INFORMATION PURSUANT TO ART. 13 REGULATION 679/2016 (hereinafter “GDPR”)
In compliance with the provisions of current legislation on the protection of personal data, the Fondazione Politecnico di Milano, with headquarters in Piazza Leonardo Da Vinci n. 32, Milan (hereinafter, the “Foundation“), wishes to provide you with the following information about the processing of your personal data. The processing of your personal data will be based on principles of correctness, lawfulness, and transparency, and will be achieved by protecting your privacy, your fundamental rights, and freedoms, in compliance with current legislation on security and protection of personal data. In particular, we inform you of the following:
1. Finality of treatment
The processing of data provided by you to the Foundation such as personal and bank details (where the training or event was for a fee) collected by the same is finalized:
(i) the correct and complete supply of the relationship/contract concerning the training and/or workshop service between you and the Foundation or between the company of which you are an employee and the Foundation.
(ii) the fulfillment of obligations established by law, by regulations or by EU regulations, as well as by instructions given by authorities or bodies authorized to do so.
The provision of data for the purposes described in points (i) and (ii) is necessary and the refusal to supply them would make it impossible for each of the parties to establish or properly manage the service supply relationship and for her to participate in the service. event organized and / or managed and / or promoted by the Foundation also possibly in collaboration with other organizations and institutions.
iii) the promotion and support of activities aimed at spreading innovation and promoting the scientific and educational cooperation of the Politecnico di Milano and of the Foundation itself, by sending an informative newsletter, in fulfillment of the institutional and public interest tasks of the Foundation, as required by its Statute and by the Presidential Decree 24 May 2001 n. 254.
2. Processing methods
The processing of your personal data may include all the operations or series of operations considered by the law as treatment. Data will be processed using paper, computer, and/or telematic means, with logic and forms in compliance with the current provisions that require the adoption of appropriate measures to guarantee an adequate level of security.
Within the structure of the Foundation, data processing will be carried out by authorized persons or data processors designated for this purpose by written deed and must operate within the limits and in compliance with the instructions given by the Foundation.
3. Legal basis of the processing
The legal basis of the processing for the purposes referred to in points (i) and (ii) of paragraph 1) is the execution of the relationship/contract concerning the training service and/or its participation in the Event (workshop, conference, congress, seminar or congress), the need to fulfill legal obligations and fulfillment of institutional and public interest tasks aimed at spreading the knowledge of the scientific and university research and innovation of the Polytechnic and the Foundation as foreseen by its Statute and by the Presidential Decree 24 May 2001 n. 254.
The legal basis of the processing for the purposes referred to in point (iii) of paragraph 1) is to be found in the performance of institutional and public interest tasks aimed at spreading knowledge of the scientific and university research and innovation of the Polytechnic and the Foundation as envisaged by its Statute and by Presidential Decree 24 May 2001 n. 254.
4. Storage times
Your data for the purposes referred to in points (i) and (ii) will be kept for the period of time required by law for contractual and fiscal requirements and in any case not later than 10 years from the termination of the existing relationship/contract between You and the Foundation or between the company of which you are an employee and the Foundation, by reason of the legal prescription of rights, to manage the phases of the contractual relationship and to resolve other issues that may arise (for example concerning any disputes and defense of mutual interests), as well as to fulfill the conservation obligations provided for by the laws including the conservation obligations prescribed in the matter of reporting. In the event of an event that is the beneficiary of public contributions, the data will be kept for the period (infra the “period of necessary preservation”) of 10 years from the date of the necessary reporting to be carried out with respect to the lender and/or that established the notice or financing; or for the different longer retention period that may be imposed by legal or regulatory provisions (the starting date of the period of necessary preservation may, therefore, be later than the date of termination of the contractual or contractual relationship). Your data for the purpose referred to in point (iii) will be processed and stored until the information service is in place: in any case, the Foundation undertakes to periodically and in any case at least annually verify the obsolescence of the data. In any case, you may communicate to the data controller that you no longer wish to receive the communications referred to in point (iii) through the specific “Unsubscribe” link contained in the individual newsletters sent by the Data Controller.
5. Data communication
The corporate personnel of the Foundation may have access to and process their data as an authorized person or data controller for the performance of their duties. Your personal data may also be communicated, for the pursuit and within the limits of the intended purposes, to third parties belonging, by way of example, to the following categories: external collaborators and consultants, subjects operating in training and speakers, to other controlling bodies and structures / subsidiaries / affiliates such as the Politecnico di Milano, the company we hold PoliHub Servizi Srl (certified business incubator), in order to exchange services between the bodies themselves and for internal administrative purposes, based on the legitimate interest in fulfilling contractual obligations and performing institutional tasks of public interest, as well as the payment service company online (such as Pay-pal and similar) and others, always within the European Union, as well as to the company of which you are an employee, based on the legitimate interest of fulfilling contractual obligations: these subjects will process your data in quality of authorized persons, managers or autonomous data controllers. Your data will also be communicated to the subject, company or entity that will operate, with autonomous means, for the purpose of promoting the workshop or the Event or that will be able to manage some phases of the organization of the same, in your own interest or in the interest of the Foundation: this person or company will operate as an independent owner or data controller.
