INFORMATION CONCERNING THE PROCESSING OF PERSONAL DATA
According to the D. Lgs. 196/2003, adjusted by the D. Lgs. 101/2018 to the GDPR 679/16 EU (Articles 13, 14)

DATA CONTROLLER

Thema S.r.l.
Via Saragat, 5 40026 Imola (Bo) – ITALY – VAT No. 02770361208
Telephone +39 0542 643496 Email: info@thema-med.com;

FINALITY OF DATA PROCESSING

1. Purposes of operating marketing

Subject to free, separate, specific consent and informed, for the supply of goods and services, through the sending of remote communications, also in newsletter mode, without prejudice to the possibility of withdrawal of consent through appropriate indication at the end of each communication or by e-mail;

PERSONAL DATA PROCESSING METHODS

  1. Data shall be processed in accordance with the principles of lawfulness, correctness and    transparency respecting the privacy, dignity and rights of interested parties;

  2. Data shall be processed, in accordance with the principles of necessity and proportionality by authorized entities appropriately trained within the structure;

  3. External entities authorized to process data are configured as joint controllers, managers, designated or authorised according to the type and mode of access. The requirements of such entities shall be verified in advance and the implementation of the necessary and appropriate technical organizational measures shall be regularly monitored;

  4. The Data Controller collects data limited to the purposes described in this policy.

LEGAL BASES FOR THE PROCESSING OF PERSONAL DATA

The processing of personal data is based on specific legal bases provided by the GDPR 679/16 EU detailed below:

1. For the purposes described in this policy, data are processed on the basis of prior, free, separate, specific and informed consent, without prejudice to the possibility of withdrawal of consent through appropriate indication at the end of each communication or by exercising their rights to the contact details of the Data Controller;

NATURE OF DATA PROVISION

1. For the purposes described, the nature of the provision of data and consent to their processing is mandatory. In their absence, it would not be possible for the Data Controller to carry out direct marketing operations, including sending newsletters;

INFORMATION COLLECTED BY THE DATA CONTROLLER

The information collected is described below:

  1. Identification data including any IDs allocated during registration;

  2. Contact data;

  3. Contact details;

  4. Preferences and interests regarding the information provided by the data controller;

RECIPIENTS OF THE INFORMATION

  1. Data may be transferred to third parties belonging to the categories described below, identified in advance on the basis of requirements for compliance with appropriate safety measures and operating as independent Data Controller, Joint Controllers or Data Processors:
    • Consultants and company collaborators for the provision of marketing and commercial services;
    • Consultants and company collaborators for the management of websites and IT applications for corporate and inter-company communication

TRANSFER OF INFORMATION OUTSIDE THE EU

1. Personal data are not subject to transfer to foreign countries of the European Union or outside the EU.
Any eventual transfer would take place in compliance with Articles 45, 46 of the GDPR 679/16 EU.

STORAGE OF PERSONAL DATA

1. Data are kept for the duration of the consent, without prejudice to the rights of the data subject, with particular reference to the right to withdrawal consent, described below;

CHANGE OF THE CONSENT OPTIONS

1. The information processed under the provision of consent provides for the possibility of revocation at any time by contacting the contact details indicated in this policy at the e-mail address info@thema-med.com;

RIGHTS OF THE DATA SUBJECT

  1. The rights of the data subject (art. from 15 to 22) provide for the possibility to:
    • a) Ask the Data Controller for access to personal data and to information concerning the purposes of the processing, to the categories of personal data processed, to the recipients or categories of recipients to whom the data are communicated and access to the data retention period;
    • b) Ask the Data Controller the rectification of personal data;
    • c) Ask the Data Controller the erasure of personal data;
    • d) Ask the Data Controller the limitation of the processing of personal data;
    • e) Ask the Data Controller the portability of personal data;
    • f) Object to the processing of personal data in the cases provided for;
    • g) Object to automated decision-making processes related to personal data, including profiling;
    • h) Exercise withdrawal of consent to the processing of personal data in the cases provided for;
    • i) Lodging a complaint with a supervisory authority.

The detailed description of the rights of the data subject can be consulted on the Regulation for the protection of personal data GDPR 679/16 EU Art. from 15 to 22.