PRIVACY
INFORMATION ON THE PROCESSING OF PERSONAL DATA
pursuant to art. 13 of Regulation (EU) 2016/679 (GDPR)
Website
Version 2024
This information is provided in accordance with the provisions of art. 13 of EU Regulation 2016/679 (in English General Data Protection Regulation , hereinafter “GDPR”) and describes the methods of processing the personal data of visitors/users who consult the website of PHSE SRL (hereinafter, “Data Controller”, “Owner” or “PHSE”) accessible electronically at the address https://phse.com/ .
- DATA CONTROLLER
1.1. The Data Controller is PHSE SRL, with registered office in Via Del Lavoro snc, p. T-S1 Località Cà dei Bolli 26817 San Martino in Strada (LO), VAT number 04176351213 .
1.2. Contact details: Telephone: 081 53941; PEC: phse@pec.com, E-mail: info.it@phse.com .
- DATA PROTECTION OFFICER
2.1. The data protection officer, who can be contacted for all matters relating to the processing of personal data and the exercise of rights deriving from the GDPR, is available at the following addresses: a) telephone: 055750808; b) e-mail: dpo.sicurdata@opendata.it.
- PERSONAL DATA PROCESSED, PURPOSE OF THE PROCESSING, LEGAL BASIS, NATURE OF THE PROVISION AND PERIOD OF RETENTION
3.1. In this paragraph, in relation to each purpose, you will be informed of the personal data processed, the legal basis of the processing, the nature of the provision and the retention period.
- Website navigation. Personal data processed: personal data implicitly transmitted during the use of internet communication protocols (IP, domain names of computers used to connect to the site, URI – Uniform Resource Identifier – addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response to the server and other parameters relating to the operating system and the user’s IT environment). Purpos : to allow navigation and consultation of the website. Legal basis: art. 6.1 lett. f) GDPR as the processing is necessary for the pursuit of the legitimate interest of the controller. Nature of the provision: necessary to be able to navigate the website. Retention period : the entire duration of the browsing session in relation to the data collected during the same and for a maximum period of seven (7) days, without prejudice to a further period if it were necessary to ascertain the responsibility for any computer crimes.
- Requests for assistance or information. Personal data processed: name, surname, email address, telephone number and other information that you may voluntarily send us in addition to those relating to browsing the website. Purpose: to respond to requests for assistance or information, which we will receive via email, telephone, chat or via the appropriate form. Legal basis: art. 6.1 lett. b) GDPR as the processing is necessary for the execution of a contract to which the interested party is a party or for the execution of pre-contractual measures adopted at the request of the same. Nature of the provision: necessary to be able to make requests for assistance or information. Retention period: for the entire duration necessary to respond to your requests for assistance or information and in any case for a maximum period of one year once we have responded to your requests.
- Provision of services . Personal data processed : identification data and data necessary for the processing and conclusion of the requested services, including name, surname, address of residence, e- mail address, telephone number and other information that may be necessary to fulfill the provision of the service. Purpose: provision of services and communications related to the performance of the established relationship. Legal basis: art. 6.1, lett. b) GDPR as it is necessary for the execution of a contract to which the interested party is a party or for the execution of pre-contractual measures adopted at the request of the same. Nature of the provision: necessary to be able to use the requested services. Retention period: ten (10) years from the provision of the service for administrative and accounting purposes.
- Legal obligations. Personal data processed: the same collected during the purchase of products and services and related delivery/provision. Purpose : to fulfill legal, accounting and tax obligations related to the provision of services. Legal basis: art. 6.1 lett. c) GDPR as it is necessary to fulfill a legal obligation to which the data controller is subject. Nature of the provision : necessary to allow correct accounting and administrative management. Retention period: ten (10) years from the provision of the service for administrative and accounting purposes.
- Customer Satisfaction. Personal data processed:name, surname, email address and telephone number. Purpose: to process studies, research, market statistics; to send you advertising, informational material, commercial information or surveys to improve the service (“customer satisfaction”) via email or text message, and/or through the use of the telephone with an operator and/or through the official pages of PHSE on social networks. Legal basis: your consent pursuant to art. 6.1 letter a) GDPR. You can withdraw your consent at any time by writing to one of the addresses provided in this information. The withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal. Nature of the provision: optional, and does not affect the other purposes of processing. Retention period: until your consent is withdrawn.
