Blastness S.p.A., with registered office in Piazza Castello, 26 20121 Milano, fiscal code and VAT number 01195440118, as Data Controller (hereinafter, “Data Controller”), hereby provides you, pursuant to and for the purposes of EU Regulation No. 2016/679 (hereinafter, “GDPR”), with information regarding the processing of personal data collected while signing and/or executing the contract with the Data Controller.
1. Personal data and source of the data
In the context of signing and/or executing the contract, the Data Controller processes personal data and contact details (e.g., name, surname, e-mail address, mobile phone number, company name, VAT number, etc.) relating to you and to your employees and collaborators.
2. Purpose, legal basis of the processing and nature of the provision of data
In the context of signing and/or executing the contract, your data will be processed for the following purposes:
- a) Managing pre-contractual and contractual relations and executing the contract.
The legal basis of the processing is the performance of contractual obligations pursuant to Article 6(1)(b) of the GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the contract with the Data Controller.
- b) Fulfilment of regulatory obligations to which the Data Controller is subject, including but not limited to tax obligations related to the execution of the contract, other administrative/accounting.
The legal basis of the processing is the fulfilment of regulatory obligations pursuant to Article 6(1)(c) of the GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the contract with the Data Controller.
- c) Defence of the Data Controller's rights in judicial and extrajudicial proceedings.
The legal basis for the processing of the data is the pursuit of the legitimate interest consisting in the protection of the interests and rights of the Data Controller pursuant to Article 6(1)(f) GDPR.
The provision of personal data is necessary; therefore, the omission of the personal data requested makes it impossible to conclude and execute the contract with the Data Controller. However, you may request to object at any time, by sending a motivated request to the Data Controller, to the processing of personal data carried out on the basis of legitimate interest, pursuant to and for the purposes of Article 21 GDPR; your request, in this sense, will be subject to evaluation and response by the Data Controller.
- d) Data Controller’s marketing purposes, i.e., to send you via e-mail commercial communications relating to products, services, initiatives and projects of the Data Controller or the other companies of the group (in particular, Nero Lifestyle S.r.l.), as well as to send you customer satisfaction surveys and/or questionnaires.
The legal basis for the processing of the data is the consent pursuant to Article 6(1)(a) GDPR and Article 130 of Legislative Decree no. 196/2003.
The provision of personal data for this purpose is optional; therefore, failure to provide the requested personal data does not make it impossible to conclude and execute the contract with the Data Controller, and your right to withdraw your consent or object to such processing at any time, easily and free of charge, in the ways indicated in the “Data subject’s rights” section of this information notice and/or with those indicated in the promotional communications that will be sent to you from time to time, remains unaffected.
3. Recipients of the data
The data may be communicated for the pursuit of the aforementioned purposes to other entities such as, for example, public authorities and law enforcement agencies, law firms, accountants, etc., who will process the data as independent data controllers for their own purposes. The following subjects may also have access to the data:
- the staff of the Data Controller, who are expressly authorised to process them, in accordance with the instructions given, pursuant to Articles 29 and 32(4) of the GDPR and 2-quaterdecies of Legislative Decree no. 196/2003;
- service providers in favour of the Data Controller, appointed as Data Processors, including but not limited to IT providers, etc. The updated list of Data Processors may be requested to the Data Controller.
Personal data are not disseminated.
4. Data retention periods
Personal data processed for the purpose indicated in points (a), (b) and (c) of section 2 above are kept only for the time strictly necessary to carry out the activities/purposes described above and, in particular, for the time required by the tax law (10 years) or for the period of prescription of possible legal actions.
The personal data processed for the purposes of marketing indicated in point (d) of section 2 above are kept until the revocation of consent or opposition to the processing or for 24 months from the moment of the last renewal of consent and of the will not to oppose the processing. This is without prejudice to the data subject's right to revoke consent or object to the processing at any time, by contacting the Data Controller, with consequent cancellation of the personal data processed for marketing purposes.
