VAMFARMA S.R.L. (Tax Code No. and VAT Registration No. 08027900961) headquartered in Via John Fitzgerald Kennedy, 5 26833, Comazzo (LODI), Italy, e-mail: firstname.lastname@example.org
The Company has appointed a Data Protection Officer (DPO) who can be reached at the following e-mail address: email@example.com.
The types of data processed
The types of data collected and processed by the Company are:
• browsing data (collected automatically).
• personal data (such as name/last name/e-mail address) obtained through the user’s spontaneous and voluntary requests sent to the addresses of the Company available in the various sections of the site.
The computer systems and software procedures that enable the functioning of the website acquire, during their customary use, a series of personal data the transmission of which is implicit in the use of Internet communication protocols.
Data are not collected in order to be associated with identified data subjects, but, due to their very nature, could allow users to be identified through processing and comparisons with data held by third parties.
This category of data includes IP addresses or the domain names of computers used by the users to access the website, and other parameters relating to the user’s operating system and computer environment.
Such data are used for the sole purpose of obtaining anonymous statistical information on the use of the website and to check its correct functioning. They are kept for the amount of time strictly necessary for the statistical analysis.
The data collected may be used to ascertain liability in the event of hypothetical cybercrimes to the detriment of the website.
Purposes of data processing
Personal data shall be processed for the following purposes:
• allow browsing and consultation of the site.
• to defend against misuse of the site or attempts at fraud.
• internal audits, management control, certification, and reporting to other Companies of the Group.
• adherence to all applicable laws, regulations, guidelines, and best practices.
• to process individual requests or complaints/adverse events.
Data processing methods/data communication
The Data Controller has adopted the appropriate security safeguards to prevent the accidental or unlawful destruction, loss, modification, unauthorized disclosure of or access to the personal data transmitted, stored or otherwise processed.
The processing of personal data is carried out mainly thought the use of computerized and/or IT tools to the extent strictly necessary for the pursuit of the purposes laid out.
To fulfill the purposes described herein, the Data Controller shall work through specifically appointed individuals who shall be acting under its authority (data processors/appointees).
We may be required to disclose Your data to third parties which can belong to the following categories:
• parent companies, subsidiaries, affiliates, and investees;
• individuals and legal entities involved in the running of this Site (e.g. system administrators, suppliers and maintenance technicians, hosting providers, and IT companies);
• suppliers of goods and/or services (e.g. professional consultants, business partners)
• parties to whom the communication of Your personal data is required by law;
The parties to whom your data is disclosed will, in turn, operate as:
a) Data Controllers, i.e., they determine the purposes and means of the processing of the Data collected.
b) Data Processors, i.e., those who process data on behalf of the Data Controller.
You may request an updated list of Data Processors from the Data Controller at any time.
Legal basis of the processing
Legal basis of the processing:
A) - pursuant to Art. 6(1)(f) - processing is necessary for the purposes of the legitimate interests pursued by the Data Controller in order to ensure that the site functions as intended and to properly manage user relations (navigation, handling disputes and administrative matters, processing requests for contact, relations with the Parent Company and its subsidiaries).
B) - pursuant to Art. 6(1)(c) - processing is necessary for compliance with a legal obligation to which the Data Controller is subject.
C) - pursuant to Art. 9(2)(g), Legislative Decree 101/18 art. 18 sexies letter z) - processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law.
Your data shall therefore be retained solely for the period of time strictly required to fulfill the purposes for which they are requested, in accordance with the time limits provided and with the data minimization principle in keeping with contractual and legal obligations.
- contact requests: one year from the date of the final response given to the data subject.
- complaints: up to a maximum of 10 years from the final response given to the data subject
- pharmacovigilance: for the duration of the life cycle of the product to which the adverse event refers to, and for a further 10 years from the withdrawal of the product itself from the market.
The processing in question shall be conducted in the EU, though the Data Controller reserves the right to transfer your Data to countries outside the European Union if the transfer is covered by adequate decisions issued by the European Commission or by appropriate safeguards provided by the current legislation. Your personal data will not be otherwise disclosed.
Rights of the data subject
At any time, you are entitled to exercise the following rights under Art. 15 et seq. of EU Regulation 2016/679:
i. right of access (art. 15 GDPR);
ii. right of rectification (art. 16 GDPR), erasure (art. 17 GDPR) or restriction (art. 18 GDPR);
iii. right to object to the processing (art. 21 GDPR);
iv. right to data portability (art. 19 GDPR);
v. right to revoke consent at any time, without prejudice to the lawfulness of the processing based on the consent given prior to revocation;
vi. the right to file a complaint with a for the protection of personal data supervisory authority (Italian Data Protection Authority) (art. 77 GDPR).
To exercise the aforementioned rights, file a report, or request additional information regarding the methods by which personal data is processed, forward all requests either to firstname.lastname@example.org or to the following address: Via John Fitzgerald Kennedy, 5 - Comazzo (LODI), Italy.