Information on the processing of personal data

This page describes how to manage this site in relation to the processing of personal data of users consulting it. This is a notice that is made in accordance with current legislation on personal data for users who interact with the services of this site in the framework of the 2016/679 EU Regulation. The information is provided for this site only and not for other websites that may be visited by the user through our links.

Data controller

Following consultation of the site, data relating to identified or identifiable persons may be processed. The “controller" of their processing is ESG Services based in Genzano di Roma.

Place of data processing

The treatments connected to the web services are handled only by technical staff in the office in charge of processing, or by people in charge of occasional maintenance operations. No data deriving from the web service is communicated or disseminated.

Purpose of the processing and legal basis of the processing

The personal data provided by users who request or intend to use services or products offered through the site as well as receive further specific content are used only to respond to requests or perform the service or provision requested and are disclosed to third parties only in the case where this is necessary for this purpose. The legal basis of these treatments is the need to give feedback to the requests of the interested parties or to carry out activities foreseen by the agreements defined with the interested parties.

With the express consent of the user, the data may be used for commercial communication activities related to offers of products or other services of the owner. The legal basis of this treatment is the consent freely expressed by the interested party.

Apart from these hypotheses, users' browsing data are kept for the time strictly necessary for the management of processing activities within the limits established by law.

Types of data processed

Navigation data

The computer systems and software procedures used to operate the site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified interested parties, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of computers used by users to connect to the website, URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the reply given by the server (done, error, etc.) and other parameters concerning the user's operating system and computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning and are deleted after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site.

Data provided voluntarily by users

The optional, explicit and voluntary sending of e-mails to the addresses indicated on the site entails the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the message. Specific summary information will be progressively reported or displayed on the pages of the site prepared for particular services on request.

Cookies

Cookies are a textual element that is inserted into the hard disk of a computer only after authorisation. Cookies have the function to streamline the analysis of web traffic or to indicate when a specific site is visited and allow web applications to send information to individual users. No personal data of users is acquired by the site in this regard. We do not use cookies to transmit information of a personal nature, nor are c.d. persistent cookies of any kind used, or systems for tracking users. The use of c.d. session cookies is strictly limited to the transmission of session identifiers (consisting of random numbers generated by the server) necessary to allow safe and efficient exploration of the site. c.d. session cookies used on the site avoid the use of other technologies that could compromise the privacy of users' browsing and do not allow the acquisition of personal identification data.

Optional provision of data

Apart from that specified for navigation data, the user is free to provide personal data to request the services offered by the owner. Failure to provide such data may make it impossible to obtain what has been requested.

Processing methods and data retention times

Personal data is processed with automated tools for the time strictly necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorised access.

Data is kept for the time strictly necessary for the pursuit of the purposes indicated in this statement and will be deleted at the end of this period, unless the data must be kept for legal obligations or to assert a right in court.

Rights of the interested parties

Within the limits and under the conditions established by law, the owner is obliged to respond to the requests of the interested party regarding personal data concerning him/her. In particular, based on the current legislation:

1. The interested party has the right to obtain from the data controller confirmation that it is or is not undergoing the processing of personal data concerning them and in this case, to obtain access to personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data in question;
  • the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if recipients of third-world countries or international organisations;
  • whenever possible, the retention period of the personal data provided or, if not possible, the criteria used to determine this period;
  • the existence of the right of the data subject to request the data controller to rectify or delete personal data or limit the processing of personal data concerning them or to oppose their treatment;
  • the right to lodge a complaint with a supervisory authority;
  • if the data are not collected from the data subject, all information available on their origin;
  • the existence of an automated decision-making process, including profiling;

2. The interested party has the right to obtain from the data controller the correction of inaccurate personal data concerning them without undue delay. Taking into account the purposes of the processing, the data subject has the right to obtain the integration of incomplete personal data, also by providing an additional declaration.

3. The data subject has the right to obtain from the data controller the deletion of personal data concerning them without undue delay and the data controller is obliged to cancel the personal data without undue delay within the limits and in the cases provided for by current regulations. The data controller communicates to each of the recipients to whom the personal data have been transmitted the eventual corrections or cancellations or limitations of the processing within the limits and in the forms provided for by the current regulations.

4. The interested party has the right to obtain the treatment limitation from the data controller.

5. The interested party has the right to receive, in a structured, commonly used and automatically readable form, the personal data concerning him/her provided to a data controller and has the right to transmit such data to another data controller without impediments from part of the data controller who supplied them.

To exercise the rights listed above, the interested party must submit a request using the following contact points through which the Data Protection Manager can also be contacted at info@esg-services.it

Requests should be sent to the Data Controller at the following address:

ESG Services L.go Giovanni Falcone, 5 - 00045 Genzano di Roma who can be contacted by the person in charge of data protection designated by the Data Controller.

The present version of the information on the processing of personal data was updated on 25 May 2018.