Consent Information for Data Processing in Accordance with Article 13 of EU Regulation 2016/679

With this communication, the company EPC European Project Consulting S.r.l. informs you that your personal data, or data relating to or referable to you, will be managed in full compliance with EU Regulation 679/2016 and Legislative Decree 196/2003 and its amendments for data processing, and in full respect of confidentiality obligations. “Processing of personal data” refers to any operation or set of operations, performed even without electronic means, concerning the collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, dissemination, deletion, and destruction of data, even if not recorded in a database.

For the establishment and execution of current contractual relationships with you, EPC European Project Consulting S.r.l. is the data controller for personal and sensitive data, also acquired verbally, directly or through third parties, relating to you. The provision of such data is mandatory for all legal and contractual obligations, and refusal to provide it or consent to its processing may make it impossible for EPC European Project Consulting S.r.l. to continue the contractual relationships. On the other hand, the failure to provide data that is not related to legal or contractual obligations will be evaluated on a case-by-case basis and may affect the commercial relationship depending on the importance of the requested data.

Specifically, we inform you that, pursuant to Article 13 of the Regulation:

Data Controller

The Data Controller, to whom you can address to exercise your rights under Articles 7 and 15-22 of the Regulation (listed below), is EPC European Project Consulting S.r.l., located at Via Giovanni Prati 11, Dueville (Vicenza), represented by the current Legal Representative; you can exercise your rights by sending communications to the following email address: info@epcsrl.eu.

Purpose of Data Processing

The personal data you provide is necessary to fulfill contractual and legal obligations, as well as to effectively manage business relationships for the provision of consulting, technical assistance, and training services offered by our company.

Processing and Retention Methods

Your personal data will be processed through the operations listed in Article 4, Point 2 of the Regulation, specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data. Processing will be carried out in both automated and manual forms, in compliance with the security measures outlined in Article 32 of the Regulation, by individuals specifically appointed, and in accordance with Article 29 of the Regulation. We inform you that, in compliance with the principles of lawfulness, purpose limitation, and data minimization, pursuant to Article 5 of the Regulation, and with your free and explicit consent expressed at the bottom of this notice, your personal data will be stored for the period necessary to achieve the purposes for which it was collected and processed. Personal data will be processed both in paper and electronic/automated formats, possibly through a cloud-hosted website managed by either the company or another Data Processor. The Data Controller will process personal data for the time necessary to fulfill the purposes mentioned above and, in any case, for no longer than necessary to carry out the ongoing activities.

Scope of Communication and Dissemination

Data may be made accessible, for communication and dissemination in compliance with legal and contractual obligations, to employees and collaborators of the Data Controller, in their capacity as Appointed and/or Internal Data Processors and/or System Administrators, to third-party companies or other entities that carry out outsourced activities on behalf of the Data Controller, in their capacity as Data Processors. All data may be communicated in Italy and abroad exclusively for the purposes specified above, to:

  • Suppliers/clients involved in activities strictly related to the provision of the product/service;
  • Credit institutions and factoring companies;
  • Debt collection companies;
  • Credit insurance companies;
  • Commercial technicians, professionals, and consultants;
  • Legal firms;
  • IT maintenance companies;
  • Public entities, within the scope of their contractual activities;
  • Transport companies;
  • Any other subject deemed necessary for normal contractual activities.

All personal data will be processed for the duration of the contractual relationships and also thereafter for legal obligations and future commercial purposes. In accordance with Article 130 of Legislative Decree 196/2003 and Article 7 of the Regulation, our company would like to send you commercial communications using your fax number or email address; your email address, provided during our previous business relationships, will be used for this purpose.

Transfer of Personal Data

In compliance with Articles 44 and following of the Regulation, to ensure the proper management of the personal data under processing, the company may, with your explicit consent, for the purposes and in the manner described in this notice, transfer your personal data to both EU Member States and third countries outside the EU.

Special Categories of Personal Data

Under Articles 9 and 10 of the Regulation, you may provide the company with data classified as “special categories of personal data,” i.e., data revealing “racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, as well as genetic data, biometric data for uniquely identifying a natural person, data concerning health, sex life or sexual orientation.” These categories of data will only be processed by the company with your free and explicit written consent.

Automated Decision-Making, Including Profiling

The company does not adopt any automated decision-making process, including profiling, as referred to in Article 22, Paragraphs 1 and 4, of the Regulation.

Data Subject Rights

At any time, you may exercise your rights under Articles 15 to 22 of EU Regulation 679/2016, including:
a) Requesting confirmation of the existence of your personal data;
b) Obtaining information on the purposes of processing, categories of personal data, recipients or categories of recipients to whom personal data has been or will be disclosed, and, if possible, the retention period;
c) Requesting rectification or deletion of data;
d) Requesting restriction of processing;
e) Requesting data portability;
f) Objecting to processing at any time, including for direct marketing purposes;
g) Objecting to automated decision-making, including profiling;
h) Requesting access to personal data and its rectification or deletion, or restricting its processing, or objecting to its processing, as well as the right to data portability;
i) Withdrawing consent at any time without affecting the lawfulness of processing based on consent before its withdrawal;
j) Lodging a complaint with a supervisory authority.

Exercising Rights

You may exercise your rights by sending:

  • A registered letter to: EPC European Project Consulting S.r.l., Via Prati 11, 36031 Povolaro di Dueville, Vicenza;
  • A PEC (Certified Email) to: epc@pec.infracom.it
  • An email to: info@epcsrl.eu.

Revoking Consent for Data Processing

In the communication necessary to exercise your rights, please include the following information:

  • Name;
  • Surname;
  • Address;
  • Email address;
  • A copy of a valid identification document;
  • Clearly indicate the request that EPC European Project Consulting S.r.l. should comply with.