Privacy EN

Personal Data Processing

Information document pursuant to Article 13 of EU Regulation 2016/679 – GDPR – Information on the processing of personal data collected from the data subject.

In compliance with EU Regulation 2016/679 (European Regulation on the protection of personal data), we provide you with the necessary information regarding the processing of the personal data provided. This information does not apply to other websites that may be accessed through links on the owner’s domain websites, for which the owner is not responsible in any way. This information is provided pursuant to Article 13 of EU Regulation 2016/679 (European Regulation on the protection of personal data) and is also inspired by Directive 2002/58/EC, as updated by Directive 2009/136/EC, regarding cookies, as well as by the Provision of the Italian Data Protection Authority of 08.05.2014 regarding cookies. Personal data that can be processed: “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Specific Information

Specific information may be presented on the pages of the Website in relation to particular services or data processing activities provided.

1 – DATA CONTROLLER

Pursuant to Articles 4 and 24 GDPR, the data controller is Dr. Stefania Grappeggia with office at Via Anzani, No. 37, 22100 Como (CO). The contact email address of the data controller is: info@olis.bio

2 – PURPOSES AND LEGAL BASIS OF PROCESSING

The personal data provided will be processed in compliance with the conditions of lawfulness under Article 6 f) of Regulation EU 2016/679 for the following purposes:

– browsing on this website;
– possible completion of forms for registration on the website;
– possible completion of data collection forms and request for contact with sending of requested information;
– possible completion of data collection forms for personnel selection;
– possible completion of data collection forms for receiving newsletters or promotional communications via email.

3 – DATA PROCESSING

Data processing is based on Article 6, paragraph 1, letter f): taking into account the reasonable expectations of the data subject at the time and within the scope of personal data collection, where the data subject can reasonably expect that such processing will take place. For specific marketing activities, the legal basis will be consent.

4 – RECIPIENTS OR CATEGORIES OF RECIPIENTS OF THE DATA

The data will not be disclosed but may be communicated by the data controller to entities linked to it, to third parties acting as Data Processors belonging to the following categories: internet providers, companies specialized in IT and telematics services, companies engaged in marketing activities, companies specialized in market research and data processing.

Your data may be transmitted to the police forces and judicial and administrative authorities, in accordance with the law, for the detection and prosecution of crimes, prevention and safeguarding against threats to public security, to enable the data controller to ascertain, exercise or defend a right in court, as well as for other reasons related to the protection of the rights and freedoms of others.

5 – TRANSFER OF DATA OUTSIDE THE EU

Some of the third parties listed in the previous paragraph (4) may be located in countries outside the European Union that nevertheless offer an adequate level of data protection, as established by specific decisions of the European Commission. The transfer of your personal data to countries that do not belong to the European Union and that do not ensure adequate levels of protection will only be carried out after conclusion of specific agreements between the data controller and these parties, containing safeguarding clauses and appropriate guarantees for the protection of your personal data, also approved by the European Commission, or where the transfer is necessary for the conclusion and execution of a contract between you and the data controller or for the management of your requests.

6 – DATA RETENTION PERIOD OR CRITERIA FOR DETERMINING THE PERIOD

Processing will be carried out both manually and electronically, with methods and tools aimed at ensuring maximum security and confidentiality. In compliance with Article 5, paragraph 1, letter e) of EU Regulation 2016/679, personal data collected will be stored in a form that allows the identification of data subjects for a period not exceeding the achievement of the purposes for which the personal data are processed. The retention period of the personal data provided depends on the purpose of the processing:

– browsing on this website (session);
– for contact request (maximum 1 year);
– data collection for personnel selection (maximum 24 months);
– receiving newsletters or promotional communications via email (maximum 24 months);
– profiling (24 months).

7 – RIGHTS OF THE DATA SUBJECTS

You may exercise your rights as expressed in EU Regulation 2016/679 by contacting the Data Controller, by sending an email to info@olis.bio or by writing to the aforementioned address of the Data Controller. You have the right, at any time, to request from the Data Controller access to your personal data (Article 15), rectification (Article 16) or erasure (Article 17) of such data or restriction of processing (Article 18) or to object to processing based on legitimate interest (Article 21). Finally, you have the right to data portability (Article 20).

8 – COMPLAINTS

If you believe that the processing of your personal data has been carried out unlawfully, you have the right to lodge a complaint with one of the competent supervisory authorities for compliance with personal data protection rules. In Italy, the complaint can be submitted to the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority).

9 – PERSONAL DATA COMMUNICATION

The communication of personal data is not mandatory. You are free to provide personal data in the areas dedicated on the website. Failure to provide personal data will result in the impossibility of using the services offered by the data controller.

10 – LEGISLATIVE REFERENCES AND USEFUL LINKS

The processing of your personal data is carried out by the data controller in full compliance with the provisions set forth by Regulation (EU) 2016/679 General Data Protection Regulation, Italian regulations on the processing of personal data and provisions of the Italian supervisory authority (http://www.garanteprivacy.it).

11 – CHANGES TO THE PRIVACY POLICY

The data controller reserves the right to modify, update, add, or remove parts of this privacy policy at its discretion and at any time. The data subject is required to periodically check for any changes to this page.