Website Disclosure

We are providing this disclosure pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”). It describes how we manage the http://www.mztax.it website (“Website”) and how we process the personal data of users who use it (“Data Subjects”).

1. The Data Controller

The Data Controller is Marchese Zanardi & Partners (“Data Controller”), with registered office in via Massimo d’Azeglio 21, Bologna, Italy. Telephone (+39) 051 238405, email info@mztax.it.

 

2. Types of Data We Process

 

Navigation Data – Log Files

During their normal operation, the computer systems and programs that control the Website’s operation acquire some personal data, the transmission of which is implicit in the use of Internet communication protocols.

This is information that is not collected to be matched with the Data Subjects, but by its very nature it could make the identification of the Data Subjects possible by processing and linking it with data held by third parties.

This category of data includes:

  • the IP addresses or domain names of the computers used by the Data Subjects;
  • the addresses in URI (Uniform Resource Identifier) notation of the requested resources;
  • the time of the request;
  • the method used to submit the request to the server;
  • the size of the file obtained in response;
  • the numeric code indicating the status of the response given by the server (successful, error, etc.);
  • other parameters relating to the operating system and computer environment of the Data Subjects.

These data are used only to obtain anonymous statistical information on the use of Website and to check the proper operation and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of computer crimes against the Website.

This category also includes data processed using cookies. To this end, reference should be made to the provisions of the Cookie Policy.

 

Information Provided Voluntarily by the Data Subjects

The optional, explicit and voluntary submission of an email address and of its related message to the addresses provided on the Website results in the subsequent acquisition of the sender’s address an of other personal data that is needed to respond to the requests.

Any further personal data (such as personal details, data concerning professional activity, position and/or role within the company, contact data such as business and/or private telephone number, email address) provided to the Data Controller or however collected by the Data Controller from third parties, will be processed by the Data Controller in accordance with this disclosure and/or the following Disclosure to Customers and in compliance with the GDPR.

 

3. Purposes of the Processing

Personal data are processed by the Data Controller for the following purposes:

    1. within the limits and only to provide the services accessible via the Website, as well as to enable users to become aware of and learn more about the actions performed by the Data Controller;
    2. manage and process, in relation to the previous point, the questions and requests to interact with the Data Controller.

Performing the actions set out in a) and b) above does not require the Data Subject’s consent since in most cases these are services or performances that are performed in response to requests made directly by the Data Subjects themselves.

 

4. Provision of Data and Consequences in the Event of Failure to Provide Data

The provision of personal data for the above purposes is optional and failure to provide such data will only prevent the Data Controller from managing and processing the Data Subject’s requests.

 

5. Recipients and Categories of Recipients

No data will be disclosed to third parties without the consent of the Data Subjects.

If disclosure to third parties, suppliers or partners of Marchese Zanardi & Partners, be required for organizational, administrative purposes or to support the services provided, the Data Controller will appoint such parties as data processors pursuant to the GDPR.

It is understood that the personal data of the Data Subjects may be freely disclosed to third parties whenever this is permitted by law or required by an order or a decision of a competent authority.

Furthermore, there is no automated decision-making process in this Website, so in particular there is no profiling system.

This Website and the services of the Data Controller are not intended for children under 16 years of age and the Data Controller does not intentionally collect personal information concerning minors. If any information on minors is unintentionally recorded, the Data Controller will promptly delete, at the request of users.

 

6. Transfer of Data

Personal data is stored on a server located in Italy.

In any case, the Data Controller, if necessary, may relocate the server, even outside the EU. In this case, the Data Controller ensures as of now that the transfer of data outside the EU will take place in accordance with the applicable legal provisions, subject to the stipulating of the standard contractual clauses required by the European Commission.

 

7. Processing Methods

Processing related to the Website’s web services is carried out by personnel outside the Data Controller’s organisation, duly appointed in writing, as Data Processor, pursuant to Article 28 of the GDPR.

All personal data are processed on paper and, mainly, in electronic format. Such data will be stored in a form that allows the identification of the Data Subjects only for the time strictly necessary to achieve the purposes for which the data were originally collected and, in any case, within the bounds of the law.

Specific security measures are observed to prevent the loss of the data, illegal or incorrect use of it, and unauthorized access to it.

 

8. Retention Period

Personal data will be retained for the time strictly necessary to achieve the objectives for which the data were collected and processed.

Once the purpose of the processing has been achieved, the personal data will be stored for 10 years, without prejudice to the legitimate interest of the Data Controller in accordance with the GDPR, or for any longer period that may be established in the future for situations that from time to time may be governed by applicable regulations or by the relevant authorities.

 

9. Rights of Data Subjects

Data Subjects may, at any time, exercise the following rights:

  1. Right to access – to obtain confirmation as to whether or not any personal data concerning the Data Subject are being processed and, if so, receive information concerning, in particular: the purpose of the processing, the categories of personal data processed and the storage period thereof, the recipients to whom such data may be disclosed (Article 15 of the GDPR);

  2. Right to correction – to obtain, without undue delay, the correction of inaccurate personal data concerning the Data Subject and the completion of incomplete personal data (Article 16 of the GDPR);

  3. Right to deletion – to obtain, without undue delay, the deletion of the Data Subjects personal data, in the conditions specified in the GDPR (Article 17 of the GDPR);

  4. Right to restriction of processing – to obtain from the Data Controller a restriction of the processing, in the conditions specified in the GDPR (Article 18 of the GDPR);

  5. Right to portability – to receive the Data Subject’s personal data that has been provided to the Data Controller, in a structured, commonly used and machine-readable format, and to have such data sent to another data controller without hindrance, in the conditions specified in the GDPR (Article 20 of the GDPR);

  6. Right to object – to object the processing of the Data Subject’s personal data, unless there are legitimate reasons for the Data Controller to continue processing it. It is also possible to unsubscribe from newsletters, automatic emails, etc. at any time. (Article 21 of the GDPR);

  7. Right to lodge a complaint with the Supervisory Authority – to lodge a complaint with the Italian Data Protection Authority, by following the instructions published on the www.garanteprivacy.it website or by sending an email to urp@gpdp.it;

  8. Right to withdraw – to withdraw the consent. The withdrawal of consent does not affect the lawfulness of the processing based on the consent conferred before the withdrawal itself (Article 7 of the GDPR).

 

10. How to the Exercise the Rights

The above rights may be exercised by submitting a written request that clearly specifies in its subject the type of right being exercised.

The request can be sent by registered letter with proof of delivery to the following address: Marchese Zanardi & Partners, via Massimo d’Azeglio 21, 40123, Bologna, Italy.