Privacy Policy
This page gathers the privacy notices of Syneto S.p.A. and the Syneto Group under the EU GDPR: the notice for the data processed through this website, followed by the notices covering prospects, end users and partners.
Privacy notice — Website
PRIVACY NOTICE PURSUANT TO ART. 13 OF REGULATION (EU) 2016/679
regarding the data processed through the website https://syneto.eu/
Data protection is a matter we take very seriously, and we therefore wish to inform you about the manner in which your data are processed and the rights you may exercise under the data protection legislation in force, in particular Regulation (EU) 2016/679 (hereinafter also: the "GDPR").
For any further processing activities not set out in this notice, carried out through Syneto's other platforms and websites, please refer to the corresponding privacy notices made available by the Data Controller.
1. Data Controller and Data Protection Officer (DPO)
Data Controller
Syneto S.p.A.
Via Cefalonia n. 70
25124, Brescia (BS)
E-mail contact: [email protected]
Data Protection Officer (DPO)
Avv. Vera Cantoni
Address for the purposes of the appointment:
Via F. Turati, n. 26,
20121 – Milano (MI)
E-mail contact: [email protected]
2. The categories of data undergoing processing
The categories of "personal data" (pursuant to Art. 4.1 of the GDPR) processed by the Data Controller may include, by way of example only and by no means exhaustively:
- Personal and identification data (including, in particular, first name, surname, etc.);
- Contact data (including, in particular, e-mail address, telephone number, IP address, etc.);
- Data relating to the role held within the Company or Entity for which the data subject acts as a contact person (for example, where mentioned in the contact request submitted);
- Personal data relating to any services provided (such as, for example, in the context of handling a request submitted through the contact section).
3. Lawfulness and purposes of the processing
Personal data are processed in accordance with the provisions of the General Data Protection Regulation (GDPR) and of any other applicable data protection legislation. Details are provided below:
3.1 Purposes based on the data subject's consent (pursuant to art. 6(1)(a) of the GDPR)
The purpose requiring consent is the following:
- a) Responding to requests or questions submitted through the contact details indicated on this website, in order to receive information about our products and services, as well as about the activities carried out by Syneto. Such requests may concern, by way of example and without limitation, the sending of commercial catalogues and price quotations, support needs, as well as proposals for commercial collaboration. Please note that, where the request is aimed at establishing a pre-contractual relationship or is made within the context of an existing contractual relationship, the processing will be based on the taking of pre-contractual steps at the request of the data subject or on the performance of the contract, pursuant to art. 6(1)(b) of the GDPR.
The retention period of the personal data, with regard to the purpose set out in this section, is:
For purpose a: until the request has been handled, unless the responses provided and the information exchanged are necessary to demonstrate the fulfilment of any contractual obligations or obligations arising from any legal relationships established (in which case the retention period will be equal to that indicated in the specific notices issued in the context of such relationships).
4. Recipients or categories of recipients of the personal data (pursuant to art. 13(1)(e) of the GDPR) *
The Data Controller may disclose your data to:
- Internal offices and functions of the Data Controller itself;
- Companies and professional operators providing IT services, including electronic data processing, software management, cloud management, website management and IT consultancy;
- Mailing companies and hosting providers.
* The complete and up-to-date list of Recipients (pursuant to art. 4.9 of the GDPR) is available from the Data Controller at the contact details indicated above.
5. Recipients or categories of recipients of the personal data (pursuant to art. 13(1)(f) of the GDPR) and transfer of data to non-EU countries
The Data Controller informs you that it does not intend to transfer your data to countries outside the EU and the EEA for the purposes indicated above.
6. Rights of the data subject (pursuant to art. 13(2)(b) of the GDPR)
The data subject, in relation to the personal data covered by this notice, may exercise the rights provided for by the EU Regulation, as listed below:
- right of access by the data subject [art. 15 of the EU Regulation] (consisting in the possibility of being informed about the processing carried out on his or her personal data and, where applicable, of receiving a copy thereof);
- right to rectification of his or her personal data [art. 16 of the EU Regulation] (the data subject has the right to obtain the rectification of inaccurate personal data concerning him or her);
- right to erasure of his or her personal data without undue delay ("right to be forgotten") [art. 17 of the EU Regulation] (the data subject has, and will have, the right to obtain the erasure of his or her data);
- right to restriction of processing of his or her personal data in the cases provided for by art. 18 of the EU Regulation, including in the case of unlawful processing or where the accuracy of the personal data is contested by the data subject [art. 18 of the EU Regulation];
- right to data portability [art. 20 of the EU Regulation] (the data subject may request his or her personal data in a structured format in order to transmit them to another controller, in the cases provided for by that article);
- right to object to the processing of his or her personal data [art. 21 of the EU Regulation] (the data subject has, and will have, the right to object to the processing of his or her personal data in the cases provided for and governed by art. 21 of the EU Regulation);
- right not to be subject to automated decision-making [art. 22 of the EU Regulation] (the data subject has, and will have, the right not to be subject to a decision based solely on automated processing).
With regard to the purposes for which consent is required, the data subject may withdraw his or her consent at any time, with effect from the moment of withdrawal, without prejudice to the time limits provided for by law. In general terms, the withdrawal of consent takes effect only for the future.
The above rights may be exercised in accordance with the provisions of the Regulation by sending an e-mail to the following address [email protected].
