Privacy Notes

PRIVACY POLICY

Information for the Whistleblower – Whistleblower – on the processing of his personal data

(ex art. 13-14 EU Reg.to 2016/679 – GDPR)

Dear Data Subject, Pursuant to and in accordance with EU Reg. 2016/679 hereinafter ‘GDPR’, we hereby wish to inform you that the aforementioned legislation provides for the protection of data subjects with respect to the processing of personal data. Such processing will be based on the principles of fairness, lawfulness, transparency and protection of your privacy and rights.

Your personal data will be processed in accordance with the legislative provisions of the above-mentioned legislation and the confidentiality obligations provided for the processing of your personal data provided through the Reporting – Whistleblowing Portal.

Data Controller: ETAFELT SRL – VAT No.: 00517960019 – Registered office: Corso Piemonte No. 66 – 10099 SAN MAURO TORINESE – mail info@etafelt.it

Categories of personal data processed: The Reporting – Whistleblowing Portal exclusively collects, where conferred, identifying data of a common nature, such as personal data (first name, last name), contact data (email, telephone), contained in the report, within which the Interested Party (otherwise defined as the “Whistleblower” or the “Whistleblower”) may communicate any special data and/or judicial data.

Purposes and legal basis of processing: in particular, your data will be processed for the purposes related to the implementation of fulfillments related to legislative obligations (Legislative Decree 24/2023 and by Law 179/2017) in order to allow the management of investigative activities necessary to assess reports regarding violations of internal and/or external regulations, contained in the Code of Ethics, any Model 231 and applicable regulations.

Method of processing. Data processing will be carried out in accordance with the principle of minimization, by authorized, formally designated and adequately trained individuals and will be carried out through the use of computer and telematic media, so as to ensure the security, integrity and confidentiality of the collected data, in compliance with the organizational, physical and logical measures provided for in current regulations.

The Reporting Portal – Whistleblowing guarantees, at all stages, the confidentiality of the content of the report and the identity of the whistleblower, which may not be disclosed without the whistleblower’s express consent to persons other than those authorized to receive or follow up on reports under Articles 29 and 32(4) of the GDPR, including through the use of encrypted communications, except in cases where (I) the report is unfounded and made for the sole purpose of harming the whistleblower or due to gross recklessness, negligence or inexperience of the whistleblower; (II) anonymity is not enforceable by law (ex. criminal investigations, inspections by supervisory bodies, etc.); (III) facts are revealed in the report such that, although unrelated to the company sphere, make it due to the Judicial Authority (e.g. crimes of terrorism, espionage, attacks, etc.).

All processing is carried out in accordance with the methods set forth in Articles 6, 32 of the GDPR and through the adoption of the appropriate security measures provided.

Categories of recipients of personal data. Your data will be processed only by personnel expressly authorized by the Owner and, in particular, by the appointed (whistleblowing) Receivers.

Dissemination: Your personal information will not be disseminated in any way.

Retention Period. We would like to inform you that, in compliance with the principles of lawfulness, purpose limitation and data minimization, pursuant to Article 5 of the GDPR, the reports and related documentation are kept for the time necessary for the processing of the report and in any case no longer than five years from the date of the communication of the final outcome of the reporting procedure, in compliance with the confidentiality obligations set forth in Article 12 of Legislative Decree No. 24 of 2023. In addition, your data will be kept for a period of time not exceeding the achievement of the purposes for which they are collected and processed and in compliance with the mandatory time periods prescribed by law.

You have the right to obtain from the controller the deletion (right to be forgotten), limitation, updating, rectification, portability, opposition to the processing of personal data concerning you, as well as in general you can exercise all the rights provided for in Articles 15, 16, 17, 18, 19, 20, 21, 22 of the GDPR.

Rights of the Interested Party

As a data subject you have the right to obtain confirmation of the existence or non-existence of personal data concerning you, even if not yet recorded, their communication in an intelligible form and the possibility of making complaints to the Control Authority.

He/she also has the right to obtain information on the origin of personal data, the purposes and methods of processing, the logic applied in the case of processing carried out with the aid of electronic instruments, the identification details of the data controller, data processors and the designated representative pursuant to Article 5, paragraph 2, the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them as designated representative in the territory of the State, managers or appointees.

The interested party also has the right to obtain the updating, rectification, and integration of data; the cancellation, transformation into anonymous form, or blocking of data processed in violation of the law, including data whose storage is not necessary in relation to the purposes for which the data were collected and/or processed; and the portability of data.

The interested party has the right to oppose, in whole or in part for legitimate reasons, the processing of personal data concerning him/her, even if pertinent to the purpose of collection; the processing of personal data concerning him/her for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication.