Privacy Policy

Company website privacy policy

 

 

Foreword
AM Technology S.r.l., c.f. and VAT nr. 03891800249, with registered office in Via Ferracina 13 - 36043 Camisano Vicentino (VI) (hereinafter, "Data Controller") informs, pursuant to Art. 13 EU Regulation no. 2016/679 (hereinafter, "GDPR"), that your data will be processed in the following terms and for the following purposes:

 

Definitions and legal references
Personal Data (or Data)
Personal data is any information relating to a natural person, identified or identifiable, even indirectly, by reference to any other information, including a personal identification number.
Use/Navigation Data
The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data (so-called log files) whose transmission is involved in the use of Internet communication protocols.
This is the information collected automatically by this Application (or by the third-party applications used by this Application) to be associated with identified interested parties, but which could, by their very nature, through processing and association with data held by third parties, allow users to be identified. This information includes: IP addresses or domain names of the computers used by the User who connects with this Application, URI (Uniform Resource Identifier) notation addresses, the time of the request, the procedure used to submit the request to the server, the size of the file received in answer, the code number indicating the status of the server response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various timeframes of the visit (e.g. the time spent on each page) and details of the itinerary followed within the Application, with special reference to the sequence of pages visited, the parameters relating to the User's operating system and computer environment.
This data may be used to obtain statistical information, also anonymous, on the use of the website and to check that it is working properly. The data may be used to ascertain responsibility in case of possible computer crimes to the damage of the website and may be shown to the Judicial Authority, should the latter expressly request it.

User
The person who uses this Application, who must correspond to or be authorized by the Data Subject and whose Personal Data are being processed.
Data subject
The natural or legal person to whom the Personal Data refer.
Data Controller (or Processor)
The natural or legal person, the public administration and any other body, association or organization that processes personal data on behalf of the data controller.
Data Controller (or Data Holder)
The natural person, legal person, public administration and any other body, association or body which is responsible, also jointly with another Controller, for deciding the purposes, means and methods of the processing of personal data and the instruments used, including the security profile, in relation to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.
This Application
The hardware or software tool by which Users' Personal Data are collected.

Cookie
Cookies are small text strings sent to the user's computer when visiting a website that store, and sometimes track, information about the use of the Site by the user.
Legal references
Notice to European Users: this privacy policy is drawn up in compliance with the obligations provided for by Articles 13 and ss EU Reg. GDPR 679/2016 as well as with the provisions of Directive 2002/58/EC, as updated by Directive 2009/136/EC, concerning Cookies.
This privacy policy exclusively concerns this Application.

 

Availability of the Policy
The Controller grants the possibility of accessing this policy: a) by browsing this website; b) each time an express request is made.

 

Collected Data
Among the Personal Data collected by this Application, either independently or through third parties, are: IP addresses; Cookies; Usage Data; first name; last name; phone number; country; email; various types of Data; city.
Personal Data may be freely provided by the User or, in the case of Usage Data, may be automatically collected when using this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, this Application may not be able to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refuse to communicate such Data, without this having any consequences on the availability of the Service or its operation.
Users who have any doubts as to which Data are mandatory are invited to contact the Controller.
The possible use of Cookies - or of other tracking tools - by this Application or by the owners of third-party services used by this Application, where not otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and warrants that he/she has the right to transmit or disclose them, releasing the Controller from any liability towards third parties.

 

Subject of processing
The Controller processes personal, identifying, and non-sensitive data (in particular, IP address, first name, last name, email, type of user - hereinafter, 'personal data' or 'data') provided by you when filling in forms on the Controller's website.

 

Purpose of processing
Your personal data may be processed for the following purposes:
1. Managing and updating the website content;
2. Fulfil pre-contractual, contractual and tax obligations arising from existing relations with you;
3. Fulfilling obligations required by law, by regulation, by EU provisions or by an order of the Authority;
4. Preventing or detecting fraudulent activity or harmful abuse of the website;
5. To exercise the Controller's rights, e.g. the right of defence in court;
6. To manage your request for information made by filling in the form;
7. Statistical purposes;
8. To allow the provision of any additional Services requested.

