Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This page describes how the website https://sapio.segnalazioni.net (hereinafter referred to as the "Platform") is managed in relation to the processing of personal data of users consulting it.
The data provided at the time of registration and/or in the content of the reports will be processed in accordance with the principles of fairness, lawfulness, transparency and protection of the confidentiality and rights of all those concerned, in compliance with the confidentiality obligations imposed by the legislation on the processing of personal data and the law on whistleblowing.
- Categories of personal data processed and purpose of processing
The Platform will process personal data concerning you, in particular your name, surname and e-mail address; this data may be directly provided by you during registration and/or taken from your reports.
Your personal data will be processed to:
- enable your registration and access to the platform;
- fulfil legal obligations, including the fulfilment of the requirements of Law 179/2017 on Whistleblowing, in the cases and under the terms provided for by the same legislation.
We also inform you that the personal data relating to the profile are not directly viewable in the report.
- Legal basis of data processing
With reference to the purposes referred to in the first point, the legal basis legitimising data processing is your consent, expressed by clicking on the appropriate button after having read this information notice; this consent is necessary and failure to give it will result in the impossibility of making a "report with registration".
With reference instead to the purposes referred to in the second point, the legal bases legitimising the processing are the legitimate interests of the data controller and the fulfilment of legal obligations.Base giuridica del trattamento dei dati
- Data processing and storage methods
Personal data will be processed by computer and telematic tools with organisational and processing logics strictly related to the above-mentioned purposes and in any case in such a way as to guarantee the security, integrity and confidentiality of the data in compliance with organisational, physical and logical measures in accordance with the provisions of the law in force.
Your personal data provided in the registration form (name, e-mail address) will be managed separately from your possible reports; the possible association of your identity with the report can only be carried out by the "Manager" in charge of managing the reports, in the cases and under the terms contemplated by the regulations.
Your personal data will be kept for a period of time related to the fulfilment of the reporting procedure and to the fulfilment of legal obligations, normally for a period of 10 years.
- Rights of the data subject (Articles 12-23 of the Regulation)
At any time it is possible to know what data are processed by the Data Controller and, if the legal requirements apply, to have them updated, supplemented, corrected or deleted, to receive a copy of them in a structured format, to request their blocking and to object at any time to their processing in the manner provided for by the EU Regulation and to receive timely feedback in this regard. When the prerequisites are met, it is possible to appeal to the Data Protection Authority.
In order to exercise the aforementioned rights, as well as to obtain more detailed information on the subjects or categories of subjects to whom the data are communicated or who become aware of them, you may contact the Data Protection Officer of the Company towards which you intend to exercise your rights, by writing to the following e-mail address: dpo@sapio.it.
- Data controller and contact details
The data controller is Sapio Produzione Idrogeno Ossigeno S.r.l., with registered office in via S. Maurilio n. 13 Milan.
The Data Protection Officer (DPO) can be contacted at the following e-mail address: dpo@sapio.it.
- To whom we disclose your data
The data will be processed only by personnel expressly authorised by the Data Controller and, in particular, by the internal staff appointed for this purpose and to the internal offices in charge or to the ordinary Judicial Authority or to the Accounting Authority (for the profiles of their respective competences).
The supplier of the platform - Digital PA S.r.l. -, who has been appointed as data processor pursuant to Article 28 of the GDPR, may become aware of some of your data, albeit in encrypted form, during maintenance and assistance operations.
The data will not be communicated to third parties or disseminated, except in cases specifically provided for by national or European Union law.