Policy on the processing of personal data pursuant to articles 13 and 14 of EU Regulation 2016/679
Cefla S.c., as the Data Controller (hereinafter: “Cefla” or “Data Controller”) pursuant to Regulation (EU) 2016/679 (known as the General Regulation for the Protection of Personal Data, hereinafter “Regulation”) and Legislative Decree no. 196/2003 (known as the Personal Data Protection Code, hereinafter “Code”) – considers privacy and the protection of personal data one of the primary objectives of its business.
We therefore ask you to carefully read this Privacy Policy before submitting any personal data to the Data Controller, as it contains important information on the protection of your personal data.
This policy:
- is intended as provided for the website ceflaengineering.com;
- forms an integral part of the Website and the services we offer;
- is provided, pursuant to Articles 13 and 14 of the Regulation, to all those who interact with the Website's web services, either through simple consultation or through the use of specific services made available through the Website, as well as with other services provided through the Website.
With regard to the processing of navigation data and the processing of personal data through cookies, please refer to the specific Cookie Policy, accessible via the link in the footer of the website or at www.cefla.com/it/cookie-policy-ue, which forms an integral part of this policy.
The processing of your personal data will be based on the principles of fairness, lawfulness, transparency, purpose and retention limitation, minimisation and accuracy, integrity and confidentiality, as well as the principle of accountability pursuant to art. 5 of the Regulation. Your personal data will therefore be processed in compliance with personal data protection legislation and the required confidentiality obligations.
1. DATA CONTROLLER
The data controller is Cefla S.c., Via Selice Provinciale, 23/A - 40026 - Imola (BO), Italy, VAT number IT 00499791200, PEC (certified e-mail) ceflasc@legalmail.it,
The Data Controller has not appointed a Data Protection Officer (“DPO”) pursuant to art. 37 GDPR.
2. PERSONAL DATA TO BE PROCESSED
Please note that the personal data to be processed, depending on your interactions with the Website, may include:
a) Personal and contact information voluntarily submitted by you in order to use the Website's services, such as name, surname, email address, telephone number, company and position, as well as any other information included by you in communications sent via contact forms or other communication channels made available by the Data Controller.
b) Navigation data: the IT systems and software procedures used to operate this Website will capture, during their normal operation, some personal data the transmission of which is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of computers used by users who log in to the website, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the digital code indicating the status of the response sent by the server (success, error, etc.) and other parameters relating to the operating system and to the user's IT environment. On this subject, please refer to the cookie policy.
c) Data collected through cookies: for details on the data collected through cookies please refer to the specific Cookie Policy.
d) Data relating to your CV, submitted voluntarily by you through the "Careers" section of the website to apply for job positions, in accordance with the relevant policy provided.
3. DATA PROCESSING PURPOSES
Your personal data will be processed, subject to your consent where necessary, for the following purposes, where applicable:
3.1 Allow the use of the Website, in compliance with the applicable general conditions;
3.2 Respond to specific requests submitted to the Data Controller, including any relating to after-sales services, including requests for Customer Service and information submitted by completing the contact forms specially provided on the Website;
3.3 Send communications and commercial proposals, including newsletters, through automated tools (SMS, MMS, email, instant messaging and online chat) and non-automated tools (postal mail, telephone);
3.4 Allow the sending of CVs, as defined in the relevant “Careers” area, in accordance with the information policy provided locally.
