PRIVACY POLICY

for the Processing of Personal Data ex art. 13 EU Regulation 2016/679

* * *

WHO WILL PROCESS THE PERSONAL DATA ?

The Website https://disclosers.it  is managed by YOUR STORY S.R.L. - P.IVA 10588070960, with registered office in Paderno Dugnano (MI), via Claudio Treves 5/7 and operational office in Milan, via Alberico Albricci 9, peo  info@disclosers.it, pec yourstory@legalmail.it

As the Data Controller of the personal data acquired here.

The Data Controller considers the protection of the personal data of its Users (also referred to as "Data Subjects") to be of paramount importance and ensures that the processing thereof will be carried out in full compliance with the European Data Protection Regulation No. 2016/679 (General Data Protection Regulation, hereinafter "GDPR") and further applicable regulations in this regard.

What is meant by "personal data"? The GDPR provides a very broad concept, referring to "any information concerning an identified or identifiable natural person; an identifiable person is any natural person who can be identified, directly or indirectly, with particular reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more features of his or her physical, physiological, genetic, mental, economic, cultural or social identity" (hereinafter the "Personal Data").

What is meant by "processing of personal data"? Again, the GDPR refers to a very broad concept that covers "any operation or set of operations, whether or not involving automated processes, applied to personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, comparison or interconnection, restriction, erasure or destruction" (hereinafter the "Treatment").

The GDPR requires the Data Controller to provide Data Subjects with a whole range of important information, including, the reasons why the relevant Personal Data is processed, how it will be used, to whom it may be intended and for how long it will be stored, as well as the rights of Users. For this reason, this privacy policy ("Policy") is intended to provide the User, in a simple and transparent manner, with all the useful and necessary information so that he/she can give his/her Personal Data in an informed manner, requesting and obtaining, at any time, clarifications and/or rectifications of the Processing. 

This Policy relates solely to the processing of data communicated by the User or otherwise obtained as a result of using the website with URL https://www.disclosers.it/. The Policy is made only for this Site and not also for other websites that may be consulted by the User through links.

 

WHAT PERSONAL DATA ARE PROCESSED?

The Holder may collect the Personal Data provided by Users of the site, including:

  • master and contact information sent through the form found in the "Contact" section (name, email and message);
  • the data provided in the "Training" section for the purpose of registration on the site in order to obtain information about the courses provided and to register for them (email, full address, C.F/P.Iva, Univoco/Pec Code);
  • bank details in the case of purchasing courses online (cardholder name and number);
  • the data provided in the event of a request for information, through e-mails and/or during calls made to the Holder's contacts;
  • biographical, contact and any other personal data communicated through the emailing of a resume;
  • the information that may have been eventually and voluntarily disclosed or posted on our social pages (Linkedin, Facebook, Instagram, Twitter);

The Controller may also collect additional data, such as the navigation data: The computer systems and software procedures used to operate the Site acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected in order to be associated with identified interested parties, but which by its very nature could, through processing and association with data held by third parties, make it possible to identify Users (e.g. IP addresses, domain names of computers used by Users who connect to the Site, browser used and its version, time of request, size of information flows, etc.). This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Site, to check its correct functioning, to ensure that it is updated and secure, to provide Users with a user-friendly browsing experience and, in any case, to identify anomalies and/or abuses. 

The above data are processed only to the extent necessary to achieve the purposes described in the following section of this Notice.

In relation to data collected through cookies, including those related to plugins and/or buttons linking to the Owner's social network pages, see the Cookies Policy.

 

WHAT IS THE PURPOSE AND LEGAL BASIS OF PERSONAL DATA PROCESSING ?

The Controller will process Users' Personal Data for:

a) "Pre-contractual/contractual purposes": respond to requests submitted, take advantage of the services made available by the Owner including by purchasing through the Site (online courses), including customer support services and technical assistance during or after purchases made, as well as allowing browsing on the Site itself - Legal basis: Art. 6, co. 1(b) GDPR. It should be noted that the subjects appointed by the Owner to perform maintenance of the Site may accidentally have access to personal data present on the Owner's computer systems: these are entirely occasional and unforeseeable events, in any case devoid of any purpose of identification of the User and of a duration limited to the performance of the maintenance work - Legal basis: Art. 6, co. 1(f) GDPR;

