Privacy and Cookie Policy
Privacy and Cookie Policy
Pursuant to Article 13 of EU Regulation 2016/679 of 27 April 2016 (“GDPR”), this information notice is provided regarding the processing of personal data collected while browsing the website equans.it (“Site”) through the use of cookies by Equans Italia S.p.A. (“Equans” or “Controller”). For any information and/or issue related to this cookie policy (“Policy”) and/or in relation to the processing of users’ personal data carried out through the cookies implemented on the Site, it is possible to contact the Controller at any time by sending a registered letter with return receipt to the registered office of Equans at Via Giorgio Stephenson 73, 20157, Milan, or by sending an email to privacy.italia.it@equans.com. Since the Site uses cookies for different purposes, as better described below, with this Policy the Controller intends to inform users about (i) what cookies are, (ii) which types of cookies are implemented on the Site, and (iii) how cookies and users’ personal data are used in relation to the preferences expressed before starting navigation and for how long, as well as (iv) remind users of the rights they can exercise pursuant to the GDPR. Therefore, the Controller asks all users to carefully read this Policy.
The Controller collects and processes the personal data of Site users through the cookies it deploys directly on the Site. With the exception of strictly necessary cookies, other cookies (performance, functionality, targeted advertising and social media cookies, both first- and third-party) are subject to the user’s consent. The user may express consent to the use of these cookies in a simplified way by following the instructions provided in the information banner that appeared upon first access to the Site, divided for each category of cookies implemented, as reported below. The Controller processes users’ personal data solely through electronic tools, in a fully automated manner and without human intervention. Therefore, employees and collaborators of the Controller will never access the content of users’ personal data obtained through cookies, meaning they will never be able to access and/or obtain directly identifiable personal information. The Controller declares that it has adopted specific security measures pursuant to Article 32 of the GDPR in order to prevent data loss, unlawful or incorrect use, and unauthorized access. In case consent is given for the use of users’ personal data through third-party technical and analytical cookies and profiling cookies (both first- and third-party), users may at any time withdraw their consent through the dedicated “preference center” section, or by submitting a request to the Controller using the methods indicated in this Policy and/or communicated by the Controller itself.
Users’ personal data collected through the use of cookies on the Site are not disclosed. Limited to the processing related to the third-party cookies listed below and for the retention periods indicated in the relevant tables, users’ personal data may be communicated to third parties, including companies belonging to the same group as the Controller and affiliated companies, as well as service providers (including IT services necessary for the operation of the Site, cloud computing services, administrative services, call center and customer support services); consultants (including accountants, auditing firms, lawyers, insurers); public authorities (including public bodies and law enforcement agencies); and partners of the Controller. These subjects will act as independent data controllers or as data processors (in which case they will be appointed in writing by the Controller pursuant to Article 28 of the GDPR and duly instructed to process personal data on behalf of the Controller). Furthermore, users’ personal data will be processed by certain employees of the Controller or appointed data processors, who have been formally designated as authorized persons for processing (pursuant to Article 29 of the GDPR), and adequately instructed to process personal data exclusively for the purposes described and in compliance with the provisions of the GDPR and any other applicable law, regulation, measure and/or authorization issued by the competent authority in the field of personal data processing. All users have the right to easily and free of charge obtain a complete list of data processors by submitting a request to the Controller using the contact methods described in this Policy.
Users’ personal data may be transferred outside the European Economic Area (EEA). In such case, where such transfer is necessary for the purposes described above, the Controller will verify the existence of adequacy decisions adopted by the European Commission on a case-by-case basis. In the absence of adequacy decisions, the Controller adopts appropriate, adequate and necessary safeguards to ensure an adequate level of protection of users’ personal data pursuant to the GDPR. Users may contact the Controller according to the methods outlined in this Policy to obtain a copy of such safeguards.
To exercise their rights or obtain further information or clarification regarding this Policy, users may contact the Controller using the following methods: by sending a registered letter with return receipt to the registered office of Equans in Via Giorgio Stephenson 73, 20157, Milan, or by sending an email to privacy.italia.it@equans.com. Furthermore, pursuant to the GDPR, users may exercise the following rights by contacting the Controller using the methods indicated in this Policy:
-
right of access: obtain confirmation as to whether or not personal data concerning you are being processed and, if so, receive information, in particular, regarding the purposes of the processing, categories of personal data processed and retention period, and the recipients to whom these data may be communicated (Article 15 GDPR);
-
right to rectification: obtain, without undue delay, the rectification of inaccurate personal data concerning you and the completion of incomplete personal data (Article 16 GDPR);
-
right to erasure: obtain, without undue delay, the erasure of personal data concerning you, where one of the cases provided for in Article 17 applies (Article 17 GDPR);
-
right to restriction: obtain from the Controller the restriction of processing in the cases provided for by the GDPR (Article 18 GDPR);
-
right to data portability: receive in a structured, commonly used and machine-readable format the personal data concerning you provided to the Controller, and obtain the transmission of those data to another controller without hindrance, in the cases provided for by the GDPR (Article 20 GDPR);
-
right to object: object to the processing of personal data concerning you, unless there are legitimate grounds for the Controller to continue the processing (Article 21 GDPR);
-
right to lodge a complaint with the Supervisory Authority: lodge a complaint with the Personal Data Protection Authority, Piazza Venezia 11, 00187 – Rome (RM).