Voilàp digital S.r.l., Voilàp Holding’s Affiliate Company, as Data Controller, would like to inform You, pursuant to Art. 13 of the European Regulation 679/2016 concerning the personal data protection ("Regulation") and to the national legislation, including the individual measures of the Supervisory Authority where applicable, that personal data You provided during the establishment of the contractual relationship, shall be processed in compliance with the legislative and contractual provisions in force and to the purposes and with the methods indicated below.


Definitions

Group: based on Article 4 of the Regulation it means the Holding and its controlled companies; in this case, we refer to all Companies, which belong to Voilàp Holding Group.


Holding: Voilàp Holding S.p.A., located in Via Archimede, n.10 – 41019 Limidi di Soliera (MO) P.IVA/C.F. 02057270361.

Personal data: in accordance with Article 4 of the Regulation it means any information relating to an identified or identifiable natural person (see “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the natural person.

Processing: in accordance with Article 4 of the Regulation it means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Data Controller: in accordance with Article 4 of the Regulation, it means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purpose and means of such processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Data Processor:in accordance with Article 4 of the Regulation, it refers to a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.

Person authorized for processing activity: it refers to anyone who acts under the authority of the Processor or the Controller and who can access to personal data and process personal data.

Data protection officer: it means a natural person designed by the Controller who exercises control, information and advice functions related to the data protection regulation.

Data subject’s consent: in accordance with article 4 of the Regulation, it means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.


a) Type of data processed General or contact personal data: name, surname, telephone number, e-mail.

b) General purposes The abovementioned data will be processed for the instauration, management and execution of contractual relationship such as, for example, the contract’s administration; bills and payments management; potential dispute management; internal controls (safety, quality of services), control management, certification, as well as legal and regulatory fulfilment (e.g. fiscal and accounting obligations).

c) Direct marketing” purpose
i. Your personal data could be used solely and exclusively after your free, voluntary, appropriate and explicit consent, always revocable, to send advertising materials/communications through mailbox, e-mail, telephone, fax, whatsapp, sms, mms, Twitter, Facebook and Linkedln.
ii. For "direct marketing" purposes, the Data Controller can process Your personal data under its legitimate interest, in compliance with your reasonable expectations, for sending advertising material/communications, and only for products and services similar or better than those you already purchased. You can, at any time, exercise the right to object, in compliance with the art. 21 par. 2 of the GDPR.

d) Communication for marketing purposes to other controlled companies by Voilàp
Based on your freely given, specific, informed, and unambiguous consent, at any time revocable, Your data could be disclosed to other Voilap Holding’s companies for commercial and/or promotional and/or advertising purposes through mailbox, e-mail, telephone, fax, whatsapp, sms, mms, Twitter, Facebook and Linkedin.

e) Comunicazione alle altre Società del Gruppo imprenditoriale I Suoi Dati personali potranno essere comunicati alle altre società del Gruppo Imprenditoriale per finalità commerciali e/o promozionali e/o pubblicitarie, da esercitarsi tramite modalità automatizzate di contatto (quali, ad esempio, posta elettronica, telefax, whatsapp, SMS, MMS, messaggistica istantanea, ecc.) e/o modalità tradizionali (quali, ad esempio, telefonate con operatore e posta cartacea). Per tali finalità di marketing, i Suoi dati personali potranno essere trattati dalle Società del Gruppo nonché comunicati, in aggiunta a queste, che opereranno in totale autonomia come distinti Titolari del Trattamento. Ognuna di queste società fornirà una propria informativa, e in ogni caso Le sarà riservata la facoltà di esercitare, in qualsiasi momento, il diritto di opposizione al trattamento e di revoca del consenso.

e) Processing method
Personal data will be processed manually or electronically, using automated tools that ensure the security and confidentiality of the data. based on legal requirements, lawfulness, and correctness principles in order to protect the confidentiality of the data subject and his/her rights maintaining technical and organizational measures in order to guarantee a proper safety level appropriate to the risk.

f) The legal bases for the processing
The legal bases of the processing for the purpose referred to letter (b) is the performance of a contract to which You are party or to take pre-contractual steps at Your request; to fulfill legal obligations (art. 6, par. 1, lett. b) e c) of the Regulation). The legal bases of processing for the purposes referred to letter c) i. and d) is the express consent (art. 6, par. 1, lett. a) of the Regulation) The legal bases of processing for the purposes referred to letter c) ii. is the legitimate interest of Data Controller.
g) Consequences of refusal
Refusal to provide data or the objection/restriction to the processing for the purposes referred to letter b), could lead to the impossibility to establish or maintain a contractual relationship or otherwise the impossibility to satisfy some of Your requests; if You don’t provide Your consent for the purposes referred to letter c) will bear any consequence, but will only lead to the impossibility to send you advertising material / communications; if you don’t provide consent for the processing referred to letter d), will bear any consequences other than the impossibility of receiving material / advertising communications from the other companies of the Group.

