Privacy policy

Please review this information regarding privacy.

The SELEX website (www.selexgc.it), hereinafter the “Website”, is owned by SELEX Gruppo Commerciale S.p.A., hereinafter “SELEX”, which manages it in its own name and on its own behalf, as well as in the interest of its member companies (hereinafter, the “Members”).

The Website redirects to the brand websites for certain specific functionalities, such as the “Submit Application” section; the privacy notices regarding the processing of personal data for such functionalities are therefore provided by the individual Members, acting as independent data controllers.

This Privacy Policy refers exclusively to the processing of personal data carried out by Selex in its capacity as “Data Controller” and describes how Selex manages the Website in relation to the processing of personal data relating to suppliers and member companies, as well as customers/users who access it (hereinafter, the “Data Subjects”), specifying which personal data are processed and for what purposes.

1. DATA CONTROLLER

The Data Controller is: SELEX, with registered office at Via Cristoforo Colombo 51 – 20090 Trezzano sul Naviglio (MI), Italy, VAT No. 04218940155, Milan Companies Register No. 996807, Share Capital €1,000,000.00 fully paid, toll-free number 800 992992.
 

2. DATA PROTECTION OFFICER (DPO)

The Data Protection Officer (“DPO”) can be contacted at the e-mail address: dpo@selexgc.it

3. CATEGORIES OF PERSONAL DATA PROCESSED

  1. Browsing Data – The IT systems and software procedures used to operate this Website acquire, during their normal operation, certain personal data of the data subject, whose transmission is implicit in the use of Internet communication protocols. These are information that, by their very nature, could, through processing and association with data held by third parties, allow the identification of the Data Subjects. This category of data includes IP addresses, the date and time of access, the pages visited (URI/URL), the method used to submit the request to the server, the numerical code indicating the status of the response given by the server (success, error, etc.), the names of the devices used by the Data Subjects connecting to the Website, and other parameters regarding the operating system and the IT environment used by the data subject.
  2. Data Collected via Tracking (“Cookies”) – Cookies are small text strings that websites visited by the user send to their device (usually the browser), where they are stored to be retransmitted to the same sites during the user’s next visit. While browsing a website, the user may also receive cookies on their device sent by other sites or web servers (so-called “third parties”). Each cookie contains various data, such as the name of the server from which it originates, a numerical identifier, etc. Cookies may remain on the system for the duration of a session (i.e., until the browser used for web browsing is closed) or for longer periods. For information regarding the purposes and management of consent related to cookies, please refer to the specific section on the Website’s “Cookie Policy.”
  3. Data Voluntarily Provided – In certain sections of the Website, some personal data are requested, such as, by way of example: first and last name, contact details, city and/or country of residence, and access credentials, which are necessary for the Data Controller to achieve the purposes of processing.

4. PURPOSES, LEGAL BASIS OF PROCESSING, AND RETETION PERIODS

The Data Controller processes your personal data for the achievement of specific purposes and only when a suitable legal basis, as provided by the applicable data protection legislation, exists. The following list refers to all processing carried out by the Data Controller through the Website, in order to allow you to use the digital channels and to enable the Data Controller to ensure their proper functioning and the compliance of the processing activities.

5. PURPOSES, LEGAL BASIS OF PROCESSING, AND RETENTION PERIODS: PURPOSES

The Data Controller processes your personal data for the achievement of specific purposes and only when a suitable legal basis, as provided by the applicable data protection legislation, exists. The following list refers to all processing carried out by the Data Controller through the Website, in order to allow you to use the digital channels and to enable the Data Controller to ensure their proper functioning and the compliance of the processing activities.

The Data Controller processes your personal data for the following purposes, legal bases, and retention periods:

Operation of the Website, location, provision of related services (e.g., responding to requests submitted via the dedicated contact form on the Website) and monitoring the proper functioning of the Website:
• Legal basis: performance of a contract to which you are a party;
• Retention: personal data are retained for the time necessary to provide the services and ensure the functioning of the Website and are subsequently deleted or anonymized, without prejudice to further ordinary limitation periods for administrative and/or accounting purposes.

Exclusively for suppliers and companies: entering access credentials to their personal area, modifying and recovering credentials, and managing the personal account:
• Legal basis: performance of a contract to which you are a party;
• Retention: personal data are retained for the time necessary to provide the services and ensure the functioning of the Website and are subsequently deleted or anonymized, without prejudice to further ordinary limitation periods for administrative and/or accounting purposes.

