WHY THIS INFORMATION
Pursuant to Regulation (EU) 2016/679 (hereinafter the “Regulation”), this page describes the processing methods:
- of the personal data of users who visit the website mic.democenterlecce.it (hereinafter the “Site”) of DEMO CENTER LECCE (hereinafter the “Company”), accessible online at the following WEB ADDRESS: mic.democenterlecce.it
- of personal data entered or collected through the Company’s social media pages.
This information does not apply to other websites, pages, or online services reachable through hyperlinks that may be published on the site but refer to resources external to the Company’s domain.
DATA CONTROLLER
Professore Fabrizio Illuminati
Codice fiscale: LLMFRZ63E30D542X
Phone: 0832 319826
Email: fabrizio.illuminati@nanotec.cnr.it, fabrizio.illuminati@cnr.it
PEC: protocollo.nanotec@pec.cnr.it
Direttore di Istituto di Nanotecnologia (Nanotec)
DATA PROTECTION OFFICER
The Company has appointed a Data Protection Officer (DPO) to verify compliance of processing activities with Italian and European regulations.
The Data Protection Officer can be reached at the following address:
Professore Fabrizio Illuminati
Codice fiscale: LLMFRZ63E30D542X
Phone: 0832 319826
Email: fabrizio.illuminati@nanotec.cnr.it, fabrizio.illuminati@cnr.it
PEC: protocollo.nanotec@pec.cnr.it
Direttore di Istituto di Nanotecnologia (Nanotec)
LEGAL BASIS FOR PROCESSING
The Company will process personal data only if there is a legal basis to do so.
Data protection legislation establishes that the processing of personal data is lawful only if and to the extent that at least one of the following conditions applies (as per Art. 6 of the Regulation):
- the data subject has given consent to the processing of their personal data for one or more specific purposes;
- the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract;
- the processing is necessary for compliance with a legal obligation to which the data controller is subject;
- the processing is necessary to protect the vital interests of the data subject or another natural person;
- the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- the processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Therefore, the legal basis for processing will depend on the reasons for which the Company has collected and uses the data.
These reasons may include, for example, the need to respond to requests received through the contact section (in which case the legal basis is the performance of a contract and/or pre-contractual measures), compliance with legal and/or regulatory obligations, or the possibility of pursuing the legitimate interests of the Company, identified case by case. Where consent is required, it will be obtained in the legally prescribed manner.
TYPES OF DATA PROCESSED AND PURPOSES OF PROCESSING
Personal data means any information relating to the user through which they can be identified. Personal data therefore includes, for example, name, surname, contact details, phone number, e-mail address, IP address, and information concerning the user’s access to the Site.
Following the consultation of the Site, as well as the use of services provided through it, the Company may collect personal data from users through telephone communications to the numbers listed on the Site, receipt of emails sent to the addresses listed on the Site, the completion of forms in the contact section, or the use of social network plugins on the Site.
Specifically, the types of data processed can be classified as follows:
BROWSING DATA
The IT systems and software procedures responsible for the operation of the Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
These are information not collected to be associated with identified individuals but which, by their nature, could allow the identification of users through processing and association with data held by third parties.
This category includes IP addresses or domain names of the computers used by users connecting to the site, URI/URL addresses (Uniform Resource Identifier/Locator) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the server’s response status (success, error, etc.), and other parameters concerning the user’s operating system and IT environment.
These data, necessary for the use of web services, are also processed to:
- obtain statistical information on service usage (most visited pages, number of visitors by hourly or daily intervals, geographic areas of origin, etc.);
- verify the correct functioning of the services offered;
- identify anomalies and/or abuses.
Browsing data are not stored for more than seven days (except for possible requirements for crime investigation by the judicial authority).
PERSONAL DATA VOLUNTARILY PROVIDED BY USERS
Optional, explicit, and voluntary sending of messages to the Company’s contact addresses, private messages sent by users to institutional social media profiles/pages (where this is possible), and the completion and submission of forms on the Company’s website result in the collection of the sender’s contact details necessary to respond, as well as any personal data included in the communications.
Specific privacy notices will be published on the Site pages dedicated to the provision of certain services.
CONSEQUENCES OF FAILURE TO PROVIDE DATA
Failure to provide data necessary to respond to requests may make it impossible for the Company to provide a complete response or the services available.
Where necessary, the Company will inform the user of the mandatory or optional nature of providing personal data (e.g., to make a specific request).
In particular, the mandatory or optional nature of providing data will be highlighted through a notice or specific marking on mandatory information.
RECIPIENTS OF DATA
Data recipients include Company personnel acting under specific instructions regarding purposes and methods of processing.
Recipients also include entities designated by the Company pursuant to Article 28 of the Regulation as data processors.
If social media plugins are used on the Site, data will be shared with the social media service and possibly with the user’s profile on the social media. In such cases, refer to the privacy policy of the respective social media platform.
In any case, processed personal data will not be disseminated.
Disclosure or dissemination of requested data to law enforcement, judicial authorities, intelligence or security agencies, or other public entities for state defense or security purposes, or for the prevention, investigation, or prosecution of crimes, remains permitted by law.
METHODS AND SECURITY OF PROCESSING
Data will be processed:
- using manual, IT, and telematic tools in a manner that ensures data availability, integrity, and confidentiality;
- with organizational methods and logics strictly related to the purposes indicated, respecting the principle of data minimization;
- by specifically appointed, identified, and authorized personnel, properly trained and made aware of the legal constraints;
- using technical and organizational security measures to prevent and/or reduce the risks of unauthorized access, destruction, or loss of data.
LOCATION OF PROCESSING
Management and storage of personal data will take place in Italy and, in any case, within the European Union.
Currently, the servers used by the Company are located within the European territory.
Data will not be transferred outside the European Union.
The Company reserves the right to change the location of servers in Italy, the EU, or non-EU countries if deemed necessary and/or appropriate. In such cases, transfers outside the EU will comply with applicable law, including agreements ensuring adequate protection and/or standard contractual clauses issued by the European Commission.
RETENTION PERIOD
Data collected by the Site will be used exclusively for the stated purposes and retained only as long as necessary for the Company’s activities.
Data will not be kept longer than necessary to fulfill the purpose for which they were processed. In determining the appropriate retention period, the Company will consider the quantity, nature, and sensitivity of personal data, the purposes for which it is processed, and the possibility of achieving those purposes by other means.
Data collected by the Site will therefore be retained for the entire duration necessary to respond to requests and, even after termination, to manage any contractual, pre-contractual, administrative, or legal obligations, or for the period allowed by Italian law to protect the Company’s legitimate interests.
DATA SUBJECT RIGHTS
Data subjects have the right to obtain from the Company, where applicable, access to their personal data, rectification or deletion, restriction of processing, objection to processing, and data portability.
Data subjects may also revoke consent at any time (see Arts. 15 et seq. of the Regulation).
Requests should be submitted to the Company by contacting the Data Protection Officer at the contacts provided above.
Data subjects who believe that the processing of their personal data through the Site violates the Regulation have the right to lodge a complaint with the Data Protection Authority, as provided in Art. 77 of the Regulation, or seek judicial remedies (Art. 79 of the Regulation).
CHANGES AND UPDATES TO THIS PRIVACY POLICY
The Company may modify or simply update, in whole or in part, this privacy notice, also considering any legislative and/or regulatory changes.
The Company undertakes not to limit any previously recognized rights without first obtaining the explicit consent of the data subject.
Changes and updates will be made available on the Site’s homepage. Major changes will be highlighted through a more visible notice (for example, where services and collected data allow, via email notification).
Logo di Next Generation EU