Privacy Policy
This privacy notice (hereinafter, "Privacy Policy") relates to the processing of your personal data (hereinafter, "Personal Data") carried out by NUR S.r.l., with registered office in San Giorgio Bigarello (MN), Via del Commercio 1/N, VAT number 01902640208, email info@nur.it (hereinafter, "NUR" or the "Data Controller"), in compliance with EU Regulation 2016/679 (hereinafter "GDPR").
1. Identity and contact details of the data controller
The Data Controller is NUR. As the Data Controller is established in Italian territory, no representative has been appointed.
2. Contact details of the data protection officer
The Data Controller has appointed a Data Protection Officer ("DPO"). The DPO can be contacted at the Data Controller's addresses or at gdpr@nur.it.
3. Purpose and legal basis of processing
Your Personal Data will be processed for the following purposes:
- a) to send you direct marketing communications, newsletters, advertising material, through traditional contact systems and automated computer systems, including commercial or promotional communications by email or SMS, or for market research and analysis. The legal basis for processing is consent, expressed in accordance with this Privacy Policy;
- b) for profiling activities to determine your habits and preferences, to provide you with a personalized service. The legal basis is your consent, expressed in accordance with this Privacy Policy. The communication of Personal Data is not a contractual obligation. You are free to provide Personal Data. If you do not provide such data, NUR will not be able to provide you with a personalized service;
- c) for purposes related to legal obligations. The legal basis is NUR's legal obligation to process Personal Data according to applicable regulations.
4. How to express consent
You can express your consent by signing a digital document through specific checkboxes.
5. Processing methods and logic
- In relation to Personal Data processed for marketing purposes (point a) section 3 of this Privacy Policy), processing will be carried out using commercial information delivery software;
- In relation to Personal Data processed for profiling purposes (point b) section 3), processing will be carried out using CRM software that allows defining tastes and preferences to offer you personalized services and communications. For further details, see the next section of this Privacy Policy.
- In relation to Personal Data processed and stored for legal obligation purposes (point c) section 3), processing will be carried out using paper tools, automated logic, and CRM management software to best manage compliance with legal obligations.
6. Automated decision-making and profiling
If you consent to the processing of Personal Data to receive personalized services through profiling, Personal Data may be subject to an automated decision-making process, with a specific algorithm that will decide which communications are most suitable for your profile or which may be of most interest to you. The expected consequences of this processing include, by way of example, the sending of highly profiled commercial communications, invitations to events deemed of interest, etc.
In accordance with Article 22 GDPR, you have the right to:
- obtain human intervention in the decision-making process by NUR;
- express your opinion;
- obtain an explanation of the decision reached by NUR;
- challenge the decision itself.
7. Source of Personal Data
Only Personal Data provided in accordance with this Privacy Policy will be processed. NUR will not process Personal Data from publicly accessible sources.
8. Recipients and categories of recipients of Personal Data
Recipients of Personal Data may include:
- communication companies that carry out commercial communication and profiling activities on behalf of the Data Controller, where the relevant consent has been given, which hold the status of data processors;
- companies that offer information society services, including, in particular, hosting services;
- companies that carry out statistical and market research, where the relevant consent has been given;
- auditing companies;
- partner companies of the Data Controller;
- HubSpot Inc., as a data processor, for the management of contact forms and the collection of data submitted, if applicable, through the HubSpot CRM platform.
9. Data categories
Personal Data will be processed. Under no circumstances may special categories of Personal Data defined in Article 9 of the GDPR be processed.
10. Data transfer
NUR intends to transfer Personal Data to entities established in a third country outside the European Union or to an international organization.
Such entities may include, for example:
- communication companies that carry out communication activities on behalf of the Data Controller;
- communication service providers;
- controlled and/or controlling organizations.
The transfer of Personal Data to such entities, where established in a third country or an international organization, is carried out in the presence of an adequacy decision by the European Commission, which has verified that the third country, the territory or one or more specific sectors within that third country, or the international organization in question ensure an adequate level of protection of rights. In any case, NUR, if it deems it appropriate, reserves the right to conclude specific separate agreements obliging such entities to adopt adequate security measures, including organizational measures, to offer appropriate guarantees for your rights. Personal Data may therefore be transferred to the following countries: United States of America. In particular, HubSpot Inc. processes Personal Data collected through the contact forms on the Site in accordance with the Data Processing Agreement signed with NUR and the Standard Contractual Clauses adopted by the European Commission. To obtain a copy of such Personal Data or the place where they have been made available, simply send the relevant request to NUR at gdpr@nur.it.
