Information on the processing and protection of personal data

Pursuant to the combined provisions of European Regulation 2016/679 (General Data Protection Regulation, hereinafter "GDPR") and Legislative Decree 196/2003 as amended (Legislative Decree 101/2018)

Art. 1. Data controller (the person or company that decides how and why to process data)

The data controller (hereinafter referred to as "Data Controller") is. Cantiere Nautico Cranchi S.p.A. - Via Nazionale, 1319 - 23010 Piantedo (Italy) - REFERENCE: Mrs. Carlotta Lucini, Mobile: +39 331 6662385, e-mail: carlotta.l@cranchi.it - website: www.cranchi.com .

2. Purpose, legal basis for processing and data processed

 

Puropses

Legal basis and nature of contribution

Type of data

a

Activities of sending newsletters, commercial communications and marketing: the performance by the Data Controller of its own promotional and/or marketing activities towards you. This category includes all activities performed to promote products, services, sold and/or provided by the Data Controller; subject to your specific consent.

 

Legal basis and lawfulness of processing: legitimate interest ex art. 6 letter f) of the Regulation - The Processing of your Personal Data will be conducted by the Data Controller and will be legally based on its legitimate interest in promoting its products and services;

Legal basis and lawfulness of processing: consent of the data subject ex art. 6 letter a) of the Regulation - The Processing of your Personal Data will be conducted by the Data Controller and will be legally based on your free, express and unequivocal consent.

identification and contact data:

 First name, last name, e-mail address, telephone number, Tax ID number, City, Country of residence, Country of mooring, sailing area, other data as may be fonished by the customer due to requests

b

Exercise the rights of the Owner, such as any right of defense in court.

Legitimate interest of the data controller (Art. 6(1)(f) GDPR): right of defense fairly balanced with the same right of data subjects

identifying and contact data:

 First name, last name, e-mail address, telephone number, Tax code, City, Country of residence, and data necessary for legal defense

3. Modalities of processing

The processing is carried out with both manual and computerized methods and with the support of paper, computer or otherwise automated means.

In any case, the data processing is carried out with the adoption of all appropriate measures to ensure the security and confidentiality of personal data, in particular in compliance with the security measures referred to in Article 32 of the European Regulation No. 2016/679 and in accordance with the principles of lawfulness, necessity and proportionality.

4. Data storage

Data are processed and stored on the tools used (e.g., computers) by the owner. The personal and special data of the data subjects are stored separately from the works and drawings made during the course of therapy.

The Holder will keep personal data for as long as necessary to fulfill the above purposes.

Specifically : 24 months for marketing purposes.

5. Communication and transmission of data

Data are not subject to communication and dissemination to third parties, except for obligations arising from the law.

Personal data may be transmitted to:

 More information regarding the entities listed above is available from the Holder's office.

6. Transfer of data outside the EU

In the management of the relationship with customers, no transfer of data to Third Countries nor to international organizations is envisaged.

Should it become necessary to transfer personal data outside the territory of the European Union to countries not considered adequate by the European Commission, the Data Controller will ensure that appropriate or adequate safeguards are in place to protect personal data and that the transfer of such data complies with applicable data protection laws.

Any transfer of data subjects' data to countries outside the European Union will, in any event, take place in compliance with the safeguards that are appropriate and adequate for the purposes of such transfer, pursuant to applicable law and in particular Articles 45 and 46 of the Regulations.

Accordingly, where required by applicable data protection laws, the Controller will ensure that service providers sign Standard Contractual Clauses approved by the European Commission.

7. Rights of data subjects (Art. 15 et seq. of the GDPR)

Art. 15 Right of access, the right to know whether any processing of one's personal data is taking place and - if confirmed - to obtain a copy of such data and to be informed about: the origin of the data; the categories of personal data processed; the recipients of the data; the purposes of the processing; the existence of automated decision-making, including profiling; the data retention period; and the rights provided by the Regulation. The Right to lodge a complaint at any time with the Supervisory Authority (Garante Privacy: Piazza Venezia nr. 11, 00187 ROMA, Tel. +39 06 696771 - PEC: protocollo@pec.gpdp.it); Art. 16 Right of the data subject to obtain the updating, rectification or integration of personal data; Art. 17 Right to erasure and the right to be forgotten; Art. 18 Right to restriction of processing, when provided for; Art. 19 Obligation of the data controller to notify rectification, erasure and/or restriction; Art. 20 Right to data portability: the right to request that the data provided to the data controller be transferred to another data controller, where the processing is based on your consent or on a contract with you and is carried out by automated means; Art. 21 Right to object, at any time on grounds relating to your particular situation, where the processing is carried out in the exercise of public authority or in the performance of a task carried out in the public interest, or without the need to give reasons for the objection, when the data are processed for direct marketing purposes; Art. 22 Right not to be subjected to a decision based solely on an automated process, including profiling.

8. automated processing

No automated data processing is carried out.

9. Instances of the Interested Parties

The requests referred to in Art. 7 above may be submitted by the Data Subjects to the Data Controller by registered letter or electronic mail to the addresses listed in Art. 1 above.