Privacy Policy for the website www.motette.it

Respect for the privacy of our visitors is of utmost importance to us. Therefore, the number and nature of data collected during browsing has been minimized, and all necessary precautions have been taken to ensure their security. Please note that this policy applies only to the website www.motette.it and not to any other websites that may be accessed by users via links on the aforementioned website. In accordance with Legislative Decree 196/2003, the Personal Data Protection Code, and the General Data Protection Regulation – EU Regulation 2016/679, SIAMI Spa – Società Italiana Acque Minerali, represented for this purpose by its current legal representative, in its capacity as Data Controller, wishes to inform you of the following.

Personal Data Processed and Purpose of Processing

Data Automatically Acquired

The IT systems responsible for the functioning of this website automatically acquire, during normal navigation, certain personal data whose transmission is inherent to the use of Internet communication protocols (IP addresses, domain names of the computers used by users who connect to the site, time of the request, method used to submit the request to the server, size of the file obtained in response, numerical code indicating the status of the server’s response, etc.), and other parameters related to the user’s operating system and IT environment. These data are used solely for the purpose of obtaining anonymous statistical information on the use of the site and to ensure it functions correctly. The collected data may be used to ascertain liability in the event of hypothetical computer crimes against the site.

Data Voluntarily Provided by Users

Personal data voluntarily provided by users via contact forms or through other forms of communication available on our website are used solely to respond to the submitted requests and, with your consent, for all purposes that require it. For example, entering an email address in the contact form entails its acquisition, which is necessary to respond to the submitted requests, as well as the acquisition of any other personal data included in the message. Your personal data may be disclosed, for the aforementioned purposes, to our specifically authorized collaborators as part of their duties. For the same purposes, if necessary, the collected data may be transferred outside the national territory where the legal conditions for such transfer are met.

Processing Methods and Retention Periods

Processing will be carried out using both paper and electronic means by the Data Controller and authorized individuals, in compliance with all precautionary measures that ensure security and confidentiality. Your personal data submitted via forms and contact modules will be retained for the time necessary to fulfill your requests. Personal data related to browsing will be retained for the purpose of verifying the management and security of the website for the time strictly necessary, which is, unless otherwise required, 6 months.

Optional Provision of Personal Data

Except for browsing data, which are recorded automatically, users are free to provide personal data (such as name, surname, address, email, etc.) requested in the site’s forms. Failure to provide such data may result in the inability to obtain what is requested.

Disclosure of Collected Data

For the purposes described above, your personal data will be known to employees, equivalent personnel, and collaborators of the Data Controller, who will operate as persons authorized to process personal data. Furthermore, your personal data will be disclosed to and processed by third parties in the following categories:

  • a) entities used by the Data Controller to manage the Site;
  • b) companies managing the Data Controller’s IT system;
  • c) companies and consultants providing legal and/or tax consulting services;
  • d) supervisory and control authorities and bodies, and in general public or private entities with public authority functions.

Entities in the above categories may operate, in some cases, in total autonomy as separate Data Controllers, and in other cases as Data Processors specifically appointed by the Data Controller in accordance with Article 28 GDPR. A complete and updated list of entities to whom your personal data may be communicated is available upon request at the Data Controller’s registered office (privacy@siami.it)

Data Subjects’ Rights

With respect to the processing described in this Privacy Policy, as a data subject, you may, under the conditions provided by the GDPR, exercise the rights established in Articles 15 to 21 of the GDPR, including in particular the following:

• Right of access – Article 15 GDPR: the right to obtain confirmation as to whether or not personal data concerning you are being processed and, if so, to access the personal data – including a copy – and receive information regarding:

  • a) the purposes of the processing
  • b) the categories of personal data concerned
  • c) the recipients to whom the data have been or will be disclosed
  • d) the data retention period or the criteria used
  • e) the rights of the data subject (rectification, erasure, restriction of processing, and right to object to processing)
  • f) the right to lodge a complaint
  • g) the source of the personal data, if not collected from the data subject
  • h) the existence of automated decision-making, including profiling;

• Right to rectification – Article 16 GDPR: the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and/or the completion of incomplete personal data;

• Right to erasure (right to be forgotten) – Article 17 GDPR: the right to obtain, without undue delay, the erasure of personal data concerning you when:

  • a) the data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • b) you have withdrawn your consent and there is no other legal basis for the processing;
  • c) you have successfully objected to the processing of personal data;
  • d) the data have been unlawfully processed;
  • e) the data must be erased to comply with a legal obligation;
  • f) the personal data were collected in relation to the offer of information society services as referred to in Article 8, paragraph 1, GDPR. The right to erasure does not apply to the extent that processing is necessary to comply with a legal obligation, to perform a task carried out in the public interest, or for the establishment, exercise, or defense of legal claims.

• Right to restriction of processing – Article 18 GDPR: the right to obtain restriction of processing when:

  • a) the data subject contests the accuracy of the personal data;
  • b) the processing is unlawful and the data subject opposes erasure and requests restriction instead;
  • c) although the controller no longer needs the data for processing purposes, they are required by the data subject for legal claims;
  • d) the data subject has objected to the processing pending verification whether the legitimate grounds of the controller override those of the data subject;

• Right to data portability – Article 20 GDPR: the right to receive the personal data concerning you, provided to the Data Controller, in a structured, commonly used and machine-readable format, and the right to transmit those data to another controller without hindrance, where the processing is based on consent and is carried out by automated means. You also have the right to have the personal data transmitted directly from one controller to another, where technically feasible;

• Right to object – Article 21 GDPR: the right to object, at any time, to the processing of personal data concerning you based on the lawful condition of legitimate interest, including profiling, unless there are compelling legitimate grounds for the controller to continue the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defense of legal claims.

• Right to lodge a complaint with the Data Protection Authority, Piazza di Montecitorio n. 121, 00186, Rome (RM). You may exercise the above rights against the Data Controller by contacting the references in the “Controller and Processors” section. The Data Controller will handle your request and provide you, without undue delay and at the latest within one month of receipt, with information about the action taken. The exercise of your rights as a data subject is free of charge under Article 12 GDPR. However, in the case of manifestly unfounded or excessive requests, especially due to their repetitive character, the Data Controller may charge a reasonable fee based on administrative costs incurred or refuse to act on the request. Lastly, please note that the Controller may request additional information necessary to confirm the identity of the data subject.

Controller and Processors

The data controller and processor is SIAMI Spa – Società Italiana Acque Minerali represented by its pro tempore legal representative. For any information regarding the processing of your personal data carried out via this website, you may contact the Data Protection Officer at privacy@siami.it.