POLICY IN ACCORDANCE WITH SECTION 13 OF LEGISLATIVE DECREE No 196/2003 AND WITH ARTICLE 13 OF REGULATION (EU) No 2016/679
In accordance with Section 13 of Legislative Decree No 196/2003 (hereinafter “Privacy Code”) and with Article 13 of Regulation (EU) No 2016/679 (hereinafter “GDPR 2016/679”), laying down provisions on the protection of persons and other subjects regarding the processing of personal data, we wish to inform you that the personal data you provide will be processed in compliance with the above mention law and the confidentiality obligations to which our Company is bound.
NTPLAST S.r.l. provides some information regarding the processing of personal data provided by user.
It is specified that, according to Article 4 of the Regulation, “processing” is to be understood as: “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”.
The personal data you voluntarily provided to NTPLAST S.r.l. at the time of registration, on the occasion of commercial relationships aimed at the conclusion of contractual agreements and their execution, promotional activities or otherwise acquired within the scope of our activity, in compliance with the laws and contractual provisions in force, are subject to processing based on the principles of correctness, lawfulness and transparency, so as to protect your privacy and your rights, in compliance with the above mention law.
If, subject to the conditions of law, you intend to request the application of the VAT rate reduced by 4%, some categories of personal data will be also processed, in accordance with Article 9 of the Regulation, especially sensitive/special data that you provided with regard to medical certifications attesting the requests relating to the different disabilities admitted to tax benefits.
Therefore, in accordance with Article 13 of the Regulation (EU) No 2016/679, we inform you of the following:
HOW TO COLLECT DATA:
This site collect users’ data in two ways:
1. Data collected in an automated manner: during the browsing of the users, the following information can be collected, which are stored in the server log files (hosting) of the site:
- internet protocol (IP) address;
- type of browser;
- parameters of the device used to connect to the site;
- name of the Internet service provider (ISP);
- date and time of visit;
- web page of origin of the visitor (referral) and exit;
- possibly the number of clicks.
These data are used for statistical and analysis purposes only in aggregate form.
The IP address is used exclusively for security purposes and is not crossed with any other data.
2. Data provided voluntarily: The site may collect other data in case of voluntary use of services by users, such as comments or communication services (contact forms, comments box, request for quote or information), and they will be used exclusively for the provision of the requested service:
- name and surname;
- e-mail address.
PURPOSE OF THE PROCESSING:
Your personal data will be processed for the following purposes:
1. Institutional, connected or instrumental to the activities of NTPLAST S.r.l. such as archiving, processing, billing, customer management;
2. To comply with legal obligations related to civil, tax, accounting laws, for the purposes of administrative management of the relationship you have established with NTPLAST S.r.l;
3. To fulfil contractual obligations, technical support and technical information, after-sales assistance;
4. Profiling, to satisfy market surveys and statistics on products subject to NTPLAST S.r.l., also directed to assess the degree of user satisfaction (customer satisfaction);
5. Direct marketing, for communication on future commercial initiatives, announcements of new products, services and offers of NTPLAST S.r.l. by sending advertising material and newsletters via e-mail and/or paper by regular post;
6. Statistics, for the collection of data and information in an exclusively aggregate and anonymous form in order to verify the correct functioning of our website. None of this information is related to the natural or legal user of the site and does not in any way allow identification. Therefore, consent is not required;
7. Security, for the collection of data and information in order to protect the security of the site (spam filters, firewalls, virus detection) and users and to prevent or unmask fraud or abuse to the detriment of the website. The data are recorded automatically and may also include personal data (IP address) that could be used, in accordance with applicable laws, in order to block attempts to damage the site itself or to harm other users, or otherwise harmful activities or constituting a crime. These data are never used for user identification or profiling, and are periodically deleted. Therefore, consent is not required;
8. Ancillary activities, for the communication to third parties that perform functions necessary or instrumental to the operation of the service and to allow third parties to perform technical, logistical and other activities on our behalf. Suppliers have access only to personal data that are necessary to perform their duties; they commit not to use the data for other purposes and are required to process personal data in accordance with the laws in force.
(“SPECIAL CATEGORIES OF DATA”, ARTICLE 9 OF THE REGULATION):
Sensitive/special data you may provide will be processed only for the operations necessary to fulfil the obligations, including pre-contractual obligations, arising from the supply relationship to the party concerned of goods, performances or services, in accordance with the principle of relevance and non-excess of the processing data necessary to fulfil contractual obligations and to apply tax benefits.
