Privacy policy

Privacy Policy

Pursuant to Article 13 of EU Reg. 2016/679 (hereinafter GDPR), we inform you that the Associazione Culturale Giuseppe Locati A.P.S. (hereinafter, for brevity, A.C. Giuseppe Locati) processes the identifying data of clients, suppliers and individuals who have voluntarily communicated their personal data to our offices, whether through direct contact or indirectly by telephone, post, fax, e-mail or website.

In accordance with the principle of accountability, it guarantees that the processing of personal data takes place in compliance with the fundamental rights and freedoms, as well as the dignity of the data subject, with particular reference to confidentiality, personal identity and the right to the protection of personal data.

In relation to the processing of personal data carried out, the Controller provides, among other things, the following information:

• “personal data” (as per Art. 4.1 GDPR) means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity;

• “processing” (as per Art. 4.2 GDPR) means any operation or set of operations, performed with or without the aid of automated processes and applied to personal data or sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Identity and contact details of the Data Controller

A.C. Giuseppe Locati A.P.S.

Registered office address: via Cernuschi 6 – I 20900 Monza MB Contact email details: info@giuseppelocati.it

Personal data collected

The personal data collected relate essentially to:

– Identifying data (first and last name, e-mail address, telephone, etc.).

Type of data processed

Browsing data

The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.

This category of data includes the IP addresses or domain names of the computers used by users who connect to the site, the addresses in URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and computing environment of the user.

This is information that is not collected in order to be associated with identified data subjects, since the data are used solely for the purpose of obtaining anonymous statistical information on the use of the site and to monitor its correct functioning; however, by their very nature, through processing and association with data held by third parties, they could make it possible to identify users.

Please note that the data could be used by the competent Authorities to ascertain liability in the event of hypothetical computer crimes.

Cookies

The site uses cookies to improve the user’s browsing experience. To obtain more information on the type of cookies used, the purposes and the ways of disabling them, you may consult the specific section.

Data provided voluntarily by the user

To access certain services reserved for users, it is necessary to register and enter some personal data.

The provision of certain identifying data is necessary in order to authenticate and verify the authorisation to access, at the various levels of the reserved areas, the individuals who access them. In no case, however, will sensitive or judicial data be processed.

The optional, explicit and voluntary sending of electronic mail to the addresses indicated on this site entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message. Specific summary notices will be progressively reported or displayed on the pages of the site set up for particular services on request.

Purposes

The data you provide may be processed for:

  1. the carrying out of the operations strictly necessary in order to proceed with the provision of the services you may have requested, including your navigation through the pages of the site;

  2. the provision of technological services (mailing lists, newsletters, etc.), also by specifically authorised third parties;

  3. activities required by laws, regulations or measures for the execution of contractual relationships;

  4. statistical processing on aggregated data in relation to the performance of the site;

  5. evaluations regarding the use of the site by users;

  6. sending updates on the cultural and informative activity of the Association dedicated to Ing. Giuseppe Locati: exhibitions, events, lectures, and related or connected activities.

On the pages of the site where your personal data are explicitly collected, you will find reported, where necessary, the further specific Privacy Notices, as well as the methods for the acquisition of your consent in the cases in which the controller relies on this legal basis for processing.

Legal basis

The processing of your personal data will be carried out on the basis of one or more of the following conditions. In particular, the processing carried out for the purposes described above, which concern:

· point 1 and point 2, have as their legal basis the need to carry out your express requests to receive a service directly available through the site: this therefore concerns the provision of data strictly necessary and connected to a pre-contractual and/or contractual phase, or functional to responding to a specific request of yours; as such, the data collected from time to time are mandatory and, should you not intend to provide them, it will not be possible to provide the service or respond to your request;

· point 3, will have as their legal basis the need to comply with a legal obligation such as, for example, the obligation to implement security measures provided for by specific laws of the banking/financial sector applicable to certain services provided through the site, and as such these data and related processing are mandatory;

· point 4, since these are anonymised data, i.e. data from which it is not possible to re-identify, even indirectly, a natural person, such data are no longer personal data; therefore the related processing is exempt from the application of privacy legislation and no particular legal basis is required

· points 5, 6 and 7, will have as their legal basis your informed and freely given consent, which will be requested from you on specific pages of the site and preceded by our specific notice or via cookies (see the section dedicated to the cookie policy). In this case the provision of data is entirely free, and in the absence of your consent the data will in no way be collected and used for such purposes. Should you have given consent, you may revoke it at any time and, from the moment of revocation, the data will no longer be processed for such purposes. For maximum clarity, we point out to you that the revocation of consent has no retroactive effect on the data processed prior to the revocation itself.