4. LAWFULNESS AND MANDATORY OR OPTIONAL NATURE OF DATA PROCESSING
|
Section |
Purposes |
Lawfulness (Article 6 GDPR) |
Nature of consent |
Consequences of refusal |
|
3.1 |
Provision of services |
Point b) – execution of the contract |
None required |
Consent is not required; however, failure to submit personal data will prevent the supply of services associated with the use of the website. |
|
3.2 |
Response to requests |
Point f) – legitimate interest |
None required |
Consent is not required; however, failure to submit personal data will prevent us from responding to your requests |
|
3.3 |
Marketing |
Point a) – consent |
Optional |
Consent is optional and can be withdrawn at any time; it will not affect services. Your failure to consent will mean that it will not be possible for us to send you marketing communications |
|
3.4 |
Applications |
Please refer to the relevant information. |
- |
- |
5. RECIPIENTS OF PERSONAL DATA
Your personal data may be shared, for the purposes set out in section 3 of this Privacy Policy, with:
5.1. Persons authorised by the Data Controller to process personal data pursuant to Articles 29 and 2-N (quaterdecies) of the Code (e.g. personnel working in sales, administration, accounting and after-sales, CRM and information systems management);
5.2. Third parties who, in providing services (e.g. technology, accounting, administrative, legal, tax and financial support and consultancy services, technical maintenance, transportation services, banking and insurance services), act as data processors pursuant to Article 28 of the Regulation. The Data Controller maintains an updated list of appointed data processors and ensures that the data subject may view it at the above-mentioned headquarters or upon request addressed to the above-mentioned contact details;
5.3. Commercial partners, Group companies, suppliers or other third parties who act, as applicable, as independent data controllers, co-controllers or processors, exclusively to the extent necessary to achieve the purposes indicated in this policy and in compliance with applicable legislation;
5.4. subjects, entities or authorities to whom the communication of your personal data is mandatory pursuant to legal provisions or orders of the authorities.
These subjects are, hereinafter, collectively referred to as “Recipients”.
6. TRANSFER OF PERSONAL DATA
Some of your personal data are shared with Recipients who may be located outside the European Economic Area. The Data Controller ensures that the processing of your personal data by these Recipients is carried out in compliance with Articles 44 - 49 of the Regulation.
The Data Controller intends to transfer Personal Data to entities established in a third country outside the European Union or to an international organisation. Such entities could be, by way of example:
- communications companies that carry out communication activities on behalf of the Data Controller;
- companies that offer hosting services;
- suppliers of services to the communications company;
- Data Controller's partner companies.
The Data Controller will take the utmost care to ensure that the level of personal protection is not affected in the event of transfer of your personal data to a third country outside the European Union or to an international organisation. Some of the services offered by the Data Controller, as detailed in this policy, may involve the transfer of personal data to third countries, particularly to the United States of America.
Such transfers take place according to the following methods:
- Transfers based on an Adequacy Decision: if the European Commission has determined that a third country ensures an adequate level of data protection, the transfer of your personal data to that country will not require any further authorisation.
- Transfers in the absence of an Adequacy Decision: for transfers to third countries for which there is no existing adequacy decision, the Data Controller primarily refers to the Standard Contractual Clauses adopted by the European Commission, carrying out, where necessary, a transfer impact assessment to verify whether the legislation and practices of the destination third country could undermine the effectiveness of the guarantees offered by the aforementioned clauses. Additional technical, contractual and organisational measures may also be adopted if the impact assessment shows that the rights and freedoms of data subjects are at risk. These measures are intended to fill regulatory gaps in the third country and to ensure that the transferred data benefit from a level of protection essentially equivalent to that ensured within the EEA. Where technically possible and appropriate according to the level of risk, the technical measures adopted include the use of advanced encryption for data in transit and at rest, with management of encryption keys under the exclusive control of the Data Controller or a trusted third party established in the European Union. If, despite the adoption of the aforementioned measures, it is not possible to guarantee a substantially equivalent level of protection, the Data Controller undertakes not to carry out the transfer or to suspend it.
For more information on data transfers and to receive a copy of the adopted adequate guarantees (e.g. the Standard Contractual Clauses), please send your request to the Data Controller.
7. STORAGE OF PERSONAL DATA
Your personal data will be entered and stored in the Data Controller's information systems in accordance with the principles of data minimisation and retention limitation pursuant to Article 5.1.c) and e) of the Regulation.
|
Section |
Purposes |
Retention time |
|
3.1 |
Provision of services related to the website |
24 months |
|
3.2 |
Response to requests |
24 months |
|
3.3 |
Marketing |
24 months |
8. RIGHTS OF THE DATA SUBJECTS
As a Data Subject, you may exercise the rights set forth in Articles 15-22 of GDPR and withdraw your consent at any time, without prejudice to the lawfulness of the processing carried out before such withdrawal.