Syneto S.p.A., in compliance with art. 19 of the EU Regulation, will inform the recipients to whom the personal data have been disclosed of any rectification, erasure or restriction of processing requested, where this is possible.
7. Right to lodge a complaint (pursuant to art. 13(2)(d) of the GDPR)
The data subject, where he or she considers that his or her rights have been infringed, has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
For further information on these rights and on how to exercise them, please refer to http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524 or send a written communication to the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
8. Possible consequences of failure to provide the data and nature of the provision of the data (pursuant to art. 13(2)(e) of the GDPR)
8.1 Where the data subject's consent applies
Please note that the purpose set out above has consent as its legal basis and that, with regard to that purpose, the data subject may withdraw his or her consent at any time, with effect from the moment of withdrawal, without prejudice to the time limits provided for by law. In general terms, the withdrawal of consent takes effect only for the future. Accordingly, the processing carried out before the withdrawal of consent will not be affected and will retain its lawfulness.
Failure to give consent, or partial consent (or its withdrawal), may prevent the full provision of the services or activities, with reference to the individual purposes for which consent is refused.
Please note that, with reference to requests for information, while consent to the processing of personal data remains free and optional, it is necessary for the handling of the request. Therefore, the submission of the request, or an equivalent expression of intent, will be regarded as the giving of consent, which may be withdrawn at any time with the consequences described above.
When the data are no longer necessary, taking into account the retention periods indicated above, they are regularly erased. Where their erasure proves impossible, or possible only with disproportionate effort due to a particular form of storage, the data may not be processed and must be archived in non-accessible areas.
9. Absence of fully automated decision-making pursuant to art. 22 of the GDPR
The use of purely automated decision-making processes as detailed in Article 22 of the GDPR is currently excluded. Should it be decided in the future to establish such processes for individual cases, the data subject will be notified separately where this is provided for by law, or through an update of this notice.
10. Methods of processing
The personal data will be processed in computerised and electronic form and entered into the relevant databases, which may be accessed, and thus known, by the staff expressly designated by the Data Controller as Processors and Persons authorised to process personal data, who may carry out consultation, use, processing, comparison and any other appropriate operations, including automated ones, in compliance with the legal provisions necessary to ensure, among other things, the confidentiality and security of the data, as well as the accuracy, updating and relevance of the data with regard to the stated purposes.
Processing of data useful for browsing purposes
The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This is information that is not collected in order to be associated with identified data subjects, but which by its very nature could, through processing and association with data held by third parties, make it possible to identify users.
The information that may be collected includes IP addresses, the type of browser or operating system used, addresses in URI (uniform resource identifier) notation, the domain name and the addresses of the websites from which access or exit was made (referring/exit pages), the time at which the request was made to the server, the method used and information on the response obtained, further information on the user's browsing of the site (see also the section on cookies) and other parameters relating to the user's operating system and computing environment.
These same data could also be used to identify and ascertain liability in the event of any computer crimes committed against the site.
Notice regarding minors under 14 years of age
Minors under 14 years of age may not provide personal data. Syneto S.p.A. shall in no way be held liable for any collection of personal data, or for any false statements, provided by a minor, and in any event, should such use be identified, Syneto S.p.A. will facilitate the exercise of the right of access and erasure submitted by the legal guardian or by the person exercising parental responsibility.
Amendments and updates
This notice bears the date of its last update in its heading.
Syneto S.p.A. may also make amendments and/or additions to this notice, including as a consequence of any subsequent amendments and/or additions to the legislation.
Legal references on the rights of the data subject
Article 15 — Right of access by the data subject
1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
- a) the purposes of the processing;
- b) the categories of personal data concerned;
- c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
- f) the right to lodge a complaint with a supervisory authority;
- g) where the personal data are not collected from the data subject, any available information as to their source;
- h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
2. Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer.
3. The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.
4. The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.
Article 16 — Right to rectification
The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Article 17 — Right to erasure ('right to be forgotten')
1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
- a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- b) the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
- c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
- d) the personal data have been unlawfully processed;
- e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
- f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).
2. Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
- a) for exercising the right of freedom of expression and information;
- b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
- d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- e) for the establishment, exercise or defence of legal claims.
Article 18 — Right to restriction of processing
1. The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:
- a) the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
- b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
- c) the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
- d) the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.
2. Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
3. A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.
Article 19 — Notification obligation regarding rectification or erasure of personal data or restriction of processing
The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.
Article 20 — Right to data portability
1. The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
- a) the processing is based on consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1); and
- b) the processing is carried out by automated means.
2. In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.
3. The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to Article 17. That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
4. The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.
Article 21 — Right to object
1. The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
2. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
3. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
4. At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.
5. In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise his or her right to object by automated means using technical specifications.
6. Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
Article 22 — Automated individual decision-making, including profiling
1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
2. Paragraph 1 shall not apply if the decision:
- a) is necessary for entering into, or performance of, a contract between the data subject and a data controller;
- b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or
- c) is based on the data subject's explicit consent.
3. In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
4. Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.
Privacy notice — Prospect
PRIVACY NOTICE PURSUANT TO ART. 13 OF EU REGULATION 2016/679
for the pre-contractual, advertising and promotional activities carried out by the Companies controlled by, affiliated with or otherwise associated with Syneto (hereinafter also: “Syneto Group”), also as Joint Controllers of the processing pursuant to art. 26 of the GDPR, towards potential partners, distributors, resellers, customers and their contact persons (hereinafter also “prospects”)
For us, data protection is a very serious matter; we therefore wish to inform you about how your data is processed and about the rights you may exercise under the current data protection legislation, in particular EU Regulation 2016/679 (hereinafter also: “GDPR”).
