product
catalog
E-Commerce contact icon Get in touch

Metal Work

50 anni, 1967 - 2017 Elite logo Logo Fondazione Bonatti

PRIVACY POLICY FOR VISITORS TO WWW.METALWORK.IT  WEBSITE

The purpose of this Privacy Policy is to describe the way in which the website WWW.METALWORK.IT  is managed, with reference to the processing of the personal data of the users/visitors consulting it.
The policy applies only to the above-mentioned website and not to other websites that may be consulted by the user through specific links.
Metal Work S.p.A. with headquarters in Via Segni, 5/7/9, Concesio (BS), Postcode: 25062, VAT REG. No.: 03472820178, TEL. 030 218711, e-mail: metalwork@metalwork.it, certified e-mail: metalworkspa-bs@legalmail.it, in its capacity as Data Controller, guarantees compliance with the legislation on the protection of personal data (Regulation 2016/679/EU legislative decree no. 196/03, as amended by legislative decree 101/2018). Users/visitors are therefore invited to read this Privacy Policy carefully before sending any kind of personal information by e-mail and/or filling in any online form on the website. 

Data Controller
In addition to the above-identified Data Controller, partner websites that may, from time to time, be involved in data processing activities can act autonomously as data controllers.

How the data are gathered
Metal Work S.p.A. gathers user data when you:  

  1. create an account,
  2. use services via IT tools
  3. make a purchase on our website, 
  4. view advertisements on our website, 
  5. subscribe to a newsletter, 
  6. contact Metal Work S.p.A. customer service,
  7. share or participate on our channels, social media and other community websites,
  8. apply for a job.

Subject matter of the processing
1) Browsing data
IT systems and software procedures used to operate this website capture personal data during normal operation, the transmission of which is implicit in the use of internet communication protocols.
This is information which could, by its very nature, through association and processing with data held by third parties, make it possible to identify users/visitors (e.g. IP address, domain names of computers used by visitors/users connecting to the site etc.).
This data is only used for statistical information and to check the site is operating correctly.
Web contact data is not however kept for more than seven days, subject to investigations into computer-related crime resulting in damage to the site.
No information resulting from the web service will be communicated or disclosed.
2) Data provided voluntarily by users/visitors
Users/visitors connecting to the site to send personal data to access services, such as:

  • Contacts (such as name and e-mail address), 
  • Age, User name and password, 
  • Profile data (such as a profile picture), 
  • Data provided during support by our customer service (such as chat logs and customer service tickets).
  • Additional data provided by the user (e.g., data used to identify a lost account) to access services, send requests by e-mail or to send their CV, should be aware that this will involve the Data Controller acquiring the sender's address and/or other personal data, which will be processed for the sole purpose of responding to the request or providing the service.

Personal data provided by users/visitors will only be communicated to third parties if such communication is required to fulfil requests they submit, or to comply with legislation (e.g., invoicing).
3) Data gathered directly from you when using the Services

  • IP address and device identifier (such as device ID, advertisement ID, MAC address, IMEI).
  • Device-related data (such as device name and operating system, browser information, including browser type and preferred language). 

4) Data obtained from our partners

  • Data we receive when you connect to a third-party social network (such as Facebook, LinkedIn, Instagram).
  • Data we receive from billing partners (if you make a purchase on the site).
  • Data gathered for advertising and analysis purposes, in order to improve the quality of the services we offer

5) Cookies
In addition to data expressly sent to the Data Controller, other types of data may be logged as a result of users browsing the site. When users access the site, they are sent a 'cookie'. A cookie is a small text file which the site can automatically send to the computer of users when they view our webpages. They facilitate the browsing experience, obtain information on the browsing habits of individual users of the site, and enable the operation of various services requiring the identification of the user's journey through different site pages. Irrespective of the presence of cookies, during any site access the site registers the type of browser (e.g., Internet Explorer, Chrome, Firefox), the operating system (e.g., Windows, Macintosh), the host and the user/browser's URL, in addition to the data on the page requested. This data may be used in anonymous, aggregate form for the statistical analysis of site use. Consult the Cookie Policy for the site to read more about how cookies are managed.

Data processing methods
Data is processed using automated tools (e.g., electronic media and procedures) and manually (e.g., paper copies) for the time strictly necessary for the purpose for which the data is gathered, and in accordance with data processing legislation.
Specific security measures are observed to prevent the loss, incorrect or illegal use of data or unauthorised access, such that access is only permitted to authorised parties or data processors appointed in accordance with current legislation. A list of Data Processors appointed in accordance with article 28 of EU Regulation 679/2016 is available at the headquarters of the Data Controller or by submitting a remote request to the above addresses. 

