Privacy Policy
1. HOLDER OF THE TREATMENT
STU Reggiane SpA, also using the registered trademark “Reggiane Parco Innovazione”, with registered office in Reggio nell'Emilia (RE), Piazza Prampolini n. 1, VAT number 02662420351, email stureggiane@comune.re.it, certified email stureggiane@legalmail.it, as Data Controller, pursuant to and for the purposes of Regulation (EU) 2016/679, relating to the “protection of natural persons with regard to the processing of personal data and on the free movement of such data”, hereby provides you with information relating to the processing of data of users of the website www.parcoinnovazione.it, specifying that the same does not apply to other sites, pages or online services accessible via hypertext links that may be published on the site but refer to resources outside the Company's domain.
2. REPRESENTATIVE OF THE DATA CONTROLLER AND DATA PROTECTION OFFICER
The figure of a Data Controller Representative is not envisaged within this organization, as this is not required pursuant to the Regulation itself.
The Data Protection Officer (DPO) can be contacted at the following email address: dpo@parcoinnovazione.it.
3. TYPE OF DATA PROCESSED AND PURPOSE OF DATA PROCESSING
a) Browsing and usage data
The computer systems and software procedures used to operate the Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes the IP addresses or domain names of the computers used by users who connect to the Site, the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, information regarding access, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), the duration of the visit to certain pages and the interaction on those pages and other parameters relating to the user's operating system and IT environment.
The data collected during the user's navigation of the Site will be processed, among other things, to manage the Site and resolve any operational problems, to obtain statistical information on the use of the Site and to monitor its correct functioning, to identify anomalies and/or abuses in the use of the Site, including the possible ascertainment of liability in the event of any computer crimes against the Site.
In this regard, users are invited to carefully read the Cookie Policy on the website, which regulates this type of data.
b) Data provided voluntarily by the user
The optional, explicit, and voluntary sending of messages to the Company's contact addresses or the completion of the "Contacts" section of the Website entails the acquisition of the sender's personal and contact details necessary to respond (name, surname, and email address), as well as all personal and personal data included in the communications sent.
This data will be processed exclusively to contact the user and respond to the request sent.
Providing personal data for this purpose is optional; however, failure to provide it will prevent the Data Controller from contacting the user.
4. LEGAL BASIS AND LAWFULNESS OF THE PROCESSING
With reference to the lawfulness of the processing, it is specified that the legal bases on which the processing of personal data referred to in letter b) of this information is based are constituted by:
• The execution of a contract to which the data subject is party or the execution of pre-contractual measures adopted at the request of the data subject (art. 6, par. 1, letter b) of the Regulation).
5. METHODS OF TREATMENT
Your personal data is processed in accordance with the principles of fairness, lawfulness, and transparency, as well as purpose limitation and data minimization, pursuant to Article 5 of the GDPR.
Data processing will be carried out automatically and/or manually, in compliance with Article 32 of GDPR 2016/679, by specifically appointed persons and in compliance with Article 29 of GDPR 2016/679.
6. RECIPIENTS OF THE PERSONAL DATA PROCESSED
The personal data provided by website users will be communicated only to direct collaborators of the Data Controller for the sole purpose of responding to user requests, as well as to those who manage and provide assistance on software and systems used by the organization for its operations.
Your data may also be communicated to:
• Public security authorities and judicial authorities, following a written request and/or for the defence needs of the Data Controller company;
• to public bodies, entities and institutions if required by law or regulation;
• Staff of the Municipality of Reggio Emilia, by virtue of the provision by the Municipality itself of resources and equipment, as well as the technical support activity provided in light of the signed agreements;
• other public and/or private entities to whom communication is strictly necessary for the pursuit of the purposes indicated above.
The recipients may themselves be the Data Controllers, in other cases the third parties are identified as Data Processors.
The personal data above will not, in any case, be disclosed to unspecified parties.
7. TRANSFER OF DATA TO A THIRD COUNTRY
No transfer of your data to a third country or to an international organisation (country outside the Union) is foreseen.
8. PERIOD OF CONSERVATION OF PERSONAL DATA
The personal data you provide will be retained for the period of time necessary to respond to the request submitted by the user and, in any case, for a maximum of 2 years from the request.
9. DATA SUBJECT'S RIGHTS
You have the right to request from the Data Controller access to, erasure, disclosure, updating, rectification, objection to processing, integration, limitation, portability, and disclosure of any breach of your personal data. You may also exercise all the rights provided for in Article 15 et seq. of Regulation (EU) 2016/679. Requests for erasure and objection may only be granted if the purposes referred to in Article 3 no longer apply.
All of the aforementioned rights may be exercised at any time by writing to the Data Controller at the company's certified email address.
10. SUPERVISORY AUTHORITY
You have the right to lodge a complaint with the competent supervisory authority, the Italian Data Protection Authority (Garante Privacy Italiano), if you believe your personal data protection rights are at risk [garanteprivacy.it].
11. AUTOMATED DECISION MAKING
Your data will not be included in any automated decision-making process.
