Art. 13 et seq. General Data Protection Regulation No. 2016/679 ("GDPR")

Introduction
Dear User, when you access and browse this website (hereinafter referred to as the "Site"), some of your personal data is acquired, stored, and managed (in technical terms, "processed") through the device you are using, including through the analysis and storage of your IP address, browsing data, cookies, and other online identifiers such as pixels.

In light of these processing activities, in compliance with applicable regulations that impose obligations regarding the protection, confidentiality, and security of your data,Noberasco S.p.A.clarifies below the purposes and means of processing in its capacity as Data Controller.

Data controller
The processing of personal data carried out following access to and interaction with the Website will be performed byNoberasco S.p.A., with registered office in Regione Bagnoli n. 5, Albenga (SV) and operational headquarters in Carcare (SV), Loc. Paleta n. 1, VAT number 01270390097.

Noberasco S.p.A. can be contacted at the following addresses:

  • by sending an email toprivacy@noberasco.it;
  • by regular mail to the address of the registered office indicated.

DPO
The Data Controller has appointed, pursuant to Article 37 of the GDPR, a Data Protection Officer ("DPO"), who can be contacted at the email address dpo@noberasco.it.
The Data Controller has made this appointment voluntarily, for greater protection and security of the personal data processed, and reports the details here in compliance with the provisions of Article 37(7) of the GDPR and in order to allow the data subject to contact the DPO pursuant to Article 38(4) of the GDPR.

Categories of data processed
The categories of data processed are as follows:

  • information relating to the user's navigation on the Site, including so-called online identifiers and data relating to the devices used;
  • personal identification and contact details freely entered by the user on the Website, such as: first name, last name, email address, phone number;
  • personal data acquired from third parties or sources, in relation to specific initiatives or purposes promoted by the Data Controller;
  • additional personal data, specifically identified, in the event of the implementation of new features or services.

Purposes, legal bases, and data retention periods
In the table below, the Data Controller lists the specific purposes for which personal data is processed, accompanied by the relevant legal basis and the maximum data retention period, if it can be specified with precision (if not, the retention criteria on which the relevant technological tool is based is indicated).

Purpose
Legal basis
Storage time
(1) Provision of navigation features on the Website, its pages, and content, such as product catalogs
6 (1) (b), for the fulfillment of requirements related to pre-contractual activities
for the duration of the user's visit to the Website, up to a maximum of 24 months.
(2) Responding to contact requests or requests for information sent by the user
6 (1) (f), for the pursuit of the legitimate interest of the Data Controller aimed at maintaining relations with users of the Website
for a maximum of 10 years from the interaction with the data subject.
(3) Management of unsolicited contacts from users of the Website, through the sending of Curriculum Vitae and/or other communications
6 (1) (b), for the fulfillment of requirements related to pre-contractual activities
for a maximum period of 12 months from the end of the selection process, unless further storage is necessary or the user consents.
(4) Analysis of usage statistics and improvement of the Website's features which, due to their specific technical functioning, are not subject to Directive 2002/58/EC ("ePrivacy").
6 (1) (f), for the pursuit of the legitimate interest of the Data Controller, aimed at improving its products and services
only for the period necessary to completely anonymize the data collected.
(5) Analysis of usage statistics and improvement of the Website's functionality through technologies that involve data processing activities pursuant to Directive 2002/58/EC ("ePrivacy")
6 (1) (a), based on the consent expressed by the data subject
until the expiration of the longest-held online identifier relating to the user, except in the case of requests for deletion or anonymization.
(6) User registration for the newsletter and subsequent management of related commercial communications regarding special offers, promotions, and news, using both automated and non-automated systems (so-called marketing purposes)
6 (1) (a), based on the consent expressed by the data subject
until the user withdraws their consent, and in this case no later than the technical time required to remove the user's data.

Further information on how we process data
If the data subject wishes to receive further information on the balance between the legitimate interests pursued by the Data Controller and the fundamental rights and freedoms of the natural person, they may contact them at the addresses indicated, and are entitled to receive a response as soon as possible and in any case within the time limits set by law.
In the event of a dispute with the user or with third parties, or in the event of an inspection by the competent authorities, the storage period may be extended until the expiry of the last applicable limitation period.
The data will not be disclosed in any way, except with the express prior consent of the data subject and within the limits of the law.

 

Consequences of failure to provide data
The provision of personal data marked as mandatory is necessary to pursue the relevant purposes: failure to provide such data will make it impossible to process it.
The provision of other personal data is optional: failure to provide such additional data may make it impossible to access certain functions or features of the Site, either in whole or in part. With reference to the so-called marketing and profiling purposes, as well as in relation to the so-called "online identifiers" that are not purely technical, consent to the processing of personal data is optional: there is no legal or contractual obligation on the user to provide such data for this purpose and/or to give consent to the processing of their personal data for this purpose.

 


No personal data will be processed through automated decision-making processes in accordance with current legislation, and in particular pursuant to Article 22, paragraphs 1 and 4, of the GDPR.
In any case, any automated processing will not have a legal effect on the data subject or significantly affect them, unless specific informed consent is obtained and in any case in compliance with the limits of the law.

 

Categories of subjects that process personal data
Within the limits of the obligations, tasks, or purposes indicated above, personal data may be processed, made available, and/or communicated to:

  • employees and/or collaborators of the Data Controller;
  • third parties appointed as Data Processors (in particular, suppliers of goods or services), including their employees and/or collaborators;
  • Judicial, administrative, and/or public safety authorities, in accordance with regulatory provisions.

The complete list of Data Processors and other third parties may be requested from the Data Controller at any time, using the contact details provided.

 

Transfer of personal data outside the European Economic Area
Personal data will be transferred to countries outside the European Economic Area for technical reasons, to entities based in countries recognized as "adequate" by the European Commission, including members of the "EU-US Data Privacy Framework," or to entities that have entered into specific Standard Contractual Clauses in the current text as approved by the European Commission.

 

Rights of the data subject
The data subject may, at any time, exercise the rights provided for in European Regulation No. 2016/679. In particular, the data subject has the right:

  • to access your personal data;
  • to obtain the rectification or erasure of the same or the restriction of processing concerning him or her;
  • to object to processing, where permitted;
  • to obtain data portability, where applicable;
  • to withdraw consent: such withdrawal does not affect the lawfulness of processing based on consent before its withdrawal;
  • to lodge a complaint with the supervisory authority: for Italy, the Italian Data Protection Authority (www.gpdp.it).

The above rights may be exercised by sending a request to the Data Controller at the addresses indicated above, and in particular to the email address indicated in the section "Data Controller."

Back to top