Pursuant to the Regulation, Autoservice Agreiter Sas shall process Personal Data based on the principles of lawfulness, fairness, transparency, limitation of purpose and retention, data minimisation, accuracy, integrity and confidentiality.
TABLE OF CONTENTS
- Data Controller
- Personal Data subject to processing
- Browsing data
- Special categories of Personal Data
- Data volunteered by Data Subjects
- Purposes of data processing
- Lawful basis and mandatory or optional nature of data processing
- Disclosure of Personal Data
- Transfer of Personal Data
- Retention of Personal Data
- Your rights
1. Data Controller
In relation to the data processing carried out through our website, the Data Controller as defined above is Autoservice Agreiter Sas. For any information regarding the processing of Personal Data by the Data Controller, including the list of Data Processors, please write to the following address: firstname.lastname@example.org
2. Personal Data subject to processing
Please be informed that as a result of website browsing, the Data Controller will collect and process Personal Data that may consist of information like name and surname, identification number, online identifier, mail address, e-mail address, landline and/or mobile telephone number or information on one or more physical, physiological, psychological, financial, cultural or social features relating to an identified or identifiable person (hereafter “Personal Data”).
The following Personal Data is processed through our website:
a. Browsing data
During normal operation, the computer systems and software used to operate our website acquire some Personal Data. The transmission of which is implicit in the internet communication protocols. The collection of this information is intended to be associated with identified parties; however, the data collected might by its nature allow users to be identified through processing and association with data held by third parties. This category of data includes IP addresses or domain names of computers used by users who connect to the website, URI (Uniform Resource Identifier) of requested resources, the time of request and method used to submit it to the server, the size of the file obtained in reply, the numerical code indicating the server response status (successful, error, etc.) and other parameters relating to the user's operating system and IT environment. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the website and to ensure its correct functioning by identifying any anomalies and/or abuses, and are therefore deleted immediately after processing. The data could be used to ascertain responsibility in the event of possible computer crimes against the website or third parties; except for this possibility, the data collected from the website is removed within a short period of time.
b. Special categories of Personal Data
If you send us your application via e-mail or through our website, you might provide us with Personal Data that falls within special categories as set forth in art. 9 of the Regulation, namely: “[…] personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and [...] genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation”. Please do not disclose this type of data unless it is strictly necessary. Please be informed that if you do choose to provide this type of data without giving your specific consent to the processing (e.g. by sending a CV), the processing on our part will relate to data made manifestly public by the Data Subject, as provided for by art. 9(1)(e) of the Regulation. Therefore, the Data Controller will be released from any liability or dispute whatsoever in connection with the processing of such data. As previously mentioned, explicit consent to the processing of special categories of Personal Data is fundamental if you do choose to disclose such information.
Please be also informed that the Data Controller may view any social media profiles made openly available on professional networking sites or platforms (e.g. LinkedIn).
c. Data volunteered by Data Subjects
We may process Personal Data of third parties that you send to the Data Controller when using certain services on our website (e.g. the request/contact/booking forms). In these cases, you act as independent Data Controller, thereby assuming all the obligations and liabilities set by law. In this sense, you release the Data Controller from any and all responsibilities and obligations with respect to any dispute, claim, compensation for damages etc. that may be received from third parties whose Personal Data has been processed through the website functions in violation of applicable data protection laws. In any case, if you provide or process Personal Data of third parties while using our website, you warrant – assuming full liability – that processing has a lawful basis in compliance with art. 6 of the Regulation.
3. Purposes of data processing
If necessary and with your specific consent, we will process your Personal Data for the following purposes:
a. Provide the services you require;
b. Respond to requests for assistance, information or bookings;
c. View CVs and contact applicants;
d. Comply with legal and tax obligations;
e. Marketing purposes: the data provided may be used, subject to explicit and specific consent, for the sending of promotional and marketing communications, including newsletters and market surveys, using automated tools (SMS, MMS, e-mails, push notifications) and non-automated tools (paper mail, telephone calls by operators). The lawful basis for the processing of your data for these purposes is art. 6, paragraph 1, letter a) of the Regulation. The processing of data for direct marketing is optional and based exclusively on your free choice, and denying your consent for this purpose will not affect the use of services on your part.
f. Commercial profiling purposes: the data provided may be used, subject to explicit and specific consent, for purposes of commercial profiling and creation of personalised offers, based on purchases made and/or browsing behaviour and/or other consumer’s data and/or data provided at the time of registration on our website and/or responses to market surveys. The processing of data for commercial profiling is optional and based exclusively on your free choice, and denying your consent for this purpose will not affect the use of services on your part.
4. Lawful basis and mandatory or optional nature of data processing
The lawful basis for the processing of Personal Data for the purposes referred to in section 3 (a-b-c) is art. 6(1)(b) of the Regulation (performance of a contract) as the data is necessary to provide the services required and/or to respond to requests from the interested party. Giving your Personal Data for these purposes is optional, but indispensable to activate the services provided by the website, to answer requests or evaluate CVs. With specific reference to the purpose 3.c and the viewing of profiles on professional networking platforms made freely available on the internet, as mentioned in section 2.b, the lawful basis is art. 6(1)(f) of the Regulation, i.e. the legitimate interest of the holder in verifying the candidate’s suitability for the open position and any potential risks.
