Privacy Policy
The purpose of this Privacy Policy is to describe how CRIF Synesgy Ratings s.r.l. manages this website with regard to the processing of the personal data of users who access it.
This is a general notice provided in accordance with the provisions of the EU General Data Protection Regulation No 679/2016 (“GDPR” or “Regulation”) and all other applicable laws for all those who visit the website.
Should users decide to use specific services, they will be provided with a specific and detailed privacy notice in accordance with Articles 13 and/or 14 of the GDPR and, where applicable, specific consent to the processing of their personal data will be requested.
The “Controller”
Following access to and use of this website, data relating to identified or identifiable individuals may be processed.
The Controller for the personal data collected is CRIF Synesgy Ratings s.r.l., with its registered office at Via Beverara 21, 40131 Bologna.
You may contact the Controller at the above postal address or via the following email addresses: Certified email (PEC): crifsynesgyratings@pec.crif.com
Place of data processing
Data processing relating to the data collected from visitors to the website is carried out at the premises of CRIF Synesgy Ratings s.r.l., as notified to the Supervisory Authority and in accordance with the provisions of the GDPR and all other applicable legislation. Personal data is handled only by individuals with appropriate technical expertise – employees or contractors – who have been specifically trained and designated as data processors.
Methods of processing
Data will be processed lawfully and fairly, in such a way as to ensure its security and confidentiality, in accordance with the provisions of the GDPR and all other applicable laws. Personal data will be processed using electronic or otherwise automated means.
Categories of personal data processed
With regard to browsing data, the IT systems and software procedures used to operate this Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the website, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, and other parameters relating to the user’s operating system and IT environment.
The optional and voluntary sending of emails to the addresses indicated on the Website or the completion of the dedicated contact form entails the collection of further personal data from the user, as specified therein (e.g. first name, surname, email address, telephone number, company name, VAT number, address, postcode, town, county, country), which are necessary to respond to their enquiries.
Finally, the Website features specific ‘buttons’ (known as ‘social buttons/widgets’) displaying the icons of social networks (e.g. LinkedIn, Facebook) and other web services (e.g. YouTube, etc.). These buttons allow users browsing the Website to access the relevant social networks with a single ‘click’. In such cases, the social network and web services collect data relating to the user, whilst the Controller will not share any browsing information or user data collected via its own website with the social networks and web services accessible via the social buttons/widgets. These services set “third-party cookies”. By clicking on the orange button in the top right-hand corner of this page, or by consulting our cookie policy [insert hyperlink to cookie policy], you can find further information about the third-party cookies present on the website.
Use of the website and purposes of processing
Your data may be processed for:
- carrying out the operations that enable navigation between the pages of the website. The Controller, like most website owners, needs to process users’ personal data collected automatically or provided by users themselves through their browsing or use of the Website to enable users to access and use the Website. This Privacy Policy, therefore, relates exclusively to the Website and does not cover other websites, pages or online services accessible via hyperlinks that may be published on it;
- carrying out operations strictly necessary to provide the services or to respond to and/or manage, where applicable, requests from users via the contact form on the Website’s home page, as well as to arrange appointments for the sales team where necessary.
- statistical analysis of aggregated data relating to the Website’s performance;
- direct marketing activities and commercial communications regarding the products and services of CRIF Synesgy Ratings s.r.l. and other companies within the CRIF Group. If, by specifically ticking the relevant tick box, the user declares/consents to receiving information, commercial communications, direct sales offers or market research regarding the products or services provided via the Website, the user’s data will be processed for this purpose. Such communications may be sent using traditional methods (telephone/post) or automated methods (email, fax, text message, etc.), always in accordance with the preferences previously expressed by the user. Following the initial telephone or email contact, should the user decide not to subscribe to any service or purchase any product, or indicate that they do not wish to be contacted again, the Controller will delete the user’s data. Similarly, users may choose to stop receiving any commercial communications at any time by using the opt-out link at the bottom of each message and, in any case, by exercising their right to withdraw consent.
- To provide the newsletter service. By ticking the relevant tick box, the user declares/consents to receiving updates on the Controller’s activities via the Website; the user’s data will also be added to the Website’s mailing list so that they may receive the relevant newsletter.
The data may also be processed for the purposes required from time to time, based on the service requested by the customer of CRIF Synesgy Ratings s.r.l. For each service requested by the customer of CRIF Synesgy Ratings s.r.l., a specific privacy notice will be provided, setting out the purposes of the processing in detail.
Legal basis for processing
The processing of the user’s personal data will be carried out on the basis of one or more of the following grounds for lawfulness. In particular, processing carried out for the purposes referred to in:
points (a) and (b) mentioned above, is based on the need to fulfil requests for the provision of a service or to respond to a request from the user. Such processing is, therefore, strictly necessary and connected to a pre-contractual stage at the data subject’s request and/or contractual in nature, or necessary to respond to a specific request from the user pursuant to Article 6(1)(b) of the GDPR. In this regard, the personal data collected from time to time via the Website is necessary. Should the user choose not to provide such data, it will not be possible to provide the service or respond to requests;
as regards point (c) mentioned above, the legal basis, to the extent that it is proportionate and necessary, is the Controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR, consisting of improving performance and verifying the correct functioning of the Website. In this regard, we also invite you to consult the Website’s Cookie Policy.
With regard to points (d) and (e) mentioned above, the Controller will use the user’s data for this purpose only following the user’s prior and specific consent. Such consent is optional and does not affect the provision of any further services requested.
You have the right to withdraw your consent for the marketing and newsletter purposes referred to in points (d) and (e) at any time, without this affecting the lawfulness of the processing based on the consent given prior to withdrawal; you also have the right to object to processing for the marketing and newsletter purposes referred to in points (d) and (e), even in part, or in relation to commercial information and offers, advertising and promotional material concerning CRIF’s own services, where such processing is carried out by automated means.