The website collects personal information from the user only in connection with specific services of the website and by means of contact forms. The user freely and consciously provides his/her data and if there is an obligation to provide it, this obligation is always made clear.
This website processes data based on:
- the expressly requested authorization to the User regarding statistics for non-anonymised purposes and by means of third-party cookies;
- the expressly requested consent for the provision of a specific service, such as the forwarding of commercial messages, handling of information requests;
- the use or consultation of this website, in relation to further methods and purposes described.
Some data, on the other hand, may be processed according to the legitimate interest of the user to benefit from the content published on the Controller's Internet websites and their proper administration and management, including the security and correct performance of the website.

 

Nature of data provision and consequences for refusal to answer
The provision of data for the above-mentioned purposes (nos. 1 to 5) is necessary to provide the Services you have requested.
The provision of data is voluntary for further purposes (handling of information requests, non-anonymised statistical purposes, provision of further requested services) and refusal to provide consent has no negative consequences on the service provided within the website and related applications. You may therefore decide not to provide any data or to later deny the possibility of processing data already provided: in this case, you will not be able, for example, to receive commercial communications and advertising material relating to the Services offered by the Controller. In any case, you will continue to be entitled to the Services referred to in points 1 to 5.

 

Data Processing systems
Your personal data is processed by the actions listed in Article 4 no. 2) GDPR, namely: collection, recording, organisation, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data. Your personal data are processed on paper, electronic and automated means.
The Controller shall process personal data for as long as necessary to fulfil the above purposes and in any case for no longer than 10 years from the end of the relationship in the case of Service Purposes and for no longer than 2 years from the collection of the data and/or from the last contact in the case of Marketing Purposes.
The Controller takes appropriate security measures to prevent unauthorised access, disclosure, modification, or destruction of Personal Data.
The processing is performed using IT and/or telematic instruments, with management methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Application (administrative, sales, marketing, legal, system administrators) or external subjects (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested to the Data Controller

 

Place of data processing
The processing operations connected to the web services of this site take place at the registered office of AM Technology S.r.l. and are carried out only by technical personnel of the Office in charge of processing, or by persons in charge of occasional maintenance operations.
Data are processed according to their storage in computer files at the company, access to which is limited to maintenance procedures.
No data resulting from the web service is communicated or disclosed.
Personal data provided by users who send contact requests are used only for the purpose of fulfilling the requested service or performance and are communicated to third parties only if this is necessary for that purpose (AM Technology S.r.l. shipping services).

 

Data Communication
Without your express permission, the Data Controller may in any case notify your data to supervisory bodies, judicial authorities as well as to all other subjects to whom the disclosure is compulsory by law for the fulfilment of the aforementioned purposes. Your data will not be diffused.

 

Data Transfer
The management and storage of personal data will take place on servers located within the European Union of the Data Controller and/or third-party companies duly appointed as Data Processors. Our servers are currently located in Italy. Data will not be transferred outside the European Union. In any case, it is understood that the Data Controller may, if necessary, move the location of the servers in Italy and/or within the European Union and/or countries outside the EU. In this case, the Data Controller hereby ensures that the transfer of data outside the EU will be carried out in accordance with the applicable legal provisions by concluding, if necessary, agreements guaranteeing an adequate protection level and/or by adopting the standard contractual clauses provided for by the European Commission.