This notice concerns the pre-contractual, advertising and promotional activities towards potential partners, distributors, resellers, customers and their contact persons (hereinafter also “prospects”), whose data is collected by the Companies of the Syneto Group indicated below, also separately and depending on the circumstances, at trade fairs, conferences, events, commercial meetings or in the context of the pre-contractual and commercial relationships established.
Such Companies act, in relation to the specific purposes set out in section 3, as Joint Controllers or, where expressly indicated, as independent Data Controllers.
For the processing activities not detailed in this notice and relating to the categories of data subjects mentioned above, please refer to the privacy notices issued by each Company in the context of the relationships maintained with those subjects.
1. Joint Controllers* and Data Protection Officers (DPO)
Joint Controller 1 Syneto S.p.A. Via Cefalonia no. 70 25124, Brescia (BS), Italy E-mail contact: [email protected] Joint Controller 2 Syneto Iberica S.L. Calle Antonio Arias no. 6 28009, Madrid (Spain) E-mail contact: [email protected] Joint Controller 3 Syneto S.R.L. No. 2 Martin Luther, Entrance A, 4th floor Timișoara (Romania) E-mail contact: [email protected] Joint Controller 4 Orizon S.r.l. Via Cefalonia no. 70 25124, Brescia (BS), Italy E-mail contact: [email protected] Joint Controller 5 Orizon Cyber Security S.L. Calle Rodríguez San Pedro no. 2, Oficina 514 28015, Madrid (Spain) E-mail contact: [email protected] |
Data Protection Officer (DPO) for Joint Controller 1 Atty. Vera Cantoni Address for the assignment: Via F. Turati no. 26, 20121, Milan (MI) E-mail: [email protected] Data Protection Officer (DPO) for Joint Controller 2 Valentina Orsorio Address for the assignment: Calle Aguarón, 23, Madrid, 28023, Madrid E-mail: [email protected] Data Protection Officer (DPO) for Joint Controller 3 Ionel Orza Address for the assignment: Strada Cuza Vodă 61, Târgu Mureș, 540036, Mureș E-mail: [email protected] |
* The essential content of the joint controllership agreement is available to data subjects upon explicit request.
2. Categories of data subject to processing
The categories of “personal data” (pursuant to Art. 4.1 of the GDPR) processed by the Companies, as Data Controllers or Joint Controllers, may be, by way of example only but certainly not exhaustively:
- Personal and identifying data (such as, for example, first and last name, date of birth, place of birth, nationality, tax code, VAT number, etc.);
- Contact data (such as, for example, address, e-mail address, IP address, telephone number, etc.);
- For legal representatives, contact persons and employees of Companies or Entities, data relating to the role held within the Company or Entity.
3. Lawfulness and purposes of the processing
The processing of personal data is carried out in compliance with the provisions of the General Data Protection Regulation (GDPR) and any other applicable data protection legislation. Details are provided below:
3.1 Purposes aimed at the performance of a contract or pre-contractual measures (pursuant to art. 6, paragraph 1 (b) of the GDPR) pursued individually by each Company of the Syneto Group indicated in section 1 above, as an independent Data Controller
- a) Carrying out of pre-contractual activities, also with reference to the first contact with the prospect (including through the exchange or, in any case, receipt of business cards) and to the possible preparation and sending of quotes and/or catalogues for the products and services of the Data Controller.
The retention period of personal data, in relation to the purposes set out in this section, is:
For purpose: a, personal data is retained for the time strictly necessary to carry out the pre-contractual activities and to manage contacts with the prospect, including requests for information and the preparation and sending of offers or informational material.
3.2 Purposes covered by the data subject's consent (pursuant to art. 6, paragraph 1 (a) of the GDPR) pursued jointly by the Companies of the Syneto Group indicated in section 1 above, as Joint Controllers
- a) Performance by the Joint Controllers, operating in the IT sector, of advertising or promotional activities, in the broadest sense of the term (for example, sending newsletters and informational material, brochure requests, organisation of events, etc.) and of further marketing activities, through automated contact methods (for example: calls without an operator, e-mails, SMS and various messaging systems, including instant and internet-based ones, also to mobile phones) and non-automated methods (sending of paper mail and calls with an operator);
- b) Performance by the Joint Controllers, operating in the IT sector, of market research and surveys (by way of example, carrying out market studies and statistical analyses regarding the degree of satisfaction, through automated contact methods (for example: calls without an operator, e-mails, SMS and various messaging systems, including instant and internet-based ones, also to mobile phones) and non-automated methods (sending of paper mail and calls with an operator).
The retention period of personal data, in relation to the purpose set out in this section, is:
For purposes: a, b, 24 months from the granting of consent, unless revoked.