b) "Purposes of ascertaining, exercising and/or defending rights": personal data acquired through this Site may be necessary to assert and protect the Holder's rights of defense in any competent forum - Legal basis: Art. 6, co. 1(f) GDPR;

c) "Purposes of the law": Personal data acquired through this Site may be used for the purpose of fulfilling legal (in case of course purchase) and regulatory obligations, as well as to give effect to legitimate requests (e.g., requests for access to or transmission of information) from Authorities and authorized parties - Legal basis: Art. 6, co. 1(c) GDPR;

d) "Pre-contractual purpose of relationship establishment and CV management": personal data contained in CVs possibly and spontaneously sent by the User to the Holder's email will be processed solely for the purpose of evaluating the application - Legal basis: Art. 6, co. 1(b) GDPR;

  1. "Marketing": Only with free consent, the sending of commercial, promotional and advertising communications by the Data Controller, through electronic means, relating to the services and activities carried out by it - Legal basis: Art. 6 co. 1 lett. a) GDPR and art. 130 "Privacy Code" (Legislative Decree 196/2003);
  2. "Newsletter": Only with free consent, The periodic sending of informative communications on the activities carried out by the Data Controller, by electronic means - Legal basis: Art. 6 co. 1(a) GDPR;
  3. "Soft spam: the User's email address provided when purchasing an online course, may be used by the Owner for the purpose of sending communications regarding products similar to those already purchased - Legal basis: Art. 6, co. 1, lett. f GDPR and art. 130 co. 4 "Privacy Code" (Legislative Decree 196/2003).

TO WHOM MAY PERSONAL DATA BE DISCLOSED ?

Users' Personal Data may be disclosed, in order to properly perform all Processing activities necessary to pursue the purposes set forth in this Notice, to: 

(a) employees and/or collaborators of the Data Controller, expressly authorized;

b) consultants and service providers of a professional and technical nature, who may also perform Processing activities on behalf of the Controller (by way of example and not limited to: consultants and professionals, IT service providers, management service providers, newsletters, third parties who collaborate with the Controller for direct marketing activities, service providers for Site maintenance, Banks/brokers/payment platforms in case of online purchases); 

c) where required by law or by the Authorities, the data may be communicated to public subjects and entities or to the Judicial Authority.

Personal Data is not otherwise disclosed to other third parties, except as required by law, in connection with legal action or legal proceedings, or when otherwise necessary to protect the rights or interests of the Data Controller.

Personal Data will not be subject to dissemination. In addition, unless expressly consented, it will not be subject to profiling.

HOW LONG WILL PERSONAL DATA BE PROCESSED ?

The Data Controller will process Users' Personal Data for the period necessary to fulfill the Purposes - listed above - for which the same were collected, as indicated in this Policy. In particular: 

- for the "pre-contractual / contractual purposes" referred to in (a), with specific reference to potential customers (mere request for information), the data will be retained for the time strictly necessary to provide the requested information, unless further retention is necessary to fulfill contractual or legal obligations in the specific case of online purchase of courses offered by the Owner; with reference to browsing data will be deleted when the browsing session ceases, unless they are necessary for the exercise or defense of rights; 

- for the "purposes of ascertaining, exercising and/or defending rights" referred to in (b) above, in the event of any litigation, the data will be retained for 10 years from the end of the court/judicial dispute, subject to further retention in the event of the statute of limitations being interrupted, as per law;

- for the "legal purposes" referred to in (c), the data will be retained for as long as necessary on the basis of the legal obligation in question;

- for the "purposes of establishing cooperative relationships and C.V. management." referred to in d): in case of lack of interest and/or non-employment, the data will be deleted after 10 months from the first possible useful contact following the sending of the same curriculum (art.111 bis D. Lgs. 196/03);

- for the "marketing" referred to in (e), the data are retained until the User expressly withdraws consent;

- for the "newsletter" referred to in (f) above, the data are retained until the User expressly withdraws consent;

- for the "soft spam" referred to in (g), the data are retained until expressly refused by the User.

Following the expiration of the retention periods for Personal Data, according to the above criteria, the Data Controller will take measures prearranged for the deletion or anonymization of data that should not be retained for further and specific legal obligations.

IS IT POSSIBLE TO REVOKE THE CONSENT GIVEN ?

