MOD P 01 _ Rev.3
POLICY ON THE PROCESSING OF PERSONAL DATA
PURSUANT TO ART. 13 OF REGULATION (EU) 2016/679 (THE “GDPR”)
SINAPSI Srl
Dear Customer, this policy has been made available by SINAPSI S.r.l., with registered office at Via delle Querce no. 11/13, Bastia Umbra (PG), Italy, Tax Code and VAT no. 02727730547 (hereinafter, the “Controller”), as the Controller (in terms of processing personal data). This policy is to inform you, pursuant to article 13 of Regulation (EU) no. 2016/679 (hereinafter, the “GDPR”), that the data you have already provided and that has been acquired, and any data you may provide in the future, as the "Data Subject", shall be processed in compliance with the principles of correctness, lawfulness, and transparency, and in such a way as to safeguard and protect your privacy and your rights.
1) The Controller
The Controller is “SINAPSI S.r.l.”, with registered office at Via delle Querce no. 11/13, Bastia Umbra (PG), Italy, Tax Code and VAT no. 02727730547, in the name of its legal representative, Massimo Valerii.
The updated list of external Processors, the parties authorised to perform processing, and the system administrators is kept at the Controller's registered office.
2) Categories of personal data processed
The Controller processes the personal data which may be communicated and collected (i) when a Data Subject registers with a Sinapsi application, and/or (ii) through any relationship with a Data Subject, and/or (iii) when a Data Subject concludes a contract to purchase any of the Controller's products or services.
Specifically, the following Personal Data may be subject to processing:
Identifying Data: data which allows the Data Subject to be directly identified, such as personal details (e.g., first name, last name, tax code, VAT no., address, etc.), and provided to the Controller and processed for the purposes of concluding and managing a contract;
Consumption Data: data relating to the supply (POD, Contracted Power, Available Power) and the levels of consumption recorded, as collected, and processed during the term of the contract;
Technical Data and energy consumption characteristics: data relating to the characteristics of the real estate property, the size of the dwelling, the composition of the nuclear family, the presence of any specific categories of occupations, and the presence of any electrical appliances;
Economic and Financial Data: data necessary for payments (e.g., IBAN) or that prove a payment has been made (payment identification details), and any other piece of data relating to the customer's solvency and timeliness;
Contact Data: contact information such as, for example, landline and/or mobile telephone number(s), email address, as provided to the Controller when concluding a contract or during its term, or data collected when a Data Subject registers with a Sinapsi application or acquired by the Controller, and which allows the Data Subject to be contacted for the purposes of managing the contractual relationship and/or providing services tailored to their needs;
Reserved Area Data: access to the Reserved Area of a Sinapsi application is only permitted to registered users (customers) through their "Profiling". In this case, the user is asked for certain “registration data”, which is necessary for the registration process, to access reserved areas, and to make use of the services offered.
Navigation Data: the IT systems and software procedures used to run and use the website and the applications acquire, as part of their normal operation, certain pieces of personal data which allow the user to be identified. The transmission of this data is inherent to the use of internet communication protocols. This type of data includes: technical cookies, validation and authentication information, the IP address(es) and domain name(s) of the device(s) used by the user to connect to the site or use the application, the URI (Uniform Resource Identifier) of the resources requested, the date and time of access, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server, and other parameters relating to the user's operating system and IT environment, the transmission of which is inherent to the use of web communication protocols or is useful in order to better manage and optimise the system to send data and emails.
3) The subject of the processing
For the purposes of this policy, the phrase, "processing Personal Data", shall mean any operation or set of operations, performed manually and/or with electronic or telecommunication means, with the aid of automated processes and applied to the Personal Data, such as the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
4) The purposes for processing and the Legal Bases
The legal bases for processing are provided, in accordance with the specific purpose pursuant, in article 6, para. 1, lett. a), b), c) and f) of the GDPR
A) For the purposes listed below, any failure to provide the requested data will make it impossible to handle a Data Subject's requests and will make it impossible to provide the services requested by the same and, specifically:
to establish a contractual relationship with the Company. Legal basis: art. 6, para. 1, lett. b) of the GDPR – the fulfilment of pre-contractual measures and the performance of the contract.
to conclude contracts for the sale of the Controller's products, provide services, including the ability to provide support services and post-sales support. Legal basis: art. 6, para. 1, lett. b) of the GDPR – the performance of the contract.
to fulfil pre-contractual, contractual, and tax obligations arising from existing relationships with the Data Subject. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – the performance of the contract + Art. 6, para. 1, lett. c) of the GDPR – tax and regulatory obligations.
