PRIVACY POLICY
Marvincla S.r.l. (hereinafter also referred to as “the Company”), in its capacity as Data Controller of personal data (hereinafter, “Data Controller”), pursuant to EU Regulation 2016/679 (hereinafter: “Regulation”), considers the protection of Personal Data to be one of the main objectives of its business.
Therefore, before providing any personal data to the Data Controller, we invite you to carefully read this Privacy Policy.
“Personal Data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
This document refers to the processing of data carried out in the course of the company’s institutional activities and is addressed to those who, although not data subjects themselves, interact with the Controller's activity in other capacities, such as independent controllers, external processors, or joint controllers.
The Data Controller can be contacted at the following email address: [email protected]
This document aims to disclose the company's privacy policy and to explain how personal data of data subjects is processed by the company, in compliance with the GDPR 2016/679.
In accordance with the provisions of the Regulation, data processing by the Company is based on the principles of lawfulness, fairness, transparency, purpose and storage limitation, data minimization, accuracy, integrity, and confidentiality.
Data Controller
The Data Controller is Marvincla S.r.l., represented by its legal representative pro tempore, with registered office in Bari, Via Giuseppe Semerari 7/c.
Personal Data Processed
The company processes the following personal data:
- Contact and fiscal data of clients, to enable communication or to perform the terms of signed contracts;
- Personal data of employees and collaborators of the company.
Purpose of Data Processing
The data processing carried out by the Company may have the following purposes:
- To enable the provision of services offered by the company;
- In relation to the company’s website:
- Registration on the website;
- Subscription to the newsletter via email;
- Sharing of content on the website;
- General information requests;
- Registration for events and initiatives;
- Possibility of being contacted again;
- Use and delivery of services offered by the company.
Legal Basis and Nature of Data Provision
Depending on the specific purposes of processing, the legal basis may be one or more of the following:
- Consent of the data subject;
- Performance of a contract;
- Fulfillment of legal obligations.
Recipients of Personal Data
Personal Data may be shared, for the purposes stated above, with:
- a. Entities typically acting as data processors under Article 28 of the Regulation, such as:
- Individuals, companies, or professional firms providing assistance and consultancy to the Company;
- Entities with whom it is necessary to interact to carry out the company’s institutional activities;
- Entities authorized to perform technical maintenance (including maintenance of network equipment and electronic communication networks).
- b. Entities, authorities, or organizations acting as independent data controllers, to whom data must be communicated by law or under authority orders.
- c. Individuals specifically authorized by the company (e.g., employees and collaborators).
Data Retention
Personal Data processed for the purposes mentioned above will be stored for the time strictly necessary to fulfill those purposes, in accordance with the principles of data minimization and storage limitation as per Article 5.1(e) of the Regulation.
In any case, the Data Controller will process the Personal Data for the time required to comply with contractual and legal obligations, and to ensure the protection of company rights and those of employees/collaborators.
Anonymous or anonymized data may be processed indefinitely.
More information regarding the data retention period and the criteria used to determine it can be requested by writing to the email address provided above.
Data Transfer Outside the EEA
No data transfers are made to or from countries outside the European Economic Area.
Data Subject Rights
The company guarantees the exercise of the data subjects’ rights, where applicable and in relation to non-anonymized data, pursuant to Articles 15 et seq. of the Regulation, such as:
- Right of access to personal data;
- Right to rectification or erasure;
- Right to restriction of processing in the cases provided for by Article 18;
- Right to data portability as provided by Article 20;
- Right to object and to withdraw consent;
- Right to lodge a complaint with the competent supervisory authority pursuant to Article 77 of the Regulation (Garante per la Protezione dei Dati Personali).
Changes to the Privacy Policy
The Company reserves the right to amend or update this Privacy Policy, in whole or in part, due to changes in applicable legislation or internal policies.