PRIVACY POLICY

The transparency and security of your data is a serious matter for us.     
Pursuant to Art. 13 of EU Regulation 679/2016 (General Data Protection Regulation – GDPR), this information notice applies to all users who consult the pages of our website www .emac-expo.com

This document does not refer to any other websites accessed by the user through links on our site.

 

INDEX

         PRIVACY POLICY

  1. THE DATA CONTROLLER
  2. CATEGORIES OF DATA SUBJECT TO PROCESSING
  3. ON WHICH LEGAL BASIS THE DATA WILL BE PROCESSED
  4. FOR WHAT PURPOSES WILL WE PROCESS YOUR DATA?

SECONDARY PURPOSES

  1. WITH WHOM DO WE SHARE YOUR DATA?
  2. WILL YOUR DATA BE TRANSFERRED TO A THIRD COUNTRY?
  3. HOW LONG WILL YOUR DATA BE STORED?
  4. WHAT DATA PROTECTION RIGHTS CAN YOU ASSERT AS A DATA SUBJECT?
  5. HOW IS YOUR DATA PROTECTED?
  6. HOW TO EXERCISE YOUR RIGHTS

 

1. THE DATA CONTROLLER

DATA CONTROLLER:

EMAC SRL

with registered office in Viale IV November 25

51016 Montecatini Terme (Pistoia),

EMAC – Expo Management Company is a trade fair operator specializing in automotive events, operating nationally and internationally, with experience and expertise in the design and management of industry events.

 

2. CATEGORIES OF DATA SUBJECT TO PROCESSING

Personal data (hereinafter referred to as “Data”) are information referring to an identified or identifiable physical subject. Through the website, we only process the following categories of data:

 

  • Data you voluntarily provide to us

There are “ordinary” personal data, which you voluntarily enter on our website when you submit an information request through the “Contacts” form (e.g., first name, last name, phone number, address, e-mail, and all other information that you freely enter in the form).

The optional, explicit, and voluntary sending of e-mails to the addresses indicated on this site involves the subsequent acquisition of your address – necessary to respond to requests or direct marketing activities via newsletter – as well as any other personal data included in the email itself.
If sensitive data (“particular”) are included, these will not be retained, but will be immediately deleted by the Data Controller.

  • Browsing data
    The computer systems and software procedures used to operate this website acquire, during their normal functioning, certain data whose transmission is implicit in the use of internet communication protocols.
    This information is not collected to be associated with identified interested individuals, but due to its nature could – through processing and association with data held by third parties – allow users to be identified. This data category of data includes:          
    – Internet protocol (IP) address associated with the device used to connect;   
    – type of browser and parameters of the device used to access the site;         
    – name of the Internet service provider (ISP);     
    – date and time of visit;     
    – webpage of origin of the visitor (referral) and exitpage;           
    – any number of clicks perfomed on the site and any preference expressed;   
    – other parameters relating to the user’s operating system and IT environment.         

  • Aggregate data: browsing navigation data may be used to obtain anonymous and aggregated statistical information on site usage and to check its correct functioning.      

  • Cookies
    Our site uses technical, profiling, analytics and third-party cookies, please read our Cookie Policy for more information.

3. ON WHICH LEGAL BASIS THE DATA WILL BE PROCESSED         
  • CONSENT

By using or consulting our website, you explicitly approve our privacy policy and consent to the processing of your personal data in relation to the methods and purposes described below. Your explicit consent will be requested only through the selection of an unticked checkbox that you will find in the “Contacts” and/or “Newsletter” form.

Consent, according to art. 4 GDPR, is any free, specific, informed, and unequivocal manifestation of will, following our clear and concise request. The consent you have given applies to all processing activities carried out for the same purpose(s).

 

  • EXECUTION OF PRE-CONTRACTUAL MEASURES

Art. 6 para. 1 lit. b GDPR): in order to handle requests sent via the contact form.

 

  • LEGAL OBLIGATION

Art. 6(1)(c) GDPR: we must process some of your data in order to comply in accordance with the legal obligations to which we are subject.

 

  • LEGITIMATE INTEREST

Art. 6 par. 1 lit. f) GDPR: the processing is carried out pursuant to Art. 6 par. f) GDPR, based on the legitimate interest of the Data Controller, adequately balanced with the rights and freedoms of data subjects, to ensure the security of the website, prevent abuses, optimize their digital activities, and protect their rights in court.

 

4. FOR WHAT PURPOSES WILL WE PROCESS YOUR DATA?

We will process your data for the following main reasons:

  • To comply with national and EU regulations.
  • To determinate liability in case of hypothetical computer crimes against the site and for investigations in case of possible disputes.
  • To enter data into our databases.
  • For marketing activities via the newsletter service.
    The newsletter service consists of sending electronic communications following the express request of the recipient; therefore, no additional consent is required beyond that provided by the data subject when completing and submitting the newsletter subscription form.
    THE provision of consent to the newsletter is therefore optional. However, failure to provide it will prevent you from receiving any communication.

You can revoke your consent to the newsletter through the appropriate disclaimer contained in the footer of each email you receive from our site.

  • For profiling activities.

