Purpose of the processing for which the personal data are intended and related legal basis
Your personal data will be processed:

  1. without your consent (article 6, letters b, c, f, GDPR [1] ), for the following purposes:
    • fulfill the pre-contractual and contractual obligations arising from the assignment of any professional assignment,
    • comply with the provisions of laws and regulations (national or community), or execute an order of judicial authorities or supervisory bodies to which the Data Controller is subject,
    • exercise the rights of the owner, in particular, the right to defense in court;
  2. with your consent (Article 7, GDPR), for the following purposes:
    • organization of events, meetings, conferences and seminars, also aimed at professional training,
    • marketing activities of various types, including the promotion of professional services, the distribution of informational and promotional material, the sending of newsletters and publications,
    • management of surveys and questionnaires, including those relating to customer satisfaction. The provision of data for the purposes referred to in the previous section (i) is mandatory. The lack of data and/or any express refusal to process it will make it impossible for the Data Controller to carry out the task assigned or the possible violation of requests from the competent Authorities.

The provision of data for the purposes referred to in the previous section (ii) is optional, with the consequence that you may decide not to provide your consent, or to revoke it at any time.

 

Categories of personal data processed
In the context of the purposes of the processing highlighted in the previous paragraph (b), only personal data will be processed having as their object, for example, name and surname, tax code, VAT number, residence, domicile, workplace, email address or PEC, telephone and fax number, employer company, role and/or company classification, etc.

Categories of recipients of personal data
For the purposes referred to in the previous paragraph (b), section (i), the personal data provided by you may be made accessible:

  1. to employees and collaborators of the owner, in their capacity as persons authorised to process data (or so-called “data processors”),
  2. to third parties who carry out outsourcing activities on behalf of the owner, in their capacity as data controllers,
  3. to judicial or supervisory authorities, administrations, public bodies and organizations (national and foreign);

Should you express your consent to the use of your personal data for the purposes referred to in the previous paragraph (b), section (ii), the same may be made accessible to the subjects indicated in the previous points (1), (2), and (3).

 

Storage and transfer of personal data abroad
The management and storage of personal data takes place in the cloud and on servers located within and outside the European Union owned and/or available to the owner and/or third-party companies duly appointed as data controllers.

The transfer of data abroad to non-EU countries takes place in accordance with the provisions contained in Chapter V, GDPR (article 46), through the adoption of standard clauses drawn up on the basis of versions no. 2004/915/EC and no. 2010/87/EU developed by the European Commission.

Your personal data will not be disclosed.

  1. Period of retention of personal data
    The personal data collected for the purposes indicated in the previous paragraph (b), section (i) will be processed and stored for the entire duration of any professional relationship established. Starting from the date of termination of such relationship, for any reason or cause, the data will be stored for the duration of the limitation periods applicable by law. The personal data collected for the purposes indicated in the previous paragraph (b), section (ii) will be processed and stored for the time necessary to fulfill such purposes and in any case for no longer than 2 years from the date on which we receive your consent.
  2. Rights that may be exercised
    In accordance with the provisions of Chapter III, Section I, GDPR, you may exercise the rights indicated therein and in particular:

    • Right of access – Obtain confirmation as to whether or not personal data concerning you are being processed and, where that is the case, receive information relating, in particular, to: the purposes of the processing, the categories of personal data processed and the retention period, the recipients to whom the data may be communicated (Article 15, GDPR),
    • Right to rectification – Obtain, without undue delay, the rectification of inaccurate personal data concerning you and the integration of incomplete personal data (Article 16, GDPR),
    • Right to erasure – Obtain, without undue delay, the erasure of personal data concerning you, in the cases provided for by the GDPR (article 17, GDPR),
    • Right to restriction – Obtain from the owner the restriction of processing, in the cases provided for by the GDPR (article 18, GDPR)
    • Right to portability – Receive in a structured, commonly used and machine-readable format, the personal data concerning you provided to the owner, as well as obtain that they are transmitted to another owner without impediments, in the cases provided for by the GDPR (article 20, GDPR)
    • Right to object – To object to the processing of your personal data, unless there are legitimate grounds for the controller to continue processing (Article 21, GDPR)
    • Right to lodge a complaint with the supervisory authority – Lodge a complaint with the Data Protection Authority, Piazza di Montecitorio n. 121, 00186, Rome (RM).

You may exercise these rights by simply sending a request via email to the PEC address of the Data Protection Officer, indicated above.

Processing methods
The processing of your personal data is carried out by means of the operations indicated in article 4, n. 2), GDPR – performed with or without the aid of computer systems – and specifically: collection, recording, organization, structuring, updating, storage, adaptation or modification, extraction and analysis, consultation, use, communication by transmission, comparison, interconnection, limitation, cancellation or destruction.

In any case, the logical and physical security of the data and, in general, the confidentiality of the personal data processed will be guaranteed, by implementing all the necessary technical and organizational measures adequate to guarantee their security.