Information on the processing of personal data

ICONT – Date Added 03/2025

Information on the processing of personal data.

Pursuant to Art. No. 13 of EUROPEAN REGULATION No. 679/2016.

Dear Interested Party,

GRS srl as the Data Controller in accordance with Article No. 13 of the European Regulation No. 679/2016 “General Data Protection Regulation (GDPR)” (hereinafter EU Regulation), laying down provisions on the processing of personal data, intends to inform you about the processing of your personal data.

The rule stipulates that anyone who processes personal data is required to inform the data subject about the data processed and the qualifying elements of the processing, which must in all cases be done in a lawful, fair and transparent manner, as well as protect the confidentiality and guarantee the rights of the data subject.

It should be noted that data processing means any operation or set of operations concerning the collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, dissemination, and destruction of data.

1. Data controller

The Data Controller is GRS srl, registered office in Via Cavalieri di Vittorio Veneto 14 in Martellago (VE) and an operating office in Via chiesa Campocroce 4 – real estate unit 0/1 – 31021 Mogliano Veneto (TV), C.F. and P. IVA 04071710273, contactable at the following addresses: phone +39 041 4069438, e-mail: info@grsnet.it.

2. Nature of Data Processed, Purpose and Legal Basis for Processing

Nature of data processed. In relation to the purposes of processing set out below, we inform you that only “common personal data” will be processed, such as:

  • Company identification data (company name, VAT number, tax code, type, address, telephone number,
    e-mail, etc.);
  • master data corporate contact person and legal officer (first name, last name, etc.);
  •  

Purposes of processing. Your personal data will be processed for the following purposes:

  1. Give feedback on your requests: by filling in, on a voluntarily basis, the form provided found in this contact area;
  2. Fulfil legal obligations;
  3. To send you informative newsletters on events and/or congrsss, etc., organized by the undersigned;

Legal basis of processing. Personal data, for the purposes set out in 2A and 2B will be lawfully processed to fulfill pre-contractual and contractual obligations between us and you (art.6, par.1 lett. b), to fulfill our legal obligations (art.6 par.1 lett. c).

Your personal data, for the purposes set out in point 2C of this information notice, may be lawfully processed with your specific separate, express, documented, prior and entirely optional consent (art. 6. parag.1 lett. a EU Regulation).

The consent you have given may be revoked at any time, without affecting the lawfulness of the processing based on the consent given before revocation (art.7 parag.3 EU Regulation)

In addition, we inform the data subject, that pursuant to Article 21 of the EU Regulation, the data subject has the right to object at any time to the processing of personal data concerning him or her carried out for the purposes of direct marketing (including profiling) and that, if the data subject objects to the processing, the personal data may no longer be processed for such purposes.

3. Data recipients and Processing methods Existence of automated decision making, including profiling

The processing of your personal data will be based on the principles of correctness, lawfulness and transparency and may be carried out by means of paper and electronic instruments both by the staff of the undersigned Company, authorized/charged with the processing of personal data, and by external parties called upon to carry out specific tasks, on behalf of the Data Controller, as Data Processors, pursuant to Art. 28 EU Regulation, subject to our letter of assignment imposing on them the duty of confidentiality and security of the processing of personal data, and the adoption of appropriate security measures to prevent loss of data, unlawful and incorrect use, and unauthorized access, in compliance with current provisions on the protection of personal data.

For the sake of brevity, the detailed list of these figures is available at the Data Controller’s office and is at your disposal.

Your personal data will not be disseminated and will not be transferred to third countries or international organizations, will not be disclosed to third parties except for legal or contractual obligations

With reference to the provisions of Art. 13 of the EU Regulation at para. 2 lett. f) and Art. 14 of the EU Regulation at para. 2 lett. g) it is hereby made known that the Data Controller at present does not have any automated system or decision-making process in use.

4. Data retention times

Your personal data will be retained for a period of time not exceeding the purposes for which they are processed, in accordance with the principle of retention limitation laid down in the EU Regulation and/or for as long as necessary for legal and contractual obligations or until the you withdraw your specific consent, and thus

  • with reference to the purposes indicated in pints 2A-2B, data will be kept for the time not exceeding the achievement of the purposes for which they are processed and/or for the time strictly necessary for the fulfillment of legal and contractual obligations;
  • with reference to the purposes stated in point 2C, the processed data will be kept no longer than 24 months after collection.

As a guarantee of the stated retention times, a periodic audit is to be conducted annually on the data processed and whether it can be deleted if it is no longer needed for the intended purposes.

5. Access to data (categories of recipients to whom data may be disclosed)

We also inform you that the data collected will never be disseminated and will not be communicated without your explicit consent, except for necessary communications that may involve the transfer of data to public bodies, consultants or other parties for the fulfillment of tax and legal obligations or for the fulfillment of purposes (where authorized), subject to our letter of assignment imposing on them the duty of confidentiality and security of the processing of personal data.

With reference to art. 13, par. 1, letter e) of the EU Regulation, we proceed to the indication of the subjects or categories of subjects (duly identified and instructed) who may become aware of the user’s personal data in their capacity as data processors or persons in charge of processing, and we provide below appropriate list by categories:

  • Partners, employees, collaborators and suppliers of the Data Controller in Italy and abroad, in their capacity as persons in charge/authorised and/or responsible for processing (e.g., offices: commercial, technical, administrative, legal, printing; system administrators, external professionals, various service providers, etc.).
  • Partner companies and/or directly connected with the writer, the activities of these being essential to the completion/execution of what you requested.

