Informativa sulla privacy - D.lgs. 196/2003 e Reg. UE 2016/679 (GDPR)

This Privacy Information Notice explains the means by which your personal data are collected and processed in relation to browsing the website www.nobilmetal.it and the sub-domains:
ceramiche.nobilmetal.com
lvattachments.nobilmetal.com
members.nobilmetal.it 
In particular, it explains the manner in which personal data acquired during browsing (browsing log and cookies) and additional services connected thereto which foresee interaction with the user, e.g. the filling of a form for participation to an event or e-mail addresses on the site, are managed.
In this regard and in full compliance with the rules on the protection of personal data ((It.) Legislative Decree 196/2003 and Regulation (EU) no. 2016/679, so-called GDPR), Nobil Metal Spa would like to invite you to read the following information notice, which was conceived and written in simple and concise language that will help you clearly understand how we process your personal data.


1. IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER
Nobil Metal Spa receives and processes your data with respect and with the utmost care
The Data Controller is Nobil Metal Spa with Registered Office in Turin, at 49 Via G. Casalis, and Headquarters in Villafranca d’Asti, at 28 Strada San Rocco.

2. SOURCE, MEANS AND LEGAL BASIS OF PROCESSING
We ask you for your data to make browsing our site easier
Browsing data
IT systems and software procedures that make this web site function use, during their normal operation, certain personal data, the transmission of which is implicit in the use of Internet communication protocols. This information is not collected to be associated to identified data subjects but may, by its very nature and through treatment and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or the domain names of the computers used by the users who connect to the site, the addresses in URI (Uniform Resource Identifier) notation of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code that indicates the status of the response given by the server (success, error, etc.) and other parameters related to the user’s operating system and IT environment. 
These data are used for the sole reason of retrieving anonymous statistical information on the use of the site and to control its correct functioning. The data may also be used to ascertain liability in case of hypothetical cyber crimes to the detriment of the site (legitimate interests of the controller).
Cookies
Cookies are short fragments of text (letters and/or numbers) that allow the web server to store on the client (the browser) information to be reused during the same visit to the site (session cookies) or during subsequent visits, even days later (persistent cookies). Cookies are stored, based on the user’s preferences, by the individual browser on the specific device used (computer, tablet, smartphone).
Similar technologies, e.g. web beacons, transparent GIFs and all forms of local storage introduced with HTML5, may be used to collect information on the behaviour of the user and on the use of the services.
Throughout this document we will refer to cookies and to all similar technologies simply by using the term “cookie”.
Based on the characteristics and the use of cookies, we can distinguish various categories:

  •  Strictly necessary cookies. These are cookies indispensable for the correct functioning of the site www.nobilmetal.it and they are used to manage login and access to the reserved functions of the site. The duration of the cookies is strictly limited to the work session (they are deleted once the browser has been shut down).
  • Technical cookies. Technical cookies are those used for the sole purpose of “transmitting a communication on an electronic communications system, or to the extent that is strictly necessary for the provider of an Information Society service who has been expressly requested by the subscriber or by the user to provide such service (see article 122(1) of the Code). These cookies are not used for other purposes and are usually installed directly by the controller or the website administrator. They may be further divided in navigation or session cookies, which guarantee the normal navigation and use of the website (allowing users to, for instance, make a purchase or authenticate themselves to access reserved areas); analytical cookies, similar to technical cookies when they are used directly by the site administrator to collect aggregated information on the number of users and on how they visit the website; functionality cookies, which allow users to browse based on a series of selected criteria (e.g. language, products selected for purchase) in order to improve the service provided thereby.
  • Analytical cookies. These cookies help improve the site’s performance, providing a better browsing experience
  • Profiling cookies. Profiling cookies are intended to create user profiles and are used to send advertising messages according to the preferences shown by the user while browsing the Web. Because of the particularly invasive nature of such devices on the users’ private sphere, the EU and Italian regulatory framework stipulate that users must be adequately informed on the use thereof and thus express their valid consent.

