WEBSITE AND COOKIE NOTICE PURSUANT TO THE GENERAL DATA PROTECTION REGULATION (GDPR) NO. 679/2016
Avid Technology S.r.l.
Palazzo T2 Strada 7- Milanofiori – 20089 Rozzano (Mi)
This privacy notice aims to inform visitors of the ation.it website (hereinafter “User” and “Data Subject”) about the management methods regarding the processing of their personal data, as prescribed by Articles 13 and 14 of EU Regulation no. 2016/679 (hereinafter, General Data Protection Regulation, “GDPR”) and current legislation. The contents of this Notice are:
Table of Contents:
- INTRODUCTION
- DATA CONTROLLER
- COLLECTION OF PERSONAL DATA AND LEGAL BASES
- PURPOSES OF PROCESSING
- SECURITY OF PERSONAL DATA
- DATA RETENTION PERIOD
- INTERNATIONAL DATA TRANSFER
- SHARING OF PERSONAL DATA
- OBLIGATION TO PROVIDE DATA AND POSSIBLE CONSEQUENCES OF REFUSAL
- TYPES OF PERSONAL DATA COLLECTED
- DATA PROTECTION OFFICER
- DATA PROTECTION RIGHTS
- CHANGES TO THE PRIVACY POLICY
- CANCELLATIONS, OBJECTIONS AND RECTIFICATIONS
- INFORMATION ON THE PRIVACY POLICY
- INTRODUCTION The protection of personal data is an opportunity for shared and transparent compliance between Avid Technology Srl (hereinafter, also “Company”) and the User who entrusts their personal data to it. It is the task of Avid Technology Srl, in fact, to protect them, preserve them from any damage, store them, and dispose of them according to the processing guidelines related to the ongoing relationship with the User. “Personal data” – also known as PII, Personally Identifiable Information – refers to demographic data, in case of registration for service requests, and identification data of navigation data on the site in application of control, security, and data analytics systems.
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- DATA CONTROLLER Avid Technology Srl is the Data Controller of personal data and can be contacted at the following email address simona.palmisano@avid.it or phone number 025778971, or by writing to the following address: Avid Technology S.r.l. Palazzo T2 Strada 7 Milanofiori 20089 Rozzano (MI) The Data Controller decides on the purposes and methods of processing personal data, as well as their security and the tools used.
- COLLECTION OF PERSONAL DATA AND LEGAL BASES The Data Controller processes the User’s personal data if at least one of the following conditions exists:
- the User has given consent to the processing for one or more purposes.
- the processing is necessary for the provision of services, therefore for the execution of a contract with the User.
- the processing is necessary to comply with a legal obligation to which the Data Controller is subject.
The avid-italia.myshopify.com website collects user data in the following ways:
- data collected in automated form, i.e., data indirectly transmitted by the User when browsing the site and thus leaving digital traces of their passage (IP, browser, network provider name) which are recorded by the servers primarily for security, control, and data analysis reasons.
- data provided on a voluntary and optional basis, i.e., data directly transmitted by the User with the intention of registering on the site and its services.
Avid Technology Srl guarantees that the collected data are also pertinent and not excessive, so that this process occurs lawfully and correctly, i.e., for explicit and legitimate processing purposes. Data processing occurs with both paper and IT tools and supports, both respecting security, storage, and accessibility criteria and procedures, within the strict scope of the stated purposes. The legal basis for processing is the consent expressed by the data subject to the processing of their personal data for one or more specific purposes highlighted in this Notice. Furthermore, the Data Controller may exercise a legitimate interest to defend its rights in court in cases of complaints or disputes with the Data Subject. Avid Technology addresses a target audience that inseparably possesses legal, fiscal, and contractual capacity, therefore minors are excluded.
- PURPOSES OF PROCESSING User data is collected by the website for the following purposes:
- to contact the User.
- to present and promote the Company’s activities.
- to promote website services and offers by sending commercial messages.
- to develop personalized services based on User needs.
- to manage subscription and sending of the site’s newsletter, and other information services.
- to enable interaction with social platforms, blogs, and forums.
- to promote participation in events and initiatives.
- to collect user opinions on service satisfaction.
- to perform statistical analyses on navigation data.
- to facilitate communication and exchange of experiences with users.
- to provide service assistance.
- to collect user feedback to improve the site.
- to inform authorities about any frauds, illegalities, and incorrect behaviors.
- to comply with legal obligations.
- SECURITY OF PERSONAL DATA Avid Technology Srl processes personal data with scrupulous attention and precisely for this reason adopts security and protection measures in strict observance of the GDPR and in line with ISO 9001 and ISO 27001 standards. Furthermore, Avid Technology Srl implements valid and appropriate practices and techniques aimed at guaranteeing in all processing processes the following conditions:
- confidentiality, i.e., the protection from unauthorized access.
- integrity, to prevent loss or damage.
- availability, to ensure continuous access to their data for the User.
Even when information is transferred to trusted third parties, and for the purposes indicated in this Notice, it is the Company’s care and attention to ensure that they similarly adopt security, technical, and operational measures, according to the same criteria exposed above.
- DATA RETENTION PERIOD Data is processed and stored for the time necessary to carry out the services, and related processing, according to the purposes described in this document. For all other purposes related to legal obligations, data retention provides for a period of time that does not exceed what is necessary and required for the fulfillment of such obligations. The retention period of personal data and company information, therefore, is determined based on these criteria:
- nature and purpose of data processing.
