- We process your personal data necessary to allow you to browse this website and view the information on its pages, to provide you with the services you have requested and, where the website allows you to log in to particular areas of the same as a registered user, we process your data to manage your logins. We may send you promotional communications or conduct profiling analyses only with your consent, which you may withdraw at any time.
- We communicate your data to our partners/suppliers/third parties only if strictly necessary for the technical requirements of managing the website, to provide you with the services available through the website or because it is required by law. If, as a result, it becomes necessary to transfer data abroad, we will take all the appropriate measures provided for by current privacy legislation.
- We apply security measures and the related controls in accordance with the law, in order to protect the privacy of your data and protect our online resources against malicious attacks and attempted fraud.
- You can exercise your rights under current privacy legislation by writing to: firstname.lastname@example.org
- What does this policy apply to?
- Who is the Data Controller and what are the DPO’s contact details?
- What types of personal data do we collect and where do we get it from?
- For what purposes do we process personal data?
- With which legal bases do we process personal data?
- To which recipients can personal data be communicated and possibly exported outside the EU?
- For how long do we retain personal data?
- What are the processing methods and security measures applied to personal data?
- What are your privacy rights and how can you exercise them?
1. What does this policy apply to?
This policy is provided only for fidiapharma.com and does not apply to other websites that may be reached via hyperlinks.
2. Who is the Data Controller and what are the DPO’s contact details?
The Data Controller is Fidia Farmaceutici S.p.A. with registered office in Via Ponte della Fabbrica 3/A – 35031 Abano Terme (PD).
If you have any questions about the processing of your personal data or to exercise your rights regarding privacy, you can contact our Data Protection Officer (hereinafter DPO) in the following ways: by email by writing to email@example.com or by normal post by writing to: Via Ponte della Fabbrica 3/A – 35031 Abano Terme (PD), FAO: Legal Department and Data Protection Officer.
When you send us a request, remember to include your contact details so we can identify you and get back to you.
3. What types of personal data do we collect and where do we get it from?
Website browsing data
During their normal operation, the computer systems and software procedures used to operate this Website acquire certain personal data, the transmission of which is implicit in the use of internet communication protocols.
This category includes IP addresses or the domain names of computers and terminals used by users, addresses in URI/URL (Uniform Resource Identifier/Locator) notation of requested resources, the time the request is made, the method used to submit the request to the server, the file size obtained in response, the numerical code indicating the response status from the server (successful, error, etc.) and other parameters related to the user’s operating system and computer environment.
This data, necessary for use of the web services, is also processed in order to:
– obtain statistical information on the use of the services (most visited pages, number of visitors per time slot or per day, geographical areas of origin, etc.);
– monitor the proper functioning of the services provided.
Data voluntarily provided by you
The voluntary sending of messages to the contact addresses on the Website involves the acquisition of your contact data, as well as the subject and content of your messages.
Your voluntary completion and submission of any forms (information acquisition forms) on the Website, involves the acquisition of your contact details as the sender, and of other data provided in the specific form, in which those fields that are considered mandatory, without the compilation of which it is not possible to send the form, are always indicated (usually with a ‘*’).
Data provided by you as a registered user
The Website may contain restricted areas, access to which requires you to register (thereby becoming a registered user of the Website). For this purpose, the data necessary to create the registration and manage it over time will be used, i.e.e: identification data of the person who wants to register, including their email address that will be used in the registration phase, as well as to send any necessary communications (so-called service communications), log in credentials: typically UserID and Password and any other access PIN and, finally, the data which, case by case, may be necessary according to the topics covered in the restricted area.
Data provided by you in relation to a service you have requested
The Website may provide services, such as access to information conveyed through specific newsletters dedicated to particular topics of interest to you, or it may allow the purchase of products and services in compliance with the regulatory system that by law governs their purchase by both companies and consumers.
In the event of your request to receive our newsletter (where the service is available), we will use your contact details and email address. Where, on the other hand, the Website provides online purchasing functionalities (e-commerce), your data will be necessary to complete the purchase and therefore full identification data, contact details and delivery address, while the data relating to payment will be directly processed by the payment service provider (e.g. bank) on which the e-commerce functionalities are based.
Profiling and marketing data
We may use your identification data, contact data, data relating to your preferences and interests indicated by your use of the Website, for the purpose of providing you with services tailored to your needs or sending you ad hoc commercial communications, only if you provide us with your prior consent.
Data from external sources
Only in relation to services that may be available on the Website, and which have been explicitly requested by you, we may collect certain data concerning you from relevant external sources, such as your membership of a professional association, should this be necessary to allow you to access the service.
4. For what purposes do we process personal data?
The purposes are the following:
a. Website technical management: Technically enable efficient browsing of the Website
b. Provision of requested services: Provide the services you have requested, including the management of your registration to specific restricted areas of the Website where present, sending information material expressly requested by you, allow you to purchase our products online where this functionality is available on the Website, and respond to your requests for information and details concerning our products or thematic sections.
c. Website security management: Manage the security of data and of our information facilities against malicious attacks and attempted fraud.
d. User analysis: Analyse your behaviour based on the use of the Website in order to adapt our services accordingly and present you with commercial proposals, subject to obtaining your voluntary consent.
e. Authority requests: Respond to any requests for information from the competent Authorities.
