Privacy Notice pursuant to Articles 13-14 of the GDPR (General Data Protection Regulation) 2016/679
Dear "Data Subject," we would like to inform you that the "EU Regulation 2016/679 of April 27, 2016, concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data" (hereinafter "GDPR") provides for the protection of individuals and other subjects concerning the processing of personal data.
DATA CONTROLLER
Zilmet SpA, the "Data Controller" of personal data processing, informs you, pursuant to Article 13 of the GDPR, that it will process the personal data provided by you in the following manner:
The data provided at the time of registration and in reports will be processed in accordance with the principles of fairness, legality, transparency, and the protection of privacy and rights, both yours and those of all interested parties, in compliance with the confidentiality obligations imposed by privacy regulations and whistleblowing laws.
LEGAL BASIS FOR PROCESSING
The processing of personal data is necessary to fulfill a legal obligation to which the data controller is subject. Personal data is processed by the Reporting Manager of Zilmet SpA in the execution of their duties or otherwise related to the exercise of their powers, with particular reference to the task of investigating any reported wrongdoings in the interest of Zilmet SpA, in accordance with current whistleblowing regulations.
Some processing is based on consent:
- disclosing your identity to parties other than the internal reporting channel managers;
- recording telephone conversations or voice messages;
- recording your meeting with the internal reporting channel manager, or documenting such a meeting.
TYPES OF DATA PROCESSED AND PURPOSES OF PROCESSING
The data provided by the reporting party in order to report alleged misconduct of which they have become aware in the course of their service relationship with Zilmet SpA, committed by individuals who interact with them in various capacities, are processed for the purpose of conducting the necessary investigative activities to verify the validity of the reported matter and the adoption of related measures.
DATA PROCESSING METHODS
The personal data collected are processed by the staff of Zilmet SpA, acting on specific instructions provided regarding the purposes and methods of processing.
Processing will be carried out using computer and telematic tools with organizational and processing logic strictly related to the above-mentioned purposes, and in any case, in such a way as to ensure the security, integrity, and confidentiality of the data in compliance with the organizational, physical, and logical measures provided by current regulations.
DATA RETENTION PERIOD
Personal data related to reports are kept and retained for the entire time necessary to fulfill the reporting process and are retained on record for a maximum of 5 years from the date of communication of the final outcome of the reporting process, subject to longer retention periods determined by requests/orders from Authorities or for the defense of the rights of the Data Controller in court.
RIGHTS OF DATA SUBJECTS
Data subjects have the right to obtain from Zilmet SpA, in the cases provided for, access to their personal data and the rectification or erasure of such data or the restriction of processing concerning them or to object to processing (Articles 15 and subsequent of the Regulation), within the limits provided by Article 2-undecies of the privacy code.
Data subjects who believe that the processing of personal data concerning them carried out through this platform violates the Regulation have the right to lodge a complaint, as provided for in Article 77 of the Regulation itself, or to bring the matter to the appropriate judicial authorities (Article 79 of the Regulation).
CONTACT INFORMATION
Data Controller: Zilmet SpA
Data Controller's Contact: info@zilmet.it
Privacy Contact: info@zilmet.it