In accordance with point (c) of Article 13(2) of the Regulation, it is recalled the possibility of withdrawing the consent at any time, without prejudice to the lawfulness of processing based on the consent given before its withdrawal.
LEGAL BASIS OF THE PROCESSING:
The processing of personal data and sensitive/specific data you provide is justified by the need to comply with the legal and tax obligations to which the Data Controller is subject, as well as the need for the execution of the contract of which you are a part, or execution of pre-contractual measures taken at your request.
The provision of your personal data and any sensitive/special data is necessary to be able to regularly fulfil the contractual and legal obligations related to the commercial relationship established by you with NTPLAST Srl: in their absence, we cannot follow up the order of purchase and billing at a reduced rate.
The processing of data for the purposes of direct marketing and profiling is based on the consent of the data subject.
COMMUNICATION AND METHODS OF PROCESSING:
The processing will be carried out in the following ways:
1. Personal data are processed in such a way as to ensure adequate security and confidentiality. To this end, the data are collected in our database and protected by appropriate security measures to prevent access or unauthorized use of personal data and equipment used for the processing;
2. Any sensitive/special data collected may be stored in NTPLAST Srl’s IT systems, reducing the use of personal and identifying data when the objectives pursued can be achieved by means of anonymous data and appropriate methods that allow identification of the data subject only in case of need. Sensitive/special data that are exceeding or no longer necessary as they relate to the carrying out of evaluation activities now exhausted will not be subject to further and/or different use by the Data Controller;
3. In compliance with the above mentioned purposes and permitted by law, your personal data may be disclosed externally in the context of: associated companies, parent companies and affiliates of NTPLAST S.r.l.; commercial partners of NTPLAST S.r.l. (producing companies, suppliers, carriers and couriers, etc.); solely for what concerns personal data, of the companies that carry out investigations related to the sphere of customer satisfaction. Given that the NTPLAST S.r.l. operates internationally, the data in question may be transferred abroad, within the territory of the EU, for the execution of the contract between you and NTPLAST Srl. These data are transferred with the help of appropriate guarantees for their protection.
TRANSFER OF DATA COLLECTED IN EXTRA UE COUNTRIES:
This website may share some of the data collected with services located outside the European Union area. In particular, with Google, Facebook e Microsoft (LinkedIn), through the social plugin and the Google Analytics service.
The transfer is authorized on the basis of specific decisions of the European Union and the Guarantor for the protection of personal data, in particular, this is the decision 1250/2016 (Privacy Shield - https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/5306161), so no further consent is required. The above mentioned companies ensure their adherence to the Privacy Shield.
PERIOD OF OF DATA STORAGE:
Personal data and sensitive/special data, object of processing in this site and in the execution of the contract, will be stored compatibly with legal and tax obligations (for example national tax or anti-fraud laws, duration of product warranty, etc.) that require the storage of data over a period of time.
With reference to personal data processed for direct marketing or profiling purposes, they will be stored in compliance with the proportionality principle and in any case until the purposes of the processing have been pursued.
In this regard, as set out by Article 21 of the Regulation, the data subject may exercise the right to object at any time to the processing of personal data concerning him/her for such purposes, including profiling.
We process visitors/users’ data in a lawful and correct manner, adopting appropriate security measures to prevent unauthorized access, disclosure, modification or unauthorized destruction of data. We are committed to protect the security of your personal data during their transmission, using the Secure Socket Layer (SSL) software, which encrypts the information in transit. Processing is carried out using IT and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated.
In addition to the Controller, in some cases, categories of employees involved in the organization of the site or external subjects may have access to the data (such as third-party technical service providers, hosting providers).
This site uses the following cookie categories:
2. Analysis cookies: used directly by the site operator to collect information, in aggregate form, on the number of users and how they visit the site. These cookies are similar to technical cookies if the service is anonymised;
3. Profiling and marketing cookies: used exclusively by third parties other than the owner of this site to collect information on users’ behaviour while browsing, and on their interests and consumption habits, also in order to provide personalised advertising.
For further information and how to disable cookies, visit https://www.ntplast.com/cookie-policy
THIRD PARTY COOKIES:
This site also acts as an intermediary for third party cookies (such as button for social networks), that are used to provide additional services and functionalities to visitors and to simplify the use of the site itself, or to provide personalised advertising. This site has no control over their cookies as they are entirely managed by third parties, and it does not have access to the information collected through these cookies. Information on the use of these cookies and their purposes, as well as on how to disable them, are directly provided by the third parties on the pages indicated below.
