DATA PROCESSING NOTICE PURSUANT TO EU REGULATION 2016/679

Dear Customer,

pursuant to current regulations on the protection of personal data (EU Regulation n. 679 of 2016), we wish to inform you that your data will be handled fairly and transparently for lawful purposes and safeguarding your confidentiality and rights.

 

Data Controller and Processor Contact Information

The Controller of the processing of your data is ORDINE DEI CAVALIERI DEL TARTUFO E DEI VINI DI ALBA, Via Castello n. 5, 12060 Grinzane Cavour (CN)¸ Italy, Tel. 0173 262159.

An updated list of parties appointed as Processors pursuant to article 28 of the GDPR is available at the Order’s registered office, and can be requested as indicated herein.

Data Controller and Processor Contact Information

The Controller of the processing of your data is ORDINE DEI CAVALIERI DEL TARTUFO E DEI VINI DI ALBA, Via Castello n. 5, 12060 Grinzane Cavour (CN)¸ Italy, Tel. 0173 262159.

An updated list of parties appointed as Processors pursuant to article 28 of the GDPR is available at the Order’s registered office, and can be requested as indicated herein.

 

Categories of personal data processed and Purposes of the processing

As Controller, ORDINE DEI CAVALIERI DEL TARTUFO E DEI VINI DI ALBA informs you that it will not use special customer data.

The personal data processed by the Controller may be used for the following purposes:

  1. For the performance of contractual agreements (registration with the Order of Knights of the Truffle and Wines of Alba and related obligations);
  2. For the performance of administrative, accounting and tax obligations;
  3. For the sending of communications, and information on the Order and events;
  4. For the publication of names on the website of the Order of Knights of the Truffle and Wines of Alba.

With reference to the purposes described under a), b) and c) above, the providing of correct data is obligatory. Refusal to provide the data and/or the providing of incorrect or incomplete information will prevent the performance of the above activities.

With reference to the purpose described under d) above, your data may only be processed with your consent, which may be withdrawn at any time.

 

Methods of processing

Your data will be processed using suitable paper, electronic and/or telematic formats in accordance with criteria which are strictly related to the above purposes, and in any case so as to guarantee the security and confidentiality of the data concerned.

Your personal data will be processed lawfully and fairly for the performance of the above purposes using computerized means, and protected by appropriate security measures to ensure their confidentiality, integrity, accuracy, availability and updating.

The personal data will only be processed by authorized persons appointed by the Controller, ORDINE DEI CAVALIERI DEL TARTUFO E DEI VINI DI ALBA, which has provided all necessary IT security measures in order to minimize any risk of breach of user privacy by third parties, updating them constantly and whenever essential.

 

Recipients or Categories of recipients of personal data

The personal data processed by the Controller may be disclosed to specific parties considered recipients of said personal data. Article 4 (9) of the Regulation defines a recipient of personal data as “a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not”.

In light of this, in order to carry out correctly all the processing activities required to pursue the purposes herein, the following recipients may need to process the data on behalf of the Controller:

  • Third parties who perform part of the processing activities and/or related and instrumental activities. Such parties have been appointed as processors.
  • Individuals, employees and/or associates of the Controller tasked with specific and/or several processing activities in relation to your personal data, who have been given specific instructions in relation to the security and correct use of the data.
  • Public and private parties who can access the data by virtue and within the limits of legal provisions, regulations or community rules. For example: social security institutes and bodies, associations of local organizations, public administrations and bodies, associations, foundations, insurance bodies or organizations.
  • Parties who need to access the data for purposes which are auxiliary to the relationship between the parties, within the limits which are strictly necessary for the carrying out of auxiliary activities, by way of example: banks and credit institutions, service providers, shipping companies and carriers.

The data will not be disseminated – in the sense of in any way disclosed to or made available for consultation by unspecified parties – without specific free and well-informed consent having been given for each type of processing.

 

Duration of the processing and criteria used for the storage of personal data

For the purposes under a), b) and c) above, your data will only be processed for as long as is necessary for the performance of the purposes for which it has been collected and stored for the time required by law. For the purposes under d)

 

Rights of data subjects

Pursuant to art. 7 of Italian Legislative Decree 196/2003 and articles 15-22 of Regulation EU n. 2016/679, data subjects may at any time exercise the right to:

  1. request confirmation of whether or not their personal data are held;
  2. obtain indications relating to the purpose of processing, the categories of personal data, the recipients or categories of recipients to whom the personal data have been or will be disclosed, and where possible the period of storage;
  3. rectification and erasure of the data;
  4. restriction of the processing;
  5. obtain portability of the data, in other words receive the data from a controller in a structured, commonly used and machine-readable format, and transmit those data to another controller without hindrance;
  6. object to the processing at any time, also in the event of processing for the purposes of direct marketing;
  7. object to any automated decision-making process, including profiling;
  8. request access to the personal data and their rectification and erasure or restriction of their processing or object to their processing, as well as the right to data portability;
  9. withdraw consent at any time without prejudice to the lawfulness of the processing based on the consent given prior to the withdrawal;
  10. Pursuant to art. 13, (2) d) of Regulation 679/2016, subjects to whom personal data relate have the right to lodge a complaint with a supervisory authority.

 In order to exercise the above rights, the Controller can be contacted by emailing segreteria@cavalierideltartufo.it, preferably entering “Privacy – exercising of GDPR rights” in the subject field.