4. Recipients or categories of recipients of personal data (pursuant to art. 13 paragraph 1 (e) of the GDPR) *
Each Company, as Data Controller or Joint Controller, may communicate your data to:
- Internal offices and functions of each Company indicated in section 1 above;
- Companies and professional operators that provide IT services, including electronic data processing, software and cloud management, website management and IT consultancy;
- Qualified professionals for the purpose of studying and resolving any legal and contractual issues, including lawyers and tax advisors;
- Transport companies, mailing companies and hosting providers, postal couriers and companies that carry out enveloping and shipping activities of the material and communications indicated above;
- Marketing and communication companies and agencies, as well as IT, mailing and hosting service providers and software platforms used for the management of promotional campaigns and communications (including CRM systems), exclusively within the marketing purpose set out in section 3.2, letters a) and b), subject to the express consent of the data subject;
- Public Administrations, competent Authorities, public Bodies and Agencies in the context of the performance of their institutional duties.
* The complete and updated list of Recipients (pursuant to art. 4.9 of the GDPR) is available from each Company, as Data Controller or Joint Controller of the personal data processing, at the contact details indicated above.
5. Recipients or categories of recipients of personal data (pursuant to art. 13 paragraph 1 (f) of the GDPR) * and transfer of data to non-EU Countries
The Companies, as Data Controllers or Joint Controllers, inform you that they have no intention of transferring your data to countries outside the EU and the EEA for the purposes indicated above.
* The updated list of adequate non-EEA countries deemed adequate by the European Commission may be obtained on the website: Adequacy decisions (europa.eu)
6. Rights of the Data Subject (pursuant to art. 13 paragraph 2 (b) of the GDPR)
The data subject may exercise the following rights:
- right of access of the data subject [art. 15 of the EU Regulation] (the possibility to be informed about the processing carried out on their Personal Data and, where applicable, to receive a copy of it);
- right to rectification of one's Personal Data [art. 16 of the EU Regulation] (the data subject is entitled to the rectification of inaccurate personal data concerning them);
- right to erasure of one's Personal Data without undue delay (“right to be forgotten”) [art. 17 of the EU Regulation] (the data subject has, and will have, the right to the erasure of their data);
- right to restriction of processing of one's Personal Data in the cases provided for by art. 18 of the EU Regulation, including in the case of unlawful processing or of the data subject contesting the accuracy of the Personal Data [art. 18 of the EU Regulation];
- right to data portability [art. 20 of the EU Regulation], the data subject may request their Personal Data in a structured format in order to transmit them to another controller, in the cases provided for by the same article;
- right to object to the processing of one's Personal Data [art. 21 of the EU Regulation] (the data subject has, and will have, the right to object to the processing of their personal data);
- right not to be subject to automated decision-making, [art. 22 of the EU Regulation] (the data subject has, and will have, the right not to be subject to a decision based solely on automated processing).
Further information regarding the rights of the data subject may be obtained by requesting from the Companies, as Data Controllers or Joint Controllers, a full extract of the articles mentioned above.
With regard to the purposes for which consent is required, the Data Subject may withdraw their consent at any time and the effects shall take effect from the moment of withdrawal, without prejudice to the terms provided for by law. As a general rule, the withdrawal of consent has effect only for the future.
The above-mentioned rights may be exercised in accordance with the provisions of the Regulation by sending, among other things, an e-mail to the address: [email protected].
In compliance with art. 19 of the EU Regulation, the Companies, as Data Controllers or Joint Controllers, shall inform the recipients to whom the personal data has been communicated of any rectifications, erasures or restrictions of processing requested, where this is possible.
To allow a faster response to your requests made in the exercise of the rights indicated above, the same may be addressed to each Company, as Data Controller or Joint Controller, by sending them to the contact details indicated in point 1.
7. Right to lodge a complaint (pursuant to art. 13 paragraph 2 (d) of the GDPR)
The data subject, if they consider that their rights have been compromised, has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures indicated by the same Authority at the following Internet address http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524 or by sending a written communication to the Italian Data Protection Authority.
8. Possible consequences of the failure to provide data and nature of the provision of data (pursuant to art. 13 paragraph 2 (e) of the GDPR)
8.1 In case of compliance with legal or contractual obligations
Please be informed that, where the purposes of the processing have as their legal basis a legal or contractual obligation (or even a pre-contractual one), the data subject must necessarily provide the requested data.
Otherwise, each Data Controller will be unable to proceed with the pursuit of the specific purposes of the processing.
8.2 In the case of the data subject's consent
For the purposes for which consent is required, the Data Subject may withdraw their consent at any time and the effects shall take effect from the moment of withdrawal, without prejudice to the terms provided for by law. As a general rule, the withdrawal of consent has effect only for the future. Therefore, the processing carried out before the withdrawal of consent shall not be affected and shall retain its lawfulness.
The failure to provide consent or the partial provision of consent (or its withdrawal) may not guarantee the full provision of the services or activities, with reference to the individual purposes for which consent is denied, and shall not constitute prejudice or impediment to the other purposes (and to the activities connected with them) not involved or expressly affected by the denial of consent or not based on such legal basis.
When the data is no longer necessary, taking into account the retention periods indicated above, it is regularly deleted. Should deletion prove impossible or only possible through a disproportionate effort due to a particular method of retention, the data may not be processed and must be archived in non-accessible areas.
9. Absence/Existence of a fully automated decision-making process pursuant to art. 22 of the GDPR
The use of purely automated decision-making processes as detailed in article 22 of the GDPR is currently excluded. Should it be decided in the future to introduce such processes for individual cases, the data subject will receive separate notice thereof where this is required by law, or through an update of this notice.
