Privacy Policy: Events
This notice is provided pursuant to Article 13 of EU Regulation 2016/679 concerning the protection of natural persons with regard to the processing of personal data, as well as the free movement of such data (hereinafter “GDPR”), to data subjects whose personal data are processed for the purpose of registering for and participating in the event organized by the Engineering Group.
This document outlines the purposes and methods by which your personal data are processed, which personal data are subject to processing, what the rights of data subjects are, and how such rights may be exercised.
1. Data Controller and Data Protection Officer
Pursuant to Article 4 of the GDPR, the data controller of your personal data referred to in this notice is the Engineering Group Company with which you or your company has a contractual relationship for supply and/or collaboration (“Controller”).
The Controller has appointed a Data Protection Officer (Data Protection Officer or “DPO”), who can be contacted at the following email address: dpo.privacy@eng.it.
2. Purposes of the processing and legal bases
The Controller will process your data to allow you to register for and participate in the event organized by the Controller.
In particular, your personal data will be processed:
a. to allow your registration, via a form specifically generated by the Controller, and participation in the event [Art. 6(1)(b) GDPR];
b. for the purpose of sending commercial and/or promotional communications to the data subject relating to products and/or services offered by the Controller [Art. 6(1)(b) GDPR]. Consent may be withdrawn at any time, interrupting such commercial and promotional activities, by sending a communication to the address dpo.privacy@eng.it;
c. for the sending of commercial and/or promotional communications to the data subject relating to products and/or services offered by other companies of the Engineering Group [Art. 6(1)(b) GDPR]. Consent may be withdrawn at any time, interrupting such commercial and promotional activities, by sending a communication to the address dpo.privacy@eng.it;
d. to carry out checks on data and network security and to prevent and counter possible cybercrimes, thus pursuing the legitimate interest of the Controller in maintaining the protection of internal IT systems and applying appropriate security measures, as well as establishing, exercising, or defending a legal claim [Art. 6(1)(f) GDPR].
The provision of your personal data for the above purposes is optional, but failure to provide them will make it impossible, in whole or in part, for the Controller to allow you to properly participate in the event.
3. Authorized persons and data recipients
The Controller will share your personal data with its employees and collaborators specifically identified and instructed in writing pursuant to Article 29 of the GDPR (“Authorized Persons”), who will process such data, under the authority of the Controller, exclusively for the purpose of performing their respective job duties.
Your personal data may also be shared with third parties, appointed as data processors by the Controller in writing pursuant to Article 28 of the GDPR, or, where required by applicable law, as independent data controllers.
With reference to such categories of third-party recipients, it is specified that your data may be shared with public authorities where this is mandatory in compliance with legal provisions or orders from competent authorities.
4. Transfer of data outside the EU
In pursuing the above purposes, your personal data will not be shared with recipients located outside the European Union / European Economic Area.
5. Data retention period
Your personal data will be retained, with logic strictly related to their security and the resilience of the systems used for their processing, for the time strictly necessary to carry out the event. In particular, the storage and processing of your data will take place in full compliance with the principles of data minimization and storage limitation pursuant to Article 5 of the GDPR.
Contact data processed for the purpose of carrying out promotional activities based on your consent will be processed for twenty-four (24) months from the date on which consent was given, unless revoked. This period may be extended by the data subject by renewing consent for processing for this purpose.
Furthermore, the Controller may retain your personal data for a longer period in order to comply with contractual and legal obligations applicable to it and, where necessary, to establish, exercise, or defend its rights in judicial and extrajudicial proceedings, in any case for the maximum period permitted by applicable law pro tempore.
6. Rights of data subjects
Pursuant to applicable law, you have the following rights.
You may exercise your rights, in accordance with Article 12 of the GDPR and within the limits set out in Article 23 of the GDPR, by writing to the Controller’s contacts indicated in this notice or to the DPO’s address: dpo.privacy@eng.it.
Without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with the competent supervisory authority where you believe that there has been a violation of your rights regarding personal data protection. Further information is available on the website https://www.garanteprivacy.it