Information notice pursuant to art. 13 of regulation (EU) 2016/679 (GDPR)

 

– Website Privacy Policy –

 

This privacy notice is provided by Ognibene Power S.p.A., with registered office in Reggio Emilia, Via Ing. Enzo Ferrari, no. 2, VAT no. 02505200358 (hereinafter the “Data Controller,” “Controller,” or “Company”) to users who access the institutional website (hereinafter the “Data Subjects”).

 

1. Subject of Processing

Through the institutional website, the Controller carries out two distinct types of personal data processing of the Data Subjects:

  • Data collection via the “Contact” form, through which the user can request information by providing the following data: country, first name and surname, company, e-mail, telephone, and any other information deemed useful;
  • Collection of unsolicited applications, by redirecting to the Infinity Platform; in this case, processing is governed by a dedicated privacy notice available in the “Careers” section.

 

Furthermore, technical and identifying data may be automatically collected during website browsing (e.g., IP address, browser type, access time) through cookies or similar tools. For further details, please refer to the Cookie Policy.

 

2. Purpose of Processing

With reference to the contact form, data is processed in order to provide feedback to information requests submitted through the website.
The legal basis for processing is the performance of pre-contractual measures at the request of the Data Subject pursuant to Art. 6, para. 1, lett. b) GDPR.

 

3. Methods of Processing

Personal data is processed through the operations set forth in Art. 4 no. 2) GDPR, namely: collection, recording, consultation, profiling, storage, retrieval, dissemination, communication, erasure, and destruction.
Personal data is processed using electronic tools and, where applicable, in paper format.

 

Data collected through the contact form is stored for no longer than 12 months from receipt, unless further retention is required to manage potential disputes.
Processing will in any case be carried out in accordance with the principles of fairness, lawfulness, and transparency, using tools and procedures designed to avoid the risk of loss, unauthorized access, and unlawful use or disclosure.

 

4. Access to Data

Personal data may be made accessible, for the purposes referred to in Art. 2:
– to employees and collaborators of the Controller, in their capacity as authorized processors;
– to third-party companies or other entities – such as professional firms, consultants, etc. – performing outsourcing activities on behalf of the Controller, in their capacity as Data Processors.

 

5. Data Disclosure

The Controller may disclose personal data to supervisory bodies, judicial authorities, and any entities to whom disclosure is legally required. These entities will process data in their capacity as independent Data Controllers.

 

6. Data Transfer

Personal data is stored in paper archives located at the Company’s headquarters in Reggio Emilia and on servers located within the European Union.
It is understood that the Controller, should it become necessary, may relocate servers and archives outside the EU. In such case, the Controller guarantees that any transfer of data outside the EU will take place in compliance with applicable legal provisions, subject to the execution of the standard contractual clauses issued by the European Commission.

 

7. Nature of Data Provision and Consequences of Refusal

Providing data through the contact form is necessary in order to handle the request. Failure to provide such data will make it impossible to receive a response.

 

8. Data Subjects’ Rights

Data Subjects have the right, within the limits set by the GDPR, to:

  • access their personal data;
  • request rectification or updating of data;
  • obtain erasure of data (in the cases provided for);
  • request restriction of processing;
  • object to processing on legitimate grounds;
  • lodge a complaint with the Data Protection Authority.

 

9. How to Exercise Rights

Rights may be exercised by writing to the Data Controller:
– by registered mail with return receipt to Ognibene Power S.p.A., Via Ing. Enzo Ferrari, no. 2, Reggio Emilia;
– by e-mail to gdpr@ognibene.com;
– by certified e-mail (PEC) to opower@legalmail.it

 

10. Data Processors

The updated list of Data Processors (including the provider of the registration system) is available at the Company’s headquarters and may be requested in writing at the above address.