For the purposes illustrated in section 3.d, the lawful basis is art. 6(1)(c) of the Regulation (compliance with legal obligations). Once provided, Personal Data must be processed for the Data Controller to comply with legal obligations.
Art. 6(1)(a) of the Regulation (your consent) is the lawful basis for the processing of data for the purposes referred to in section 3.e. In this respect, activities that involve the direct sending of advertising material, direct sales or market surveys and commercial communications in relation to products or services similar to those you purchased, the Data Controller may use your e-mail and mail addresses without your consent, in accordance with and within the limits allowed by art. 130, paragraph 4 of the Italian Data Protection Code and the by the Decision of the Italian Data Protection Authority of 19 June 2008. The lawful basis for the processing of your data for this purpose is Art. 6(1)(f) of the Regulation (legitimate interest).
For the purposes listed in section 3.f, the lawful basis is art. 6(1)(a) (consent).
5. Disclosure of Personal Data
For the purposes listed in section 3, your Personal Data may be shared with:
a. Parties who typically act as Data Processors, namely: i) persons and/or organisations providing us assistance and counselling services on marketing and communication; ii) persons and/or organisations who assist us in providing certain services (e.g. hosting providers) iii) persons and/or organisations who perform technical maintenance activities (including maintenance of network equipment and electronic communication networks); (collectively, “Recipients”);
b. Persons, entities or authorities to whom Personal Data must be disclosed by virtue of legal provisions or orders given by a competent authority;
c. Parties authorised by the Data Controller to perform activities that are strictly related to the provision of services or for the purposes listed in section 3, who have committed themselves to confidentiality or have legal obligation to confidentiality (e.g. employees).
6. Transfer of Personal Data
Some of your Personal Data is shared with Recipients who may be located outside the European Economic Area. The Data Controller ensures that these Recipients process your Personal Data in compliance with the Regulation. Transfer of Personal Data may be based on an adequacy decision, on Standard Contractual Clauses approved by the European Commission or on another appropriate legal basis. For further information please contact the Data Controller by sending an e-mail to: email@example.com
7. Retention of Personal Data
Personal Data processed for the purposes referred to in section 3(a-b) will be kept only for as long as strictly necessary to achieve those purposes. In any case, since data is used in order to provide services, the Data Controller will process the Personal Data up to the time allowed by Italian law (art. 2946 of the Italian Civil Code and subsequent amendments). With regard to any CVs submitted through the Website or by e-mail (see section 3.c), the Personal Data will be kept for as long as necessary for the purpose. The Data Controller may contact the candidate again shortly before the indicated deadline to ask for an extension of the retention period.
Personal Data processed for the purposes referred to in section 3(d) will be stored for as long as provided for by applicable laws and regulations.
Personal Data processed for the purposes referred to in section 3(e) and 3(f) will be kept until we have consent; if you do not withdraw your consent, your data will be stored for a time deemed appropriate.
For more information on our data retention policy and criteria, please contact: firstname.lastname@example.org
8. Your rights
Pursuant to Art. 15 and following of the Regulation, you have the right to obtain access to your Personal Data at any time. You have the right to request from the Data Controller rectification or erasure of your data, as well as to object to and restrict processing of your data in the cases provided for by Art. 18 of the Regulation. You have the right to obtain the Personal Data concerning you in a structured, commonly used and machine-readable format in compliance with Art. 20 of the Regulation.
Requests must be submitted in written form and sent at: email@example.com
In any case, you also have the right to lodge a complaint with the competent Supervisory Authority (Italian Data Protection Authority) if you consider that the processing of your Personal Data infringes the applicable law, pursuant to Art. 77 of the Regulation.
What are cookies?
A „Cookie“ is a small test that is sent to the computer for identification on the browser used by the user or to save informations and settings in the browser, deactivating the request settings on your browser. Taking these steps, there can be the risk that you don’t have access to most websites or they are not even functioning anymore.
The site and relevant sub domains using the following cookies:
Navigation Cookie: They are indispensible for the navigation and usage from a website; without this cookie there can be the risk that you don’t have access to most websites or they are not even functioning anymore.
Functionality Cookies: Saving your settings, these cookies increase the functionality of the website. They include settings that you have chosen (for example, username or language) and improve the usage of the website.
Performance Cookie: They are coming from us or third parties. The informations that are saved by these cookies are anonym and are not individually from one person and are not used for marketing purposes.
Cookies marketing and targeting purposes: third parties are using them for advertising purposes. No personal data is being exchanged, but it will still create a connection with your computer or device, so it can follow the saved information.
