NORO HALL SUPPLIERS PRIVACY POLICY

TITLE: Sala Noro and Associates

LEGAL HEAD OFFICE: via Tornielli 12 Novara

E-MAIL: novara@dottcomm.it

PIVA 01717420036

Information on the processing of suppliers' personal data in accordance with Articles 13 and 14 of EU Regulation 2016/679

Data controller

The Data Controller is Sala, Noro and Associates which holds and processes personal data protected by EU Regulation 2016/679 according to the principles of fairness, lawfulness and transparency and protection of your privacy and rights.

Data processed

The data that will be processed are:
- With regard to suppliers natural persons: personal data, telephone number and/or e-mail, CF and PIVA, activities carried out or goods sold, fees accrued and paid, IBAN for the payment of fees.
- With regard to suppliers legal persons: name; reference company; contact channels of contact persons.

Purposes and legal bases
Your data will be processed for purposes related to contractual obligations, legal obligations and legitimate interests. Specifically, the purposes concern:
1. Contractual relationship management.
2. Corresponsation of entitlements.
3. Keeping of accounts.
4. Exercise of a legitimate interest in asserting or defending a right in court, as well as in administrative or arbitration and conciliation proceedings.

The legal bases laid for the processing operations and related purposes are:
- Fulfillment of contractual obligations ex art 6 lett b) of the GDPR, with reference to the purposes under numbers 1 and 2.
- Fulfillment of legal obligations ex art 6 lett c) of the GDPR, with reference to the purpose mentioned in number 3.
- Legitimate interest ex art 6 lett f) of the GDPR, with reference to the purpose under number 4.

The processing of such data is necessary for the proper management of the relationship, consequently, their provision is mandatory for the implementation of the above purposes. Any non-disclosure or incorrect disclosure of such data may be a cause of impossibility for the Holder to provide the service and ensure the appropriateness of the processing itself.

Method of processing
Your personal data will be processed through electronic means and will not be subject to automated decisions.
Your personal data will be processed in accordance with the modalities set forth in Articles 6 and 32 of the GDPR through the adoption of appropriate security measures.

Communication and dissemination
Your data will not be disseminated in any way, but are subject to exclusive communication to:
- Credit institutions for the payment of entitlements.
- Public bodies (Provincial Directorate of Labor, Revenue Agency).
- Companies, consultants and freelancers, including in associated form, with regard to the management of litigation
- Companies, consultants and freelancers, including in associated form, with regard to accounting management
- Companies, consultants and freelancers, including in associated form, with regard to the management of IT infrastructure and the provision of e-mail services.

In any case, the data will be processed only by personnel authorized by the Owner.

Retention
Your data will be kept for the time necessary to conclude the contract and for the time stipulated by tax and accounting regulations. Specifically:
- 10 years from the termination of the contractual relationship.
- 10 years in compliance with obligations to preserve accounting records.
- In case of action before the judicial authority, until the conclusion of the judgment.

Exercise of rights
You can always exercise your rights under the GDPR in Articles 15 to 22, namely right of access, right to rectification, right to erasure, right to restriction, right to portability, and right to object.
To exercise your rights, you can send a request to novara@dottcomm.it by entering "GDPR exercise of rights" as the subject, following which you will be contacted as soon as possible (this is within 30 days in any case) in response to your request.
If you believe that the processing of your personal data is contrary to current legislation, you can always lodge a complaint with the Garante per la protezione dei dati personali, pursuant to Article 77 GDPR.