11. Data retention period
- Personal Data processed for marketing purposes (point a) section 3 of this notice) are processed and stored by NUR until you request cancellation and/or revocation, as a Data Subject;
- Individual Personal Data processed for profiling purposes (point b) section 3), as acquired from time to time, are processed and stored by NUR for a period not exceeding 12 (twelve) months from collection;
- Personal Data processed and stored for legal obligation purposes (point c) section 3) are processed and stored by NUR in accordance with applicable regulations, in any case for a period not exceeding 10 (ten) years from the termination of the contract's effects, unless otherwise required by law.
12. Optional nature of consent and consequences of non-consent
- In relation to Personal Data processed for marketing purposes (point a) section 3 of this notice), the communication of Personal Data is not a contractual obligation. You are free to provide Personal Data. If you do not provide such data, NUR will not be able to carry out any marketing activities.
- In relation to Personal Data processed for profiling purposes (point b) section 3 of this notice), the communication of Personal Data is not a contractual obligation. You are free to provide Personal Data. If you do not provide such data, NUR will not be able to carry out any profiling activities.
- In relation to Personal Data processed for legal obligation purposes (point c) section 3 of this notice), the communication of Personal Data is a legal obligation.
13. Your rights
a) Right to object
As a Data Subject, you have the right to object under the following terms:
- the right to object at any time, for reasons connected to your particular situation, to the processing of Personal Data concerning you pursuant to Article 6, paragraph 1, letters e) or f) of the GDPR. NUR shall refrain from further processing your Personal Data, unless NUR demonstrates the existence of compelling legitimate grounds for processing that override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims;
- where Personal Data is processed for direct marketing purposes, you have the right to object at any time to the processing of Personal Data concerning you for such purposes, including profiling to the extent that it is connected to direct marketing;
- in the event of objection to processing for direct marketing purposes, Personal Data shall no longer be processed for such purposes. You may object to the processing of your Personal Data for direct marketing purposes even partially, for example by objecting only to the sending of promotional communications through automated and/or digital means, or to the sending of paper communications and/or to receiving telephone communications;
- where your Personal Data is processed for scientific or historical research purposes or for statistical purposes pursuant to Article 89, paragraph 1 of the GDPR, for reasons connected to your particular situation, you have the right to object to the processing of Personal Data, unless the processing is necessary for the performance of a task carried out in the public interest.
b) Other rights
NUR also wishes to inform you of the existence of the following rights:
- Right of access: you have the right to obtain from NUR confirmation as to whether or not Personal Data concerning you is being processed and to access your Personal Data and specific information, in accordance with Article 15 of the GDPR;
- Right to rectification: you have the right to obtain from NUR the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of processing, you have the right to have incomplete personal data completed, including by providing a supplementary statement, in accordance with Article 16 of the GDPR;
- Right to erasure, including the right to withdraw consent: you have the right to obtain from NUR the erasure of your Personal Data without undue delay or to withdraw consent to processing, if the grounds defined in Article 17 of the GDPR apply. You have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given prior to withdrawal;
- Right to restriction of processing: you have the right to obtain from NUR restriction of processing, when the conditions defined in Article 18 of the GDPR apply;
- Right to data portability: you have the right to receive your Personal Data provided to the Data Controller in a structured, commonly used and machine-readable format, and you have the right to transmit such data to another controller without hindrance from NUR, as provided for in Article 20 of the GDPR;
- Right of the contracting party to object to commercial communications: as a contracting party, you have the right to object at any time, free of charge, to receiving commercial communications from NUR;
- Right to lodge a complaint with the Supervisory Authority: you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), to report a violation of data protection regulations, in accordance with Article 77 of the GDPR.
14. How to exercise your rights
You can exercise the rights indicated in this Cookie Policy by sending requests directly to NUR at gdpr@nur.it, or by sending the relevant communication by registered letter to Via del Commercio 1/N, San Giorgio Bigarello (MN), Italy.
You may lodge a complaint with the Italian Data Protection Authority according to the procedures provided on the official website, addressing it to the contacts available at https://www.garanteprivacy.it/home/footer/contatti.
15. Accessibility of the Privacy Policy
The Privacy Policy is available at www.nur.it/privacy-policy or at NUR's offices. If expressly requested, NUR may provide the information orally, provided that your identity is verified, through a telephone request to 0376 369728.
16. Modifications
NUR may modify this Privacy Policy, including to adapt to changes in national and/or European Union regulations, or to technological innovations. Any new versions of the Privacy Policy will be reported on the website www.nur.it (hereinafter, the "Site"). We invite you to periodically check the Privacy Policy. Any modification will be communicated through a pop-up on the Site or other methods and/or digital tools.
If NUR substantially modifies the Privacy Policy, providing for new processing purposes and/or categories of Personal Data processed, NUR will inform you, requesting the necessary consents, through a pop-up on the Site or other methods and/or digital tools.