to allow the use of all the functions and features of the system and to monitor their correct functioning. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – necessary for the provision of the service; lett. f) legitimate interest based on technical and security aspects.
to allow the Data Subject to register and/or access a reserved area. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – the performance of the contract.
to verify the eligibility of Points of Delivery (PODs) for the services requested by the Data Subject, including by querying systems, platforms or interfaces made available by distributors or by other authorised parties in the energy sector. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – the fulfilment of pre-contractual measures adopted at the Data Subject's request and the performance of the contract.
to allow the association, modification, and management of the connection parameters between PODs, electronic meters, user devices, and any other equipment necessary for the provision of the services requested by the Data Subject. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – performance of the contract and the supply of the services requested by the Data Subject.
to allow the activation, configuration, interruption, and deactivation of the services requested by the Data Subject to monitor, remotely read, automate, and manage consumption. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – performance of the contract and the supply of the services requested.
to develop, improve, verify, and optimise the performance of the algorithms, application platforms, and digital services offered by the Controller, including through the aggregate analysis of the data collected. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – the Controller's legitimate interest to continuously improve its services, the features and functions, and the security of information systems.
to verify the creditworthiness, including in terms of the timeliness of payments, prior to or in the course of the contractual relationship. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – the Controller's legitimate interest in managing commercial risk.
to detect, prevent, mitigate, and investigate any fraudulent or illegal activity in relation to the services supplied. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – legitimate interest in security and fraud prevention.
to fulfil the obligations established by law, regulation, EU legislation or any order issued by a competent Authority (such as, for example, regarding anti money-laundering). Legal basis: Art. 6, para. 1, lett. c) of the GDPR
to exercise the Controller's rights, for example, the right to defend itself in a court of law. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – legitimate interest.
to handle a contact request received by email or through the contact form found on the site. Legal basis: Art. 6, para. 1, lett. b) of the GDPR – pre-contractual measures requested by the Data Subject.
Personalisation of the services and an analysis of consumption: data relating to the use of the services, consumption, preferences, and the methods of interaction with the platforms and tools made available by the Controller is processed for the purposes of personalising the services provided, configuring the features and functions requested by the Data Subject, providing technical support, optimising the performance of systems, performing functional analyses, and ensuring the correct fulfilment of the contractual obligations. Processing is aimed at the continuous improvement of the services, optimising performance, and developing new feature and functions. Legal basis: - Art. 6, para. 1, lett. b) of the GDPR – the performance of the contract and Art. 6, para. 1, lett. f) of the GDPR – the Controller's legitimate interest in improving the service.
to allow the technological evolution and maintenance of the applications. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – legitimate interest in the continuation and improvement of the service.
to allow hypothetical computer crimes to be investigated. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – legitimate interest.
to allow the statistical analysis of the use of the applications, including to monitor their correct function and to safeguard security aspects. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – legitimate interest.
to allow monitoring and assessment regarding the use of the applications by users. Legal basis: Art. 6, para. 1, lett. f) of the GDPR – legitimate interest.
B) Providing the Personal Data requested is voluntary with regard to pursuing the additional purposes listed below and, as such, any failure to provide such data for these purposes shall have no impact whatsoever on the ability to conclude or manage a contract. Consent for these purposes is always optional and, where given, may be withdrawn at any time in accordance with the methods described in the section of this policy entitled, "The Data Subject's rights":
Marketing in terms of:
sending informative newsletters, SMS messages, push notifications and/or informational and promotional email communications, by S.r.l. in relation to its own initiatives as well as those of its subsidiaries and affiliates.
sending special offers and promotions by SMS message and/or email, as well as newsletters relating to special offers and promotions regarding the Company's products and services.
sending invitations to events or training courses by SMS message and/or email, as well as newsletters relating to invitations to events, workshops organised by Sinapsi or by a third party, and including training courses on the Company's products.
Legal basis: Art. 6, para. 1, lett. a) of the GDPR – the Data Subject's consent.
assessing the level of satisfaction on the quality of the products purchased (Customer Satisfaction), by Sinapsi sending questionnaires and/or making telephone calls aimed at improving communication, the services provided, and targeting commercial proposals in line with the Data Subject's interests and tastes. Legal basis: Art. 6, para. 1, lett. a) of the GDPR – the Data Subject's consent.
Profiling consumption for commercial development or marketing purposes or for personalised offers in addition to the service requested. Legal basis: Art. 6, para. 1, lett. a) of the GDPR – the Data Subject's consent.
Transferring or communicating consumption data to third parties who use it for their own independent commercial purposes as autonomous Controllers. Legal basis: Art. 6, para. 1, lett. a) of the GDPR – the Data Subject's consent.