10. Methods of processing
Personal data will be processed in paper, computerised and telematic form and entered into the relevant databases, which may be accessed, and therefore known, by the staff expressly designated by each Company, as Data Controller or Joint Controller, as Processors and Authorised Persons for the processing of personal data, who may carry out consultation, use, processing, comparison and any other appropriate operation, including automated ones, in compliance with the legal provisions necessary to guarantee, among other things, the confidentiality and security of the data as well as the accuracy, updating and relevance of the data in relation to the declared purposes.
This notice and subsequent updates are published on the websites of the Companies of the Syneto Group indicated in section 1 above (https://syneto.eu/ and https://orizon.one/).
Privacy notice — End user
PRIVACY NOTICE PURSUANT TO ART. 14 OF EU REGULATION 2016/679
for the advertising and promotional activities carried out by the Companies controlled by, affiliated with or otherwise associated with Syneto (hereinafter also: “Syneto Group”), as Joint Controllers of the processing pursuant to art. 26 of the GDPR, towards the end customers and their contact persons of the products and services purchased through the commercial network of the Syneto Group (hereinafter also: “end user”)
For us, data protection is a very serious matter; we therefore wish to inform you about how your data is processed and about the rights you may exercise under the current data protection legislation, in particular EU Regulation 2016/679 (hereinafter also: “GDPR”).
This notice concerns the advertising and promotional activities carried out towards end customers and their contact persons of the products and services purchased through the commercial network of the Syneto Group (partners and resellers).
Your personal data has not been collected directly from you by the Companies of the Syneto Group, but has been communicated to them by the partner or reseller with whom you established the contractual relationship for the purchase of products and/or services, in the event that you previously gave your consent to the transfer of the data to the Companies of the Syneto Group, for the advertising and promotional purposes set out in section 3 below.
For the processing activities not detailed in this notice, carried out towards the categories of data subjects mentioned above by the partners or resellers acting as independent Data Controllers, please refer to the privacy notices issued by such partners or resellers in the context of the relationships maintained with those subjects.
1. Joint Controllers* and Data Protection Officers (DPO)
Joint Controller 1 Syneto S.p.A. Via Cefalonia no. 70 25124, Brescia (BS), Italy E-mail contact: [email protected] Joint Controller 2 Syneto Iberica S.L. Calle Antonio Arias no. 6 28009, Madrid (Spain) E-mail contact: [email protected] Joint Controller 3 Syneto S.R.L. No. 2 Martin Luther, Entrance A, 4th floor Timișoara (Romania) E-mail contact: [email protected] Joint Controller 4 Orizon S.r.l. Via Cefalonia no. 70 25124, Brescia (BS), Italy E-mail contact: [email protected] Joint Controller 5 Orizon Cyber Security S.L. Calle Rodríguez San Pedro no. 2, Oficina 514 28015, Madrid (Spain) E-mail contact: [email protected] |
Data Protection Officer (DPO) for Joint Controller 1 Atty. Vera Cantoni Address for the assignment: Via F. Turati no. 26, 20121, Milan (MI) E-mail: [email protected] Data Protection Officer (DPO) for Joint Controller 2 Valentina Orsorio Address for the assignment: Antonio Arias, no. 6, Country: SPAIN, City: Madrid, Province: Madrid, Postal code: 28009 E-mail: [email protected] Data Protection Officer (DPO) for Joint Controller 3 Ionel Orza Address for the assignment: city of Tg. Mureș, Via Cuza Vodă no. 61, Apt. 1, province of Mureș, Postal code 540036 E-mail: [email protected] |
* The essential content of the joint controllership agreement is available to data subjects upon explicit request.
2. Categories of data subject to processing
The categories of “personal data” (pursuant to Art. 4.1 of the GDPR) processed by the Joint Controllers may be as follows:
- Personal and identifying data (such as, for example, first and last name, date of birth, place of birth, nationality, tax code, VAT number, etc.);
- Contact data (such as, for example, address, e-mail address, IP address, telephone number, etc.);
- For legal representatives, contact persons and employees of Companies or Entities, data relating to the role held within the Company or Entity.
3. Lawfulness and purposes of the processing
The processing of personal data is carried out in compliance with the provisions of the General Data Protection Regulation (GDPR) and any other applicable data protection legislation. Details are provided below:
3.1 Purposes covered by the data subject's consent (pursuant to art. 6, paragraph 1 (a) of the GDPR)
a. Performance by the Joint Controllers, operating in the IT sector, of advertising or promotional activities, in the broadest sense of the term (for example, sending newsletters and informational material, brochure requests, organisation of events, etc.) and of further marketing activities, through automated contact methods (for example: calls without an operator, e-mails, SMS and various messaging systems, including instant and internet-based ones, also to mobile phones) and non-automated methods (sending of paper mail and calls with an operator);
b. Performance by the Joint Controllers, operating in the IT sector, of market research and surveys (by way of example, carrying out market studies and statistical analyses regarding the degree of satisfaction, through automated contact methods (for example: calls without an operator, e-mails, SMS and various messaging systems, including instant and internet-based ones, also to mobile phones) and non-automated methods (sending of paper mail and calls with an operator).
The retention period of personal data, in relation to the purposes set out in this section, is:
For purposes: a, b, 24 months from the granting of consent, unless revoked.
Please note that your personal data has been communicated to the Joint Controllers by the partner or reseller with whom you established the contractual relationship for the purchase of products and/or services of the Syneto Group, since you expressly gave your consent to the transfer of the data for the purposes indicated above.