Visits to a website may result in receiving cookies either from the site visited (“first-party”) or from sites managed by other organisations (“third-party”). A notable example is represented by the presence of “social plugins” for Facebook, Twitter, Google+ and LinkedIn. These are parts of the page visited that are generated directly by the aforementioned sites and are incorporated in the page of the host site. The most common use of social plugins aims at sharing content on social networks. The presence of these plugins involves the transmission of cookies from and to all sites managed by these parties. The management of information collected by “third parties” is governed by the related information notices, which we would like to ask you to read.

To guarantee more transparency and for ease of use, please find below the URLs of the various information notices and the manners in which cookies are managed.
Facebook information notice: https://www.facebook.com/help/cookies 
Facebook (configuration): access your account. Privacy section
Twitter information notice: https://support.twitter.com/articles/20170514 
Twitter (configuration): https://twitter.com/settings/security
Google+    http://www.google.it/intl/it/policies/technologies/cookies
Google+ (configuration)    http://www.google.it/intl/it/policies/technologies/managing
YouTube    information notice: https://www.youtube.com/static@template=privacy_guidelines
Among third-party cookies we have also included certain components of Google Analytics, a web traffic analysis service provided by Google. Google Analytics can collect and anonymously analyse information on use behaviour. This information is collected by Google Analytics, which treats it in order to draw up reports on the websites themselves. This site does not use (and does not allow third parties to use) Google’s analysis tool to monitor or collect personal identification information. Google does not associate the IP address to any other data held by Google, nor does it attempt to link an IP address to a user’s identity. Google may also disclose this information to third parties where this is required by law or where such third parties process the aforementioned information on behalf of Google. For more information, please consult the following link: https://www.google.it/policies/privacy/partners 
The majority of Internet browsers are initially set to automatically accept cookies. You can find our cookies among the settings of your browser.
You can change these settings to block cookies or to receive notifications that cookies are being sent to the device of the user. There are various ways to manage cookies. You can refer to the instructions manual or to the help screen of your browser to find out how to regulate or change the settings of your browser. 
If you block the storage of cookies, we can no longer guarantee a correct functioning of the site: certain functions of the site may not be available and it may no longer be possible to view certain content. In addition, blocking cookies does not remove advertisements. Simply put, these will no longer be personalised.
The rules on the protection of personal data provide that we can store cookies on your device if they are strictly necessary for the functioning of this Site. We need your consent for all other types of cookies.
This Site uses various types of cookies. Some cookies are placed by third-party services that appear on our pages. It is possible to change or revoke your consent at any time from our site’s cookies settings page.
Contact forms or e-mail 
During browsing, certain parts of the Site may contain a contact form for registration to events organised by Nobil Metal Spa. The data may be used for the creation of an archive used to send suggestions or future initiatives of the Company by e-mail.
In addition, the optional, explicit and voluntary sending of e-mail to the addresses contained in this site results in the subsequent acquisition of the sender’s address, necessary to reply to the requests, as well as of other personal data that may have been inserted in the message. 

3. LEGAL OBLIGATIONS RELATED TO THE PROVISION OF PERSONAL DATA
Nobil Metal Spa specifies whether there are specific legal or contractual obligations related to the provision of personal data and the consequences of the refusal to provide them
Browsing data and certain cookies are necessary for the functioning of the Site; profiling cookies and the provision of personal data in the contact forms are optional and there is, therefore, no legal obligation.

4.  EXTENT OF THE CIRCULATION OF DATA
Your data will be processed by the smallest number of people possible, duly authorised by Nobil Metal Spa
Where appropriate and in conformity with the law and applicable requirements, we may transmit your personal data, by various means and for various reasons, to the following categories of persons:

  • External service providers who act on our behalf (including external consultants, business partners and professionals, IT consultants and persons tasked with technical support who perform checks and development activities on our IT systems);
  • External providers of IT services and services related to the archival of documents in outsourcing, in the event where there is a suitable agreement for the processing of data (or similar protections);

Nobil Metal Spa shall not sell, transfer or distribute your Data to third parties.
If, in the future, Nobil Metal Spa merges with another business or Company or is acquired thereby (or if there is a very high probability of this occurring), we may share your personal data with the (potential) new owners of the business or of the Company.

