PRIVACY NOTICE REGARDING THE PROCESSING OF PERSONAL DATA

Pursuant to Legislative Decree No. 196 of June 30, 2003 (“Personal Data Protection Code”) and EU Regulation 2016/679 (hereinafter “GDPR”), collectively referred to as (hereinafter “Privacy Policy”), we hereby inform you of the following:

Data Controller: The Data Controller is Sofin Srl, with registered office in Modena (MO), Via Bellini 70/2, registered with the Modena Chamber of Commerce under number 02876220365 and tax ID number 02876220365, in the person of its legal representative at the time (hereinafter also referred to simply as “Company”). The Data Controller can be contacted at the following email address

privacy@Carcover.it.

Purpose of the Processing: Personal data is requested, collected, and processed without your explicit consent, for the following purposes:

  • for activities strictly related to and necessary for the establishment of contractual relationships, including the collection of information prior to the conclusion of the sales contract;

  • for the management of business relationships in connection with administrative, accounting, ordering, shipping, billing, and service activities;
  • to comply with obligations established by law, a regulation, EU legislation, or an order from the Authority;
  • to exercise the rights of the Data Subject, such as the right to a legal defense.

The processing of personal data will be based on the principles of fairness, lawfulness, and transparency; such processing may be carried out within the European Union using manual, computerized, and telematic means by the Data Controller, Data Processor, and persons in charge of or authorized to process the data, with appropriate security and confidentiality measures in place and with a commitment not to disclose or communicate the data to unrelated third parties.

Legal Basis for Data Processing: The legal basis for processing for the purposes set forth in the preceding paragraph relates to the performance of the sales contract or the fulfillment of legal obligations. Under the law, consent to processing is not required where processing is necessary (i) to fulfill obligations arising from a contract or (ii) to fulfill a request for services to which the data subject is a party or (iii) to comply with legal obligations or (iv) to pursue a legitimate interest of the Data Controller.

Recipients/Categories of Recipients of Personal Data: Personal data may be disclosed, exclusively for the purposes indicated above, to the following categories of recipients:

  • individuals, companies, associations, or professional firms that provide assistance and consulting services to Company —with particular, though not exclusive, reference to matters related to accounting, administration, law, labor law, social security, taxation, and finance—who need access to the data for purposes ancillary to the performance of contracts relating to the provision of services, within the limits strictly necessary for the performance of their duties;
  • any public administration office to which records and documents are normally addressed and/or where such offices expressly request them, providing a valid reason.

These parties act as independent data controllers or data processors who have been duly appointed and instructed by the Data Controller. The list of the parties to whom the Data Subject’s data has been or may be disclosed is available to you

assignment at the Company and can be easily obtained by submitting a written request to the Data Controller.

The data subject’s personal data will not be disclosed under any circumstances.

Data Retention Period: The data in question will be retained for the period strictly necessary to fulfill the purposes for which the data subject has provided consent or, where this is not necessary, in the cases provided for by law and, therefore, until the sales contract has been fully executed and until the time limits for which retention is required by law have expired.

Rights of the Data Subject: The data subject may exercise their rights with respect to the Data Controller at any time pursuant to Articles 15–22 of the GDPR. These rights may be exercised by submitting an informal request to the Data Controller, including through a designated representative, to which an appropriate response will be provided without delay. Requests addressed to the Data Controller may be sent to the following email address: privacy@Carcover.it.

Specifically:

Access to Data and Portability: The Data Subject has the right, throughout the duration of the contractual relationship and until the data is deleted, to request from the Data Controller access to their personal data, the rectification or erasure of such data, or the restriction of processing concerning them, or to object to the processing of their data, in addition to the right to data portability. Where the legal requirements are met, the Data Subject has the right to receive the personal data concerning him or her that has been provided to the Data Controller in a structured, commonly used, and machine-readable format, as well as to transmit such data to another data controller.

Withdrawal of Consent: The Data Subject has the right to withdraw consent, if given, at any time without affecting the lawfulness of processing based on consent given prior to withdrawal. To withdraw consent to processing, simply send a notice to that effect to the following address: privacy@Carcover.it.

How to Exercise Your Rights: To exercise the rights listed above, the Data Subject may submit a request to the Data Controller using the contact information provided in this document. Requests are free of charge, unless they are particularly burdensome, and will be processed by the Data Controller as quickly as possible, and in any case within one month.

Appeal to the Data Protection Authority: If you believe there has been a violation of the regulations governing the processing of personal data, you have the right, as the data subject, to file a complaint with the Data Protection Authority in accordance with the procedures and deadlines outlined on the Authority’s website: www.garanteprivacy.it.