INFORMATION ON THE PROCESSING OF PERSONAL DATA
Information pursuant to Art. 13 and Art. 14 of Reg. (EU) 679/2016, so-called GDPR)

Dear Interested,

Below we provide you with some information that we need to bring to your attention, not only in order to comply with legal obligations, but also because transparency and fairness towards the persons concerned is a fundamental part of our activity.

Data controller

The Data Controller of your personal data is Krupps S.r.l., which is responsible to you for the lawful and correct use of your personal data and which you may contact for any information or request at the following addresses:

VAT NumberIT04251180289
HeadquarterVia Austria 19 — 35127, Padova (PD) — Italia
Contact information049 7625156, info@krupps.it, krupps@pec.it

Data Protection Officer

The Data Protection Officer (DPO) can be contacted at the following addresses:

Contact informationdpo@krupps.com — Xifram S.r.l.

Data source

The data processed are communicated by you or by third parties, such as recruitment or employment agencies, and/or collected from publicly accessible sources. Some of these sources are publicly accessible: Yes.

Treatments

Your personal data are collected and processed, by automated, semi-automated and non-automated means, as specified below:

Personnel recruiting and selection

Purpose and legal basis— Recruitment of personnel to the company, on the basis of: Execution of a contract and/or pre-contractual measures
Data CategoriesBiographical data, Contact data, Address data, Identification/recognition document data, Employment data
Storage Time*Common data: 2 years from research year
Data recipientsAuthorities and public administrations with respect to which there is a legal obligation to communicate, Data Processors appointed pursuant to Art. 28 EU Reg. 2016/679 (see Register of Data Processors), Authorised Persons appointed pursuant to Art. 29 EU Reg. 2016/679 , other persons for whom the communication of the data is necessary for the performance of the declared purposes of the controller

Management and maintenance of IT systems

Purpose and legal basisManagement and maintenance of the network and information systems, based on: Legitimate interest of the Data Controller in the protection of the network and computer systems; legal obligation limited to what is provided for by the regulations on system administrators
Data CategoriesAccess and identification data
Storage Time*Common data: 2 years from the year of termination of the contractual relationship for accounts, passwords and user names; 18 months for system administrators’ obligations
Data recipientsData Processors appointed pursuant to Art. 28 EU Reg. 2016/679 (see register of data processors), Authorised Data Processors appointed pursuant to Art. 29 EU Reg. 2016/679 , other persons for whom the communication of data is necessary for the fulfilment of the declared purposes of the data controller

Defence of interests and rights of the Controller

Purpose and legal basis— Preventing and/or detecting possible abuses and defending the rights and interests of the Holder, on the basis of: Legitimate interest of the Holder to protect its rights and interests in court or in the preparatory stages of its possible establishment
Data categoriesData useful for the defence of the holder’s interests and rights
Storage Time*Data useful for the defence of the Controller’s interests and rights: The data will be retained for as long as the Data Controller has an interest in exercising its right or interest
Data recipientsAuthorities and public administrations with respect to which there is a legal obligation to communicate, Data Processors appointed pursuant to Art. 28 EU Reg. 2016/679 (see Register of Data Processors), Authorised Persons appointed pursuant to Art. 29 EU Reg. 2016/679 , other persons for whom the communication of the data is necessary for the performance of the declared purposes of the controller

Data protection compliance management

Purpose and legal basis— Personal data protection obligations, based on: Legal obligation
Data CategoriesBiographical data, Contact data, Address data
Storage time*Common data: For as long as strictly necessary to fulfil the purposes
Data recipientsAuthorities and public administrations with respect to which there is a legal obligation to communicate, Data Processors appointed pursuant to Art. 28 EU Reg. 2016/679 (see Register of Data Processors), Authorised Persons appointed pursuant to Art. 29 EU Reg. 2016/679 , other persons for whom the communication of the data is necessary for the performance of the declared purposes of the controller

* In addition to the time required for the accrual of prescriptive periods in relation to reciprocal rights and the retention time of backups.

Automated process
The processing is not based on automated decision-making.
The Controller does not use automated decision-making or monitoring systems to provide information relevant to recruitment.

Provision of data
Failure to provide compulsory data may entail legal and contractual consequences, while failure to provide optional data may result in the processing not being carried out or being carried out only partially. Therefore, in the event of failure to provide data, the data subject may not obtain the expected result or may only obtain it partially.

Extra-EU data transfer
The processing of personal data (e.g. storage, archiving and preservation of data on its own servers or in the cloud) will be circumscribed within the areas of circulation and processing of personal data of the countries that are part of the European Union, with an express prohibition to transfer them to non-EU countries that do not guarantee (or in the absence of) an adequate level of protection, or, in the absence of the protection tools provided by the EU Regulation 2016/679 (third country judged adequate by the European Commission, group BCR, model contractual clauses, consent of the data subjects, etc.).

Rights of the data subject

  • You have the right, in accordance with Articles 15 et seq. of EU Reg. 2016/679, to request from the Controller access to your personal data, as well as its rectification and deletion or oblivion;
  • You also have the right to request data portability or restriction of processing;
  • You have the right, on grounds relating to your particular situation, to object to processing based on legitimate interests of personal data concerning you;
  • You have the right to see the essential contents of any signed co-ownership agreements;
  • For processing based on consent, you have the right at any time to withdraw your consent, without prejudice to the lawfulness of the processing based on the consent given before the withdrawal;
  • You may also lodge a complaint with the Italian Data Protection Authority, with registered office in Piazza Venezia 11, 00187 — Rome — protocollo@pec.gdpd.it.

To exercise your rights or to request additional information, you may contact the Controller using the contact information above.

Amendments to this notice
We reserve the right to update our Privacy Policy. We will notify you of changes as we deem appropriate and update the date in this Privacy Policy. We therefore recommend that you consult our Privacy Policy periodically, including by requesting a copy from the Data Controller.

Last updated: 31/07/2024