Furthermore, should you be under 16 years of age, in order to process your data for these purposes it will be necessary to obtain authorisation from the holder of parental responsibility over you.

Where the controller can rely on another legal basis (legitimate interest, public interest…), you will be provided with a dedicated and specific Notice.

Method of processing, security measures and retention periods

All data will be processed predominantly in electronic format. The personal data, as well as any other information associable, directly or indirectly, with a specific user, are collected and processed by applying technical and organisational security measures such as to guarantee a level of security appropriate to the risk, taking into account the state of the art and the costs of implementation, or, where provided for, security measures prescribed by specific legislation such as, by way of non-exhaustive example: measures provided for by applicable rulings issued by the Data Protection Authority or by specific regulations for the banking/financial sector, and they will be accessible only to specifically authorised personnel.

Precisely with reference to the aspects of the protection of personal data, you are invited, pursuant to Art. 33 of the GDPR, to report to the controller any circumstances or events from which a potential “personal data breach” could arise, in order to allow an immediate assessment and the adoption of any actions aimed at countering such an event, by sending a communication to databreach@iccrea.bcc.it . It is recalled that a personal data breach means “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”.

The measures adopted by the controller do not exempt the user/client from paying the necessary attention to the use, where required, of passwords/PINs of adequate complexity, which must be periodically updated as well as carefully kept and made inaccessible to others, in order to avoid improper and unauthorised use.

The personal data processed will be retained in a form that allows the identification of the data subjects for a period of time not exceeding that necessary to achieve the purposes for which they are processed, without prejudice to the need to retain them for a longer period following requests from the competent Authorities in matters of the prevention and prosecution of crimes or, in any case, to assert or defend a right in legal proceedings.

Categories of Recipients of the personal data

The personal data will be processed by personnel specifically authorised by the controller as well as by third parties, possibly also established in countries outside the European Union, only where this is necessary for reasons of operability and maintenance of the site and of the services made available through the site itself, without prejudice to any obligations provided for by legal provisions (e.g.: inspections by the tax Authority).

In no case, however, will they be disseminated to the public.

As provided for by the GDPR, the controller appoints as personal data processors the third-party companies that carry out, in whole or in part, the activities in question exclusively on behalf of the controller. In the case of the involvement of third parties established in countries outside the European Union, for the related transfer of data abroad, appropriate safeguards are adopted corresponding to the adequacy decisions issued by the European Commission and/or by the national Data Protection Authority, adapted from time to time to the case. Further information regarding cases of any transfers of data to countries outside the European Union and the related safeguards adopted, as well as information regarding the companies appointed as personal data processors, may be requested from the DPO.

The personal data provided by users who forward requests for the sending of informational material (various documentation, reports, answers to questions, publications, etc.) are used solely for the purpose of carrying out the requested service or performance and are communicated to third parties only in the case where this is necessary for that purpose (example: the service for shipping the publications).

Rights of data subjects

In relation to the processing of your personal data carried out through this site, at any time, in your capacity as a data subject, you may exercise the rights provided for by the GDPR. In particular you may:

· access your personal data, obtaining evidence of the purposes pursued by the controller, the categories of data involved, the recipients to whom they may be communicated, the applicable retention period, the existence of automated decision-making processes, including profiling, and, at least in such cases, meaningful information on the logic used, as well as the significance and the possible consequences for the data subject, where not already indicated in the text of this Notice;

· obtain without delay the rectification of inaccurate personal data concerning you;

· obtain, in the cases provided for by law, the erasure of your data;

· obtain the restriction of the processing or object to it, where permitted on the basis of the legal provisions applicable to the specific case;

· in the cases provided for by law, request the portability of the data you have provided to the controller, that is, to receive them in a structured, commonly used and machine-readable format, and also request the transmission of such data to another controller, where technically feasible;

· where you deem it appropriate, lodge a complaint with the supervisory authority.

For the processing of personal data for which the legal basis is consent, you may always revoke it and, in particular, exercise the right to object to direct marketing.

To exercise these rights, it will be sufficient to contact the DPO with reference to the contact details reported at the beginning of this Notice.

To obtain further information regarding your rights and privacy legislation in general, we invite you to visit the website of the Data Protection Authority, at the address http://www.garanteprivacy.it/

Notice published on: 07 May 2024.