Privacy Notice Pursuant to Articles 13–14 of the GDPR Regarding the Processing of Personal Data
WHISTLEBLOWING policy
Data Controller
NOVASFER S.r.l. UNIPERSONALE (hereinafter also the “CONTROLLER”), with registered office at Via G. Galilei, 3 – Fr. Carzago 25080 – Calvagese della Riviera (BS) – Tel.: 030/6809011 – Fax: 030/6800172 – Tax Code: 01512690171 – VAT No.: 00634230981, represented by its legal representative, in its capacity as Data Controller, informs you that Regulation (EU) No. 2016/679 (GDPR) and Legislative Decree 196/2003 as amended regulate the protection of personal data. The Controller processes data in accordance with the principles of fairness, lawfulness, transparency, and necessity, as provided for by the aforementioned legislation. To this end, pursuant to Articles 13-14 of the GDPR, we provide the following information.
Data Protection Officer (“DPO”)
An internal Data Protection Officer has been appointed within the company to organize the daily management of personal data. They can be contacted via the following email: whistleblowing@novasfer.it
Types of Data Processed
The receipt and management of reports involve the processing of so-called “common” personal data (name, surname, job role, any other information related to the unlawful conduct, whether proven or alleged), and may also involve, depending on the content of the reports and attached documents, the processing of so-called “special” personal data (data concerning health conditions, sexual orientation, or trade union membership as per Article 9 GDPR) and data relating to criminal convictions and offences (as per Article 10 GDPR).
Purpose and Legal Basis of Processing
Personal data are collected and processed for purposes strictly related to the management of reports of unlawful conduct in violation of national/EU laws and, where adopted, of the Company’s Code of Ethics and Organizational, Management and Control Model.
In accordance with the applicable legislation (EU Directive 2019/1937 and Legislative Decree No. 24/2023), the legal basis for such processing is:
- For the processing of common data, Article 6.1(c) of the GDPR (“compliance with a legal obligation to which the controller is subject”).
- For the processing of special and judicial data, Article 9.2(g) of the GDPR.
Processing Methods
The Controller undertakes to process only the data necessary to achieve the purposes essential to the management of the reported activities, in a lawful, fair, and transparent manner. Processing is carried out by the Controller, including by electronic means, automated tools, and systems for receiving oral reports equipped with appropriate security (file encryption), organizational, technical, and physical measures to protect information from alteration, destruction, loss, theft, or improper or unlawful use.
Reports and related documentation will be retained for five years from the date of communication of the final outcome of the reporting procedure.
The identity of the reporting person and any other information from which such identity can be directly or indirectly inferred will be processed exclusively by persons authorized under Article 29 GDPR and will not be disclosed to other parties without the specific consent of the person concerned, as required by Article 12(2) GDPR. Consent is optional and is provided at the time of reporting via the platform.
Data Disclosure and Transfer
Your data will not be disseminated but will be processed by the following entities, by way of example and not limited to:
- public authorities in fulfillment of specific legal obligations and judicial authorities acting as independent data controllers
- external companies entrusted with reporting management services and IT service providers, acting as Data Processors pursuant to Article 28 GDPR, subject to confidentiality obligations and solely for the purposes assigned to them
- Supervisory Body
- Legal advisors potentially involved in the investigation phase
- Other internal functions potentially involved in the preliminary investigation and investigation phase, specifically authorized and bound to confidentiality
The list of external Data Processors is available at the registered office of the Company.
Data Subject Rights
Pursuant to Articles 15 to 22 of the GDPR, and within the limits set forth in Article 2-undecies of the Privacy Code, you may exercise the right to:
- a) access your personal data;
- b) correct them in case of inaccuracies;
- c) delete the data;
- d) restrict processing;
- e) data portability, i.e., to receive the personal data provided in a structured, commonly used, and machine-readable format, and to transmit them to another Data Controller without hindrance;
- f) object to processing, where applicable.
You may also lodge a complaint with the Data Protection Authority located at Piazza Venezia 11, 00187 Rome.
For further information about this privacy notice or any privacy-related matters, or if you wish to exercise your rights, you can contact the appointed internal Delegate at the following email address: whistleblowing@novasfer.it
