Pursuant to art. 13 and 14 of the European Regulation (EU) 2016/679 (hereinafter GDPR), and in relation to the personal data of which the Data Controller will become available, we communicate the following:

Holder of the treatment

INNOVA S.r.l.

via 1 Maggio, 8 – 38089 Storo (TN)

VAT number 01827470228

Tel 0465670104

E-mail info@innovaenergie.com

1. Type of data, purpose and legal basis of the processing:

Client

TYPE OF DATA
COMMUNICATED DATA
Personal details
Contact details
Tax code/VAT number
Bank details
Chamber measures
CCIA registration certificates
Data for declarations for first home or renovations facilities (in the case of private customers)
Navigation data

PURPOSE
Processing of estimates or information upon request of the interested party
Fulfillment of contractual obligations
Fulfillment of tax and accounting obligations
Direct marketing/newsletter/promotional activities of the Data Controller
Protection of the rights of the owner

LEGAL BASIS
Execution of pre-contractual
Execution of a contract
Fulfillment of a legal obligation
Consent of the interested party Legitimate interest of the Data Controller
Legitimate interest of the Data Controller

Providers

TYPE OF DATA
COMMUNICATED DATA
Personal details
Contact details
Tax code/VAT number
Bank details
Chamber of commerce measures
Registration certificates CCIA DVR or Self-certification - DURC, list of employees (in the case of workers or maintenance on the company website of the Owner)
Web navigation data

PURPOSE
Requests for information, quotes, business contacts
Fulfillment of contractual obligations
Fulfillment of tax and accounting obligations
Protection of the rights of the owner

LEGAL BASIS
Execution of pre-contractual measures
Execution of a contract
Fulfillment of a legal obligation
Legitimate interest of the Data Controller

Internal references, collaborators of Customers/Suppliers

TYPE OF DATA
COMMON DATA
Name/surname
Contact details

PURPOSE
Request for informations, quotes, business contacts
Fulfillment of contractual obligations

LEGAL BASIS
Execution of pre-contractual measures
Execution of contract

Shareholders, Legal representatives and / or Administrators of the Owner / Customers / Company Suppliers

TYPE OF DATA
COMMUNICATED DATA
Personal data
Contact data
Tax code

PURPOSE
Fulfillment of contractual obligations
Fulfillment of legal obligations
Protection of the rights of the owner

LEGAL BASIS
Execution of contract
Fulfillment of legal obligations
Legitimate interest of the Data Controller

2. How we process your data:

The Data Controller has adopted adequate security measures in order to preserve the confidentiality, integrity and availability of the data subject's personal data and imposes similar security measures on third party suppliers and Managers. There is no automated decision-making process based on your data, including profiling. The data is processed using manual and IT tools, with logic strictly related to the purposes of the processing.

If the Data Controller intends to further process your personal data for a purpose other than that for which they were collected, before such further processing, he will provide you with information regarding this different purpose and any further relevant information asking, if necessary, your consent.

If the Data Controller uses the e-mail coordinates provided by the Data Subject in the context of the sale of a product or service for the direct sale of its products or services, it may not request the consent of the Data Subject, as long as it is of services similar to those of the sale. The interested party can refuse such use, initially or on the occasion of subsequent communications.

Data provision and refusal - The provision of personal data is necessary for the purposes of carrying out the aforementioned purposes and the refusal by the interested party to provide personal data makes it impossible to fulfill the contract.

3. Recipients of personal data:

Your personal data - which will not be disclosed - may be disclosed to: employees or collaborators of the Data Controller, subjects who provide assistance and consultancy in IT, accounting, administrative, legal, tax, insurance and financial matters; subjects, bodies or authorities to whom the communication of personal data is mandatory by virtue of legal provisions or orders of the authorities, banks and / or credit institutions. The subjects to whom your personal data will be communicated by the Data Controller will be able to process them as authorized for the processing or as data processors.

4. Transfer of data abroad:

There is no transfer of data to non-EU countries. If necessary, the transfer of data to non-EU countries takes place for the execution of the contract concluded with the interested party or the execution of pre-contractual measures adopted at the request of the interested party, as provided in derogation from art. 49 lett. b) GDPR; in this case, the Data Controller ensures the adoption of adequate guarantees of confidentiality and security.

5. Retention period:

The data are kept for the time necessary for the pursuit of the purposes indicated in the information, for legal obligations or to assert a right in court. Once the limitation period has expired, personal data will be permanently deleted or, alternatively, anonymized. For the purposes of direct marketing / newsletter / promotional activities of the Data Controller, the data will be kept until the consent is revoked or the data subject requests for cancellation.

6. Rights of the data subject:

You have the right to ask the Data Controller: to access your personal data; to request the correction of inaccurate data or the integration of incomplete ones; to request cancellation (under the conditions indicated in art.17 GDPR); to limit their processing (under the conditions of Article 18 of the GDPR); to oppose their treatment; to request a copy of their personal data in electronic format and the right to transmit such personal data to use them as part of the service of other Data Controllers (so-called data portability); not to be subject to a decision based exclusively on an automated decision-making process, including in the matter of profiling, if the decision has a legal effect on the user or entails an equally significant effect;www.garanteprivacy.it