INFORMATION ON THE PROTECTION OF PERSONAL DATA – GENERAL DATA PROTECTION REGULATION Institution SRL, in the course of its activities, pays the utmost attention to the security and confidentiality of personal data of users who visit or use the services offered on its website. The following policy has been drafted in compliance with the provisions of the new Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. WHAT PERSONAL DATA MAY BE COLLECTED Institution SRL may collect the following categories of personal data about you: • Registration Data – Information relating to biographical data (name, surname, gender, address, tax code, VAT number) and contact details (telephone number, mobile number, email address, fax number). • Other Personal Data – Information you provide when filling in the fields indicated in the registration forms. • Purchase Data – Information relating to the type of services you have purchased. • Site Usage Data – Information on how the site is used, including the opening or forwarding of our communications, as well as data collected through cookies. No personal data is collected for this purpose. No use is made of cookies for the transmission of personal information, nor are persistent cookies or any user-tracking systems used. If you provide personal data of third parties, you must first ensure that the individuals concerned have read this Privacy Policy. We also ask you to help us keep your personal data up to date by informing us of any changes. PURPOSES FOR WHICH YOUR PERSONAL DATA MAY BE USED The processing of personal data must be legitimized by one of the legal bases provided under applicable data protection regulations, as described below:
Institution SRL, such as accreditation, newsletter subscription, and activity enrollment. 2. b) Sale of services and products available online Institution SRL processes your Registration Data and Account, as well as Purchase Data, in order to complete the purchase of online services and products. Legal basis: Fulfillment of contractual obligations. Providing this data is necessary to finalize the online purchase; otherwise, it cannot be completed. 3. c) Marketing to provide promotional offers Institution SRL may use your biographical and contact data for marketing and advertising purposes, including informing you of promotional campaigns through automated contact means (email, SMS, mass messaging tools, etc.) and traditional methods (e.g., calls from an operator). 4. d) Customer satisfaction surveys Institution SRL may use your biographical and contact data to conduct surveys to assess customer satisfaction with the services provided. You can withdraw your consent at any time by emailing institutionsrl@gmail.com. 5. e) Compliance with legally binding requests Institution SRL may process your contact data to comply with a legal obligation and/or defend its rights in legal proceedings. Legal basis: Legal obligations that Institution SRL is required to fulfill. Note: You can withdraw your consent to the use of your data at any time by sending an email to info@institution.it or by using the dedicated link to delete your data. HOW WE KEEP YOUR PERSONAL DATA SAFE Institution SRL uses a wide range of security measures to improve protection and maintain the safety, integrity, and accessibility of your personal data. Your full personal data is stored on our secure servers (or in secure paper copies), or those of our suppliers or business partners, and is accessible and usable only under our security standards and policies (or equivalent standards for our suppliers or business partners). TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION The personal data collected by Institution SRL may be transferred to countries outside the European Union or the European Economic Area. Such countries may not offer a level of personal data protection equivalent to that guaranteed within the EU. In such cases, transfers will be carried out in full compliance with applicable data protection regulations, adopting all necessary measures to ensure adequate data protection. These measures include, where necessary, the use of Standard Contractual Clauses approved by the European Commission, which impose specific
contractual obligations on data recipients in third countries to ensure the security and protection of personal information.
HOW LONG WE KEEP YOUR PERSONAL DATA We keep your personal data only as long as necessary to fulfill the purposes for which it was collected or for any other legitimate related purposes. If personal data is processed for two different purposes, we will retain it until the longer retention period has expired. However, we will no longer use the data for the purpose whose retention period has ended. We restrict access to your data to only those who need to use it for relevant purposes. Any of your personal data that is no longer necessary, or for which there is no legal basis for retention, will be irreversibly anonymized (and may be retained in this form) or securely destroyed. Here are the retention periods for each of the purposes listed: • Site access and account creation: Data may be kept for the duration of the relationship and no more than 10 years thereafter. • Contractual obligations: Data may be kept for the duration of the contract and up to 10 years after, to verify any outstanding obligations (e.g., invoices). • Marketing purposes: Data may be kept for 24 months from the last time you gave consent (unless you opt out of receiving future communications). • Customer satisfaction surveys: Data may be kept for 24 months from the last time you gave consent (unless you opt out). • In case of legal dispute: Data may be retained for as long as necessary to pursue or defend legal claims.
WHO WE MAY SHARE YOUR PERSONAL DATA WITH Your personal data may be accessed only by authorized employees and external providers designated, where necessary, as data processors, who support the provision of our services. Please contact us by email if you would like to view the list of data processors and other parties with whom your data may be shared. Please note: To complete purchases on the site, you will be redirected to platforms that provide these services. The data you provide on such platforms will be processed exclusively by the operators of those platforms, as independent data controllers, with no prior notice to Institution SRL
CONTACTS If you have any questions about the processing of your personal data, please send an email to info@institution.it.
YOUR RIGHTS REGARDING PERSONAL DATA AND YOUR RIGHT TO LODGE A COMPLAINT Under certain conditions, you have the right to request: • Access to your personal data • A copy of your personal data • Correction of your data • Deletion of data where there is no legal basis for retention • Objection to processing where permitted under applicable law • Restriction of how we process your personal data • Withdrawal of previously given consent The exercise of these rights is subject to some exceptions aimed at safeguarding the public interest (e.g., the prevention or detection of crimes) and our own interests (e.g., professional confidentiality). If you exercise any of the above rights, we are obliged to verify that you are entitled to do so and will generally respond within one month. For any complaints or concerns about the way your personal data has been handled, we will do our best to address them. However, if you wish, you can contact the data protection authority (Data Protection Authority) using the contacts available at www.garanteprivacy.it. CHANGES TO THE POLICY This privacy policy may be subject to changes over time, including in relation to updates in applicable regulations or the introduction of new services offered through the website. Any updates will be published on this page and, where relevant, communicated to users through appropriate channels (e.g., email or website notifications). Users are therefore encouraged to periodically review this page to stay informed about any updates.