NOTICE PROVIDED PURSUANT TO ARTICLES 13-14 OF THE GDPR (GENERAL DATA PROTECTION REGULATION) 2016/679
Pursuant to the GDPR regulation, the processing of Data will be based on the principles of fairness, lawfulness, transparency, data minimization, and protection of your confidentiality and rights.
1. Data Controller
Viking S.r.l., with registered office at Via del Lavoro 20, 51013 Chiesina Uzzanese (Pistoia), Italy, VAT No. 01262180472 (the “Company”, “Viking” or the “Controller”), guarantees compliance with personal data protection regulations by providing the following information regarding the processing of data communicated or otherwise collected while browsing this website.
2. Processed Data, Purposes, and Legal Basis for Processing
Personal Data collected automatically when browsing our Websites.
The IT systems and software procedures used to operate our websites acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. These data (such as domain names, IP addresses, operating systems used, browser device types used for connection) are not accompanied by any additional personal information and are used to:
1. obtain anonymous statistical information on website usage;
2. manage monitoring requirements regarding the use of the website;
3. ascertain liability in the event of hypothetical cybercrimes.
The legal basis legitimizing the processing of such data is the necessity to make the website functionalities available following the User’s access.
Data voluntarily provided by the User
Personal data voluntarily provided by the User are collected and processed for the following purposes:
a) to carry out customer relationship activities based on contractual agreements – existing or under negotiation – or to respond to a specific request or topic for which interest has been expressed;
b) for administrative purposes and compliance with legal obligations such as accounting and tax requirements, or to comply with requests from judicial authorities;
c) with specific consent (Consent to informational communications), to send informational communications or invitations to meetings relating exclusively to Viking Products and Services; this consent excludes in any case authorization to send commercial, promotional, advertising, or profiling communications;
d) with specific consent (Consent to promotional communications), to send promotional and commercial communications relating exclusively to Viking products and services; this consent excludes in any case authorization to send advertising communications, including those from third parties;
e) in the case of submitting a curriculum vitae, exclusively for personnel selection purposes within Viking.
The legal basis legitimizing the processing is the execution of a contract to which the data subject is party or the execution of pre-contractual measures adopted at the request of the same. In the cases expressly indicated, the legal basis is the consent freely given by the data subject.
Data collected through the E-mail Marketing Platform
For complete information, please note that when sending communications, Viking uses E-mail Marketing Platforms with servers located in Europe, which, through statistical tracking systems (for example web beacons), allow detection of the opening of a message, clicks made on hyperlinks contained within e-mails, from which IP address or with which browser type the e-mail is opened, and other similar details. The collection of such data is functional to the use of the platforms and constitutes an integral part of the functionalities of the system chosen by Viking for E-mail Marketing activities.
The legal basis legitimizing the processing of Personal Data voluntarily provided by the User while browsing the Website or automatically collected when we send e-mails or communications are:
1. a contract to which the data subject is party;
2. the authorization expressly given by the data subject to receive information on Viking services (Consent to informational communications);
3. the authorization expressly given by the data subject to receive commercial information on Viking services (Consent to promotional communications).
The data present on the E-mail Marketing Platform are minimal and strictly related to the grouping of recipients exclusively according to the points above.
3. Nature of Data Provision
Apart from what is specified for browsing data and data collected through the E-mail Marketing Platform, the provision of data:
1. with regard to the purposes referred to in letters a), b) and f) is optional, but any refusal will make it impossible for Viking to fulfill the contractual obligations undertaken.
2. with regard to the purposes referred to in letters c), d) and e) is also optional and their use is subject to the release of explicit consent by the User; any refusal will make it impossible for Viking to send newsletters and informational material regarding its services, invitations to events and initiatives, or replies to questions submitted by the User.
4. Processing Methods and Data Retention Periods
The collected data will be processed through electronic or otherwise automated, IT and telematic tools, or through manual processing strictly related to the purposes for which the personal data were collected and, in any case, in such a way as to ensure their security at all times.
Personal Data will be managed exclusively on servers located within the European Union and protected by GDPR Regulation 2016/679.
The data are retained for the time strictly necessary to manage the purposes for which they are collected, in compliance with current regulations and legal obligations, in accordance with the principle of data minimization.
In any case, Viking applies rules that prevent indefinite data retention and therefore limits the retention period to 3 years from the granting of authorization or from the termination of the contract for the services requested from Viking.
5. Authorized Persons, Data Processors and Data Disclosure
The processing of collected data is carried out by internal Viking personnel specifically identified and authorized for processing according to specific instructions provided in compliance with current regulations.
The collected data, where necessary or instrumental to the execution of the indicated purposes, may be processed by third parties appointed as External Data Processors or, depending on the case, communicated to them as independent Data Controllers, specifically:
1. companies belonging to our corporate group for the purposes referred to in point 2 letters a), b) and f), in their capacity as External Data Processors authorized for this purpose by Viking;
2. individuals, companies, associations, or professional firms providing assistance and consultancy activities to our Company, for the purposes referred to in point 2 letters b) and f);
3. companies, entities, associations that perform services connected and instrumental to the execution of the above purposes (analysis and market research services exclusively aimed at activities carried out by Viking and maintenance of IT systems).
The collected data, in any case, will never be transferred outside the European Union, nor to third-party companies beyond what is stated herein or for purposes other than those indicated.
6. Profiling Activities
The website does not carry out any type of automated profiling nor does it operate in a way that displays content related to the interests and behavior shown by the User during browsing. Likewise, it does not contain elements or third-party technical tools that adopt such mechanisms to deliver advertising or commercial content unrelated to Viking.
8. Rights of the Data Subject
At any time, it is possible to access your Personal Data, object to processing, or request the deletion, modification, or updating of all personal information collected by Viking, exercising the right to restriction of processing and the right to data portability, by sending:
- a registered letter with return receipt to Viking S.r.l. Via del Lavoro n.20 – 51013 Chiesina Uzzanese (PT);
- an e-mail to the certified PEC address viking@legalmail.it.
9. Data Protection Officer and Authorized Personnel
The Data Controller has appointed the internal Data Protection Officer, who can be contacted at the following e-mail address privacy@vikingitaly.com;
The updated list of personnel authorized to process data is kept at the registered office of the Data Controller.
