PRIVACY AND COOKIE POLICY
Information provided pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter GDPR) and Legislative Decree 196/2003 “Personal Data Protection Code” as amended by Legislative Decree 101/18
- GENERAL INFORMATION
Data subjects are informed of the following general information, which applies to all areas of processing:
- All data of the individuals with whom we interact is processed lawfully, fairly, and transparently, in compliance with the general principles set forth in Article 5 of the GDPR;
- Specific security measures are observed to prevent data loss, unlawful or incorrect use, and unauthorized access, pursuant to Article 32 of the GDPR.
Data Subjects’ Contact Details and Rights
- The Data Controller is this Organization, which you may contact to exercise all the rights provided for by Articles 15-21 of the GDPR (right of access, rectification, erasure, restriction, portability, and objection), as well as to revoke any previously granted consent; If their requests are not met, data subjects may lodge a complaint with the Supervisory Authority for the Protection of Personal Data (GDPR – Art. 13, paragraph 2, letter d).The company has appointed a DPO, who can be contacted at dpo@gallidataservice.com
2) DATA PROCESSING RELATED TO THE OPERATION OF THIS SITE
Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.
| Purpose and legal basis of processing
(GDPR – Art. 13, paragraph 1, letter c) |
This data is used solely to obtain statistical information on the use of the site and to verify its proper functioning. The data may also be used to ascertain liability in the event of hypothetical computer crimes against the site (legitimate interests of the data controller). |
| Scope of communication
(GDPR – Art. 13, paragraph 1, letters e, f) |
The data may be processed exclusively by internal personnel, duly authorized and trained in data processing (GDPR – Art. 29) or by any persons responsible for maintaining the web platform (in this case appointed as external data processors) and will not be disclosed to other parties, disseminated, or transferred to countries outside the EU. Only in the event of an investigation may they be made available to the competent authorities. |
| Data retention period
(GDPR – Art. 13, paragraph 2, letter a) |
Data is generally retained for short periods of time, except for any extensions related to investigative activities. |
| Provision
(GDPR – Art. 13, paragraph 2, letter f) |
The data is not provided by the data subject but is acquired automatically by the site’s technological systems. |
Cookies
What are cookies? Cookies are short text files (letters and/or numbers) that allow the web server to store information on the client (browser) to be reused during the same visit to the site (session cookies) or later, even days later (persistent cookies). Cookies are stored, based on user preferences, by the individual browser on the specific device used (computer, tablet, smartphone). Similar technologies, such as web beacons, clear GIFs, and all forms of local storage introduced with HTML5, can be used to collect information on user behavior and use of services. Throughout this policy, we will refer to cookies and all similar technologies simply by the term “cookies.”
Cookie policy and how to manage preferences
The complete cookie policy can be viewed by clicking the appropriate link in the banner (click the lock-shaped icon at the bottom right).
The site may contain links to third-party sites and third-party cookies; for more information, please review the privacy policies of any linked sites.
Managing preferences via banner and dedicated button
In accordance with the “Guidelines on the use of cookies and other tracking tools” adopted by the Italian Data Protection Authority, published in the Official Journal No. 163 of July 9, 2021, and in force from January 8, 2022, users can always easily change their preferences by clicking the appropriate lock-shaped button visible at the bottom right of every page.
Managing preferences via major browsers Users can decide whether or not to accept cookies using their browser settings (please note that, by default, almost all web browsers are set to automatically accept cookies). This setting can be changed and customized for different websites and web applications. Furthermore, the best browsers allow you to define different settings for first-party and third-party cookies. Cookies are typically configured from the “Preferences,” “Tools,” or “Options” menus.
