Privacy GDPR 2018 and Legal Notes
Privacy Policy (updated GDPR 2018)
The user is requested to read the following instructions carefully.
Xonelectronics.eu of XON Electronics Srl, with headquarters in via Giosuè Carducci, 9 Orbassano (TO), Italy, as data controller, informs you pursuant to art. 13 Legislative Decree 6/30/2003 n. 196 (hereinafter, "Privacy Code") and art. 13 EU Regulation no. 2016/679 (hereinafter, "GDPR") that your data will be processed in the manner and for the following purposes:
1. Object of the treatment
The Data Controller processes personal, identifying and non-sensitive data (in particular, name, surname, tax code, VAT number, email, telephone number - hereinafter, "personal data" or even "data") communicated by you during the registration on the owner's website and/or when subscribing to the newsletter service offered by the owner and for invoicing the purchased items.
2. Purpose of the treatment
Your personal data are processed:
A) without your express consent (art. 24 letter a, b, c Privacy Code and art. 6 letter b, and GDPR), for the following Service Purposes:
- allow you to register on the website;
- manage and maintain the website;
- allow you to subscribe to the newsletter service provided by the Data Controller and any additional Services you may request;
- fulfill the pre-contractual, contractual and tax obligations deriving from existing relationships with you;
- fulfill the obligations established by law, by a regulation, by community legislation or by an order of the Authority;
- prevent or detect fraudulent activity or abuse harmful to the website;
- exercise the rights of the Owner, for example the right of defense in court.
B) Only with your specific and distinct consent (Articles 23 and 130 of the Privacy Code and Article 7 of the GDPR), for the following Marketing Purposes:
- send you via email newsletters, commercial communications and/or advertising material on products or services offered by the Data Controller
We point out that if you are already our customer, we will be able to send you commercial communications relating to the Controller's services and products similar to those you have already used, unless you disagree (art. 130 c. 4 Privacy Code).
3. Processing methods
The processing of your personal data is carried out by means of the operations indicated in art. 4 Privacy Code and art. 4 no. 2) GDPR and precisely: collection, registration, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, cancellation and destruction of data. Your personal data is subjected to both paper and electronic and/or automated processing.
The Data Controller will process personal data for the time necessary to fulfill the aforementioned purposes and in any case for no more than 10 years from the termination of the relationship for the Service Purposes and for no more than 2 years from the last acceptance of this regulation (last order) of data for Marketing Purposes.
4. Access to data
Your data may be made accessible for the purposes referred to in art. 2.A) and 2.B):
- to employees and collaborators of the Data Controller or of the companies of the Group the Data Controller is part of, in their capacity as persons in charge and/or internal data processors and/or system administrators;
- to the company XON Electronics Srl of which the Data Controller is a part (for example, for support activities in the feasibility study of the customer's project, for technical project management activities, for the storage of personal data, etc.) or to third parties (for example, providers for the management and maintenance of the website, suppliers, credit institutions, professional firms, etc.) who carry out outsourced activities on behalf of the Data Controller, in their capacity as external data processors.
5. Data communication
Without your express consent (ex art. 24 letter a), b), d) Privacy Code and art. 6 lett. b) and c) GDPR), the Data Controller may communicate your data for the purposes referred to in art. 2.A) to supervisory bodies, judicial authorities as well as to all other subjects to whom the communication is mandatory by law for the accomplishment of the aforementioned purposes. Your data will not be disclosed.
6. Data transfer
The management and storage of personal data will take place on servers located within the European Union of the Data Controller and/or of third-party companies appointed and duly appointed as Data Processors. Currently the servers are located in Italy. The data will not be transferred outside the European Union. In any case, it is understood that the Data Controller, if necessary, will have the right to move the location of the servers to the European Union and/or non-EU countries. In this case, the Data Controller ensures from now on that the transfer of non-EU data will take place in compliance with the applicable legal provisions by stipulating, if necessary, agreements that guarantee a level of pr