4. Recipients or categories of recipients of personal data (pursuant to art. 14 paragraph 1 (e) of the GDPR) *
Each Joint Controller may communicate your data to:
- Internal offices and functions of each Joint Controller;
- Companies and professional operators that provide IT services, including electronic data processing, software and cloud management, website management and IT consultancy;
- Qualified professionals for the purpose of studying and resolving any legal and contractual issues, including lawyers and tax advisors;
- Marketing and communication companies and agencies, as well as IT, mailing and hosting service providers and software platforms used for the management of promotional campaigns and communications (including CRM systems);
- Transport companies, postal couriers and companies that carry out enveloping and shipping activities of the communications indicated above;
- Public Administrations, competent Authorities, public Bodies and Agencies in the context of the performance of their institutional duties.
* The complete and updated list of Recipients (pursuant to art. 4.9 of the GDPR) is available from each Joint Controller of the personal data processing at the contact details indicated above.
5. Recipients or categories of recipients of personal data (pursuant to art. 14 paragraph 1 (f) of the GDPR) * and transfer of data to non-EU Countries
The Joint Controllers inform you that they have no intention of transferring your data to countries outside the EU and the EEA for the purposes indicated above.
* The updated list of adequate non-EEA countries deemed adequate by the European Commission may be obtained on the website: Adequacy decisions (europa.eu)
6. Rights of the Data Subject (pursuant to art. 14 paragraph 1 (e) of the GDPR)
The data subject may exercise the following rights:
- right of access of the data subject [art. 15 of the EU Regulation] (the possibility to be informed about the processing carried out on their Personal Data and, where applicable, to receive a copy of it);
- right to rectification of one's Personal Data [art. 16 of the EU Regulation] (the data subject is entitled to the rectification of inaccurate personal data concerning them);
- right to erasure of one's Personal Data without undue delay (“right to be forgotten”) [art. 17 of the EU Regulation] (the data subject has, and will have, the right to the erasure of their data);
- right to restriction of processing of one's Personal Data in the cases provided for by art. 18 of the EU Regulation, including in the case of unlawful processing or of the data subject contesting the accuracy of the Personal Data [art. 18 of the EU Regulation];
- right to data portability [art. 20 of the EU Regulation], the data subject may request their Personal Data in a structured format in order to transmit them to another controller, in the cases provided for by the same article;
- right to object to the processing of one's Personal Data [art. 21 of the EU Regulation] (the data subject has, and will have, the right to object to the processing of their personal data);
- right not to be subject to automated decision-making, [art. 22 of the EU Regulation] (the data subject has, and will have, the right not to be subject to a decision based solely on automated processing).
Further information regarding the rights of the data subject may be obtained by requesting from the Joint Controllers a full extract of the articles mentioned above.
With regard to the purposes for which consent is required, the Data Subject may withdraw their consent at any time and the effects shall take effect from the moment of withdrawal, without prejudice to the terms provided for by law. As a general rule, the withdrawal of consent has effect only for the future.
The above-mentioned rights may be exercised in accordance with the provisions of the Regulation by sending, among other things, an e-mail to the address: [email protected].
In compliance with art. 19 of the EU Regulation, the Joint Controllers shall inform the recipients to whom the personal data has been communicated of any rectifications, erasures or restrictions of processing requested, where this is possible.
To allow a faster response to your requests made in the exercise of the rights indicated above, the same may be addressed to each Joint Controller, by sending them to the contact details indicated in point 1.
7. Right to lodge a complaint (pursuant to art. 14 paragraph 2 (e) of the GDPR)
The data subject, if they consider that their rights have been compromised, has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures indicated by the same Authority at the following Internet address http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524 or by sending a written communication to the Italian Data Protection Authority.
8. Nature of the provision of data
8.1 In the case of the data subject's consent
For the purposes for which consent is required, the Data Subject may withdraw their consent at any time and the effects shall take effect from the moment of withdrawal, without prejudice to the terms provided for by law. As a general rule, the withdrawal of consent has effect only for the future. Therefore, the processing carried out before the withdrawal of consent shall not be affected and shall retain its lawfulness.
The failure to provide consent or the partial provision of consent (or its withdrawal) may not guarantee the full provision of the services or activities, with reference to the individual purposes for which consent is denied, and shall not constitute prejudice or impediment to the other purposes (and to the activities connected with them) not involved or expressly affected by the denial of consent or not based on such legal basis.
When the data is no longer necessary, taking into account the retention periods indicated above, it is regularly deleted. Should deletion prove impossible or only possible through a disproportionate effort due to a particular method of retention, the data may not be processed and must be archived in non-accessible areas.
9. The source from which the personal data originates and, where applicable, the possibility that the data comes from publicly accessible sources (pursuant to art. 14 paragraph 2 (f) of the GDPR)
The Joint Controllers have obtained the data they process from the following sources: partners or resellers of the products and/or services of the Companies of the Syneto Group.
10. Absence/Existence of a fully automated decision-making process pursuant to art. 22 of the GDPR
The use of purely automated decision-making processes as detailed in article 22 of the GDPR is currently excluded. Should it be decided in the future to introduce such processes for individual cases, the data subject will receive separate notice thereof where this is required by law, or through an update of this notice.
