Information pursuant to art. 13 of the EU Regulation n. 2016/679 of 27 April 2016
This information is provided pursuant to and by effect of art. 13 of the EU Regulation n. 2016/679 of 27 April 2016 (hereinafter also "GDPR") concerning the protection of natural persons with regard to the processing of personal data.
Specifically, Eumedica Srl, as Data Controller, wishes to inform that in implementation of the obligations arising from the GDPR, is required to provide some information regarding the methods and purposes of the processing of personal data, some of which may be acquired for the execution of the business relationship.
- DATA CONTROLLER
- PROCESSED DATA AND PURPOSE OF THE TREATMENT
- The data processed for the management and the correct execution of the purchase contract through e-commerce are acquired through the Storeden platform, owned by Projectmoon S.r.l. The data acquired through the "Shop Eumedica Active" form, and are: name and surname, e-mail address, telephone number, VAT number / Fiscal code, delivery address and billing address, in case this is different from the delivery address, details of the payment method, which shall be carried out with Pay Pal mode. The acquisition of such data can take place as follows
- as a guest user not registered on the site;
- after registration to the Storeden technology platform. Registration can be done by filling out the registration form or through third-party systems (such as Google or Facebook), entering the access credentials in the appropriate section of the registration form.
The data controller referred to in point 1 is PROJECTMOON SRL with registered office in Lancenigo di Villorba (TV), Via Roma 4/18, tel. 0422 608043, mail email@example.com, firstname.lastname@example.org, pec: email@example.com.
Eumedica S.r.l. is the independent holder of the data acquired through the Storeden platform as necessary for the proper fulfilment of the contractual obligations assumed in relation to the services provided through the Platform, as well as the obligations deriving from the law.
These data may be processed for the fulfilment of all the obligations imposed by law (such as, but not limited to: tax purposes, anti-money-laundering purposes pursuant Law 231/07 and subsequent amendments), as well as for the management of any critical phase or litigation related to the same and in case of any other organizational and management needs.
The provision of necessary and essential personal data is mandatory for the execution of the business relationship and for the legal and contractual obligations. Any refusal to supply them, in whole or in part, may give rise to the impossibility for the company to execute the contract or to correctly fulfil the legal and contractual obligations.
The data supplied, in case of purchase of class 1 medical devices, will be used to send you by e-mail the declaration of conformity of the medical device to the directive 93/42 EEC, in order to provide you with the necessary documentation to proceed with the deduction of medical expenses.
- The processing may also be carried out for marketing purposes related to the promotion of the products offered by Eumedica S.r.l.
- The Company informs you that, for the direct sale of its products, the e-mail address provided by you during the contractual relationship will be used for the promotion of products similar to those sold through e-commerce, unless expressly indicated to the contrary.
- The processing may also be carried out to elaborate anonymous statistical and market research and studies pursuant to Art. 11 GDPR.
We remind you that Eumedica S.r.l. actually does not process your data necessary to make the payment but receives only the communication of the payment by the PayPal owner.
- LEGAL BASIS OF TREATMENT
- The legal basis of processing for the above data is:
- as regards point 1, letter B), the need to execute the contract concluded through e-commerce and to fulfill legal and fiscal obligations;
- as regards point 2, letter B), the consent expressed by the Customer for the direct marketing purposes indicated above;
- with regard to point 3, letter B),, the legitimate interest of the Owner;
- with regard to point 4, letter B), art. 11 of GDPR.
The consent of the Customer is freely revocable at any time by writing an e-mail to: firstname.lastname@example.org
The Customer may at any time oppose the processing of the data referred to in paragraph 3 letter B) by sending an e-mail to: email@example.com
- METHOD OF TREATMENT
Please note that personal data will be kept and controlled, also in relation to technical progress, to the nature of the data and to the specific characteristics of the treatment, through the adoption of appropriate and preventive security measures, both physical and logical, in order to minimize the risk of destruction or loss of data; unauthorized access; not allowed or not in accordance with the purpose of the collection treatment.
The treatment will be carried out by the owner and by the persons expressly authorized by the owner.
- DURATION OF DATA STORAGE
In addition, the data provided will be kept for the following period:
- Purpose of direct marketing: same duration as for the execution of the contractual relationship and for the legal obligations with the notice that, at the expiration date, such data will be automatically deleted or made anonymous in a permanent and non-reversible manner.
- ADDRESSEES AND CATEGORIES OF ADDRESSEES
The data may be communicated to well-defined individuals resident in Italy, and only by the Data Controller for the purposes indicated and for the legal, fiscal, accounting and administrative obligations (by way of example and not exhaustive: lawyer, accountant, etc.) , in order to ensure the correct execution of the business relationship, which will remain holders of independent treatment, unless it is proceeded to the nomination as external managers of the treatment
The Data Controller uses a third party program to send newsletter, which guarantees a communication system protected by SSL and TLS protocols, as well as security and anti-spam measures. The supplier's servers are located within the Italian territory
The list of persons appointed as external processors is available at the following references: Eumedica S.r.l. with registered office in Noventa Padovana (PD), via Risorgimento n. 14, chap. 35027 that is to the number 049.8932720
Data controlled by Projectmoon S.r.l. will in no case be disclosed.
- RIGHTS OF THE INTERESTED PARTY
- to access, rectification, cancellation, limitation and opposition to the processing of data;
- to obtain, without any impediment, from the data controller the data in a structured format of common use and legible by an automatic device to transmit them to another data controller;
- to revoke the consent to the processing, without prejudice to the lawfulness of the treatment based on the consent acquired before the revocation;
In this regard, we inform you that the deadline for replying to the interested party is, for all the rights, one month from receipt of the request, which can be extended up to three months in cases of particular complexity.
The exercise of the aforementioned rights can be exercised through written communication to be sent by e-mail to: firstname.lastname@example.org or registered letter to / r at: Noventa Padovana (PD), via Risorgimento n. 14, chap. 35027.
The Customer may at any time oppose the processing of the data referred to in point 1 letter B) by Projectmoon S.r.l. sending an email to email@example.com
- WARRANTY AUTHORITY COMPLAINT
The complaint is the instrument that allows the interested party to contact the Guarantor to complaint about a violation of the regulations regarding the protection of personal data pursuant to art. 77 of the GDPR and to request verification to the Authority.
The instrument of the claim differs from the notification because it allows specifying in more detail the violation for which it intends to solicit the intervention of the Guarantor.
- TRANSFER OF DATA ABROAD
This privacy statement may require an update from time to time, e.g. due to the implementation of new technologies or data processing for purposes other than those indicated. The Owner therefore reserves the right to modify or supplement this privacy statement at any time. In this case, it will be the responsibility of the Data Controller to publish the changes and inform the Data Subject (eg by e-mail communication).