top of page

Processing of personal data

 

PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA(MEMBERS and USERS)​


Pursuant to European Regulation 2016/679 on the protection of personal data (GDPR)​

 

In accordance with the provisions of European Regulation 2016/679 on the protection of personal data (“GDPR”) and the Italian Privacy Code, Legislative Decree 196/2003, as amended by Legislative Decree 101/2018, we hereby inform you that the undersigned organisation is the Data Controller of your data classified as “Personal Data”.

The processing of information concerning you shall be carried out in accordance with the principles of fairness, lawfulness and transparency, in order to protect your privacy and your rights.
 

Data Controller and Contact Details

The Data Controller is DENTROFUORI ETS, with registered office at Via Piero Capponi 19.

For further information, the Data Controller may also be contacted at the following email address: dentrofuoriets@gmail.com
 

Types of Data Processed

The processing will concern the following types of personal data, strictly relevant to the purposes for which they are collected:

  • Identification data such as name, address, place and date of birth, identity documents, tax code, etc.

  • Contact details: telephone numbers and email addresses

  • Information relating to education, culture and employment, such as educational qualifications, educational background, profession, current and/or previous employment
     

The data will be collected on the occasion of:

  • Completion of the Association membership form or membership requests submitted through other means

  • The process of joining the Association

  • Participation in Association events

  • Monitoring of participants in specific projects

  • Participation in trade fairs and industry events

  • Submission of requests by email, telephone or in person
     

The processing will not normally concern sensitive data, as defined under Article 9 of the GDPR, “Special Categories of Personal Data”, namely data “…revealing racial or ethnic origin, religious, philosophical or other beliefs, political opinions, membership of political parties, trade unions, associations or organisations of a religious, philosophical, political or trade union nature, as well as personal data revealing health status and sex life”.
 

Categories of Data Subjects

The personal data collected relates to members, prospective members, or users who make use of the services, participate in events/initiatives organised by the Data Controller, or simply contact the Data Controller to request information.

 

Purposes of Processing and Legal Basis

Personal data is processed for various purposes, some of which are strictly related to the Association’s institutional activities, while others concern more specific initiatives.

  1. Collection of members’ data and management of the related records.

  2. Sending service-related communications concerning the life of the Association.

  3. Organisation, promotion and implementation of all activities and initiatives promoted or carried out by the Association, including the sending, in digital and/or paper form, of invitations, communications and documentation relating to events and activities.

  4. Acknowledgement and response to users’ requests received through digital channels (website, social media, email, etc.) or directly during meetings, events, trade fairs, etc.

  5. Accounting, administrative, tax and other obligations required under Italian, European or international law.

 

Should the Data Controller introduce additional processing purposes other than those described above, this Privacy Notice will be updated accordingly and consent to processing will be requested, where required, in the most appropriate manner.

The legal basis for processing primarily relates to the performance of the agreement between the parties, as well as compliance with legal obligations. Data is also processed on the basis of the Data Controller’s legitimate interest in maintaining its relationship with its members, reporting on activities carried out and communicating any initiatives concerning them.

Where necessary, explicit consent to processing will also be obtained. The Data Subject has the right to withdraw such consent at any time by contacting the Data Controller, without this affecting their membership of the Association.

When participating in public social innovation initiatives and related calls for proposals, including European calls, the

Association may also act as a Data Processor pursuant to Article 28 of the GDPR, following its appointment by the organisation acting as Data Controller. In the context of these projects, the purposes of processing also include monitoring activities related and instrumental to project management, and the legal basis is the performance of a task carried out in the public interest.

Video and Photographic Material

Public events or events of public interest organised by the Data Controller may involve the collection and processing of audio and video content (hereinafter also referred to as the “Material”) by the Data Controller and by parties supporting it, with full respect for the personal dignity and decorum of the Data Subjects concerned.

The Material may be published and disseminated through media channels, including, by way of example, the Data Controller’s website and social media channels, brochures and informational materials, for educational or cultural purposes, or where the recordings relate to events, ceremonies or matters of public interest or taking place in public, as provided for by Article 97 of the Italian Copyright Law.

In such cases, the explicit consent of the individuals filmed or photographed is not required. If a Data Subject wishes to have an image of themselves removed or does not wish to be filmed or photographed during an event, they may contact the Data Controller, which will assess the possibility of removing the relevant material.

In the case of Material produced during private events, the Data Controller will provide appropriate information and obtain the relevant consent from the Data Subjects concerned.

Methods and Duration of Processing

Personal data is processed using electronic procedures and systems and/or manually (e.g. in paper form) for the period strictly necessary to achieve the purposes for which the data was collected and, in any event, in accordance with the applicable legal provisions.

In addition, the Association is required to retain certain information in accordance with legal requirements (e.g. for administrative and tax purposes) and for a period reasonably necessary to meet legal requirements, resolve disputes and prevent fraud and abuse.

The Data Controller has adopted appropriate physical, technical and organisational security measures to ensure the integrity, confidentiality and availability of the data.

For certain processing activities, particularly those relating to the monitoring of funded projects, data may be pseudonymised and/or aggregated.

Provision of Data

In general, the provision of data required for membership of the Association, compliance with legal obligations and contractual performance is necessary. Any objection to processing, in whole or in part, may result in the Data Controller being unable to establish the membership relationship and/or continue the existing membership relationship.

For all other purposes, users are free to provide their personal data. Failure to provide such data may only result in the inability to obtain what has been requested or to remain adequately informed about the activities and life of the Association.

Communication and Transfer of Personal Data

Personal data may be accessed by individuals specifically appointed and authorised to process it, who receive appropriate operational instructions in this regard. In addition, data may be processed by external legal or natural persons whom the Data Controller may engage in connection with managing its relationship with users or in pursuit of its institutional purposes.

Such parties act either as external Data Processors pursuant to Article 28 of the GDPR or as independent Data Controllers where the conditions for appointment as a Data Processor do not apply.

Personal data may be disclosed to other public or private entities (e.g. local authorities, Italian and European public bodies, supervisory authorities, law enforcement agencies, banking institutions, project partners, etc.) exclusively for the fulfilment of obligations arising from law or contract and solely within the purposes set out above.

 

Personal data is managed and stored in the cloud and/or on servers located within the European Union.

Where, for specific organisational and/or technological requirements, it is necessary to transfer data outside the European Union, the Data Controller undertakes to ensure adequate levels of protection and safeguarding of personal data, in compliance with applicable legislation (as provided for in Chapter V of the GDPR – Articles 45, 46 and 49), including through the use of standard contractual clauses.

Personal data will not be disclosed or made publicly available without the authorisation of the Data Subjects concerned.

 

Rights of Data Subjects

The GDPR grants Data Subjects numerous rights, which we ask you to consider carefully (Articles 15–22). In particular, Data Subjects have the right to:

  • Access:

    • confirmation as to whether or not personal data concerning them is being processed;

    • information regarding the transfer of data to a third country or an international organisation;

    • obtain a copy of the personal data being processed (provided that this does not adversely affect the rights and freedoms of others);

  • Rectification;

  • Erasure (right to be forgotten);

  • Restriction of processing;

  • Notification obligation in the event of rectification or erasure of personal data or restriction of processing;

  • Data portability;

  • Objection.
     

The Data Subject also has the right to receive prompt notification in the event of a personal data breach that may adversely affect their dignity and freedom.
 

Finally, the Data Subject has the right to lodge a complaint with the Italian Supervisory Authority – Garante per la protezione dei dati personali – Piazza Venezia 11 – 00187 Rome – urp@gpdp.it.

bottom of page