The User, in accordance with Art. 7 co. 3 GDPR, has the right to rescind, at any time, the possible consent provided for one or more specific purposes, without affecting the lawfulness of the processing based on the consent given before revocation. The procedures for revoking consent are very simple: simply contact the Data Controller using the contact channels provided within this Policy (e.g., by writing to the email info@disclosers.it), or, where provided, by selecting the option to "unsubscribe" from services based on the consent in the emails received by the User.

WHAT ARE THE USER'S RIGHTS ?

The User has the right to ask the Data Controller, pursuant to Articles 15-22 GDPR, for theaccess to your personal data (you can contact us to find out whether your personal data are being processed and the legal information about the processing), the rectification (correction of inaccurate data or supplementation of incomplete data), the deletion - oblìo - of the same (obtain the deletion of personal data, in cases of law), the limitation of processing (obtaining the submission of data to storage only, excluding other activities in cases of law), to oppose to their processing (stop further processing of your personal data for reasons related to your particular situation, subject to the prevalence of compelling legitimate reasons, in cases of law), as well as the portability (where applicable in the present case, to obtain the data in a structured, commonly used and machine-readable format and also to obtain their direct transmission to another Data Controller, in the cases provided for by law). The relevant requests may be sent to the Controller's contacts, indicated above, enclosing your identity document, for the purpose of identification by the Controller. For more information, you may visit the Guarantor's Site. https://www.garanteprivacy.it/Regolamentoue/diritti-degli-interessati.

Without prejudice to the right to appeal to any other administrative or judicial forum, the User has the right to propose complaint to the Garante, Supervisory Authority for the Protection of Personal Data, in the known location (see https://www.garanteprivacy.it/home/diritti/come-agire-per-tutelare-i-tuoi-dati-personali), if it believes that the Processing of its Personal Data conducted by the Data Controller was in violation of the GDPR and/or applicable law.

I contact details of the Holder for the exercise of the aforementioned rights are those indicated in the introduction and below: YOUR STORY S.R.L., With registered office in Paderno Dugnano (MI), via Claudio Treves 5/7, and operational office in Milan, via Alberico Albricci 9, peo  info@disclosers.it.

WHERE AND HOW ARE PERSONAL DATA PROCESSED ?

Personal Data will be processed by the Data Controller within the territory of the EU, at the offices where the Data Controller conducts its business. Should it become necessary for technical and/or operational issues, or for the pursuit of legitimate interests, to use subjects located outside the EU, it is hereby informed that such subjects will be appointed as Data Processors and the transfer of Personal Data to such subjects will be limited to the performance of specific activities. Any transfer to non-EU countries, in addition to cases where this is guaranteed by adequacy decisions of the European Commission, will be carried out in such a way as to provide appropriate and adequate safeguards in accordance with Articles 45, 46, 47, 49 GDPR.

Personal Data will not be subject to dissemination or fully automated decision-making. 

Personal Data will be processed by automated and non-automated means, with logic strictly related to the purposes themselves and, in any case, in such a way as to ensure the security and confidentiality of the data.

In order to ensure the Security of users' personal data, the Controller will take adequate and appropriate technical and organizational measures in accordance with the provisions of Article 32 GDPR.

THE USER HAS AN OBLIGATION TO PROVIDE PERSONAL DATA ?

The User must provide Personal Data for the "Pre-contractual/Contractual Purposes" referred to in the paragraph on the Purposes of Processing, lett. a), as well as for the consequent and related purposes (lett. b, c, d), as they are necessary to receive the requested information and/or evaluation of the curriculum vitae sent. In case the User does not want the Personal Data to be processed for these purposes, he/she will not be able to use the services and/or information requested. On the other hand, the provision of Personal Data for the Purposes referred to in letters e) and f), is always optional: any failure to provide and/or consent, will only result in the impossibility for the Owner to carry out the marketing activity and the sending of the newsletter.

 

MINORS 

The Site is not intended for minors. Without the consent of a parent or guardian, pursuant to Article 8 GDPR, except as permitted by applicable law, we will not, to the best of our knowledge, collect personal data from minors. You must be at least 16 years of age to provide us with personal data and 18 years of age to perform any transactions on the Site. Should we be informed and/or become aware that a minor has provided us with their Personal Data through our contact channels, we will delete it immediately.

 

CHANGES AND UPDATES

Please note that this Policy may be subject to change due to the introduction of new data protection regulations and, consequently, Users are encouraged to check this page periodically.

en_USEN
Privacy Policy