Right to object
As a Data Subject, you have the right to object under the following terms:
- the right to object, on grounds relating to your particular situation, at any time to the processing of Personal Data related to you pursuant to Article 6, paragraph 1, points e) or f) of GDPR. The Data Controller shall then no longer process your personal data unless the Data Controller can demonstrate compelling legitimate grounds for data processing which override your interests, rights and freedoms or for the establishment, enforcement or defence of legal claims;
- Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data related to you for such purposes, which includes profiling to the extent that it is related to such direct marketing purposes;
- In the event of objection to processing for direct marketing purposes, personal data shall no longer be processed for such purposes. You may object to the processing of personal data for direct marketing purposes even only partially, e.g. by objecting to the sending of promotional communications via automated and/or digital tools, or to the sending of hard copy communications and/or to telephone communications;
- If your personal data are to be processed for scientific or historical research purposes or statistical purposes pursuant to Article 89, paragraph 1 of GDPR, you have the right, on grounds relating to your particular situation, to object to processing of your personal data, unless such processing is necessary for the performance of a task for reasons of public interest.
Additionally, you are entitled to other rights summarised below:
- Right of access: you have the right to obtain confirmation from the Data Controller as to whether or not your personal data are being processed and to access your personal data and specific information, pursuant to Article 15 of GDPR;
- Right to rectification: you have the right to obtain from the Data Controller without undue delay the rectification of any inaccurate personal data related to you. In consideration of the purposes of data processing, you have the right to obtain the integration of incomplete personal data, including by providing a supplementary statement, pursuant to Article 16 of GDPR;
- Right to erasure ("right to be forgotten"), including the right to withdraw consent: you have the right to obtain from the Data Controller the erasure of your personal data without undue delay or to withdraw consent to the processing of personal data, if the grounds set out in Article 17 of GDPR apply. You have the right to withdraw your consent at any time without prejudice to the lawfulness of any data processing based on consent previously granted by you;
- Right to restriction of processing: you have the right to obtain from the Data Controller restriction of processing, when the conditions defined in Article 18 of GDPR apply;
- Right to data portability: you have the right to receive your personal data supplied to the Data Controller in a structured, commonly used and machine-readable format and the right to transmit such data to another Data Controller without hindrance from the Data Controller mentioned in this Privacy Policy, as provided for by Article 20 of GDPR;
- Contracting party's right to object to commercial communications: As a contracting party, you have the right to object at any time, free of charge, to receiving commercial communications from the Data Controller;
- Right to lodge a complaint with a Supervisory Authority: you have the right to lodge a complaint with the Data Protection Authority to report a violation of personal data protection regulations, pursuant to Article 77 of GDPR.
Exercise of rights
Requests may be submitted, subject to preliminary identification of the Data Subject, by sending:
- a certified email to: ceflasc@legalmail.it
- a registered letter with return receipt to the address: via Selice Provinciale 23/a Imola
9. LODGING A COMPLAINT WITH THE SUPERVISORY AUTHORITY
If you believe that the processing of your Personal Data by the Data Controller violates the provisions of the GDPR, you have the right to lodge a complaint with the Data Protection Authority as provided for by art. 77 of GDPR, or to take appropriate legal action (Article 79 of GDPR).
10. CHANGES
The Data Subject reserves the right to amend or simply update the content of this Privacy Policy, in part or completely, as a result of, among others, changes in the applicable legislation. The Data Controller therefore recommends that you regularly visit this section to become aware of the most recent and updated version of this Privacy Policy, in order to always be up-to-date on the personal data collected and on the use made of such data by the Data Controller. Should the Data Controller substantially modify this Privacy Policy, introducing new processing purposes and/or categories of personal data, the Data Controller will see to informing you in order to obtain from you the required consent, via a pop-up on the website or through different methods and/or IT tools.
Latest update: 22.07.2026
Imola