How to block cookies in your browser settings:
1. Click “Extras” on the menu and select “internet settings”.
2. Select the “Privacy” panel.
3. To set what types of cookies are blocked or allowed, move the slider. Generally, if the slider is all the way up, all cookies are blocked; if the slider is down, all cookies are allowed.
4. Click “OK“ to conclude the action.
More information: https://support.microsoft.com/it-it/help/17442/windows-internet-explorer-delete-manage-cookies
1. Go to Menu and then to “Options”.
2. Select the “Privacy” panel.
3. Set Firefox will to: Use custom settings for history.
4. Remove the check mark from “Accept cookies from sites”.
5. Click “OK” to close the “Options” window.
1. Click the Chrome menu on the browser toolbar and go to “Settings”.
2. Select „Show advanced settings“.
3. In the "Privacy" section, click the Content settings button.
4. In the "Cookies" section, select "Block sites from saving any data".
5. Click “OK” to conclude the action.
1. Choose Safari Preferences, and then click on “Privacy”.
2. In the “Block cookies” section, specify if and when Safari should accept cookies from websites.
3. To see an explanation of the options, click the “Help” button (question mark).
4. For more information on the cookies that are being saved on your computer, click on “Show cookies”
The table below lists i cookie used from the site and explains his finality and deadline:
_ga, 2 years, This cookie is used to distinguish the users.
_gat, 2 years, This cookie limits the sent requests.
_gid, 1 day, This third party cookie Google Analytics is used for monitoring purposes from the requirement rate on the servers at the company. With this cookie you can find out, in which areas of the website improvement is needed. The cookie _gid does not offer personal identification from users, because there can’t be used personal data.
_unam, 9 months, This cookie is used as a part of the ShareThis service and is monitoring the „Click-Stream“ activity, for example, websites seen and navigated on, the time spent on the sites. The ShareThis service is only identifying you personally, when you have registered yourself separately with an account on ShareThis and you have given them your consent.
_stid, 1 year, Social Media Sharing
__utma, This from Google Analytics created third party cookie is used to separate users and sessions; it also creates statistics about the traffic on the website.
__utmt, This from Google Analytics created third party cookie helps the processing from user accesses; it also creates statistics about the traffic on the website.
__utmb, This from Google Analytics created first party cookie helps the determination from new opened sessions; it also creates statistics about the traffic on the website.
__utmc, This from Google Analytics created first party cookie is configurated to be interoperabile with urchin.js. At first this cookie has decided in interaction with __utmb, if the user is in a new session at the moment or if he has called a new site.
__utmz, This from Google Analytics created first party cookie is used to identify the traffic source or the campagne, that shows, how the user has ended on this site.
__utmv, This from Google Analytics powered first party cookie is used to save variable data on visitors level and creates statistics about the traffic on the website.
_icl_current_language, This cookie saves a spoke worth for the website. As long as the cookie is positionated as a answer on a user action and aslong as the action has a short deadline, it can be shown as absolutely necessary.
wpml_referer_url, This cookie saves a spoke worth for the website. As long as the cookie is positionated as a answer on a user action and aslong as the action has a short deadline, it can be shown as absolutely necessary.
Cookie_Policy_Accepted_*, This first party cookie is set from our website to mark the consent of the user for using the cookies while showing the website. Because of that the cookie banner gets blocked all the time when the user is calling up our website. That cookie does not save any personal data.
PHPSESSID, This cookie is a reference on a unique session ID, that was picked by our website code for a current browser session. This cookie does not save any personal data. The session ends when the browser gets closed by the user.
c_user, 3 months, .facebook.com
Datr, 2 years, .facebook.com
Dpr, 5 days, .facebook.com
fe_typo_user, 0 sessions, necessary to use the site with all of his functionalities.
Fr, 3 months, .facebook.com
mobile_detected, 0 sessions, .holidaycheck.com
pl, 2 months, .facebook.com
sb, 2 years, .facebook.com
wd, 5 days, .facebook.com
xs, 3 months, .facebook.com
Webtracking – Google Analytics:
You can block cookies with a corresponding setting in your browser software; however, in this case and where applicable, you may not be able to use all website functions. Furthermore, you can prevent Google from capturing data related to your website usage (incl. your IP address) with the help of the cookies and from processing this data, if you download and install the available browser plugin on this link https://tools.google.com/dlpage/gaoptout?hl=en-GB.
Here you find general information about Google Analytics and safeguarding your data: https://support.google.com/analytics/answer/6004245?hl=en
By using this website you agree to the processing of the collected data by Google and/or other web analytics service providers in the above described way and mentioned purpose.
Using Social Plugins
Social Plugins are integrated on these websites via the so-called “2 click solution”. According to standard, these buttons do not transmit data to third parties. The user manually activates the transmission of his/her data to the respective social network operator and to the installation of third party cookies. However, this only applies to this one site and to the selected service. Via the “cog wheel” icon, the user can save respective preferences and change them anytime.
Should you activate the Social Plugins, please read the following explanations about their function and about which data is transmitted.