11. Methods of processing
Personal data will be processed in paper, computerised and telematic form and entered into the relevant databases, which may be accessed, and therefore known, by the staff expressly designated by each Joint Controller as Processors and Authorised Persons for the processing of personal data, who may carry out consultation, use, processing, comparison and any other appropriate operation, including automated ones, in compliance with the legal provisions necessary to guarantee, among other things, the confidentiality and security of the data as well as the accuracy, updating and relevance of the data in relation to the declared purposes.
This notice and subsequent updates are published on the websites of each Joint Controller (https://syneto.eu/ and https://orizon.one/).
Privacy notice — Resellers, distributors and customers
PRIVACY NOTICE PURSUANT TO ART. 13 OF EU REGULATION 2016/679
for the advertising and promotional activities carried out by the Companies controlled by, affiliated with or otherwise associated with Syneto (hereinafter also: “Syneto Group”), as Joint Controllers of the processing pursuant to art. 26 of the GDPR, towards partners, distributors, resellers, customers and their contact persons
For us, data protection is a very serious matter; we therefore wish to inform you about how your data is processed and about the rights you may exercise under the current data protection legislation, in particular EU Regulation 2016/679 (hereinafter also: “GDPR”).
This notice concerns the advertising and promotional activities towards partners, distributors, resellers, customers and their contact persons, whose data is collected by the Companies of the Syneto Group indicated below, as Joint Controllers, also separately and depending on the circumstances, at trade fairs, conferences, events, commercial meetings or in the context of the existing contractual – commercial relationships.
For the processing activities not detailed in this notice and relating to the categories of data subjects mentioned above, please refer to the privacy notices issued by each Company in the context of the relationships maintained with those subjects.
1. Joint Controllers* and Data Protection Officers (DPO)
Joint Controller 1 Syneto S.p.A. Via Cefalonia no. 70 25124, Brescia (BS), Italy E-mail contact: [email protected] Joint Controller 2 Syneto Iberica S.L. Calle Antonio Arias no. 6 28009, Madrid (Spain) E-mail contact: [email protected] Joint Controller 3 Syneto S.R.L. No. 2 Martin Luther, Entrance A, 4th floor Timișoara (Romania) E-mail contact: [email protected] Joint Controller 4 Orizon S.r.l. Via Cefalonia no. 70 25124, Brescia (BS), Italy E-mail contact: [email protected] Joint Controller 5 Orizon Cyber Security S.L. Calle Rodríguez San Pedro no. 2, Oficina 514 28015, Madrid (Spain) E-mail contact: [email protected] |
Data Protection Officer (DPO) for Joint Controller 1 Atty. Vera Cantoni Address for the assignment: Via F. Turati no. 26, 20121, Milan (MI) E-mail: [email protected] Data Protection Officer (DPO) for Joint Controller 2 Valentina Orsorio Address for the assignment: Antonio Arias, no. 6, Country: SPAIN, City: Madrid, Province: Madrid, Postal code: 28009 E-mail: [email protected] Data Protection Officer (DPO) for Joint Controller 3 Ionel Orza Address for the assignment: city of Tg. Mureș, Via Cuza Vodă no. 61, Apt. 1, province of Mureș, Postal code 540036 E-mail: [email protected] |
* The essential content of the joint controllership agreement is available to data subjects upon explicit request.
2. Categories of data subject to processing
The categories of “personal data” (pursuant to Art. 4.1 of the GDPR) processed by the Joint Controllers may be, by way of example only but certainly not exhaustively:
- Personal and identifying data (such as, for example, first and last name, date of birth, place of birth, nationality, tax code, VAT number, etc.);
- Contact data (such as, for example, address, e-mail address, IP address, telephone number, etc.);
- For legal representatives, contact persons and employees of Companies or Entities, data relating to the role held within the Company or Entity.
3. Lawfulness and purposes of the processing
The processing of personal data is carried out in compliance with the provisions of the General Data Protection Regulation (GDPR) and any other applicable data protection legislation. Details are provided below:
3.1 Purposes covered by the data subject's consent (pursuant to art. 6, paragraph 1 (a) of the GDPR)
a. Performance by the Joint Controllers, operating in the IT sector, of advertising or promotional activities, in the broadest sense of the term (for example, sending newsletters and informational material, brochure requests, organisation of events, etc.) and of further marketing activities, through automated contact methods (for example: calls without an operator, e-mails, SMS and various messaging systems, including instant and internet-based ones, also to mobile phones) and non-automated methods (sending of paper mail and calls with an operator);
b. Performance by the Joint Controllers, operating in the IT sector, of market research and surveys (by way of example, carrying out market studies and statistical analyses regarding the degree of satisfaction, through automated contact methods (for example: calls without an operator, e-mails, SMS and various messaging systems, including instant and internet-based ones, also to mobile phones) and non-automated methods (sending of paper mail and calls with an operator).
The retention period of personal data, in relation to the purpose set out in this section, is:
For purposes: a, b, 24 months from the granting of consent, unless revoked.
4. Recipients or categories of recipients of personal data (pursuant to art. 13 paragraph 1 (e) of the GDPR) *
Each Joint Controller may communicate your data to:
- Internal offices and functions of each Joint Controller;
- Companies and professional operators that provide IT services, including electronic data processing, software and cloud management, website management and IT consultancy;
- Qualified professionals for the purpose of studying and resolving any legal and contractual issues, including lawyers and tax advisors;
- Marketing and communication companies and agencies, as well as IT, mailing and hosting service providers and software platforms used for the management of promotional campaigns and communications (including CRM systems);
- Transport companies, postal couriers and companies that carry out enveloping and shipping activities of the communications indicated above;
- Public Administrations, competent Authorities, public Bodies and Agencies in the context of the performance of their institutional duties.