 

Data storage
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be stored until the fulfilment of such contract is completed.
- Personal Data collected for purposes related to the legitimate interest of the Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When the processing is based on the User's permission, the Controller may keep the Personal Data for a longer period until such permission is revoked. In addition, the Controller may be obliged to store Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the storage period, the Personal Data will be deleted. Therefore, at the end of this period, the right of access, cancellation, rectification, and the right to Data portability can no longer be applied.
Personal data will be stored in paper and/or electronic/computerised form for as long as is strictly necessary to fulfil the purposes set out above in compliance with your privacy and current regulations.
User data processed by the Controller will be kept and stored on the platform of a third-party provider, duly appointed as data controller.
For analysis purposes aimed at developing and improving the service, the user's personal data may be stored for 36 months.
For the purposes of direct marketing and profiling, if any, the data will be stored for a maximum period equal to that provided for by the applicable legislation (24 and 12 months respectively).
Invoices, accounting documents and transaction data are stored for 10 years in accordance with the law (including tax obligations).
In case of exercising the right to be forgotten through a request for cancellation of personal data processed by the data controller, please note that such data will be kept, in a protected form and with limited access, solely for the purpose of investigating and prosecuting criminal activities, for a period not exceeding 12 months from the date of the request, and will thereafter be securely and irreversibly deleted or anonymised.
Data relating to telematic traffic, excluding in any case the contents of communications, will be stored for a period not exceeding 6 years from the date of communication, pursuant to Article 24 of Law No. 167/2017, which implemented EU Directive 2017/541 on anti-terrorism.
If no active action (e.g. browsing, searches and/or any other way of using the service) is performed on this website for a period of 27 months, you will be classified as an inactive user and the relevant personal data will be deleted

 

Intellectual Property Rights
The owner of the website is the holder of the intellectual property rights or has rights of use over all the elements accessible on the website, in particular text, images, graphics, logos, icons, sounds, software, etc.
Any duplication, representation, modification, publication, partial or total adaptation of the website's elements is prohibited, regardless of the means or processes used, except with prior written authorisation sent to info@am-technology.it.
Any improper or unauthorised use of the website or the elements it contains is a violation and will be prosecuted in accordance with the provisions of Article L.335-2 et seq. of the Intellectual Property Code.

 

Rights of the data subject
As a data subject, you have the rights provided for in Article 15 GDPR, i.e. the rights to:
A) obtain confirmation of the existence or non-existence of your personal data, even if not yet stored, and its communication in intelligible form;
B) get the information about:
• The origin of the personal data;
• the purposes and processing methods;
• the logic applied in case of electronic processing;
• the identity of the data controller, data processors and the designated representative and of the persons or categories of persons to whom the personal data may be communicated or who may become aware of them in their capacity as designated representative in the territory of the Country, data processors or persons in charge of processing;
C) get:
• the updating, rectification or, where interested, the integration of data;
• the cancellation, transformation into anonymous form or blocking of data processed in breach of the law, including data whose storage is not necessary in relation to the purposes for which the data were collected or subsequently processed;
• the confirmation that the operations referred to above have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disclosed, except where this turns out to be impossible or involves the use of means clearly excessive in relation to the safeguarded right;
D) object, in whole or in part:
• for legitimate reasons concerning your personal data processing, even if relevant to the purpose of collection;
• the use of your personal data for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communications, using automated calling systems without the intervention of an operator by email and/or through traditional marketing methods by telephone and/or paper mail. Please note that the data subject's right to objection for direct marketing purposes by automated means is extended to traditional means and that, in any case, the data subject's right to object may be exercised even partially. Therefore, the data subject may decide to receive only communications by traditional means or only automated messages or neither of the two types of communication.
• where applicable, he also has the rights set out in Articles 16-21 GDPR (Right to rectification, Right to be forgotten, Right to restriction of processing, Right to data portability, Right to object), as well as the right to complain to the Supervisory Authority.
No personal information about the user will be published, exchanged, transferred, or sold to third parties without informing the user.

 

Amendments to this Policy
This Policy is subject to change. We therefore recommend you check this Policy regularly and refer to the most up-to-date version.

 

 

PRIVACY MANAGEMENT SYSTEM - Documentation drawn up in compliance with the provisions of EU REG. 2016/679 "General Data Protection Regulation" and Legislative Decree 196/2003 "Data Protection Code, laying down provisions for the adaptation of the national system to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free circulation of such data and repealing Directive 95/46/EC".