Customer Privacy Notice

CUSTOMER PRIVACY NOTICE PURSUANT TO ARTICLES 13 AND 26 OF REGULATION (EU) 2016/679 (“GDPR”)

Pursuant to applicable personal data protection legislation, CRIF S.p.A., with registered office at Via della Beverara 21, Bologna, VAT No. 02083271201 (“CRIF”), and CRIBIS S.r.l., with registered office at Via dei Valtorta 48, Milan, VAT No. 01691720468 (“CRIBIS”), acting as Joint Controllers of your personal data (the “Joint Controllers”), are required to provide you with certain information concerning its processing. The essence of the joint controllership arrangement entered into by the Joint Controllers is available upon request using the contact details set out below.

1. Purposes of processing and legal bases

1.1 Necessary purposes

The Joint Controllers process personal data in the course of their ordinary business activities for the following purposes:

  1. “Instrumental” purposes, strictly connected with the provision of the services supplied from time to time by the Joint Controllers, including collection of information prior to entering into a contract; collection of documents and information required to perform ongoing activities; reminders concerning the return of signed contractual materials and documentation; and settlement of amounts due. Legal basis: Article 6(1)(b) GDPR.
  2. “Mandatory” purposes, connected with obligations imposed by laws, regulations and European Union legislation, as well as by measures issued by authorities legally empowered to do so. Legal basis: Article 6(1)(c) GDPR.

Providing personal data for these purposes is necessary and the relevant processing does not require consent. Refusal to provide such data will make it impossible to establish and manage the contractual relationship.

1.2 Additional purposes and legal basis

The Joint Controllers also process personal data in the course of their ordinary business activities for CRIBIS information and/or commercial promotional purposes, market analysis or initiatives otherwise connected with the Joint Controllers’ business, including through automated calling or messaging systems such as SMS, MMS, e-mail and fax. Legal basis: Article 6(1)(a) GDPR.

Providing personal data for this purpose is optional and the relevant processing requires the Data Subject’s consent. Refusal to provide consent will have no adverse consequences. Any further processing for different purposes is excluded.

2. Retention periods

  1. For the processing referred to in Section 1.1, personal data will be retained for ten years after termination of the contractual relationship for the purposes described therein. This period reflects applicable tax and accounting requirements.
  2. For the additional purpose referred to in Section 1.2(c), personal data will be processed and retained for a maximum of 36 months or, in any event, until consent is withdrawn.
  3. You may withdraw your consent to the processing referred to in Section 1.2(c) at any time by writing to dirprivacy@crif.com.

 

3. Processing methods

Personal data is processed using manual, computerised and electronic means according to procedures strictly related to the stated purposes and, in all cases, in a manner designed to ensure its confidentiality and security.

4. Categories of recipients

For the purposes described in Sections 1.1 and 1.2, the Joint Controllers may disclose personal data to third parties belonging to the following categories:

  • third parties performing activities ancillary to and connected with contract performance and compliance with legal and/or administrative obligations applicable to the Joint Controllers;
  • persons authorised to process personal data and third parties appointed as Processors;
  • CRIF Group companies, including companies outside the European Union, acting as independent Controllers and providing their own notice pursuant to Article 14 GDPR.

 

5. Transfers outside the European Union

For the additional purposes described in Section 1.2, the Joint Controllers may disclose personal data to CRIF Group companies established outside the European Economic Area.

Such transfers may take place without specific authorisation where the relevant third country is recognised by the European Commission as ensuring an adequate level of protection. In the absence of an adequacy decision, transfers to recipients in third countries may be carried out by adopting and documenting the appropriate safeguards under Article 46 GDPR. In the absence of an adequacy decision or appropriate safeguards, transfers may take place where the conditions and further requirements under Chapter V GDPR apply, including, in specific circumstances, the derogations under Article 49 GDPR.

A list of countries in which CRIF Group companies are established is available at https://www.crif.it/chi-siamo/la-nostra-presenza-globale/.

6. Data Subjects’ rights

Under Chapter III GDPR, as a Data Subject you have the right to: (i) obtain confirmation as to whether personal data concerning you is being processed and receive the information listed in Article 15 GDPR; (ii) obtain rectification of inaccurate personal data and completion of incomplete personal data; (iii) obtain erasure of personal data pursuant to and within the limits of Article 17 GDPR; (iv) obtain restriction of processing in the cases set out in Article 18 GDPR; (v) receive personal data concerning you in a structured, commonly used and machine-readable format in the cases provided for by Article 20 GDPR; (vi)

object to processing pursuant to and within the limits of Article 21 GDPR, including solely in relation to automated contact methods; and (vii) withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

You may exercise these rights against either or both Joint Controllers.

7. Joint Controllers

The Joint Controllers are CRIF S.p.A., Via della Beverara 21, 40131 Bologna, VAT No. 02083271201, and CRIBIS S.r.l., Via dei Valtorta 48, 20127 Milan, VAT No. 01691720468. The complete list of Processors is available at the Joint Controllers’ registered offices.

To exercise rights under Chapter III GDPR, use the following contact details: CRIF: dirprivacy@crif.com; certified e-mail (PEC): crif@pec.crif.com. CRIBIS: dirprivacy@cribis.com; certified e-mail (PEC): cribis@pec.crif.com.

You may also lodge a complaint with the Italian Data Protection Authority by following the instructions available on its website.

8. Data Protection Officer

For any questions concerning the processing of your personal data, you may contact the Data Protection Officer using the following details: CRIF: dirprivacy@crif.com; PEC crif@pec.crif.com. CRIBIS: dirprivacy@cribis.com; PEC cribis@pec.crif.com.

Do you have any questions or want to receive a quotation?

Ask for information immediately