Privacy Policy
With this Privacy Policy, the Data Controller, as defined below, wishes to inform you of the purposes and methods of the processing of your personal data, as well as of the rights granted to you under Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR").
DATA CONTROLLER
MCR CONFERENCE SRL Via Finlandia, 26 - 50126 Florence, Italy
Tax Code / VAT No.: 06230780485
(+39) 055 0541807 | (+39) 333 6581076 Certified e-mail (PEC): mcrconference@legalmail.it
CATEGORIES OF PERSONAL DATA PROCESSED
The processing activities carried out are aimed at the collection of the following personal data:
| Category | Type |
|---|---|
| Ordinary data | Profiling cookies |
| Ordinary data | Browsing logs |
| Ordinary data | Personal identification data |
CATEGORIES OF DATA SUBJECTS
The processing activities carried out concern the following categories of data subjects:
| Category |
|---|
| Website users |
PURPOSES OF THE PROCESSING AND LAWFUL BASIS OF THE PROCESSING
1. WEBSITE – Browsing Data
Obtaining anonymous statistical information on website usage, verifying the proper functioning of the website, and establishing liability in the event of hypothetical cybercrimes committed against the Data Controller.
The data you provide will be processed for the following purposes:
| Lawful Basis of the Processing | Purpose | Description |
|---|---|---|
| Legitimate Interest – Art. 6(1)(f) GDPR | Technical maintenance of the website. | Data analysis for the purpose of developing and maintaining the website. |
| Legitimate Interest – Art. 6(1)(f) GDPR | Unlawful use of the website. | Establishing liability in the event of potential cybercrimes committed against the website and/or the data subjects. |
| Legitimate Interest – Art. 6(1)(f) GDPR | Statistical analysis. | Anonymous statistical analysis of website usage. |
Nature of the provision of data: Mandatory.
Consequences of refusal to provide data: Failure to provide the data will make it impossible for the company to deliver the web service offered.
Personal data retention period: The data are retained for 30 days.
Minimum data protection measures: Standard protection measures.
Processing methods: The processing is carried out by electronic means.
2. WEBSITE – Requests submitted through the website
Requests submitted by data subjects through the Data Controller's website. The data you provide will be processed for the following purposes:
| Lawful Basis of the Processing | Purpose | Description |
|---|---|---|
| Performance of a Contract – Art. 6(1)(b) GDPR | Submission of requests through the tools of the web platform. | Submission of requests through the tools of the web platform. |
Nature of the provision of data: Optional.
Consequences of refusal to provide data: Failure to provide the data will make it impossible for the Data Controller to respond to the data subject's requests.
Personal data retention period: Until the request has been fulfilled.
Minimum data protection measures: Standard protection measures.
Processing methods: The processing is carried out by electronic means.
3. WEBSITE – Use of the Service and Restricted Area
Use of the services offered through the restricted area of the Data Controller's website. The data you provide will be processed for the following purposes:
| Lawful Basis of the Processing | Purpose | Description |
|---|---|---|
| Performance of a Contract – Art. 6(1)(b) GDPR | Registration. | Registration within the restricted area. |
| Performance of a Contract – Art. 6(1)(b) GDPR | Use of the service reserved for users. | Use of the service provided through access to the restricted area of the website. |
Nature of the provision of data: Optional.
Consequences of refusal to provide data: Failure to provide the data will make it impossible for the Data Controller to provide services through the restricted area of the website.
Personal data retention period: Until the user account is deleted.
Minimum data protection measures: Standard protection measures.
Processing methods: The processing is carried out by electronic means.
4. FACEBOOK SOCIAL MEDIA PAGE
When a user interacts with the Page administered by the Data Controller, Facebook (the "Social Media") collects information such as, for example, the types of content viewed or interacted with, the actions performed, as well as information about the devices used (IP addresses, operating system, browser type, language settings, cookie data).
Page Insights are aggregated statistics created from certain events logged by Facebook's servers when users interact with Pages and the content associated with them.
As explained in Facebook's Privacy Policy, the Social Media also collects and uses information to provide statistical data collection services, known as Page Insights, to page administrators, in order to enable them to understand how people interact with the content available on their pages.
Details on the processing carried out by Facebook are available at the following link:
https://www.facebook.com/privacy/explanation
Details on the personal data processed for Insights are available at the following link:
https://www.facebook.com/legal/terms/information_about_page_insights_data
Details on the cookies used by Facebook are available at the following link:
https://www.facebook.com/policies/cookies/
The Data Controller, as administrator of the Page, and Facebook Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) are joint controllers, in accordance with Article 26 of the GDPR, for the processing of such personal data logged for the events provided through Page Insights ("Insights Data").