Statistical analysis of the Website’s performance:
• Legal basis: for more information, the data subject is invited to consult the “Cookie Policy”;
• Retention: refer to the periods indicated in the “Cookie Policy.”

Prevention and detection of fraud/abuse/fraudulent activities carried out through the Website:
• Legal basis: legitimate interest of the Data Controller;
• Retention: for the period established by the Data Controller, without prejudice to the right of the data subject to object;

Establishment, exercise, or defense of a right of the Data Controller in judicial proceedings:
• Legal basis: legitimate interest of the Data Controller;
• Retention: for the entire duration of judicial and/or extrajudicial proceedings and/or enforcement actions, until the expiry of all applicable appeal periods.

After the periods indicated above, the data will be permanently deleted or anonymized.
 

6. PROVISION OF DATA AND CONSEQUENCES OF REFUSAL TO CONSENT TO PROCESSING

Personal data requested from you for contractual and service purposes, to comply with specific legal obligations to which the Data Controller is subject, and in cases of legitimate interest, are mandatory; therefore, failure to provide them would prevent the provision of the services offered or the responses you request. In cases of the Data Controller’s legitimate interest, your right to object to the processing remains fully preserved.

7. METHODS OF PROCESSING

The processing of data will be carried out primarily using electronic or otherwise automated tools, and, subordinately, by manual means, in accordance with methods and using means suitable to ensure the security and confidentiality of the data, in compliance with the GDPR. In particular, all technical, IT, organizational, logistical, and procedural security measures will be adopted to ensure an adequate level of data protection as required by law and to minimize the risks of destruction, loss, unauthorized access, or processing not in accordance with the purposes of collection, allowing access exclusively to persons authorized to process the data by the Data Controller or by persons appointed by the Data Controller. The data will also be managed and protected in environments with controlled access at all times.

8. RECIPIENTS OF DATA: INTERNAL ENTITIES

The data, processed for the purposes referred to in Article 4 above, may be disclosed to:

Internal entities of SELEX, for their respective purposes, who will process the data as persons expressly designated and authorized by the Data Controller to process data pursuant to Articles 29 of the GDPR and 2‑quaterdecies of Legislative Decree 196/2003, as amended and aligned with the GDPR by Legislative Decree 101/2018, such as, by way of example: employees, collaborators, and directors of the Marketing, E-commerce, Administration and Accounting, Legal Affairs, and IT departments.

9. RECIPIENTS OF DATA: EXTERNAL ENTITIES

External entities of SELEX, who will process the data on behalf of SELEX, as Data Processors expressly appointed pursuant to Article 28 of the GDPR, such as, by way of example:

  • Companies, consultants, or professionals possibly entrusted with the installation, maintenance, updating, and, in general, the management of SELEX’s hardware and software, or those used by SELEX to provide its services;
  • Public and/or private entities, natural and/or legal persons (legal, administrative, and tax consulting firms, Judicial Offices, etc.) where disclosure is necessary or functional for the proper fulfillment of contractual obligations in relation to the services provided, as well as obligations arising from the law.

The complete and updated list of Data Processors is available upon request by contacting the toll-free number 800 992992 or can be consulted at SELEX’s headquarters.

Data may, in any case, be disclosed to third parties for legal obligations or specific requests from Judicial Authorities and/or Public Authorities. Your personal data will not be transferred abroad.

Data Dissemination – Under no circumstances shall the personal data covered by this notice be disseminated to undefined or unauthorized subjects.

10. TRANSFER OF PERSONAL DATA OUTSIDE THE EU

The Data Controller does not transfer personal data to third countries or international organizations located outside the EU.

11. RIGHTS OF THE DATA SUBJECT

  1. By contacting the Data Controller, you can exercise the rights provided for in Articles 15 to 22 of the GDPR and, in particular, request: access to your personal data, deletion, rectification of inaccurate data, completion of incomplete data, data portability pursuant to Article 20 of the GDPR for processing based on a contract or consent, restriction of processing in the cases provided for in Article 18 GDPR, as well as objection to processing pursuant to Article 21 of the GDPR in cases of the Data Controller’s legitimate interest.
  2. The data subject may exercise their rights by contacting the Data Controller through a written communication sent to the DPO at the e-mail address dpo@selexgc.it.
  3. Furthermore, the data subject has the right to lodge a complaint with the supervisory authority responsible for data protection, in particular in the Member State in which they reside or normally work, or in which the alleged violation occurred.
  4. It should be noted that this privacy notice may be supplemented with additional elements/information to best meet any informational needs of the Data Subject regarding “Privacy” and to accommodate regulatory developments.

Last updated: 26/02/2021