controller may disclose your data for the purposes set out in Article 2 to supervisory bodies (such as IVASS), judicial authorities, insurance companies for the provision of insurance services, as well as to those parties to whom disclosure is required by law for the fulfillment of the aforementioned purposes. These parties will process the data in their capacity as independent data controllers.
Your data will not be disclosed.
6. Security
The data is stored and monitored using appropriate preventive security measures, aimed at minimizing the risks of loss and destruction, unauthorized access, and unauthorized processing or processing that is not consistent with the purposes for which the data is processed.
7. Data
transfer Personal data will be managed and stored within the European Union.
8. Rights of the interested party.
In your capacity as interested party, you have the rights set forth in art. 15 GDPR , specifically the rights to:
- obtain confirmation of the existence or otherwise of personal data concerning you, even if not yet recorded, and their communication in an intelligible form;
- obtain information on:
- the source of the personal data;
- the purposes and methods of processing;
- the logic applied in the event of processing carried out with the aid of electronic instruments;
- the identification details of the data controller, data processors, and the designated representative pursuant to Article 5, paragraph 2 of the Privacy Code and Article 3, paragraph 1, of the GDPR;
- the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of it in their capacity as designated representative in the territory of the State, data processors, or persons in charge of processing;
obtain:
- updating, rectification, or integration of data;
- deletion, anonymization, or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which it was collected or subsequently processed;
- certification that the operations referred to in letters a) and b) have been brought to the attention, including their content, of those to whom the data was communicated or disseminated, except where such compliance proves impossible or involves a manifestly disproportionate effort compared to the right being protected;
- object, in whole or in part, for legitimate reasons, to the processing of your personal data, even if pertinent to the purpose of collection.
Where applicable, you also have the rights set forth in Articles 16-21 of the GDPR (right to rectification, right to be forgotten, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.
9. How to exercise your rights
You may exercise your rights at any time by sending a communication:
1. by email, to the address: info@miotti.legal
2. or by registered mail, to Miotti Law Firm, Via Gregorio VII, 154, Rome
10. Owner, manager and persons in charge
The Data Controller is Giacomo Miotti (CF MTTGCM77H08H501Y )
The updated list of data controllers and processors is kept and can be consulted at the Data Controller’s headquarters.