6. Rights of the interested party
In relation to the aforementioned data processing, you may exercise the rights referred to in art. 13 GDPR 679/16 as better expressed in the articles 15-16-17-18-20-21 and 22 GDPR 679/16 and specifically you will be entitled to:
1) obtain confirmation of the existence or not of personal data concerning you, even if not yet recorded, and their communication in intelligible form;
2) ask the data controllers to access personal data, in addition to the right to data portability;
3) obtain the updating and rectification or, when interested, the integration of the data;
4) object, in whole or in part: a) for legitimate reasons to the processing of personal data concerning him, even if pertinent to the purpose of the collection; b) to the processing of personal data concerning him for the purpose of sending institutional communications.
5) obtain the cancellation and transformation into anonymous form or blocking of data processed in violation of the law, including those for which conservation is not necessary for relation to the purposes for which the data were collected or subsequently processed;
6) revoke the consent at any time without jeopardizing the lawfulness of the processing based on the consent given before the revocation, in the cases provided for by the law;
7) to lodge a complaint with a supervisory authority;
8) obtain the attestation that the operations referred to in the superior numbers 4 and 6 have been brought to the knowledge, also with regard to their content, of those to whom the data have been communicated or disseminated, except for the case in which such fulfillment it proves impossible or involves the use of means manifestly disproportionate to the protected right.
The interested party may exercise the above rights by sending a communication: to the Fondazione Politecnico di Milano, located in Piazza Leonardo Da Vinci n. 32, Milan, or by writing to the email email@example.com.
This page sets forth a description of the methods of managing the information contained on the website www.fondazionepolitecnico.it, with reference to the processing of the personal data of users who visit the site. This constitutes disclosure provided also in accordance with European regulation no. 679/2016 (hereinafter, “GDPR”) of legislative decree 196/2003 as subsequently amended and supplemented t- to those who visit the website. The disclosure is given solely for the website in question and not also for other websites that may be visited by the user through the links, with respect to which reference is made to the respective disclosure notices on privacy policies.
THE “CONTROLLER” OF THE DATA PROCESSING
After visiting this website, the data related to persons who are identified or identifiable may be processed. The “controller” of the processing of such data is the Fondazione Politecnico di Milano, with registered office at Piazza Leonardo Da Vinci, 32, Milan (hereinafter, the “Fondazione” or the “Controller”).
PLACE OF THE DATA PROCESSING
The data processing related to the web services of this website take place at the registered office and operating headquarters of the Fondazione, located in Italy, and are handled solely by employees and collaborators authorized to handle data processing or by possible persons delegated to conduct occasional maintenance operations. No navigation data, as better defined above, deriving from the web service is disclosed or disseminated.
TYPES OF DATA PROCESSED AND TIMEFRAME OF PRESERVATION
The IT systems and software procedures used for the operation of this website gather, over the course of their ordinary operation, certain personal data the transmission of which is implicit in the use of internet communication protocols.
This is information that is not gathered in order to be associated with identified interested parties, but that by its nature could, through elaborations and associations with data in the possession of third parties, allow for the identification of the users.
This data category includes the IP addresses or the domain names of the computers used by users who connect to the website, the addresses in notation URI (Uniform Resource Identifier) of the resources requested, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the state of the response given by the server (successful outcome, error, etc.) and other parameters related to the user’s operating system and IT environment.
These data are used solely for purposes of extracting anonymous statistical information on the use of the website and to control the proper functioning of the same, and they are canceled after the elaboration. The data may be used to verify liability in the event of hypothetical cyber crimes committed against the Fondazione Politecnico di Milano and/or against third parties; except for this possibility, at resent the data gathered are kept for the timeframe established under the applicable legal framework or under the University’s rules.
See the long version of the disclosure on cookies: [www.fondazionepolitecnico.it/en/cookies-policy].
Data on curricula vitae sent voluntarily to the dedicated address and/or uploaded through the portal of the Fondazione Politecnico di Milano
The Fondazione takes part in projects and tender procedures/competitions of various types which occur one after the other and with respect to which the candidate selection processes may take place over long periods of time and/or be reopened at irregular and not uniformly pre-established. The personal data set forth in the curricula vitae sent voluntarily to the addresses and forms indicated in the website and/or provided for open positions shall be used solely for purposes of assessing the candidate’s profile and the selection of the same and, if the candidate’s profile is not selected, they will be immediately canceled unless you provide your consent for their entry onto a database of the Fondazione which could later select your profile for participation in a project or tender procedure/competition. If you grant your consent to the entry onto the above-mentioned database, your data will be preserved for 5 years from the moment in which you provided your consent to the processing, subject to the right to revoke such consent at any time. The eventual mailing of sensitive data (related, in particular, to racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership in parties, trade unions, associations or organizations of a religious, philosophical, political or labor-related nature, and personal data capable of revealing the state of health and sexual preferences) gives rise to the immediate cancellation of the data in the absence of a written statement of consent from the relevant person to their processing of such data by the Fondazione. In any case, we ask that you refrain from sending us any document containing your personal data, even if such data is not sensitive in nature if you do not want your data to be processed in accordance with the methods and for the purposes described in this document.