h) Data retention
Personal data will be stored by the Data Controller/Data processors, if appointed, in compliance with the aforementioned purposes and for the time strictly necessary to fulfill the purposes for which the data are collected.
In particular, Your data will be stored:
• for the achievement of the purposes indicated at letter b) for 1 year from the collection; as long as the processing is necessary to fulfill legal obligations; for the duration of the contract and until there are obligations related to the performance of the contract;
• for the purposes referred to letter c) i., your data will be stored for a maximum period of 24 months, without prejudice to any withdrawal of the consent that will lead, without delay, to the deletion of the personal data collected
• for the purposes indicated at letter c) ii., your data will be stored for a maximum period of 24 months, without prejudice to any objection to the processing, in which case your data will no longer be processed for this purpose.
Your personal data may be stored for more than the abovementioned periods in case of anonymization in order to make them, in a definitive and irreversible way, no longer attributable to the identity of the data subject (for example to carry out market research and statistical analysis of reactivity to fairs / events promoted by the Controller and the methods and / or propensity to purchase products with the possibility of creating profiles referred to anonymous groups of consumers outlined for common characteristics such as age groups, geographical area of residence, etc.).

i) Subjects or categories of subjects (recipients) to whom the data may be communicated or disseminated
Personal data may be disclosed only for the purposes indicated above to third parties, including:
• the other Voilàp Holding’s companies;
• other subjects may become aware of personal data as Data Processors or Authorized, as in the case of our employees, who are assigned the tasks necessary for the execution of the contract signed by You. An updated list of data processors is available on request;
• subjects to whom the right to access your data is recognized by provisions of law and secondary legislation.
Any transfer of personal data to a third country outside the European Union or to an international organization, will take place based on an adequacy decision of the European Commission pursuant to art. 45, paragraph 1, of the Regulations, or based on the consent of the data subject or the performance of the contract pursuant to art. 49, paragraph 1, lett. a) and b) of the Regulations. In no case, the personal data processed will be disseminated.

j) Data subject rights i
You may, at any time, exercise your rights towards the Data Controller pursuant to arts. 15 and ss. of the GDPR, in particular:
- right of access and rectification (articles 15 and 16 of the Regulations): has the right to obtain confirmation that the processing of personal data is currently underway and, in this case, to obtain access to them. It also has the right to request the correction of inaccurate data and the integration of incomplete data. If you wish, we will provide you with a copy of your data in our possession;
- right to delete data (Article 17 of the Regulations): in the cases provided for by the current legislation (eg personal data are no longer necessary with respect to the purposes for which they were collected or otherwise processed, revocation of consent, unlawful processing, etc.), you may request the cancellation of your personal data to which the Data Controller will answer without delay;
- right to have the processing of personal data restricted (Article 18 of the Regulation): in the cases provided for by current legislation (incorrect personal data, unlawful processing of data, etc.) you have the right to obtain the limitation of your personal data processing;
- right to data portability (Article 20 of the Regulation): you have the right to receive your data in a structured format, commonly used and readable by automatic device, in order to transmit them to another Controller or, if required, we will provide the direct transmission of your data to another Controller;
- right of object (Article 21 of the Rules): has the right to object, at any time, for reasons connected with your particular situation, to the processing of personal data concerning you pursuant to art. 6, par. 1, letters e) or f), including profiling based on these provisions (legitimate interest of the Data Controller).
- consent withdrawal: it is your right, pursuant to art. 13, paragraph 2, lett. c) of the Regulations, withdrawal at any time the consent previously issued without prejudice however to the lawfulness of the processing carried out based on the consent given prior to the revocation.

k) To exercise these rights, data subjects can alternatively:
contact the Data Controller and / or the Data Protection Officer by e-mail to the following email address privacy@voilap.com, or • sending a registered mail to the addresses indicated in points m) or n) of this privacy notice, if necessary, using the forms made available on the Data Protection Authority website (www.garanteprivacy.it). Upon receipt of your request, the Data Controller has one month to take all necessary actions. The one-month time can be extended to two months in case of complex request or numerous requests. Within this period, despite the exercise of your rights, you may receive additional automated communications whose submission was planned prior to your request.

l) Right to lodge a complaint with a Supervisory Authority:In case you may believe that a violation of your rights is in action, you can lodge a complaint with a Supervisory Authority in compliance with the terms reported on the Supervisory Authority website (http:// www.garanteprivacy.it)..

m) Data Controller
The Data Controller is Voilàp Holding S.p.A., with offices in Via Archimede, n. 10 - 41019 Limidi di Soliera (MO), VAT / C.F. 02,057,270,361.

n) Data Protection Officer:The Data Protection Officer is Dott. Donato Eugenio Caccavella, with registered office located in Bologna, Via Giuseppe Brini n. 45 - 40128, tel. 051/0562070, fax 051/0822768.