5) Methods of processing
Personal Data may be processed using the operations indicated under art. 4, no. 2) of the GDPR and, specifically, the collection, recording, organisation, storage, structuring, consultation, handling, alteration, selection, retrieval, alignment, use, combination, disclosure, transmission, dissemination or otherwise making available, blocking, communication, erasure, and destruction of data.
The data collected will be processed manually, with telecommunication and computer means and/or with electronic or, in any case, automated tools. The logic employed will be strictly related to the purposes for which the Personal Data was collected and, in any case, in compliance with the security provisions under art. 32 of the G.D.P.R. 2016/679.
The Controller will process Personal Data for the time necessary to achieve the purposes referred to above and, in any case, for no longer than 10 years from the termination of the relationship for Service Purposes and for no longer than 5 years from the date the data was collected for Marketing Purposes.
Once these terms have expired, the data will be destroyed, deleted or rendered anonymous, in line with the technical deletion and backup procedures.
6) Recipients of data
Data may be processed by external parties operating as Controllers such as, purely by way of example, banking institutions, supervisory and control authorities and bodies, and, in general, parties, both public and private, duly authorised to request such data.
A Data Subject's data may be processed for the purposes given under point 4) of this policy:
by the Controller's employees and collaborators, in their capacities as parties authorised to perform processing and/or by system administrators;
by external parties appointed as Processors, who have been provided with suitable operating instructions. These parties are, essentially:
marketing companies and companies used for commercial campaign promotion services;
companies that offer management and maintenance services for information systems;
professional firms for managing tax and accounting activities, and for legal advice;
consulting firms for managing the administration of personnel;
companies operating in the sectors of energy, technology, energy efficiency, research and development, and digital services and partners operating as autonomous Controllers, subject to the Data Subject's consent.
7) Transferring Personal Data to a country outside the European Union
Data Subjects should note that data is stored on servers located in countries within the European Union.
8) The Data Subject's rights
With regard to the data processed under this policy, Data Subjects may, at any time, exercise their right to:
Access (art. 15 of Regulation (EU) no. 2016/679). The right to obtain confirmation as to whether or not Personal Data concerning the Data Subject is being processed and, where that is the case, access to the Personal Data which concerns them;
Rectification (art. 16 of Regulation (EU) no. 2016/679). The right to obtain, without undue delay, the rectification of the inaccurate Personal Data concerning the Data Subject and/or to have any incomplete Personal Data supplemented;
Erasure (art. 17 of Regulation (EU) no. 2016/679). The right to obtain, without undue delay, the erasure of the Personal Data concerning the Data Subject. The right to erasure does not apply to the extent that processing is necessary to fulfil a legal obligation or to perform a task carried out in the public interest or to establish, exercise or defend a right in a court of law;
Restrict processing (art. 18 of Regulation (EU) no. 2016/679). The right to obtain a restriction on the processing;
Portability (art. 20 of Regulation (EU) no. 2016/679). Understood as the right to obtain from the Controller the Personal Data concerning the Data Subject in a structured, commonly used, and machine-readable format in order to transmit this data to another Controller without hindrance;
Object to processing (art. 21 of Regulation (EU) no. 2016/679). The right to object to the processing of the Personal Data concerning the Data Subject;
Withdraw consent to processing (art. 7, para. 3 of Regulation (EU) no. 2016/679). Being without prejudice to the lawfulness of any processing carried out on the basis of the consent obtained prior to withdrawal and which cannot, clearly, concern those cases in which processing is necessary, for example, to fulfil a legal obligation to which the Controller is subject or to perform a task carried out in the public interest or connected to the exercise of official authority vested in the Controller;
File a complaint with a Supervisory Authority (art. 51 of Regulation (EU) no. 2016/679).
Data Subjects may exercise their rights free of charge pursuant to article 12 of the GDPR. However, in the event of manifestly unfounded or excessive requests, including repeated requests, the Controller may charge the Data Subject a reasonable fee, given the administrative costs incurred by the Controller to handle the Data Subject's requests. Alternatively, the Controller may refuse to respond to such requests.
Lastly, Data Subjects should note that the Controller may request further, necessary information in order to confirm their identity.
9) Methods by which to exercise these rights
Data Subjects may, at any time, exercise their rights by sending:
a registered letter with return receipt to: SINAPSI s.r.l Via delle Querce no. 11/13 – 06083 Bastia Umbra (PG), Italy
an email to: privacy@sinapsitech.it
10) Minors
The Controller's Services are not intended for individuals under the age of 18. The Controller will not intentionally collect the Personal Data of minors. In the event that information concerning a minor is inadvertently acquired, the Controller will delete this information promptly.
I declare that I have read and that I understand the Privacy Policy