5. METHODS OF PROCESSING OF THE DATA
Your data will be processed in a way that guarantees confidentiality, integrity and availability
We undertake to adopt all suitable and reasonable measures to protect the personal information we retain from improper use, loss or unauthorised access. For this purpose, we have implemented a series of suitable technical and organisational measures. These include measures for handling any suspected data breach.

6. DECISION-MAKING BASED ON AUTOMATED PROCESSING
Your data will not be processed by fully automated decision-making processes
The processing of your personal data by Nobil Metal Spa does not foresee any automated decision-making that may produce legal effects that concern you or similarly significantly affect you.

7. DATA RETENTION PERIOD
Your data will be retained for the time that we deem necessary for the purpose for which they were collected
Browsing data will be retained for brief periods of time, except in the case of possible extensions related to investigation activities.
The cookies will be retained based on what is indicated in the cookies settings page.
Data collected from the contact forms will, instead, be retained for the entire duration of our professional relationship. Whenever you receive an e-mail from Nobil Metal Spa you will have the possibility - in case you no longer wish to receive communications and invitations from us - to cancel your subscription by clicking on the appropriate button present in all e-mails.

8. TRANSFER OF THE DATA ABROAD
Your data will not be transferred outside the European Union
The management and retention of your personal data will take place on servers located inside the European Union and owned by Nobil Metal Spa and/or by third Companies tasked and duly appointed as Data Processors. 
It shall, in any case, be understood that Nobil Metal Spa, whenever necessary, will have the right to move the management and/or retention of the personal data in Italy and/or the European Union and/or non-EU Countries. In such case, Nobil Metal Spa hereby guarantees that the transfer of the data outside the EU will take place in compliance with the applicable legal provisions, stipulating, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses set forth by the European Commission.

9. RIGHTS OF THE DATA SUBJECT
You have the right to request access to, the rectification, the portability and the erasure of your data, as well as the right to restriction and objection to processing
Pursuant to articles 7 and 23 of (It.)Legislative Decree 196/2003 and in accordance with the following articles of the GDPR 679/2016, you have the right, where applicable, to request from Nobil Metal Spa:

  • Article 6 - revocation of consent: you may ask to revoke the consent granted at any time;
  • Article 15 - access: you may request confirmation as to whether or not personal data concerning you are being processed, as well as additional clarifications regarding the information contained in this information notice;
  • Article 16 - rectification: you may ask to rectify or complete the data that you have provided us, if they are inaccurate;
  • Article 17 - erasure: you may request that your data be erased, if they are no longer necessary for our purposes, in case of revocation of consent or your objection to the processing, in case of unlawful processing, or if there is a legal obligation of erasure or if the data concern persons younger than sixteen.
  • Article 18 - restriction of processing: you may request that your data be processed only for purposes of retention, with the exclusion of other processing operations, for the period necessary for the rectification of your data, in case of unlawful processing for which you oppose erasure, if you must exercise your rights before the courts and the data we hold may be useful to you, and, lastly, in case of objection to the processing pending the verification whether our legitimate grounds override yours.
  • Article 20 - portability: you may request to receive your data or to have them transmitted to another controller of your choice in a structured, commonly used and machine-readable format.
  • Article 21 - objection to processing: you may at any time object to the processing of your data, unless we have legitimate reasons to perform processing that override yours, e.g. for the establishment, exercise or defence of legal claims.
  • Article 22 - objection to automated decision-making: you may object to automated decision-making, if the Controller performs this type of processing.

Further, we would like to inform you that you have the right to lodge a complaint with the Supervisory Authority, which in Italy is the Data Protection Authority (http://www.garanteprivacy.it).
You may at any time request to exercise the aforementioned rights from Nobil Metal Spa by sending an e-mail to the address privacy@nobilmetal.it.