Data provided voluntarily by the user or otherwise gathered by the Controller
Data such as first name, last name and e-mail address and other contact information (mailing addresses and/or telephone numbers) provided by the user shall be used in order to send you an institutional informational notice from the Controller of the processing in the form of a “newsletter”, by traditional mail, e-mail, telephone and using electronic methods (including MMS and SMS, WhatsApp, Instagram, Telegram, WeChat, Viber and social media such as Facebook, LinkedIn, Twitter). Your data will be preserved as long as the information service will remain in place: in any case, the Fondazione undertakes to verify periodically and, in any case, at least once annually, the obsolescence of the data. In any case, you may notify the Controller of the processing that you no longer wish to receive the informational newsletters, through the dedicated link “Unsubscribe” set forth in the individual newsletters sent by the Controller: in such case, your data may be preserved for a maximum of 3motnhs from the cancellation or cessation of the service for administrative reasons.
METHODS AND PURPOSES OF THE PROCESSING
The personal data will be eventually processed by the Fondazione in hard copy format and/or using automatized instruments for the time strictly necessary to achieve the purposes for which they were gathered.
In addition to what is specified for navigation data and cookies that are regulated in the long version of the disclosure, the personal data provided by users are processed for the following purpose:
1) for navigation on the website
2) to answer eventual requests by users and examine CVs sent
3) to enter CVs on the database of the Fondazione
4) for the mailing of informational communications
GRANT OF DATA
In addition to what is specified for navigation data, the cookies are governed as set forth in the long version of the disclosure. The grant of data for the purposes of mailing a request for information and CVs is optional, but the failure to grant such data shall prevent the Controller from answering the requests received and examining the CVs.
The grant of the data for the purposes of mailing and entering CVs on the database is optional and the failure to grant or the failure to consent shall prevent the Controller from entering the data on the database in the event that it is not immediately selected for an open position. The grant of the data for the receipt of newsletters is optional and the failure to grant data shall prevent the Controller from sending you informational notices.
LEGAL BASIS FOR THE PROCESSING AND TIMEFRAME OF PRESERVATION
The legal basis for the processing for navigation referred to in point 1) of paragraph “Methods and purposes of the processing” are to allow for the use of the service and the functions of the website (and, where necessary, the consent), for such purposes, the data are preserved for the timeframe specified above and in the long version of the disclosure on the cookies.
The legal basis for the processing of the data related to point 2) of the paragraph “Methods and purposes of the processing “above are the Controller’s legitimate interest; the data are preserved as better indicated above in the paragraph “Types of data processed” and are canceled within the above-mentioned terms.
The legal basis for the entry of CVs on the database of the Fondazione referred to in point 3) of the paragraph “Methods and purposes of the processing are the consent of the relevant person in question; the data are preserved as better indicated above in the paragraph “Types of data processed” and are canceled within the above-mentioned terms.
The legal basis for the processing for the purposes referred to in point 4) of the paragraph “Methods and purposes of the processing” lie in the performance of institutional duties and duties in the public interest aimed at raising awareness on the scientific and university-based innovation and research of the Politecnico and of the Fondazione as envisaged under the By-laws of the Fondazione and Presidential Decree no. 254 of 24 May 2001: the data are preserved as better indicated above in the paragraph “ Types of data processed” and are canceled within the above-mentioned terms.
RIGHTS OF DATA SUBJECTS
In relation to the above-mentioned processing of data, you may exercise the rights referred to in art. 13 GDPR 679/16 as better expressed in arts. 15-16-17-18-20-21 and 22 GDPR 679/16 and specifically, you will be entitled:
1) to obtain confirmation of the existence or inexistence of personal data concerning you, even if not yet registered, and their communication in an intelligible form;
2) to request the Controller of the processing for access to the personal data and the right to data portability;
3) to obtain an update and correction or, if you should so desire, the supplementation of the data;
4) to oppose, in whole or in part: a) for legitimate reasons, the processing of the personal data concerning you, even if pertaining to the purpose of the data collection; b) the processing of the personal data concerning you for purposes of mailing advertising material or direct sales or for conducting market research or making commercial communications.
5) to obtain the cancellation and transformation to anonymous form or a block on the data processed in breach of the law, including those the preservation of which is not necessary for the purposes for which the data have been gathered or subsequently processed;
6) to revoke the consent at any time without impairing the lawfulness of the data processing based upon the consent granted prior to the revocation, in the cases provided by law;
7) to submit a complaint to a supervisory authority;
8) to obtain certification that the operations referred to in numbers 4 and 6 above have been brought to the attention, also with regard to their contents, to those to whom the data have been disclosed or disseminated, except in the case that the foregoing turns out to be impossible or entail the use of means that are manifestly disproportionate to the right protected.
In any case, you may exercise your rights by sending a request to the Fondazione Politecnico di Milano, with a registered office at Piazza Leonardo Da Vinci, 32, Milan at the following e-mail firstname.lastname@example.org.
As for informational communications, you will have the possibility of revoking your consent to the processing by clicking on the link “unsubscribe” within the communications received.