1. Identity and contact details of the data controller
The Data Controller is NUR. NUR is a company established in the Italian territory, therefore no representative has been appointed.
2. Contact details of the data protection officer
The Controller has appointed a data protection officer ("DPO"). The DPO can be contacted at the Controller's addresses or at the following addresses email@example.com.
3. Purpose of processing and legal basis of processing
Your Personal Data will be processed for the following purposes:
c) For purposes related to relevant legal obligations. The legal basis for the processing is NUR's legal obligation to process Personal Data in accordance with applicable law.
Ways of expressing consent
You will be able to express your consent by signing a computerized document through specific flagboxes.
5. Treatment modalities and logic
· With regard to the Personal Data processed and stored for the purposes referred to in point c), number 3 (legal obligations), the processing will take place using paper-based tools, automated logic and the use of CRM-type management software that will allow the best possible management of the fulfilment of legal obligations.
6. Automated decision making and profiling
If you consent to the processing of your Personal Data in order to benefit from personalized services through profiling, your Personal Data may be subject to an automated decision-making process, with a specific algorithm that will decide which communications are best suited to your profile or which may be of most interest to you. The processing carried out in this way has, as expected consequences, by way of example, the sending of highly profiled commercial communications, the sending of invitations to events considered of interest, etc..
In accordance with Article 22 GDPR, you have the right to:
· Obtain human intervention in decision making from NUR
· express your opinion;
· Obtain an explanation of the decision reached by NUR;
· challenge the decision itself.
7. Source of Personal Data
8. Recipients and categories of recipients of Personal Data
They may be recipients of Personal Data:
· communications companies that carry out commercial communication and profiling activities on behalf of the Data Controller, where consent has been given, and which have the status of data processors;
· companies offering information society services, including, in particular, those offering hosting services;
· companies that carry out statistical and market surveys, if consent has been given;
· audit firms;
· the partner companies of the Owner.
9. Data categories
Personal Data will be processed. In no case may special Personal Data defined in Article 9 of the GDPR be processed.
10. Data Transfer
NUR intends to transfer Personal Data to entities established in a country outside the European Union or to an international organization.
Such parties could be represented, for example, by:
· communications companies that carry out communications activities on behalf of the Data Controller;
· communications company service providers;
· controlled and/or controlling organizations.
The transfer of Personal Data to such subjects, if established in a third country or an international organization, is carried out in the presence of an adequacy decision by the European Commission, which has verified that the third country, the territory or one or more specific sectors within the third country, or the international organization in question guarantee an adequate level of protection of your rights. In any case NUR, if it considers it appropriate, reserves the right to conclude specific separate agreements that oblige such subjects to adopt adequate security measures, also organizational, aimed at offering appropriate guarantees for your rights. Personal Data may thus be transferred to the following countries: United States of America. To obtain a copy of such Personal Data or the place where it has been made available, simply send the relevant request to NUR, at the email address firstname.lastname@example.org.
11. Personal Data Retention Period
· The Personal Data processed for the purposes referred to in point a) number 3 of this statement (marketing purposes) are processed and stored by NUR until you request their cancellation and / or revocation, as a Data Subject;
· The individual Personal Data processed for the purposes of point b) number 3 (preference determination purposes), as acquired from time to time, are processed and stored by NUR for a period of time not exceeding 12 months (twelve) from collection;
· The Personal Data processed and stored for the purposes of point c), number 3 (fulfillment of legal obligations) are processed and stored by NUR in accordance with the provisions of the regulations in force, in any case for a period of time not exceeding 10 (ten) years starting from the termination of the effects of the contract in case of conclusion of the same, unless otherwise required by law.
12. Optional nature of consent and consequences of non-consent
· In relation to Personal Data processed for the purposes set out in point a) number 3 of this policy (marketing purposes), the disclosure of Personal Data is not a contractual obligation. You have the option to provide Personal Data. If you do not communicate such Personal Data, NUR will not be able to carry out any marketing activities.
· With respect to Personal Data processed for the purposes set forth in point b) number 3 of this Policy (preference determination purposes), the disclosure of Personal Data is not a contractual obligation. You have the option to provide Personal Data. If you do not communicate such Personal Data, NUR will not be able to perform any profiling activities.
· In relation to Personal Data processed for the purposes set out in point c) number 3 of this policy (legal obligations), the disclosure of Personal Data is a legal obligation.
13. Your rights
a) Right of objection
As a Data Subject, you have the right to object in the following terms:
· the right to object at any time, on grounds relating to your particular situation, to the processing of Personal Data relating to you pursuant to Article 6(1)(e) or (f) of the GDPR. NUR shall refrain from further processing your Personal Data, unless NUR demonstrates the existence of compelling legitimate grounds for processing that override your interests, rights and freedoms or for the establishment, exercise or defense of a legal claim;
· where Personal Data is processed for direct marketing purposes, you have the right to object at any time to the processing of Personal Data relating to you carried out for such purposes, including profiling insofar as it is related to direct marketing;
· if you object to the processing of your Personal Data for direct marketing purposes, your Personal Data will no longer be processed for such purposes. You may object to the processing of your Personal Data for direct marketing purposes even if only in part, for example by objecting only to the sending of promotional communications by automated and/or digital means, or to the sending of paper communications and/or the receiving of telephone communications;
· where your Personal Data is processed for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) of the GDPR, you have the right, on grounds relating to your particular situation, to object to the processing of Personal Data, unless the processing is necessary for the performance of a task carried out in the public interest.
b) Other rights
NUR would also like to inform you of the existence of your following rights:
· Right of access: you have the right to obtain confirmation from NUR that Personal Data concerning you is or is not being processed, and to access your Personal Data and specific information, in accordance with Article 15 of the GDPR;
· Right of rectification: you have the right to obtain from NUR the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you have the right to obtain the integration of incomplete personal data, including by providing a supplementary declaration, in accordance with Article 16 of the GDPR;
· Right to data deletion, including the right to withdraw consent: you have the right to obtain from NUR the deletion of your Personal Data without undue delay or to withdraw your consent to the processing, if the grounds defined in Article 17 of the GDPR exist. You have the right to revoke your consent at any time, without affecting the lawfulness of the processing based on the consent you gave before revocation;
· Right to restriction of processing: you have the right to obtain from NUR the restriction of processing, when the hypotheses defined in Article 18 of the GDPR apply;
· Right to data portability: you have the right to receive in a structured, commonly used and machine-readable format, your Personal Data provided to the Data Controller and you have the right to transmit it to another Data Controller without impediment from NUR, as provided for in Article 20 of the GDPR;
· Contractor's right to object to commercial communications: as a contracting party, you have the right to object at any time, free of charge, to receiving commercial communications from NUR;
· Right to lodge a complaint with the Data Protection Authority: you have the right to lodge a complaint with the Data Protection Authority, to complain about a violation of the rules on the protection of personal data, in accordance with Article 77 of the GDPR.
14. How to exercise your rights