The joint controllership agreement between the Data Controller and Facebook covers the creation of such events and their aggregation into Page Insights made available to each administrator.
The lawful basis of the processing is the legitimate interest of the Data Controller, pursuant to Art. 6(1)(f) GDPR. Accordingly, your prior consent to the processing is not required.
The data you provide will be processed for the following purposes:
| Lawful Basis of the Processing | Purpose | Description |
|---|---|---|
| Legitimate Interest – Art. 6(1)(f) GDPR | Review of Facebook Page Insights | Statistical surveys concerning the use of elements contained within the Facebook page administered by the Data Controller. |
Nature of the provision of data: Mandatory.
Consequences of refusal to provide data: Failure to provide the requested data will make it impossible for the Data Controller to provide services through the Page published on Facebook.
Personal data retention period: The data collected will be processed for the time strictly necessary to achieve the purposes described above, as specified in the Facebook policies referred to above.
Minimum data protection measures: Security measures adopted by the Joint Controller Facebook Ireland Limited.
Processing methods: The processing is carried out by electronic means by the Joint Controller Facebook.
RECIPIENTS OF THE PERSONAL DATA
| Role | Recipient or Category of Recipient |
|---|---|
| Data Processor | Hosting service providers |
| Data Processor | ICT systems maintenance services |
| Data Processor | Supplier |
| Person authorised to process data (Internal) | Staff employed by the Data Controller |
RIGHTS OF THE DATA SUBJECT – COMPLAINT TO THE SUPERVISORY AUTHORITY
In relation to the processing operations described in this Privacy Policy, as a data subject you may, under the conditions laid down by the GDPR, exercise the rights enshrined in Articles 15 to 22 of the GDPR and, in particular, the following rights:
- right of access – Article 15 GDPR: the right to obtain confirmation as to whether or not personal data concerning you are being processed and, where that is the case, to obtain access to your personal data;
- right to rectification – Article 16 GDPR: the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and/or the completion of incomplete personal data;
- right to erasure ("right to be forgotten") – Article 17 GDPR: the right to obtain, without undue delay, the erasure of personal data concerning you. The right to erasure does not apply to the extent that the processing is necessary for compliance with a legal obligation, for the performance of a task carried out in the public interest, or for the establishment, exercise or defence of legal claims.
- right to restriction of processing – Article 18 GDPR: the right to obtain the restriction of processing where: (a) the data subject contests the accuracy of the personal data; (b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; (c) the personal data are needed by the data subject for the establishment, exercise or defence of legal claims; (d) the data subject has objected to the processing pending the verification of whether the legitimate grounds of the controller override those of the data subject.
- right to data portability – Article 20 GDPR: the right to receive, in a structured, commonly used and machine-readable format, the personal data concerning you which you have provided to the Data Controller, and the right to transmit those data to another controller without hindrance, where the processing is based on consent and is carried out by automated means. In addition, the right to have your personal data transmitted directly from this controller to another controller, where technically feasible;
- right to object – Article 21 GDPR: the right to object, at any time, to the processing of personal data concerning you which is based on the lawful basis of legitimate interest, including profiling, unless there are legitimate grounds for the Data Controller to continue the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
- right not to be subject to automated individual decision-making – Article 22 GDPR: the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her, unless such a decision is necessary for entering into, or the performance of, a contract, or you have given your consent. In any event, automated decision-making shall not concern your personal data, and you may at any time obtain human intervention on the part of the controller, express your point of view and contest the decision.
- right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali): http://www.garanteprivacy.it;
- the right to withdraw the consent given at any time, and as easily as it was given, without affecting the lawfulness of the processing based on the consent given prior to its withdrawal.
The above rights may be exercised vis-à-vis the Data Controller by contacting the details indicated in the DATA CONTROLLER section, in the first part of this Privacy Policy. The exercise of your rights as a data subject is free of charge pursuant to Article 12 GDPR. However, in the case of manifestly unfounded or excessive requests, in particular because of their repetitive character, the Data Controller may charge a reasonable fee, taking into account the administrative costs incurred in handling your request, or refuse to act on your request. Finally, please note that the Data Controller may request additional information necessary to confirm the identity of the data subject.
Privacy Policy last updated on 30-11-2020