5. Extra-EEA Data transfer
The Data Controller may transfer you personal data to the United Kingdom on the basis of the relevant Adequacy Decision adopted by the European Commission.
With regard to the other possible transfers of data to Third Countries outside the European Economic Area, the Data Controller informs you that the transfer will be carried out according to one of the modalities set out in Articles 44 et seq. of the GDPR, such as, for example, the adoption of Standard Clauses approved by the European Commission, the selection of subjects participating in international programmes for the free movement of data or operating in countries considered safe by the European Commission, in compliance with Recommendations 01/2020 adopted on 10 November 2020 by the European Data Protection Committee. Alternatively, transfers may be necessary on the basis of one of the exceptions set out in Article 49 of the GDPR, for example with the informed consent of the data subject or to perform a contract concluded between the data subject and the Data Controller or pre-contractual measures taken at the request of the data subject, or a contract concluded between the Data Controller and another natural or legal person for the benefit of the data subject, or for important reasons of public interest or to establish, exercise or defend a right in court or, again, to protect the vital interests of the data subject or of other persons where the data subject is physically or legally incapable of giving consent. Further information on possible transfers and the related safeguards implemented can be obtained, upon request, from the Data Controller.
6. Data subject’s rights
Data subjects may assert their rights and/or request information on the processing of their data by contacting the Data Controller. The GDPR grants the right to:
- a) withdraw the consent given, with the understanding that withdrawal of consent shall not affect the lawfulness of the processing based on the consent prior to the withdrawal;
- b) access or obtain a copy of the personal data as well as to know the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular if they are recipients in third countries or international organisations; where possible, the period for which the personal data are to be stored or, if this is not possible, the criteria used to determine that period; the existence of the data subject’s right to request from the data controller the rectification or erasure of personal data or the restriction of the processing of personal data concerning him or her or to object to their processing; the right to lodge a complaint with a supervisory authority; where the data are not collected from the data subject, all available information on their source; the existence of an exclusively automated decision-making process, including profiling, and, at least in such cases, meaningful information on the logic used, as well as the importance and the envisaged consequences of such processing for the data subject;
- c) rectification and integration of inaccurate or outdated data;
- d) erasure, whenever the data are no longer necessary in relation to the purposes pursued, or if the data subject decides to withdraw consent or objects to the processing and there are no other legal grounds for keeping the data, or if the data are processed unlawfully, or have to be erased because of a legal obligation;
- e) restriction of processing if the data subject contests the accuracy of the personal data, for the period necessary for the controller to verify the accuracy of the personal data; if the processing is unlawful and the data subject objects to the erasure of the personal data and requests instead that their use be restricted; even though the controller no longer needs them for the purposes of the processing, if the personal data are necessary for the establishment, exercise or defence of legal claims; if the data subject has objected to the processing, pending verification as to whether or not the legitimate reasons of the controller prevail over those of the data subject.
In cases of exercise of the rights referred to in points c), d), and e), the data subject has the right to know the recipients to whom the personal data have been transmitted and the right that the Controller communicates to them the rectification, erasure or restriction of the processing, unless this proves impossible or involves a disproportionate effort.
- f) data portability, i.e. to receive in a structured, commonly used and machine-readable format the personal data concerning him/her, including the direct transfer of the same by the Controller to other Controllers, where the processing is carried out by automated means and is based on consent or contract;
- g) object to the processing where the processing is based on the legitimate interest of the Controller, as already specified in point 2 above;
- h) lodge a complaint to the competent Supervisory Authority (for Italy, the Garante per la protezione dei dati personali, https://www.garanteprivacy.it).
7. Contact details
You may contact the Data Controller and exercise your right listed in the previous Paragraph by sending an email to privacy@blastness.com or by sending a registered letter with advice of receipt to the Data Controller's head office in La Spezia, Via P. E. Taviani n.164 – 19125.