To this end, from among all the data in our possession, we will use that requested by the Authority under applicable law.
f. Exercise of Privacy Rights: Respond to your requests to exercise your privacy rights, as provided for by current data protection legislation.
To this end, we will use the Data voluntarily provided by you.
5. With which legal bases do we process personal data?
We must comply with a legal requirement when data is processed for the above purposes e. Authority requests and f. Exercise of Privacy Rights.
On the other hand, the legal basis is to meet your requests when we process data for the above purposes: a. Website technical management and b. Provision of requested services.
On the other hand, we have a legitimate interest in processing the data in the case of the above purpose c. Website security management, consisting of the need to put in place measures to protect data and technical infrastructures against the risk of unforeseen events or illegal or malicious acts that could compromise their confidentiality, availability and integrity.
The legal basis, on the other hand, is your voluntary and prior consent to processing, in the case of the purpose described above: d. User analysis.
6. To which recipients can personal data be communicated and possibly exported outside the EU?
Personal data is processed by personnel specifically authorised by the Data Controller, as well as by third parties, also possibly established in countries outside the European Union, only when this is necessary for the operational and maintenance needs of the Website and the services made available thereon, without prejudice to any obligations provided for by law.
As provided for by the GDPR, the Data Controller contractually identifies third party companies that perform processing on behalf of said Data Controller as Data Processors.
Should it be necessary to involve third parties established in countries outside the European Union, the appropriate applicable safeguards in terms of adequacy decisions issued by the European Commission, standard contractual clauses again defined by the Commission or by the competent National Personal Data Protection Authority or the exceptions provided for by the GDPR will be adopted on a case by case basis for the related transfer of data abroad.
Further information regarding possible transfers of data to countries outside the European Union and the related guarantees adopted, as well as information regarding the companies appointed as Data Processors, can be requested from the DPO.
7. For how long do we retain personal data?
The personal data processed will be retained for a period of time not exceeding that required for achievement of the purposes indicated above and in compliance with any terms provided for by law, except for the need to keep it for a longer period of time following requests from the competent authorities for the prevention and prosecution of crimes or, in any case, to assert or defend a right in court.
8. What are the processing methods and security measures applied to personal data?
All data will be processed mainly in electronic format and collected and processed by applying the technical and organisational measures consistent with a level of security appropriate to the risks, taking into account the state of the art and the implementation costs and, where applicable, the security measures prescribed by specific legislation.
In using the functionalities of this Website and with reference to personal data protection aspects, in accordance with Art. 33 of the GDPR, users are invited to report to the Data Controller any circumstances or events that may result in a potential “data breach”, by sending a communication to the following email address firstname.lastname@example.org, in order to allow the Data Controller to assess the event and adopt the measures and procedures provided for by law.
It should be noted that a data breach is “any security breach that involves the accidental or unlawful destruction, loss, modification, unauthorised disclosure or access to personal data transmitted, stored or otherwise processed“.
The measures adopted by the Data Controller do not exempt the user of the Website from paying the necessary attention, where the use passwords/PINs is required for a specific Website service, choosing passwords/PINs of adequate complexity, and which must be periodically kept update and safeguarded and make inaccessible to others, in order to avoid improper and unauthorised use.
9. What are your privacy rights and how can you exercise them?
In relation to the processing of personal data carried out through the Website, as a data subject, you may at any time exercise the rights provided for by the GDPR; in particular request to:
– access your personal data, obtaining evidence of the purposes pursued by the Data Controller, the categories of data involved, the recipients to whom it may be communicated, the applicable retention period, the existence of automated decision-making processes, including profiling, and, at least in such cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject if not already indicated in the text of this Policy;
– obtain, without undue delay, rectification of any inaccurate personal data concerning you;
in the cases provided for by law, obtain the erasure of your data;
– obtain restriction of processing or object to the same, when admitted on the basis of the legal provisions applicable to the specific case. Be aware that it is always possible to object to any direct marketing actions;
– in the cases provided for by law, obtain portability of the data you have provided to the Data Controller, i.e. receive it in a structured, commonly used and machine-readable format and also request to transmit such data to another data controller, if technically feasible;
In addition, if you deem it appropriate, you may lodge a complaint with the Supervisory Authority (Personal Data Protection Authority).
Please note that for the processing of personal data where consent is the legal basis, you may withdraw it at any time by addressing your request via email to the DPO, or by using, where present on the Website, appropriate means to withdraw/provide consent in relation to specific processing.
For further information concerning your rights and the privacy provisions in general, please visit the website of the Personal Data Protection Authority at https://www.garanteprivacy.it/
Policy published on: May, 2, 2022