ATT.03 – GDPR – CUSTOMER/SUPPLIER PRIVACY POLICY
Rev.00 September 27th 2018

To all Customers and Suppliers of Orion Italia Srl

The following information is provided pursuant to Legislative Decree 196/2003 and art. 13 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR 2016/679).

Data Controller – art. 13 paragraph 1 lett. [a] [b] GDPR 2016/679

The Data Controller responsible is Orion Italia Srl situated in via G. Orsi, 35 29122 Piacenza email
privacy@orionitalia.com Tel. 0523 591161. You can contact the above mentioned Controller in order to exercise your rights recognized by the GDPR and to learn the updated list of all data processors.

1. Type of personal data collected
Common data, bank details, company data.

2. Purposes of the processing and legal basis for which the personal data are intended – art. 13 paragraph 1 lett. [c] [d] GDPR 2016/679
The personal data you provide may be used solely for the following purposes:
administrative, accounting, commercial, organizational purposes within the established professional relationships;
purposes related to legislative obligations in the field of Work Safety;
approval of suppliers and management of purchases and sales pursuant to the internal procedures of the Quality System;
or any other purpose necessary for the management of the contractual relationship.
The legal basis of the aforementioned purposes is that of compliance with contractual obligations between the customer/supplier and the Controller.

A further purpose is foreseen:
sending informative and promotional material associated with company products.

The legal basis for the aforementioned purpose is consent.

Data communication to third parties through the company management system of Orion Italia Srl
is allowed without the need for further consent.

No further processing is envisaged based on the legitimate interests pursued by the Controller.

3. Data communication and dissemination – art. 13 paragraph 1 lett. [e] [f] GDPR 2016/679
Data may be communicated to subjects linked to the company such as consultants and
third-party professionals. The data could also be transferred abroad.

4. Processing and data storage - art. 13 paragraph 2 lett. [a] GDPR 2016/679
The processing of personal data consists in the collection, registration, organization, storage and communication of said data to third parties indicated on the consent form attached.

The processing of personal data is carried out for the purposes set out above, in accordance with
what established by Article 5 of the European Regulation on the processing of personal data, collected:
on paper: contact details, business cards, data on transport documents, invoices, offers, documents belonging to the UNI EN ISO 9001.2015 management system;
online: contact details, business cards, data on documents of transport, invoices, offers and more generally, documents belonging to the UNI EN ISO 9001.2015 management system,
in compliance with the rules of lawfulness, legitimacy, confidentiality and safety provided by current legislation.

Data will be stored in our archives and computer archives for the period of time necessary for the purposes for which they were collected or subsequently treated in accordance with the provisions set out by legal obligations.

5. Rights of data subjects - art. 13 paragraph 2 lett. [b] [c] [d] GDPR 2016/679
Data subjects have the right to obtain access to personal data and to correct them.
For legitimate reasons, data subjects have the right to cancel, limit or oppose the
processing that concerns them. In order to exercise the above, the interested party must contact the Data Controller.
Moreover, the interested party can always contact the European Data Protection Supervisor.

6. Nature of the provision of personal data and consequences of a possible refusal to
answer - art. 13 paragraph 2 lett. [e] [f] GDPR 2016/679
The provision of personal data is optional, however a refusal could exclude the possibility of establishing a working relationship.

Regarding the data, there is no automated decision-making process, nor a single processing treatment that involves profiling.

It is not the intention of the Data Controller to disseminate data, nor to transmit it to third parties for purposes other than those expressly indicated herein.


Piacenza, September 27th 2018
Orion Italia Srl
Share by: