Data Controller and point of contact
Pursuant to and for the purposes of Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the «GDPR» or the «Regulation»), read in conjunction with Legislative Decree no. 196 of 30 June 2003, as amended and supplemented by Legislative Decree no. 101 of 10 August 2018 (the «Privacy Code»), this notice (the «Notice») provides data subjects (the «Data Subject» or, in the plural, the «Data Subjects») with the information concerning the processing of personal data carried out by the Data Controller indicated below in relation to the consultation of the website accessible at atlanticanalytics.it and its subdomains (the «Site») and to interaction with the services made available therein.
The Data Controller is Atlantica Analytics S.r.l., with registered office in Rome, Via Giulio Caccini no. 1, 00198, tax code and VAT number IT18282581000, registered with the Companies Register of Rome (the «Controller» or «Atlantica»). The Data Subject may contact the Controller for any communication and for the exercise of the rights recognised by applicable law at the following addresses: email address accounts@atlanticanalytics.it or the postal address of the registered office indicated above.
As at the date of adoption of this Notice, the Controller — in view of the nature, scope, context and purposes of the processing carried out — is not required to designate a Data Protection Officer under Article 37 GDPR; should this circumstance change, prompt notice will be given by updating this Notice. In the meantime, any request concerning the protection of personal data may be addressed to the Controller at the contact details indicated above.
This is a courtesy English translation; the binding Italian version prevails in the event of any discrepancy.
Categories of personal data processed
The following categories of personal data are processed, in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality set out in Article 5 GDPR:
- Browsing data. The IT systems and software procedures responsible for the operation of the Site acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category includes, by way of example: the IP addresses or domain names of the devices used by the Data Subjects, the URI/URL (Uniform Resource Identifier / Locator) identifiers of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the server's response, the type, language and version of the browser and operating system used, the referrer, the screen resolution and further parameters relating to the user's operating system and IT environment.
- Data provided voluntarily by the Data Subject. The personal data spontaneously provided by Data Subjects by completing the demo-request, contact and application forms available on the Site, or by sending communications to the email addresses made available. As a rule, such data includes: first and last name, professional email address, telephone number, company name and professional role, as well as any further content, including free-form text, entered in the text field of the message.
- Data relating to applications. In the case of unsolicited applications or applications in response to job postings published in the «Careers» section of the Site, the Controller will process the data contained in the curriculum vitae and the attachments transmitted, including information relating to education, professional experience, contact details and, where spontaneously provided by the Data Subject, further elements useful for the assessment of the profile. The Data Subject is invited not to provide data belonging to the special categories referred to in Article 9 GDPR (such as, by way of example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, data concerning health or sex life), unless such information is strictly necessary for examining the application.
- Data derived from tracking tools. Data collected through cookies and assimilable technologies, as described in detail in the Cookie Policy, which forms an integral and substantial part of this Notice.
The Controller does not knowingly process the personal data of natural persons under the age of sixteen pursuant to Article 8 GDPR. The services offered on the Site are intended exclusively for professionals and legal entities operating in the real-estate and financial sectors.
Purposes and legal bases of the processing
The Data Subject's personal data are processed for the purposes set out in detail below, each supported by an appropriate legal basis under Article 6 GDPR:
| Purpose | Legal basis | Nature of provision |
|---|---|---|
| (a) To enable browsing of the Site, deliver the requested content and ensure its security, stability, operational continuity, defence against abuse and diagnosis of malfunctions. | Article 6(1)(b) GDPR — performance of pre-contractual measures and provision of the requested service. Article 6(1)(f) GDPR — the Controller's legitimate interest in protecting the IT infrastructure and preventing unlawful activities. | Necessary to use the Site. |
| (b) To handle requests for information, demos, contact or documents made by the Data Subject through the forms or contact details published on the Site and to manage the related correspondence. | Article 6(1)(b) GDPR — pre-contractual measures at the Data Subject's request. | Necessary for a response: failure to provide it precludes the processing of the request. |
| (c) To manage unsolicited applications or responses to recruitment postings published on the Site, and to carry out the consequent suitability assessments. | Article 6(1)(b) GDPR — pre-contractual measures at the Data Subject's request. For any special-category data provided by the Data Subject, Article 9(2)(a) GDPR — explicit consent. | Necessary for the assessment of the application. |
| (d) To comply with the legal, regulatory or authority obligations to which the Controller is subject in relation to the exercise of its business, and to establish, exercise or defend a right in legal proceedings. | Article 6(1)(c) GDPR — compliance with a legal obligation; Article 6(1)(f) GDPR — legitimate interest in protecting the Controller's rights. | Mandatory by law. |
| (e) To send, subject to the Data Subject's specific consent, informational and promotional communications relating to Atlantica's services (newsletters, event invitations, research reports) by email or other electronic channels. | Article 6(1)(a) GDPR — the Data Subject's freely given, specific, informed and unambiguous consent, which may be withdrawn at any time. | Optional: the absence of consent does not affect the use of the Site or the handling of other requests. |
| (f) To process aggregated and anonymised statistical analyses on the use of the Site in order to improve its content, structure and user experience. | Article 6(1)(f) GDPR — the Controller's legitimate interest in improving its service, balanced against the Data Subject's rights. For processing that requires identifiers comparable to non-technical cookies, Article 6(1)(a) GDPR — consent. | Optional, in the manner described in the Cookie Policy. |
The processing based on the Controller's legitimate interest has been preceded by a balancing test (legitimate interest assessment) aimed at verifying that the interests pursued are not overridden by the Data Subject's interests, fundamental rights and freedoms; a summary copy of that assessment may be requested from the Controller.
Processing methods and security measures
The processing of personal data is carried out by means of the operations or set of operations indicated in Article 4(2) GDPR, using manual, IT and telematic tools, with logics strictly related to the purposes and, in any case, in such a way as to ensure the security, integrity and confidentiality of the data, in compliance with Articles 25 and 32 GDPR.
In particular, the Controller adopts technical and organisational measures appropriate to the risk, including, purely by way of example: (i) encryption of data in transit by means of currently supported TLS protocols; (ii) encryption of data at rest by means of state-of-the-art symmetric-key encryption algorithms; (iii) access management on a need-to-know basis with multi-factor authentication for administrative components; (iv) logging of access and read/write operations on systems containing personal data; (v) daily backups, geographically redundant across distinct geographical areas within the European Economic Area; (vi) documented incident response and disaster recovery procedures; (vii) periodic vulnerability assessments conducted by qualified parties; (viii) ongoing training of personnel authorised to process the data.
The Controller's IT infrastructure is hosted with qualified cloud-service providers, with data centres located in the European Union (as a rule, in the Milan region, AWS eu-south-1). The Controller adopts contractual clauses and due-diligence procedures aimed at ensuring the level of protection required by the GDPR, including with regard to the providers designated as processors.
Categories of recipients of the personal data
The Data Subject's personal data may be made accessible, to the extent strictly necessary to pursue the purposes referred to in section no. 03, to the parties indicated below, all duly instructed and, where the conditions are met, appointed as processors pursuant to Article 28 GDPR or authorised to process pursuant to Article 29 GDPR:
- the Controller's internal personnel (employees, collaborators and self-employed workers) duly authorised and instructed to process the data, in particular the personnel of the commercial, marketing, human-resources, administration, technology and legal functions;
- providers of hosting, cloud computing, content delivery, backup, IT security, email, customer relationship management (CRM), marketing automation, statistical analysis of Site use, videoconferencing and document-sharing services;
- professional advisers (in particular, legal, tax, accounting and labour advisers) engaged by the Controller in the exercise of its business, including for the purposes of establishing, exercising or defending rights in legal proceedings;
- banking and insurance institutions and debt-collection companies, to the extent necessary for the performance of contractual or legal obligations;
- judicial authorities, public-security authorities and other authorities or public administrations entitled to receive the data by virtue of provisions of law or regulation or by order of the authority.
An up-to-date list of the processors designated by the Controller may be requested at the contact details indicated in section no. 01. The Data Subject's personal data are not subject to dissemination, understood as being made available to an indeterminate range of parties, in any form, including by making them available or accessible for consultation.
Transfer of data to third countries
For the pursuit of the purposes described, the Controller, as a rule, uses providers established within the European Economic Area and infrastructure located within the territory of the European Union. Should, exceptionally, a transfer of personal data to a third country or to an international organisation become necessary pursuant to Chapter V of the GDPR, the Controller will first verify the existence of at least one of the following conditions for lawfulness:
- the adoption, by the European Commission, of an adequacy decision pursuant to Article 45 GDPR relating to the country of destination or the sector concerned;
- the signing of Standard Contractual Clauses approved by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021, accompanied, where necessary, by supplementary measures of a technical, contractual or organisational nature suitable to compensate for any protection gaps in the third country, as indicated by the European Data Protection Board (recommendations 01/2020 and 02/2020);
- the applicability of one of the derogations exhaustively provided for in Article 49 GDPR.
The Data Subject may request information from the Controller on the transfers in place and a copy of the safeguards adopted at the contact details indicated in section no. 01.
Data retention period
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the storage limitation principle set out in Article 5(1)(e) GDPR. Once the purposes pursued have been exhausted, the data will be deleted or irreversibly anonymised, subject to any further retention periods imposed by legal obligations or necessary for the establishment, exercise or defence of a right in legal proceedings. As a guideline, the following retention periods are indicated:
| Purpose | Retention period |
|---|---|
| Browsing data and technical logs | Up to 30 days from collection, unless reasons of IT security, incident investigation or retention under Article 132 of the Privacy Code require a further period. |
| Handling of requests for information and demos | 24 months from the last significant interaction with the Data Subject, unless a contractual relationship is established, in which case the terms proper to the relationship established apply. |
| Applications | 24 months from receipt, without prejudice to the Data Subject's right to request its early deletion. |
| Marketing communications subject to consent | Until withdrawal of consent and, in any case, no later than 24 months from the Data Subject's last documented interaction with the communications sent. |
| Tax, accounting and contractual obligations | 10 years from the close of the financial year to which the document refers, pursuant to Article 2220 of the Civil Code and applicable tax legislation. |
| Establishment, exercise or defence of a right in legal proceedings | For the duration of the proceedings and until the relevant time limits for appeal have elapsed. |
Rights of the Data Subject
The Data Subject is granted the rights set out in Articles 15 to 22 of the GDPR, which may be exercised, free of charge, at the Controller's contact details indicated in section no. 01, by means of a communication accompanied by suitable documentation to prove the identity of the applicant. In particular, the Data Subject has the right to:
- access the personal data concerning them, pursuant to Article 15 GDPR, including the right to obtain a copy thereof;
- rectification of inaccurate data and completion of incomplete data, pursuant to Article 16 GDPR;
- erasure («right to be forgotten»), pursuant to Article 17 GDPR, where one of the cases contemplated therein applies;
- restriction of processing, pursuant to Article 18 GDPR, in the cases of contesting the accuracy of the data, unlawfulness of the processing, the data no longer being necessary in relation to the purposes, or a pending objection;
- portability of the data provided, pursuant to Article 20 GDPR, receiving them in a structured, commonly used and machine-readable format, or obtaining their direct transmission to another controller, where technically feasible;
- objection to the processing, pursuant to Article 21 GDPR, in the cases of processing based on legitimate interest or on a task carried out in the public interest, and, at any time and without any need for justification, to processing for direct-marketing purposes, including profiling to the extent connected to it;
- not be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, pursuant to Article 22 GDPR;
- withdraw the consent given, at any time and without prejudice to the lawfulness of the processing carried out before the withdrawal, pursuant to Article 7(3) GDPR;
- lodge a complaint, pursuant to Article 77 GDPR, with the Italian Data Protection Authority (Piazza Venezia no. 11, 00187 Rome,
garante@gpdp.it,www.gpdp.it) or with the competent supervisory authority of the Member State of habitual residence, of work or of the place where the alleged infringement occurred, and to bring judicial proceedings pursuant to Articles 78 and 79 GDPR.
The Controller undertakes to respond to the requests received within one month of receipt, extendable by up to two further months in view of the complexity of the request or the number of requests received, with a reasoned communication to the Data Subject.
Nature of the provision and consequences of refusal
The provision of personal data by the Data Subject is, as a rule, optional. Any refusal to provide it entails the following consequences: (i) for the browsing data strictly necessary for the operation of the Site, the unavailability of the related functions; (ii) for the data necessary to respond to the requests made through the contact or demo forms, the Controller's inability to handle the request; (iii) for the data provided as part of applications, the inability to assess the candidate's profile; (iv) for the data processed for marketing purposes, merely the inability to receive the related communications, without prejudice to the use of the Site.
Automated decision-making and profiling
In the context of the processing connected to browsing the Site, the Controller does not carry out solely automated decision-making processes that produce legal effects or similarly significantly affect the Data Subject pursuant to Article 22 GDPR. In the event that, in relation to specific services offered to its professional clients, automated or profiling logics are adopted, a separate notice will be provided indicating the logic used and the consequences envisaged for the Data Subject, as well as the measures adopted to protect their rights, freedoms and legitimate interests.
Changes to this Notice
The Controller reserves the right to make changes to this Notice at any time, giving evidence of them by publishing the updated version on the Site, indicating the effective date. In the case of changes that substantially affect the processing in progress and that require the Data Subject's consent, the Controller will collect consent again in the manner provided for by applicable law. The Data Subject is invited to consult this Notice periodically.
Contacts and jurisdiction
For any communication, request or exercise of rights, the Data Subject may contact the Controller at the email address accounts@atlanticanalytics.it or at the postal address of the registered office. Communications may be drawn up in Italian or English. For any dispute arising in relation to the interpretation, performance or validity of this Notice, the Court of Rome shall have exclusive jurisdiction, without prejudice to the mandatory provisions of law protecting the Data Subject as a consumer, where applicable.