 

SECONDARY PURPOSES

Data processing to comply with legal obligations: We are subject to certain legal obligations in the operation of the website. This includes, among other things, the obligation to ensure the security of your data when using the site. For this purpose, we may process your data as part of the measures to ensure data security.


Processing of data on the basis of legitimate interest:
Storage of access data in server log files: when you visit our website, we may store access data in server log files, such as file name requested, date and time of access, volume of data transferred and requesting provider.     
We use this data exclusively to ensure efficient site operation. For security purposes (spam filters, firewalls, virus detection), the data automatically recorded may also possibly include personal data such as IP address, which may be used in accordance with applicable laws, to block attempts to damage the site or harm other users, or to prevent harmful or criminal activities.

 

5. WITH WHOM DO WE SHARE YOUR DATA?

We always take appropriate measures to ensure that your data is processed, protected, and transmitted in accordance with applicable legal requirements.

 

THIRD-PARTY SERVICE PROVIDERS

We make use other companies and professionals to perform certain activities on our behalf, all of whom are appointed pursuant to art. 28 EU Reg. 679/2016.

In addition to us, in some cases, categories of authorized personnel involved in the organization or external subjects (such as third-party technical service providers, IT companies) may have access to the data.

We guarantee that they cannot use the data for any other purposes and are also required to process personal data in compliance with this Privacy Policy and under applicable data protection regulations.

 

6. WILL YOUR DATA BE TRANSFERRED TO A THIRD COUNTRY?

Our site does not transfer any of your data to non-EU countries, but the voluntary use of links and social plugins may result in your data being shared with services located outside the European Union, according to the Privacy Policy of each service and legal entity.

 

7. HOW LONG WILL YOUR DATA BE STORED?

Pursuant to Art. 17 GDPR, your data will be stored for as long as we are legally required to do so or for as long as your data are needed for the purposes stated in Section 4. Your data will then be deleted in compliance with the principle of data minimization.

 

  • WITH REFERENCE TO PROCESSING FOR THE PURPOSE OF SENDING A RESPONSE: Data will be stored no longer than two years from the first contact, without prejudice to the data subject’s objection to the processing. In any case, deletion can be requested by sending an email.
  • WITH REFERENCE TO PROCESSING FOR NEWSLETTER AND PROFILING PURPOSES:

Data will be stored for no longer than the time necessary to achieve the purposes for which it is processed and for a maximum of 12 months for profiling, and 24 months for “general” marketing, in full compliance with limitation principle provided by the GDPR; or until consent is withdrawn.

  • WITH REFERENCE TO BROWSING DATA:
    Only data collected for monitoring purposes will remain on the servers for a period of 12 months and in any case according to the technical times necessary for the management of the site.
  • FOR LEGAL OBLIGATIONS:
    In any case, data of a civil, accounting or tax nature will be stored for a period of ten years, as required by law.

 

8. WHAT DATA PROTECTION RIGHTS CAN YOU ASSERT AS A DATA SUBJECT?

You may assert various rights that belong you as a data subject. In particular, these rights are:
Right to information

You may ask us which of your personal data we are actually processing.
Right of access

You may access your personal data undergoing processing and request a copy of it.    
Right to rectification

You may rectify your personal data at any time by requesting the correction of inaccurate data and the integration of incomplete data.        
Right to erasure

You can request at any time to delete your personal data.
However, please note that the right to erasure is not an absolute; therefore, in certain cases (for example to fulfil a legal obligation) the request my legitimately be denied. The email with the subject “Deletion of personal data” must contain:

  • First and last name of the requester;
  • Written request for deletion;
  • Email address used for registration;
  • Password for accessing your personal area (if available);
  • Copy of identity card or passport;
  • Contact address and telephone number.

Right to portability

You may request the portability of your data, i.e. to receive personal data concerning you in a structured, commonly used and machine-readable format. Therefore, you have the right to request that your data con be transmitted to another Controller.         
Right to object

You may object to a certain processing of your personal data without necessarily requesting its deletion. From the moment of objection, the Data Controller will cease to process your data.  
Right to restriction

You mayr equest the restriction of processing of your personal data. In certain cases, for example when exercising the right to objection, the restriction is a natural consequence. If processing is restricted, any use of data by the Controller may be possible only with your consent.   
Right to lodge a complaint with a supervisory authority

We work together with you to obtain a fair resolution to any data protection complaints. You have the right to file a complaint with the Data Protection Authority if you believe that our processing of your personal data violates applicable data protection law.

9. HOW IS YOUR DATA PROTECTED?

We have adopted appropriate technical and organizational security measures to ensure the protection of the data. For this purpose, we have developed a reliable internal security approach.

Personal data are processed using automated tools for the time strictly necessary to achieve the purposes for which they were collected. Specific security measures are taken to prevent data loss, unlawful or improper use, and unauthorized access.

 

 10. HOW TO EXERCISE YOUR RIGHTS

– The Data Controller may be contacted at the following email address: segreteria@emacfiere.com, at the certified email address emacsrl@arubapec.it, or by sending a registered letter to the headquarters of the Data Controller.

– The Data Protection Officer (DPO)/ Data Protection Officer (RPD) can be contacted at dpo@emacfiere.com