Privacy policy for VDS Rail S.r.l. Customers

Informative provided in accordance with articles 13 and 14 of EU Regulation 2016/679 (GDPR)

In accordance with Articles 13 and 14 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), having regards to personal data which will be processed by VDS Rail S.r.l. Company, in the person of the Controller and all the Agents involved in the personal data processing, for the purpose of the establishment and execution of the contractual relationship with the Customer, as well as for the discharge of tax obligations arising therefrom, the following Rules will apply:

1. Purpose of the processing of Personal Data.

The processing of personal data aims to the explicit and legitimate purpose of the regular performance of a contract to which the data subject is party in compliance with the legal obligations prescribed for this purpose. The personal data will be used by VDS Rail S.r.l. Company for the compliance of tax and administrative obligations. In accordance with the Regulation (ex art. 7 GDPR), when the Customer gives a specific and distinguished consent, the data could be used by VDS Rail S.r.l. Company, to send e-mail, mail, newsletter, marketing communications and advertising material on products and services offered by the Controller so as to determine the degree of satisfaction with the quality of services.

2. Modalities for the processing of Personal Data.

The processing of Personal Data is carried out by the Controller as well as the employees of the VDS Rail S.r.l. Company, who work under the direct authority of the Controller and have been previously identified, properly instructed and designated as “Data Processors” In addition to the VDS Rail S.r.l. employees, personal data could be processed by third parties, designated on purpose as “External Processors” which could be commissioned by the Company to take care of some commercial activities and/or services so as to comply with tax and fiscal obligations imposed by the law to ensure the correct performance of a contract and the achievement of purposes mentioned under the first paragraph. The processing will be performed whether or not by automated means, such as collection, recording, organization, storage, adaptation or alteration, consultation, use, disclosure by transmission, alignment or combination, restriction, erasure or destruction. The personal data shall be collected for specified, explicit and legitimate purposes in accordance with the principle of adequacy, pertinence, accuracy and proportionality with respect to the purposes for which they are processed; they will also be updated and stored in such a way as to allow identification of data subjects for a period of time not exceeding that necessary to achieve the purposes for which they are processed; The processing will ensure the security of personal data as well as their integrity and confidentiality. Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject. VDS Rail S.r.l. Company does not take any automated decision-making, including profiling, referred to in Article 22(1) and (4), of the EU Regulation n. 679/2016.

3. Provision of data.

The provision of common data, including sensitive data, is strictly necessary for the performance of the activities mentioned under paragraph 1.

4. Refusal to provide data.

Any refusal by the Customer to provide personal data as indicated in point 3, may imply the impossibility to fulfill activities referred to in point 1 and therefore the regular execution of the existing contractual relationship between the parties or the violation of the rules referred to in point 1.

5. Data communication.

Personal data may be disclosed to the “Data Processors” of V.D.S. Rail S.r.l Company and may be communicated, for the purposes referred to in paragraph 1, also to third parties, for the commercial, accounting and administrative management of the relationship, for the performance of the necessary operations of accounting management, invoicing, storage of accounting documentation and, more generally, for the correct fulfillment of the purposes indicated in point . In this case the same subjects will be identified as external data processors or data processors, in compliance with the current provisions of the GDPR.

6. Data disclosure.

Personal data are not subject to disclosure.

7. Data transfer abroad.

Personal data will not be transferred to European Union Countries or third countries fort the purposes referred to point 1.

8. Data storage.

The personal data provided will be stored for as long as necessary for the purpose of carrying out the assignment and for the ten years following the archiving of the contractual position.

9. Rights of the data subject.

The GDPR confers to the Customer the exercise of specific rights, including: a) the right to obtain from the Controller the confirmation of the existence of his personal data and their availability in intelligible form; b) the right to be informed about from which source the data originate, the purposes and the method of the processing, meaningful information about the logic involved to the treatment, about the identification details of the Controller and of the persons to whom the data can be disclosed; c) the right to obtain the updating, rectification and integration of data, cancellation, transformation into anonymous form or blocking of data processed in violation of the law; d) the right to object, on legitimate grounds, to processing of the data; e) the right to data portability. The exercise of your rights can be done by sending a request by e-mail to the address: <privacy AT vdsrail.com>.

10. Controller.

The data controller is the company VDS Rail s.r.l. (Registered Office in Sesto Fiorentino (Firenze), Località Osmannoro, Via Arno 23/25, Cap 50019, Stradario 05323 (C.F. e P.IVA 01678370485)

Copyright 2016 © VDS Rail – All rights reserved.
Certified email: vdsrail@legalmail.it
VAT: IT01678370485 - Share capital: 99.000€ fully paid
Registered office VDS Rail Srl Via Arno, 23-25, 50019 Sesto Fiorentino (FI) Italy.