Form newsletter Testo PRIVACY STATEMENT IN ACCORDANCE WITH ART. 13 OF EU REGULATION 2016/679 Table of Contents 1. Data Controller 2. Type of personal data processed 3. Purpose and methods of data processing 4. Legal basis for processing 5. Recipients/Categories of recipients of the personal data 6. Collection of data and consequences should they not be provided 7. Revocation of consent 8. Data retention period 9. Rights of the data subject 10. Complaint to the Supervisory Authority for the Protection of Personal Data 11. Personal data of minors This statement is given in accordance with art. 13 of EU Regulation 2016/679 (hereinafter, also just “Regulation” or “GDPR”): 1. Data Controller The Controller is Sammontana S.p.A. (hereinafter also “Sammontana”), via Tosco Romagnola 56, 50053 Empoli (FI), Tel.: +39 05717076, Fax: +39 0571707447, E-mail: firstname.lastname@example.org, PEC: email@example.com 2. Type of personal data processed Sammontana collects and processes personal data relevant to the Data Subject and, specifically, identification and contact data such as name, surname, phone number, e-mail (hereinafter jointly defined as “Personal Data” or just “Data”). 3. Purpose and methods of data processing The Personal Data required when registering for the website’s newsletter (hereinafter also just “Website”) are collected and processed for the following purposes: A) to allow us to send you Sammontana’s newsletter; B) for direct marketing purposes by the Controller and, specifically: a) to send information and promotional material regarding goods and services and future promo-advertising activities by the Controller, all the aforementioned also through e-mail, text and picture messages and fax; b) to send commercial communications and information, promotional and advertising material (e.g. brochures, catalogues, samples, newsletters, e-mail, etc.), material relevant to marketing campaigns and events, carry out market research through questionnaires, also through e-mail, text and picture messages, fax containing information relevant to products, events or promotions; c) anonymously and/or pseudonymised, to carry out market research and statistical analysis of the responsiveness to prize events promoted by the Controller and on the methods and/or propensities to consume with the possible creation of profiles which refer to anonymous consumer groups defined by common characteristics (age groups, geographical area of residence, etc.); d) to contact you and keep you updated regarding Sammontana’s new initiatives by sending communications, special offers and promotional material via mail, including e-mail, text and picture messages and fax. Personal Data will be processed by the Controller, Processors and third parties authorised to process the data (“Authorized” or “Appointees”), in compliance with all of the measures appropriate to guarantee security and confidentiality, using paper and with the aid of IT instruments (including management and use of database marketing), pursuant to principles of law, protecting the confidentiality of the Data Subject and his/her rights by adopting appropriate technical and organisational measures to guarantee an adequate level of security for the risk. 4. Legal basis for processing The legal basis of the processing for the purposes set out in point 3 is freely expressed consent pursuant to art. 6, paragraph 1, lett. a), of the Regulation. 5. Recipients/Categories of recipients of the personal data Your Personal Data can be communicated exclusively for the above purposes, to the following categories of recipients: - persons, companies, associations or professional firms that provide services and activities of assistance and consultancy to our Company, with particular but not exclusive reference to accounting, administrative, legal, tax and financial matters, who need to access the Data for purposes that are auxiliary to the correct sending of Sammontana’s newsletter and relevant activities, within the limits strictly necessary for the performance of its duties; - associate companies, companies belonging to the same Corporate Group as our Company; - parties whose right to access your Data is recognised by provisions of the law and secondary legislation; - public or private bodies that manage the delivery service for ordinary and commercial correspondence; - other parties may gain knowledge of your Personal Data, such as our employees who are assigned the tasks necessary to carry out the newsletter service. These parties act as Authorized, Controllers or Processors pursuant to art. 28 of the EU Regulation, parties that Sammontana uses to carry out its activities and which offer suitable guarantees of compliance with the regulations on the processing of Personal Data. Your Data will not be transferred abroad to extra UE countries. Your Personal Data will not be disclosed in any way. 6. Collection of data and consequences should they not be provided The provision of your Personal Data marked with an asterisk (*) on the form for registration on the Website is optional but necessary to achieve the purposes set out in point 3, lett. A). Failure to provide your Personal Data will have no other consequences, except for the impossibility to receive Sammontana’s newsletter. The provision of your Personal Data not marked with an asterisk (*) on the registration form is optional. Should you not provide such Data there will be no consequences. The provision of the Data for the purposes set out in point 3, lett. B) is optional, therefore, any refusal to give consent to the processing of Data for these purposes will have no consequences for the purposes of receiving newsletters from Sammontana. 