INFORMATION ON THE PROCESSING OF PERSONAL DATA FOR COMPLAINTS
Art 13 – 14 GDPR Regulation EU 2016/679
The following information is provided on the processing of personal data transmitted to the Company:
1. Data Controller and Data Protection Officer (DC/DPO)
The Data Controller is the company Marcolin S.p.A., with registered office in Zona Industriale Villanova 4, 32013 Longarone (BL), VAT Reg. No. 00298010257 (hereinafter for the sake of brevity “the Company” or the “Data Controller”).
The Company has also appointed a Data Protection Officer (DPO) who can be contacted at: email@example.com.
2. Type of data processed, purposes and legal basis for processing
The generic personal data (contact details) of the complainant and information indicated by same complainant in the complaint are collected and processed in order to manage requests/reports/complaints or to answer any requests for information and to fulfil any related legal obligations. If the data subject provides any health data (e.g. allergies, side-effects of products, etc...) in the complaint, the Data Controller will have to process this type of data for which the express consent of the data subject is required.
The legal basis for the processing is therefore: fulfilment of the obligations of a request made by the data subject (contractual or pre-contractual obligations), legal obligations and the express consent of the data subject for the management of any health data provided.
3. Disclosure of data to third parties - Recipients of the data
The Company may transmit the data processed for the purposes indicated above to: i) subjects in the company; ii) third companies involved in the request/complaint; iii) insurance companies.
4. Data transfer to third countries
The Data Controller will not transfer the data processed to third countries. However, if data is transferred to third countries, such transfer will be performed in accordance with the regulation concerning the transfer of data to third countries applicable at the time of the transfer.
5. Processing methods and data retention times and criteria
The data will be processed in printed and digital format and will be retained for the period necessary for the accomplishment of the purpose(s) indicated above and, after fulfilment of such purpose(s), for the further time limit set by law regarding the retention of contracts and administrative data and/or for the purpose of defence in legal proceedings if necessary (ten years from the last use and/or event interrupting the statute of limitations).
6. Transmission of Data
The transmission of data is obligatory for the performance of the contract and for legal purposes. Non-transmission of data will make it impossible to fulfil the purposes indicated above. Consent to processing is obligatory for health data. Non-consent will make it impossible to manage the complaint.
7. Data subject’s rights, Withdrawal of Consent and Complaint to the Supervisory Authority
The data subject has the right to request access to his or her personal data, rectification, cancellation and restriction of the data, to object to the processing and to exercise the right to data portability at any time.
In any case, the data subject has the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
In the case of an alleged infringement, the data subject, assumptions existing, also has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement.
8. Profiling and automated decision-making processes
The processing is not performed using automated decision-making processes (e.g. profiling).
9. Contacts and questions
Send an email to the address indicated below to receive the complete list of privacy representatives appointed for each area and activity and of the Data Processors/to obtain more information about the transfer of data to countries outside the EU, about the mechanisms and protection of the transfer of data as of article 44 et seq. of the GDPR/to exercise the right to withdraw consent already given/to exercise your rights (access, rectification, cancellation, restriction, objection, portability: firstname.lastname@example.org.