Your personal data may also be communicated to external recipients of the files concerning you, in the performance of the activities and to external parties interacting with the writer, always and exclusively for activities functional to the purposes described above, external parties called upon to carry out specific tasks, on behalf of the Data Controller, as Data Processors, pursuant to Article 28 of the EU Regulation.

For the sake of brevity, the detailed list of these figures is available at our office and is at your disposal.

6. e 7. Communication and transfer of data

Without the need for express consent (Art. 6 par. 1 (b), (c) and (f) of the EU Regulation), the Data Controller may disclose your data for the purposes set out in points 2A to 2F to supervisory bodies, judicial authorities, as well as to those entities to whom disclosure is mandatory by Law for the fulfillment of the above purposes.

These parties will process the data in their capacity as autonomous data controllers.

Personal data are stored on devices located at the Data Controller’s premises or at providers, within the European Union.

Your data will not be disseminated.

To ensure the security of such transfers, we only use entities that offer the necessary guarantees to put in place appropriate technical and organizational measures so that the processing carried out complies with EU Reg. 679/2016.

Both with regard to data on its own devices and any data held at providers, the Data Controller has put in place appropriate technical and organizational measures to ensure an appropriate level of security, in full compliance with the EU Regulation.

8. Consequences of non-disclosure of data

The personal data in items 2A-2B of this policy are necessary, without such data it would be impossible for us to proceed with registration (creation of your personal account), fulfill contractual and legal obligations.

Personal data, on the other hand, referred to in point 2C are optional the refusal to provide them will not entail any consequences and will not affect your request to proceed with the registration as well as to perform your contractual and legal obligations. You may therefore decide not to provide any data or subsequently deny at any time to process data already provided.

9. Rights of the data subject

In your capacity as a data subject, you have the rights set out in Articles No. 15 to 22 of the EU Regulation below, namely, you have the right to:

  • obtain confirmation of the existence and processing of personal data concerning him or her, and if so, obtain access to his or her data (so-called right of access);
  • Obtain information about the purposes of the processing, the categories of data concerned, the recipients or categories of recipients to whom the data have been or will be disclosed, particularly if recipients in third countries or international organizations, the expected data retention period or the criteria used to determine this period; and where the data are not collected from the data subject, obtain all available information about their origin;
  • Obtain the rectification of data concerning him or her (so-called right of rectification)
  • Obtain the deletion of data concerning him or her (so-called right to be forgotten);
  • Obtain limitations on processing (so-called right to limitation of processing);
  • Obtain portability of data, i.e., receive them from a data controller in a structured, commonly used, machine-readable format and transmit them to another data controller without hindrance (so-called right to data portability);
  • object to the processing at any time (so-called right to object). We specifically inform you, as required by Article 21 of the EU Regulation, that where personal data are processed for direct marketing purposes (including profiling), the data subject has the right to object at any time to the processing of personal data concerning him or her carried out for such purposes, and that where the data subject objects to the processing for direct marketing purposes, the personal data may no longer be processed for such purposes;
  • To be made aware (with an opportunity to object) of the existence of automated decision-making regarding natural persons, including profiling;
  • revoke consent at any time without affecting the lawfulness of processing based on the consent given before revocation;
  • Propose a complaint to a supervisory authority (Data Protection Authority).

It should be noted that there may be conditions or limitations to the data subject’s rights. It is therefore not certain that, for example, you have the right to data portability in all cases, this depends on the specific circumstances of the processing activity.

Another example: in case you decide to object to the processing of your data, the Data Controller has the right to evaluate your request, which may not be accepted if there are compelling legitimate grounds for processing that override your interests, rights and freedoms.

10. Ways of exercising rights

Without any formality you may at any time exercise your rights clearly and explicitly by sending:

– a registered letter with return receipt to the writer (see the address on the letterhead);

– an e-mail to info@grsnet.it.

Or by contacting the Data Controller directly at: +39 041 4069438.

11. Minors

What is offered by the Data Controller and the subject of the relationship with you in place does not involve the intentional acquisition of personal information referring to minors. In the event that information about minors is unintentionally recorded, the Data Controller will delete it in a timely manner upon request or notification by the data subject.

12. D.P.O. (R.P.D.) – Appointees/Authorized Persons – Processors.

Below we provide you with some information that it is necessary to bring to your attention, not only to comply with legal obligations, but also because transparency and fairness towards the Interested Parties is a founding part of our activity.

D.P.O. (Data Protection Officer) – R.P.D. (Data Protection Officer). You may also contact the Data Protection Officer to obtain information and make requests about your data or to report inefficiencies or any problems you may encounter.

The Data Controller has appointed Mr. Nicola Ghinello as Data Protection Officer who can be contacted at the following numbers: phone +39 348 3165267, e-mail: nicola.ghinello@dpo-rpd.com.

Appointees/Authorized Persons. The updated list of the Data Processors/Authorized Persons is kept at the offices of the Data Controller.

Data Processors.

For brevity, the detailed list of these figures is available from our office.

Follow Us

Head Office

ITALY (HQ)
Via Cavalieri di V. Veneto 14
30030 Martellago – Venice
Italy
VAT No. (IT)04071710273

UAE Office

GRS srl (DWTCA Branch) Sheikh
Rashid Tower, Floor 19 Dubai
(UAE)

UK ­OFFICE

7 Southfields Road SW18 1QW
London (United Kingdom)