- Marketing. Personal data processed: name, surname, email address and telephone number. Purpose: to make personalized commercial proposals based on the products or services you have purchased, or which you are interested in while browsing our site. Legal basis : your consent pursuant to art. 6.1 letter a) GDPR. You can withdraw your consent at any time by writing to one of the addresses provided in this information notice. The withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal. Nature of the provision: optional, and does not affect the other purposes of processing. Retention period: until your consent is withdrawn.
- Fraud prevention. Personal data processed: behavior on the website, including IP addresses. Purpose: security and prevention of fraudulent conduct, for which the owner uses an automatic control system that involves the detection and analysis of user behavior on the site associated with the processing of personal data, including the IP address. Legal basis: art. 6.1 lett. f) GDPR as the processing is necessary for the pursuit of the legitimate interest of the owner. Nature of the provision: necessary to be able to navigate the website. Storage period: seven (7) days, except in the case of an anomaly. In this case the data will be stored until the behavior is ascertained and, in the case of legal action, until the end of the same.
3.2. In relation to cookies , please read the cookie policy available on this website.
3.3. Your personal data may be processed, if necessary and after its provision for the purposes indicated above, to ascertain, exercise or defend a right in court, on the basis of the legitimate interest of the data controller (art. 6.1 letter f) GDPR).
- DATA RECIPIENTS.
4.1. The processed data will not be disclosed to third parties except in cases provided for by law.
4.2. In order to provide the requested services, the data controller may entrust your personal data to various service providers, with whom it has drawn up a specific contract aimed at protecting your personal data and complying with the legislation on the protection of personal data. These are entities identified as data controllers pursuant to art. 28 GDPR to whom the data controller has entrusted, by way of example but not limited to, the following services: i) individuals, companies or professional firms that provide assistance and consultancy to PHSE in accounting, administrative, legal, tax, financial and debt collection matters relating to the provision of the Services; ii) entities with whom it is necessary to interact for the provision of the Services; iii) or entities delegated to carry out technical maintenance activities (including maintenance of network equipment and electronic communication networks).
4.3. The owner may communicate your personal data to subjects, entities or authorities to whom communication is mandatory by virtue of provisions of law or orders of the authorities. These subjects will operate as independent data controllers.
4.4. Your personal data may be processed by persons authorised by PHSE pursuant to art. 29 GDPR, who have undertaken to maintain confidentiality or have an appropriate legal obligation of confidentiality, such as the owner’s employees.
4.5. The complete list of data controllers is available by sending a request to the owner at one of the contact points indicated in this information.
- DATA TRANSFER
5.1. Some of your Personal Data are shared with Recipients who may be located outside the European Economic Area including offices in the UK and Singapore. PHSE Srl ensures that the processing of your Personal Data by these Recipients occurs in compliance with the Regulation. Indeed, transfers may be based on an adequacy decision or on the Standard Contractual Clauses approved by the European Commission.
- RIGHTS OF THE DATA SUBJECTS
6.1. In relation to the data itself, the interested party, or a person delegated in writing, can exercise the following rights, also by writing to the contact points of the owner indicated in this information: a) the right of access pursuant to art. 15 GDPR; b) the right to rectification pursuant to art. 16 GDPR; c) the right to be forgotten pursuant to art. 17 GDPR; d) the right to restriction of processing when one of the hypotheses provided for by art. 18 GDPR applies; e) the right to receive certification that the operations carried out pursuant to arts. 16, 17 and 18 GDPR have been brought to the attention of those to whom the data were communicated, unless this proves impossible or involves a disproportionate effort (art. 19 GDPR); f) the right to data portability pursuant to art. 20 GDPR; f) the right to object to the processing of personal data pursuant to art. 21 GDPR; g) the right not to be subject to a decision based solely on automated processing pursuant to art. 22 GDPR; g) the right to withdraw consent at any time pursuant to art. 7 GDPR.
6.2. You have the right to lodge a complaint with a supervisory authority, pursuant to art. 77 GDPR.
6.3. To exercise your rights, you may contact the data controller or the data protection officer at the contact points indicated in this notice.
- FURTHER INFORMATION
7.1. The data controller remains available for any clarification needed and, should the processing be modified with respect to that described in this document, the data controller will provide a specific updated information.
7.2. The protection of your data and compliance with the principles set forth by the legislation, with particular reference to the principle of transparency, are values of primary importance to us. We would be grateful if you would help us by reporting any misunderstandings of this document or by suggesting improvements to the owner’s references as indicated above.
[ ] having read the privacy policy[ ] consent to the processing of personal data for Customer Satisfaction purposes[ ] consent to the processing of personal data for marketing purposes