PRIVACY POLICY FOR THE MYRENT MANAGER APP — Articles 13–14 EU Regulation 2016/679 “GDPR”
WHO IS THE DATA CONTROLLER?
The Data Controller is Dogma Systems Srl a Socio Unico, Via Sant’Ubaldo 30, 60030 – Monsano (AN), +39 071.90.90.188, E mail: info@dogmasystems.com
More information is available at: https://dogmasystems.com/
WHO IS THE DATA PROTECTION OFFICER?
The Data Protection Officer (or DPO) is your point of contact for any issue or matter concerning the application of the GDPR. They can be reached at the following E-mail: privacy@dogmasystems.com
WHAT IS THE PURPOSE OF THE DATA PROCESSING?
In compliance with EU Regulation 2016/679 on the processing of personal data and their free movement and Legislative Decree 196/2003 as amended (“Personal Data Protection Code”), we inform you, as the “Data Subject”, that we process your data for the following purposes:
a) contractual, administrative, tax, and accounting purposes, as well as to respond to information requests or to comply with legal obligations;
b) marketing purposes towards existing customers, through the same digital communication channel used in the ongoing relationship, in order to send advertising material, promotional or commercial communications relating to products marketed by the Data Controller like those previously purchased or serviced, unless the data subject refuses such use either initially or in subsequent communications.
Should there be any need to pursue further purposes of processing not indicated in this notice, we will inform you in advance about the new processing methods.
WHAT IS THE LEGAL BASIS FOR DATA PROCESSING?
The legal bases vary depending on the purposes indicated above. Specifically:
a) Pursuant to Article 6 GDPR, letters b) and c), processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures requested by the data subject, as well as for compliance with legal obligations to which the Data Controller is subject;
b) Pursuant to Article 130, paragraph 4 of Legislative Decree 196/2003, processing is carried out for the direct sale of the Data Controller's own products or services to existing customers, and only for products and services like those previously contracted, using the same digital communication channel used in the current relationship.
FROM WHOM DO WE COLLECT DATA?
Where possible, we always collect personal data directly from the Data Subject.
WHAT CATEGORIES OF DATA DO WE PROCESS?
We primarily request and process only personal data classified as “ordinary”, such as name, surname, tax code, VAT number, email address, and telephone number. Providing these personal data (as specifically indicated during the establishment of the relationship) is mandatory to use our services. Failure to provide them may result in an inability to deliver the requested service, meet deadlines, or may lead to partial or total non-execution of the requested activity.
TO WHOM DO WE DISCLOSE PERSONAL DATA?
Data are processed at the Data Controller's registered and operational offices, as well as in any other place where the parties involved in the processing may be located. Your personal data may be disclosed to public bodies and competent institutions in order to comply with legal and regulatory obligations and may also be disclosed to external companies performing outsourced activities on behalf of the Data Controller, as data processors. These processors are duly accredited and authorized to process data exclusively for the above-mentioned purposes, including the proper management of the contractual relationship. All data processors are individually identified in our management system and have received appropriate instructions to ensure the rights of the data subjects, including the obligation to respect confidentiality.
HOW DO WE PROCESS THE DATA?
Your personal data will be processed by the Data Controller using both paper and digital formats. Only personnel authorized by the Data Controller will be allowed to access the data to perform processing operations or system maintenance. We adopt all appropriate technical and organizational measures to prevent unauthorized access, disclosure, alteration, or destruction. We also clarify that no automated decision-making process is used within our organization.
ARE DATA TRANSFERRED OUTSIDE THE EU?
In carrying out the activities of the Data Controller, personal data may be transferred outside the EU. The Data Controller will carry out such transfers in compliance with the safeguards provided for in Articles 44 et seq. of the GDPR. Your data will not be disclosed to unauthorized third parties for purposes other than those specified in this notice.
HOW LONG DO WE RETAIN DATA?
We will process your data for the time necessary to achieve the purposes for which they were collected and will retain them for the duration of the contractual relationship. They may also be retained after the end of the relationship for the time necessary to settle contractual obligations and comply with applicable legal requirements. At the end of the retention period, the data will be destroyed, returned, or further processed in compliance with the principle of data minimization, ensuring the protection of the data subject's rights and freedoms and always with appropriate security measures.
WHAT ARE YOUR RIGHTS?
The Data Subject has the right to request from the Data Controller access to their personal data and the rectification or erasure of such data or restriction of processing concerning them, or to object to processing, as well as the right to data portability, under the GDPR. You may request a digital copy of your data at any time or request the automatic transfer to another company. Where applicable, you may also object or withdraw previously given consent. You have the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it). Any request to exercise your rights will be assessed within the limits of Articles 23 GDPR and Articles 2-undecies and 2-duodecies of the Italian Privacy Code. To exercise these rights or request further information, please send a request via email to the Data Controller or DPO using the “Data Subject Rights Exercise Form” available in the dedicated section of the company's website.