7. Revocation of consent It is your right to withdraw the consent previously given for the purposes set out in point 3 lett. A) and B) at any time, without affecting the lawfulness of the processing carried out based on the consent given before its withdrawal. In order to withdraw your consent for the processing, it will be sufficient to send your request for revocation of consent to the Controller by registered letter, fax or e-mail to the addresses and contact details indicated in point 1 of this information statement. 8. Data retention period The Data in question will be retained for the period strictly necessary to achieve the purposes indicated in point 3 and, therefore: (i) until the consent is withdraw for the purposes set out in point 3, lett. A); (ii) for the maximum period of retention of 36 months for the purposes set out in point 3, letter B), without prejudice to the revocation of consent for which Sammontana will proceed without delay with the cancellation of your Personal Data. 9. Rights of the data subject You can exercise, at any time, your rights towards the Controller, pursuant to arts. 15 et seq. of the Regulation that we reproduce here below for your convenience: — Right of access and rectification (arts. 15 and 16 of the Regulation): You have the right to obtain confirmation that your Personal Data is being processed and, in this case, to obtain access to them. You also have the right to request the rectification of inaccurate Personal Data that concerns you and to obtain the completion of incomplete Data. If you wish, we will provide you with a copy of your Data in our possession. — Right to erasure of the data (art. 17 of the Regulation): in the cases envisaged by current legislation (e.g. the personal data is no longer necessary for the purposes for which they were collected or otherwise processed, revocation of consent, unlawful processing, etc.), you can request the erasure of your Personal Data, which Sammontana will carry out without delay. — Right to restriction of processing (art. 18 of the Regulation): in the cases provided for by current legislation (inaccuracy of personal data, unlawful processing of data, etc.) you have the right to obtain the restriction of the processing of your Personal Data. — Right to data portability (art. 20 of the Regulation): You have the right to receive your Data in a structured, commonly used and machine-readable format, in order to send the same to another Controller, where the same is required, or we will provide to send your Data directly to the other Controller. — Right to object (art. 21 of the Regulation): You have the right to object at any time, for reasons connected to your particular situation, to the processing of the Personal Data that concerns you pursuant to art. 6, paragraph 1, letter e) or f) of the Regulation, including profiling based on such provisions (legitimate interest of the Controller). To exercise these rights it will be sufficient to contact the Controller by registered letter, fax or e-mail at the addresses indicated in point 1, also using the forms made available on Data Protection Supervisory Authority’s Website (www.garanteprivacy.it). Upon receipt of your request, Sammontana has one month to take all the necessary actions. Within this deadline, despite the exercise of your rights, you may receive further automated communications whose sending was planned prior to your request. The deadline of a month can be extended to two months in the event of a complex or numerous requests. 10. Complaint to the Data Protection Supervisory Authority Should you believe that there has been a violation of your right to the protection of the Personal Data, it is your right to lodge a complaint with the Supervisory Authority for the Protection of Personal Data using the methods and in compliance with the terms on the website of the Data Protection Supervisory Authority (http://www.garanteprivacy.it). 11. Minors’ personal data The services of this website are aimed at the general public and are not intended for minors under the age of 14. We do not knowingly collect personal data from users under this age group. Should the personal data belonging to a minor under the age of 14 be released, the Controller will immediately cancel the same.