Below are the links to the guides for managing cookies for the main browsers:
Internet Explorer: http://support.microsoft.com/kb/278835
Internet Explorer [mobile version]: http://www.windowsphone.com/en-us/how-to/wp7/web/changing-privacy-and-other-browser-settings
Chrome: http://support.google.com/chrome/bin/answer.py?hl=en-GB&answer=95647
Safari: http://docs.info.apple.com/article.html?path=Safari/5.0/en/9277.html
Safari [mobile version]: http://support.apple.com/kb/HT1677
Firefox: http://support.mozilla.org/en-US/kb/Enabling%20and%20disabling%20cookies
Android: http://support.google.com/mobile/bin/answer.py?hl=en&answer=169022
Work: http://help.opera.com/opera/Windows/1781/it/controlPages.html#manageCookies
Further information
- allaboutcookies.org (for more information on cookie technologies and how they work)
- youronlinechoices.com/it/a-proposito (allows users to opt out of the installation of the main profiling cookies)
- garanteprivacy.it/cookie (collection of the main regulatory measures on the matter by the Italian Data Protection Authority)
Specific services
The site may contain data collection forms aimed at guaranteeing the user any services/functionalities (e.g.: request information, registration, assistance, open a ticket, check ticket status, etc.).
| Purpose and legal basis of processing
(GDPR – Art. 13, paragraph 1, letter c) |
Identification and contact information necessary to respond to data subjects’ requests may be requested. Sending the request is subject to specific, free, and informed consent (GDPR-Art. 6, paragraph 1, letter a) |
| Scope of communication
(GDPR-Art. 13, paragraph 1, letters e, f) |
The data is processed exclusively by duly authorized personnel trained in data processing (GDPR-Art. 29) or by any persons responsible for maintaining the web platform or providing the service (in this case appointed as external data processors). The data will not be disclosed or transferred to non-EU countries. |
| Data retention period
(GDPR-Art. 13, paragraph 2, letter a) |
The data is retained for Timeframes compatible with the purpose of collection. |
| Provision
(GDPR-Art. 13, paragraph 2, letter f) |
Providing data in the mandatory fields is necessary to obtain a response, while the optional fields are intended to provide staff with additional information to facilitate contact. |
Data provided voluntarily by the user
The optional, explicit, and voluntary sending of email and/or regular mail to the addresses indicated on this site entails the subsequent acquisition of the sender’s address, which is necessary to respond to requests, as well as any other personal data included in the message. If the sender submits their CV as a professional application, they remain solely responsible for the relevance and accuracy of the data submitted. Please note that any CVs without authorization to process data will be immediately deleted.
3) PROCESSING OF DATA RELATED TO RELATIONSHIPS ESTABLISHED WITH CURRENT AND POTENTIAL CUSTOMERS AND SUPPLIERS
3.1 Object of the processing
The organization processes personal identification data of customers/suppliers (e.g., name, surname, company name, personal/tax details, address, telephone number, email address, bank and payment details) and their operational contacts (name, surname and contact details), acquired and used in the provision of the services provided.
3.2 Purpose and legal basis of processing
The data is processed to:
- conclude contractual/professional relationships;
- fulfill pre-contractual, contractual, and tax obligations arising from existing relationships, as well as manage the necessary communications related to them;
- fulfill obligations established by law, regulation, EU legislation, or an order from the Authority
- exercise a legitimate interest or right of the Data Controller (for example: the right of defense in court, the protection of creditor positions; ordinary internal operational, management, and accounting needs).
Failure to provide the aforementioned data will make it impossible to establish a relationship with the Data Controller. The aforementioned purposes represent, pursuant to Article 6, paragraphs b, c, and f, suitable legal bases for the lawfulness of the processing. If processing is intended for other purposes, specific consent will be requested from the data subjects.
3.3 Processing Methods
Personal data is processed using the operations indicated in Art. 4(2) of the GDPR, specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure, and destruction of data. Personal data is processed both on paper and electronically and/or automatically. The Data Controller will process personal data for the time necessary to fulfill the purposes for which it was collected and the related legal obligations.
3.4 Scope of Processing
The data is processed by internal personnel duly authorized and trained pursuant to Art. 29 of the GDPR. You can also request the scope of personal data disclosure, obtaining precise information on any external parties acting as independent data processors or controllers (consultants, technicians, banks, carriers, etc.).
4) POLICY UPDATES
Please note that this policy may be subject to periodic revision, including in light of applicable legislation and case law. Therefore, we encourage you to periodically review this policy.