Privacy Policy for Customers

Dear Customer,

with this information (“Policy”), prepared pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), we indicate the purposes and methods of processing of your personal data carried out for the purposes of executing the contract stipulated/in the process of being stipulated with Lucente SpA ( "company" or "Holder”). The information is intended to be provided to the legal representative of the Customer who, in the name and on behalf of the Customer, signs the contract with the company, as well as the directors, employees, collaborators and contact persons of the Customer who act as the so-called Point of Contact with the Customer (“Point of contact”), all as “data subjects” pursuant to the GDPR.

1. DATA CONTROLLER and DPO

The Data Controller is Lucente SpA with registered office in Modugno (BA), via dei Gerani n. 6, Fiscal Code and VAT number 00252370721, email address: lalucentespa@postecert.it. For privacy-related issues, in addition to the Data Controller, it is possible to contact the Data Protection Officer (“DPO”), email address: dpolalucente@studiodirevisori.it.

2. PERSONAL DATA SUBJECT TO PROCESSING

In order to execute the contract, the Data Controller collects and processes the data subject's personal data, including: name, surname, date of birth, tax code, identity documents and/or identification documents, residential address, and the email address of the Customer and/or the Contact Point. With regard to the Contact Point's personal data, it is specified that the source of the personal data, as applicable, is the Customer and/or the Contact Point itself.

3. PURPOSE OF THE PROCESSING OF PERSONAL DATA

Your personal data may be processed by the Data Controller for the following purposes:

3.1 execution of pre-contractual and contractual measures of the relationship entered into/in the process of being entered into between the Data Controller and the Customer, as well as management of related obligations, such as, for example, management of commercial contacts, invoicing, payment management, debt collection and so on;

3.2 ensure compliance with the legal obligations, regulations and European standards to which the Data Controller is subject;

3.3 to ascertain, exercise or defend in judicial and/or extrajudicial proceedings the rights or interests of the Data Controller or third parties, expressly including debt collection;

3.4 allow the Data Controller to complete a potential merger, sale of assets, transfer of business or business unit, by communicating your personal data to the third party(ies) involved and/or to the consultants responsible for managing the transaction;

3.5 carry out preliminary checks on the Client and/or the subjects operating on its behalf, apply the internal measures, policies and procedures adopted by the Company in compliance with the legislation (for example, Legislative Decree 231/2001, GDPR, Legislative Decree 81/2008 and/or ISO reference standards).

4. LEGAL BASIS OF THE PROCESSING

With reference to the purposes referred to in point 3.1, the legal basis for the processing of the Customer's personal data is represented by art. 6 (1) (b) GDPR – “processing necessary for the performance of a contract or for the implementation of pre-contractual measures taken at your request”, while the legal basis for the processing of personal data by the Contact Point is represented by art. 6 (1) (f) GDPR – “legitimate interest of the owner or third parties". With reference to the purposes referred to in point 3.2, the legal basis for the processing is represented by art. 6 (1) ( ​c ) GDPR – “the processing is necessary for compliance with a legal obligation to which the data controller is subject”. With reference to the purposes referred to in point 3.3, 3.4 e 3.5 the legal basis for the processing is represented by art. 6 (1) (f) GDPR – “legitimate interest of the owner or third parties".

With particular reference to purposes based on the legitimate interest of the Data Controller or third parties pursuant to Art. 6(1)(f) GDPR, it is specified that the Data Controller's legitimate interest in processing the data is fairly balanced with your interests, rights, and fundamental freedoms. Processing based on the Data Controller's legitimate interest is not mandatory, and you may object to such processing using the methods described in this Policy. In such a case, the Data Controller may not process your personal data for this purpose unless it demonstrates overriding legitimate grounds. The provision of personal data is necessary for the conclusion and/or performance of the contract between the company and the Customer. Refusal to provide personal data prevents the establishment of the contractual relationship and/or the fulfillment of the related obligations.

5. STORAGE PERIOD

Personal data, in general, are stored for a period not exceeding eleven years subsequent to the termination of the contractual relationship, without prejudice to the Data Controller's right to retain personal data for a different or further period for the sole purpose of allowing the latter to pursue specific purposes indicated in the Privacy Policy.

6. AUTOMATED DECISIONS

Under no circumstances will the personal data collected for the above purposes be subjected to automated processing, including profiling pursuant to Art. 22 of the GDPR. 

7. RECIPIENTS AND DATA TRANSFER

Your data may be shared with:

  1. persons authorized by the Data Controller to process personal data who have undertaken to maintain confidentiality or are subject to an appropriate legal obligation of confidentiality;
  2. consultants, suppliers and Partner commercial data of the Data Controller, for the purposes of executing the contract;
  3. other companies which, in various capacities, operate in the Data Controller's working context;
  4. companies specialized in debt collection activities, legal and tax consultants appointed by the Data Controller;
  5. third parties involved in carrying out activities strictly connected and functional to the conclusion and/or execution of extraordinary transactions involving the Data Controller.

Except for the aforementioned cases, your personal data will not be disclosed, except to individuals, entities, or authorities to whom disclosure is mandatory by law or regulation. Your personal data will not be transferred outside the European Economic Area.

8. EXERCISE OF THE RIGHTS OF THE INTERESTED PARTY

In accordance with the GDPR, you have the right to request from the Data Controller access to your personal data, its rectification or erasure, or to object to its processing, at any time, where applicable. You may also request restriction of processing in the cases provided for in Article 18 of the GDPR. In the cases referred to in Article 20 of the GDPR, the data subject has the right to obtain the personal data concerning him or her in a structured, commonly used, and machine-readable format, and, if technically feasible, to transmit that data to another controller without hindrance. Requests can be sent to the following email address: dpolalucente@studiodirevisori.itFinally, we remind you that you always have the right to lodge a complaint with the competent supervisory authority (Italian Data Protection Authority), pursuant to Article 77 of the GDPR, if you believe that the processing of your data violates applicable law.

9. CHANGES

The Data Controller reserves the right to update this Privacy Policy at any time and to inform interested parties using the tools deemed most appropriate. For any further information or questions, please contact the Data Controller at the following email address: lalucentespa@postecert.it.