* The complete and updated list of Recipients (pursuant to art. 4.9 of the GDPR) is available from each Joint Controller of the personal data processing at the contact details indicated above.
5. Recipients or categories of recipients of personal data (pursuant to art. 13 paragraph 1 (f) of the GDPR) * and transfer of data to non-EU Countries
The Joint Controllers inform you that they have no intention of transferring your data to countries outside the EU and the EEA for the purposes indicated above.
* The updated list of adequate non-EEA countries deemed adequate by the European Commission may be obtained on the website: Adequacy decisions (europa.eu)
6. Rights of the Data Subject (pursuant to art. 13 paragraph 2 (b) of the GDPR)
The data subject may exercise the following rights:
- right of access of the data subject [art. 15 of the EU Regulation] (the possibility to be informed about the processing carried out on their Personal Data and, where applicable, to receive a copy of it);
- right to rectification of one's Personal Data [art. 16 of the EU Regulation] (the data subject is entitled to the rectification of inaccurate personal data concerning them);
- right to erasure of one's Personal Data without undue delay (“right to be forgotten”) [art. 17 of the EU Regulation] (the data subject has, and will have, the right to the erasure of their data);
- right to restriction of processing of one's Personal Data in the cases provided for by art. 18 of the EU Regulation, including in the case of unlawful processing or of the data subject contesting the accuracy of the Personal Data [art. 18 of the EU Regulation];
- right to data portability [art. 20 of the EU Regulation], the data subject may request their Personal Data in a structured format in order to transmit them to another controller, in the cases provided for by the same article;
- right to object to the processing of one's Personal Data [art. 21 of the EU Regulation] (the data subject has, and will have, the right to object to the processing of their personal data);
- right not to be subject to automated decision-making, [art. 22 of the EU Regulation] (the data subject has, and will have, the right not to be subject to a decision based solely on automated processing).
Further information regarding the rights of the data subject may be obtained by requesting from the Joint Controllers a full extract of the articles mentioned above.
With regard to the purposes for which consent is required, the Data Subject may withdraw their consent at any time and the effects shall take effect from the moment of withdrawal, without prejudice to the terms provided for by law. As a general rule, the withdrawal of consent has effect only for the future.
The above-mentioned rights may be exercised in accordance with the provisions of the Regulation by sending, among other things, an e-mail to the address: [email protected].
In compliance with art. 19 of the EU Regulation, the Joint Controllers shall inform the recipients to whom the personal data has been communicated of any rectifications, erasures or restrictions of processing requested, where this is possible.
To allow a faster response to your requests made in the exercise of the rights indicated above, the same may be addressed to each Joint Controller, by sending them to the contact details indicated in point 1.
7. Right to lodge a complaint (pursuant to art. 13 paragraph 2 (d) of the GDPR)
The data subject, if they consider that their rights have been compromised, has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures indicated by the same Authority at the following Internet address http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524 or by sending a written communication to the Italian Data Protection Authority.
8. Possible consequences of the failure to provide data and nature of the provision of data (pursuant to art. 13 paragraph 2 (e) of the GDPR)
8.1 In the case of the data subject's consent
For the purposes for which consent is required, the Data Subject may withdraw their consent at any time and the effects shall take effect from the moment of withdrawal, without prejudice to the terms provided for by law. As a general rule, the withdrawal of consent has effect only for the future. Therefore, the processing carried out before the withdrawal of consent shall not be affected and shall retain its lawfulness.
The failure to provide consent or the partial provision of consent (or its withdrawal) may not guarantee the full provision of the services or activities, with reference to the individual purposes for which consent is denied, and shall not constitute prejudice or impediment to the other purposes (and to the activities connected with them) not involved or expressly affected by the denial of consent or not based on such legal basis.
When the data is no longer necessary, taking into account the retention periods indicated above, it is regularly deleted. Should deletion prove impossible or only possible through a disproportionate effort due to a particular method of retention, the data may not be processed and must be archived in non-accessible areas.
9. Absence/Existence of a fully automated decision-making process pursuant to art. 22 of the GDPR
The use of purely automated decision-making processes as detailed in article 22 of the GDPR is currently excluded. Should it be decided in the future to introduce such processes for individual cases, the data subject will receive separate notice thereof where this is required by law, or through an update of this notice.
10. Methods of processing
Personal data will be processed in paper, computerised and telematic form and entered into the relevant databases, which may be accessed, and therefore known, by the staff expressly designated by each Joint Controller as Processors and Authorised Persons for the processing of personal data, who may carry out consultation, use, processing, comparison and any other appropriate operation, including automated ones, in compliance with the legal provisions necessary to guarantee, among other things, the confidentiality and security of the data as well as the accuracy, updating and relevance of the data in relation to the declared purposes.
This notice and subsequent updates are published on the websites of each Joint Controller (https://syneto.eu/ and https://orizon.one/) .
Looking for the cookie policy?
Cookies are governed by ePrivacy, not GDPR, and are documented on a separate page that explains which cookies the site sets and how to manage them.
To exercise your data-subject rights, write to [email protected]. The Data Protection Officer (Avv. Vera Cantoni) can be reached at [email protected].