Generally, it is recalled that the tracking of users does not involve their identification, unless the user is already registered for the service and is not already “logged in”. In this case, the user has already expressed his/her consent directly to the third party when registering for the relevant service (eg. Facebook).
- Google Inc.
- Google Analytics
It is used to analyse the use of the site by users, compile reports on the site activity and user behaviour, check how often users visit the site, how the site is tracked and which pages are visited most frequently. The information is combined with information recollected from other sites in order to create a comparative picture of the use of the site compared to other sites of the same category.
Collected data: identifier of the browser, date and time of the interaction with the site, page of origin, IP address.
Place of data processing: European Union – as the anonymisation of the service is active.
The collected data do not allow personal identification of users and are not intersected with other information related to the same person. They are processed in an aggregate and anonymised way (truncated to the last octet). According to a specific agreement (DPA), it is forbidden to Google Inc. (processor) to cross these data with those obtains from other services.
Further information on Google Analytics cookies can be found on the Google Analytics Cookie Usage on Websites.
Users can selectively disable (opt-out) the collection of data by Google Analytics by installing the appropriate component provided by Google (opt out) on their browser.
- Clicky Web Analytics
PLUGIN SOCIAL NETWORK:
This site also incorporates plugins and/or buttons in order to allow easy sharing of content on your favourite social networks. When the user visits a page of our website that contains a plugin, his/her browser directly connects to the servers of the social network from where the plugin is loaded. This server can track his/her visit to the site and, if necessary, associate it with his/her social network account, in particular, if the user is connected at the time of the visit or if he/she has recently browsed one of the websites containing social plugins.
If you do not want the social network to record the data related to the visit on this website, you must exit your social account and possibly delete the cookies that the social network has installed in your browser.
On this site are installed plugins with advanced privacy protection features of users. These plugins do not send cookies or access cookies on the user’s browser when opening the page but only after clicking on the plugin.
The collection and use of information by these third parties are governed by the respective privacy policies, to which please refer:
RIGHTS OF THE DATA SUBJECT:
The data subject has the right, referred to in Article 7 of the Privacy Code and Article 15 (right of access) of the Regulation (EU) No. 2016/679, or the rights to:
1. Obtain confirmation as to whether or not personal data concerning him/her exist, regardless of their being already recorded, and communication of such data in intelligible form;
2. Be informed of: a) the source of the personal data; b) the purposes and methods of the processing; c) the logic applied to the processing, if the latter is carried out with the help of electronic means; d) the identification data concerning data controller, data processors and the representative designated as per Section 5(2), Privacy Code, and Article 3(1), GDPR; e) the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated representative(s) in the State’s territory, data processor(s) or person(s) in charge of the processing;
3. Obtain: a) updating, rectification or, where interested therein, integration of the data ; b) erasure, anonymization or blocking of data that have been processed unlawfully, including data whose storage is unnecessary for the purposes for which they have been collected or subsequently processed; c) certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected;
4. Object, in whole or in part: a) on legitimate grounds, to the processing of personal data concerning him/her, even though they are relevant to the purpose of the collection; b) to the processing of personal data concerning him/her, where it is carried out for the purpose of sending advertising materials or direct selling or else for the performance of market or commercial communication surveys;
5. The right of lodging a complaint with a supervisory authority for any matter relating to the mentioned processing of data.
Furthermore, in accordance with Articles 16-22 of the Regulation (EU) No 2016/679, the data subject can exercise:
I. Right to rectification (Article 16);
II. Right to be forgotten (erasure, Article 17);
III. Right to restriction of processing (Article 18);
IV. Right to obtain from the Controller the notification of any rectification or erasure of personal data or restriction of processing to the recipients to whom the data have been transmitted (Article 19);
V. Right to data portability (Article 20);
VI. Right to object (Article 21);
VII. Right to object the automated making (Article 22).
In this way, you are allowed to access your data to:
a) Verify their truthfulness;
b) Change them if they become inaccurate;
c) Incorporate them into a supplementary statement;
d) Request to erasure them.
The data subject can at any time withdraw his or her consent expressed in relation to the above mentioned purposes, except for the impossibility to continue the business relationship as indicated and without prejudice to the processing of previously acquired data to fulfil tax-fiscal obligations dependent on contracts concluded.
The data subject can exercise his/her rights at any time by sending his request to the e-mail address firstname.lastname@example.org
The Data Controller is NTPLAST S.r.l., in the person of its legal representative pro tempore Filippo Falcolini, with registered office in Via Gaetano Donizetti, 20 – 00198 Roma; e-mail: email@example.com