- regulatory compliance.
- any disputes on complaints.
- management of services connected to the site.
At the expiry of all foreseen terms, the User’s data will be deleted and destroyed according to adequate technical procedures and in accordance with “best practices” of Information Security.
- INTERNATIONAL DATA TRANSFER Currently, Avid Technology Srl does not perform any international data transfer to Third Countries outside the European Union. In view of continuous changes and business expansion beyond European borders, it may happen that company processes, followed by Users’ personal data, may also be subject to transfers to third-party providers in other non-EU countries. Consequently, User data could in the future be shared and/or transferred to third-party providers in these countries. Should international data transfer occur, it would comply with the legitimacy requirements set out in the articles of the aforementioned Regulation, current privacy laws, and the procedures governing the transfer itself. In this case, the Data Controller respects the described conditions (Transfers of personal data to third countries or international organizations – Arts. 44, 45, 46, 47, 48, 49, 50), without prejudice to other provisions of this Regulation. All provisions of this chapter will be applied to ensure that the level of protection of natural persons guaranteed by the GDPR Regulation is not prejudiced.
- SHARING OF PERSONAL DATA The data subject’s personal data will not be shared with other parties except in cases where it is obligatory, otherwise consent is optional, explicit, and voluntary. Access to data may occur by certain internal processing personnel within the organization for all operations necessary for administrative, managerial purposes, and for the provision of internal services: this includes personnel from Avid Technology S.r.l. areas such as administration, human resources, legal affairs, and information systems. The same may occur by certain external parties, such as service providers, acting as Data Processors. The Data Controller guarantees the training of all those who, within the organization, access data under its authority in accordance with the specific processing in question. For third parties designated as Data Processors, Avid Technology Srl follows the GDPR rules on the matter, ensuring that they are compliant and adequate to current regulations.
- OBLIGATION TO PROVIDE DATA AND POSSIBLE CONSEQUENCES OF REFUSAL During browsing and use of the site’s services, the User may choose whether or not to provide their personal data by giving consent. Any total or partial refusal would compromise the correct execution of activities connected to the provision of Internet site services, and this would make it impossible to provide such services.
- TYPES OF PERSONAL DATA COLLECTED Regarding data collected in automated form, these are information recorded on the site’s servers and stored in “log files,” in detail:
- IP, “Internet Protocol” address.
- parameters of the device used to connect to the site (PC, tablet, smartphone).
- anonymous traceability of consulted pages and clicks made.
- name of the internet service provider (ISP).
- browser type.
- date and time of start and end of browsing.
- references to the referring web page (referral) and the exit page.
- cookie registration (for details, see the “Cookie Policy – Extended Cookie Information” notice).
The collected data are used in aggregated form, and for statistical purposes only, to allow the Company to carry out market analyses related to site management and development strategies. The IP address, which identifies the device connected to the internet, is processed for security purposes, excluding aggregations with other data that could identify the User. Regarding data provided on a voluntary and optional basis, the site User can request contact to receive informative material by providing their personal data and consent to processing. This processing is necessary for the provision of services offered by the site, and occurs through the use of forms or registration forms filled out by the User in which they themselves enter their personal and identification data, including their email account and other contact details.
- DATA PROTECTION OFFICER The Data Controller has not appointed a Data Protection Officer (DPO).
- DATA PROTECTION RIGHTS It is the Data Subject’s right (Art. 15 GDPR) to know the existence of their personal data collected and processed by the Data Controller, therefore to know its content and origin, verify its accuracy and possibly modify it, integrate it with other information, request its erasure or transformation into anonymous form, block its use in case of presumed legal violation or even definitively object to processing. All requests for information and any complaints can be directed to the Data Controller at the addresses disclosed in this Notice.
- CHANGES TO THE PRIVACY POLICY This Notice is subject to possible modifications and updates in order to incorporate changes in national and/or community legislation, or to adapt to technological innovations or for organizational reasons of Avid Technology Srl. Avid Technology Srl will be diligent to inform the User by sending communications using available company communication tools or by promptly updating this notice and the site’s interaction tools (registration forms, cookie consent software, extended cookie information, etc.). Changes, like the current one due to adaptation to the new GDPR code, will continue to apply the rules in force unless the data subject is unfavorable to the proposed changes and requests the cessation of processing and consequent deletion of their data. The User must, however, independently and periodically verify the update status of this Notice, and in any case consult it every time they are informed of changes made.
- CANCELLATIONS, OBJECTIONS AND RECTIFICATIONS At any time, the User can request rectification, total or partial objection, and revocation of the processing of their data, and, if applicable, obtain its erasure. After the retention periods indicated above, the User’s personal data will in any case be erased and destroyed through adequate technical procedures. The cases for deletion are therefore the following:
- personal data are no longer necessary following the cessation of the relationship with the Data Controller.
- the data subject performs a revocation.
- the data subject objects to the processing.
- retention periods have expired.
Pursuant to Arts. 13 and 14 of the GDPR, the Data Subject has the right to lodge a complaint with a supervisory authority.
- INFORMATION ON THE PRIVACY POLICY The Data Controller is responsible for this Privacy Policy. Last revision date is 30/10/2018.