The data will be processed on the basis of different legal grounds for processing, depending on the specific service provided by CRIF. For each service requested by a CRIF customer, a specific privacy notice will be provided detailing the applicable legal basis.
Recipients of personal data
The Controller, for the same purposes indicated under ‘Use of the website’ and ‘Purposes of processing’ in this Privacy Policy and/or in any event for purposes strictly functional to the services provided by the Website, may disclose the user’s data to parties acting as data processors pursuant to Article 28 of the GDPR, who will carry out or provide specific services such as:
- Hosting and back-end infrastructure (these services are designed to host data and files that enable the Website to function and to process data in order to allow the user to access and use the Website)
- Shipping and logistics
- Website administration (administrative, sales, marketing and legal staff, as well as system administrators).
- Cookie management via an external provider.
The user may at any time request an up-to-date list of data processors from the Controller.
Data may be disclosed to various categories of recipients, depending on the service requested by the CRIF Synesgy Ratings client. For each service requested by the CRIF Synesgy Ratings client, a specific privacy notice will be provided detailing the recipients of the personal data.
Transfer of personal data
Generally, data provided by CRIF Synesgy Ratings’ customers will not be transferred outside the European Economic Area. However, personal data may be transferred to a country outside the European Economic Area, in accordance with the conditions set out in Chapter V of the GDPR. In particular, such a transfer may take place without specific authorisation if the third country to which the transfer is made is among those which, according to the European Commission, ensure an adequate level of protection. In the absence of such an adequacy decision adopted by the European Commission, such transfers to third countries may be carried out by adopting the appropriate safeguards referred to in Article 46 of the Regulation, on the basis of which the aforementioned transfer of personal data takes place. In the absence of an adequacy decision or appropriate safeguards, the transfer of personal data to third countries may be carried out provided that the conditions and further requirements laid down in the GDPR are met, including the possibility of making use, in specific situations, of the derogations provided for in Article 49 of the GDPR. Furthermore, such a transfer may take place on the basis of the individual service provided by CRIF or following the installation of third-party cookies. For each service requested by a CRIF customer, a specific privacy notice detailing the transfer will be provided; similarly, the Cookie Policy allows users to review the privacy notices of the third-party controllers of the relevant cookies, manage their installation and, where applicable, opt out. In any event, with regard to the services provided by CRIF, should personal data be transferred outside the European Union, the transfer will be carried out in accordance with the provisions of the GDPR and all other applicable laws (as will be indicated, from time to time, in the specific privacy notices).
Provision of data
You are free to provide the personal data necessary to enable CRIF Synesgy Ratings s.r.l. to provide the requested services.
Failure to provide such data may make it impossible for the undersigned company to provide the requested information or services.
Retention period
For each service or initiative requested by a CRIF customer, a specific privacy notice will be provided detailing the retention period for personal data or the criteria used to determine that period.
CRIF processes and retains browsing data for the time required to fulfil the purposes for which it was collected. Therefore:
- Data collected for purposes necessary for the performance of a contract between the Controller and the user will be retained until the performance of that contract or request has been completed, and for the duration of its processing or the term of the contract.
- where processing is based on the user’s consent, such as for subscribing to marketing communications, the Controller may retain personal data for a maximum period of 5 years unless such consent is withdrawn;
- where processing is based on the user’s consent, such as for subscribing to the newsletter, the Controller may retain personal data for a maximum period of 24 months or until such consent is withdrawn or the user unsubscribes from the newsletter.
- Furthermore, the Controller may be obliged to retain personal data for a longer period in order to comply with a legal obligation or to retain it on the basis of its legitimate interest in the management of any ongoing litigation or pre-litigation matters.
As regards browsing data, the Controller will delete such data 12 months after the last online interaction relating to the Controller’s communications or to content published on the Website, where the Controller has direct evidence of such interaction (e.g. clicks, opens, replies). For information regarding the retention periods for data processed via cookies, please consult the Website’s relevant cookie policy and/or the orange button in the top right-hand corner of this page.
CRIF Synesgy Ratings retains personal data for the shortest possible period required by the service provided to CRIF Synesgy Ratings’ clients or as required by applicable law. For each service requested by a CRIF Synesgy Ratings client, a specific privacy notice will be provided detailing the retention period for personal data or the criteria used to determine that period.
Cookies
For details regarding the use of cookies on this website, please refer to the Cookie Policy available on this website.
Rights of data subjects
We inform you that, in accordance with the GDPR, subject to the conditions of lawfulness and the manner in which the processing is carried out, where the relevant conditions are met, you may exercise the following rights: to access your personal data, to request its rectification or erasure, or to restrict its processing. You also have the right to object to the processing, as well as the right to request data portability. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, in accordance with Article 22 of the Regulation. Furthermore, you may withdraw your consent at any time, it being understood that the withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
In any event, for every service requested by a customer of CRIF Synesgy Ratings s.r.l., a specific information notice will be provided detailing the rights that may be exercised and the procedures for doing so.
In such cases, requests must be sent to CRIF Synesgy Ratings s.r.l., via Beverara 21, 40131 Bologna, certified email (PEC): crifsynesgyratings@pec.crif.com
The data subject may also lodge a complaint with the Italian Supervisory Authority by following the instructions at the following link: http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524.
Data Protection Officer
If you have any questions regarding the processing of your personal data, you may contact the Data Protection Officer using the following contact details:
Changes to this Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy at any time by informing users on this page and, where possible, on the Website. Please therefore check this page regularly, referring to the date of the last update shown at the bottom.