Privacy Policy
DATEV KOINOS S.R.L. processes data provided by users in accordance with the provisions of European Regulation 679/2016 (“GDPR”). This document constitutes an information notice pursuant to Article 13 of the GDPR, for those who interact with the website owned by DATEV KOINOS S.R.L. www.auditev.com during Internet browsing.
This privacy policy applies to users browsing the website and does not concern users who decide to purchase products: in such cases, a specific privacy notice will be provided within the Terms&Conditions provided at the moment of the check out.
Following consultation of this site, data relating to identified or identifiable persons may be processed.
1. DATA CONTROLLER
DATEV KOINOS S.R.L., with registered and operational office in Milan, Corso Garibaldi 86, VAT No. IT03336420967, is the Data Controller.
2. TYPES OF DATA PROCESSED
Browsing data
The IT systems and software procedures responsible for the operation of this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes IP addresses, domain names of the computers used by users connecting to the site, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request, and other technical parameters relating to the user’s operating system and IT environment.
Such data are processed exclusively for the purpose of ensuring the proper functioning, maintenance, and security of the website and its associated IT systems.
Contact Data
Only in case of expressly given consent, email address, first name and last name provided by users during the registration process will be used by the Data Controller in order to send him commercial communications via e mail.
3. PURPOSES OF PROCESSING
The personal data referred to in point 2(a) are processed solely for the purpose of obtaining anonymous statistical information on the use of the site and to ensure its proper functioning also to ascertain possible responsibility in the event of hypothetical cybercrimes against the site.
The data referred to in point 2(b) are processed to send the user commercial communications relating to the Controller’s services and products, via e mail, based on its freely given consent.
4. LEGAL BASIS FOR PROCESSING
The personal data referred to in point 2(a) are processed by the Controller for the performance of contractual measures pursuant to Article 6(1)(b) of the GDPR, to ensure the proper functioning of the site and on the basis of its legitimate interest pursuant to Article 6 (1) (f) of the GDPR, in relation to the possible activities aimed to keep its IT systems secure, preventing unauthorized access or cyberattacks).
The personal data referred to in point 2(b) are processed by the Controller for marketing purposes, pursuant to Article 6(1)(a) of the Regulation.
5. EXTRA EU TRANSFER
No data derived from the site are transferred outside the European Union.
Personal data are processed within the European Union and are not transferred outside the European Economic Area.
Should the Controller transfer personal data outside the European Economic Area in the future, such transfers will be carried out in compliance with Articles 44 et seq. of Regulation (EU) 2016/679 and, where applicable, on the basis of appropriate safeguards, including adequacy decisions adopted by the European Commission, Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs).
6. DATA RETENTION
Browsing data (including system logs) are retained for a period not exceeding 30 days, unless further retention is necessary to investigate security incidents or comply with legal obligations.
Personal data relating to user and used by the Data Controller for marketing purposes are retained for 2 years from the collection, except in case the user withdraw the consent before, by clicking on the unsubscribe link included at the bottom of each e mail and/or exercises its right of opposition pursuant to art. 11 below; in such cases, the data will be erased before.
7. DATA PROVISION
Apart from what is specified for browsing data, whose processing is necessary to ensuring the proper functioning, maintenance, and security of the website and its associated IT systems, the provision of Contact Data is optional and marketing activities will be carried out by the Data Controller only in case of consent of the user.
Failure to provide such data will not impact the possibility to browse the website and to proceed with the purchasing of product.
8. ACCESS TO PERSONAL DATA
Personal data may be accessed by duly authorized personnel of the Controller who are involved in the management and operation of the website and related services, as well as by third-party service providers acting on behalf of the Controller and appointed as Data Processors pursuant to Article 28 of Regulation (EU) 2016/679.
Such access is limited to what is strictly necessary for the performance of the respective tasks and is granted in accordance with the principles of data minimization and confidentiality. All individuals authorized to process personal data are subject to appropriate confidentiality obligations.
In providing the Service, Datev Koinos will entrust the processing to Datev International GmbH, appointed as sub-processor for the hosting, development, management and maintenance of the technological and systems infrastructure of the Service, as well as for the statistical and technical analysis and for optimising early problem resolution processes, and Datev.it S.r.l., appointed as sub-processor by Datev Koinos in relation to the assistance services related to Auditev Care provided to the Client and/or to its end users, and as sub-processor by Datev International GmbH for the technological support and management of the Service
To obtain and consult an updated list of appointed Data Processors, you may contact: privacy@datevkoinos.it.
9. METHODS OF PROCESSING
The processing of personal data is carried out in accordance with the principles of fairness, lawfulness, and transparency.
Personal data are processed using automated tools for the time indicated in paragraph 6.
Specific security measures are implemented to ensure, among other things, the security, confidentiality, integrity, and availability of systems and services, and to prevent the risk of data loss, unlawful or improper use, and unauthorized access.
10. APPOINTMENT OF DATA PROTECTION OFFICER (DPO)
Pursuant to Article 37 of the GDPR, Datev Koinos shall designate and appoint a Data Protection Officer (DPO).
The Data Protection Officer is Eng. Paolo Pesarin, domiciled for the purposes of the appointment at the Controller’s registered office.
11. DATA SUBJECT RIGHTS
Data subjects may exercise, at any time, the rights provided for under Articles 15 to 22 of Regulation (EU) 2016/679, including:
- the right to obtain confirmation as to whether personal data concerning them are being processed and, where that is the case, access to such data (right of access);
- the right to request the rectification of inaccurate personal data and the completion of incomplete data (right to rectification);
- the right to obtain the erasure of personal data in the cases provided for by law (right to erasure);
- the right to request the restriction of processing under the conditions set out in Article 18 of the GDPR (right to restriction);
- the right to receive personal data in a structured, commonly used and machine-readable format and to transmit that data to another controller, where technically feasible (right to data portability);
- the right to object, at any time, to the processing of personal data based on the Controller’s legitimate interest, for reasons relating to their situation.
Where processing is based on consent, the data subject also has the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Data subjects also have the right to lodge a complaint with a supervisory authority, in the Member State of their habitual residence, place of work, or place of the alleged infringement.
You may exercise your rights at any time by sending:
- a registered letter with return receipt to the registered office of DATEV KOINOS S.R.L., Milan, Corso Garibaldi 86;
- an email to: privacy@datevkoinos.it.