Purposes of data processing
In addition to those indicated in the individual disclosures that appear before filling in the forms in the various sections of the site, the purposes of the data processing carried out by the Data Controller are as follows:

  1. to gather, store and process data to manage and fulfil contractual or pre-contractual obligations connected with the performance of the relationship established or being established and the provision of the service offered on the site;
  2. to use your personal data (in particular the e-mail address) for purposes relating to the performance of our activity, such as offering personalised content such as newsletter services or sending direct marketing communications;
  3. to process the personal data provided and the data captured when browsing the site, to deliver a service consistent with the information sent during use of the service;
  4. to gather, store and process data to carry out statistical analysis in an anonymous and/or aggregate form;
  5. to comply with all regulatory and legal requirements and response to any request from the data protection authorities or any other competent authority; 
  6. to manage and cancel subscriptions to our newsletter.

Legal basis for processing
The legal basis for customer data being processed by the Data Controller via the site indicated above consists, as regards the information referred to in point a) and f) above, of a request in contract or pre-contractual understandings established with the interested parties, while as regards points b), c) and d), the legal basis is to be found in the legitimate interest of the Data Controller in the free economic initiative referred to art. 41 of the Italian Constitution, and as regards point e) the legal basis is to be found in a legal obligation. With regard to further and future purposes that may require consent, such consent shall be requested on a specific form and shall also be considered a valid legal basis.

Recipients
In addition to the Data Controller, in some cases certain categories of data processors and authorised parties involved in the operation of the corporate organisation could have access to the data (administration, commercial, marketing and legal personnel and system administrators). Furthermore, the Data Controller may use external parties (suppliers of third-party technical services, transport providers, hosting providers, cloud services, IT companies, communication agencies) who will be appointed as external data processors. An up-to-date list of data processors can be requested at any time from the Data Controller, via the address indicated above.

Transfer of data to countries outside the EU
The Data Controller does not transfer the data of Customers/Users/navigators of the side to other countries outside the European Union.  
Data processed by the Data Controller will not be disclosed. 

Data processing location 
Data connected with the web services of this site are processed in Italy and hence, in accordance with EU Regulation 2016/679 are to be considered eligible as falling within the EU.  
Data are only processed by technical personnel appointed by the Data Controller. 

Data storage location and timescales 
Data is processed for the time required to provide the service requested by users, then destroyed using secure methods, such as shredding paper documents and wiping electronic copies.

Optional or compulsory data
Apart from the information stated regarding browsing data captured automatically, users/visitors can choose whether or not to provide their personal data. Failing to provide the data may prevent requests from being fulfilled. Optionally, expressly and voluntarily choosing to send an e-mail to addresses on this site will result in the user's address being captured, for the purpose of fulfilling requests for services, products and/or information, in addition to any other personal data entered on forms.

Rights of Data Subjects
In accordance with the GDPR, data subjects have the right to obtain information on its existence at any time, in addition to the content and origin, check its accuracy or ask for it to be supplemented, updated or amended.
Requests should be sent to: Metal Work S.p.A. at the addresses indicated above.
With regard to processing the aforementioned data, customers have the right to obtain the following from the Data Controller:

  1. confirmation of the existence of their personal data, its communication in an intelligible format, understanding of its origin, and the logic at the basis of its processing;
  2. deletion of their personal data within a reasonable timescale, its transformation to make it anonymous, or block data processed in breach of legislation, 
  3. to have it updated, supplemented or amended;
  4. a statement that the operations referred to in 2) and 3) above were made known to parties to whom the data was communicated, except where this is impossible or involves disproportionate methods;
  5. Customers also have the right to have their personal data amended or deleted, or its processing restricted;
  6. Customers have the right to withdraw consent to processing which is optional and is not related to executing the contract agreed with the Data Controller;
  7. Users also have the right to object to their data being processed, even if it is relevant for the purpose it was collected, request data portability, exercise their right to be forgotten, and contact the ordinary judicial authority or the Supervisory Authority for the protection of personal data to report any alleged breach. In Italy, this Supervisory Authority can be contacted via certified e-mail sent to: protocollo@pec.gdpd.it, or via registered post with acknowledgement of receipt sent to the Supervisory Authority for the protection of personal data, based at Piazza Venezia no. 11 – Postcode 00187, Rome (Italy).

Automated decision-making processes
Automated decision-making processes are not implemented on aggregate data collected, other than to improve site management.

Minors
This Site and the Data Controller Services are not intended for children under the age of 18, and the Data Controller does not knowingly collect personal information from children. In the event that information about minors is unintentionally recorded, the Data Controller will delete it in a timely manner upon the users' request.

Applications for employment
Metal Work S.p.A.’s Privacy Policy for candidates can be accessed from this link.

Third-party services
The Services may have links to external sites, outside our control. These Privacy Policies only cover the way in which Metal Work S.p.A. processes personal and non-personal data gathered through the Services. By accessing any external site, you agree to the privacy policies of that site. The external sites may have different policies regarding the gathering, use and disclosure of personal data, over which Metal Work S.p.A. has no control and is not responsible for the privacy practices of such third parties.
Therefore, it is advisable to consult the privacy policies of all third-party services. 

Final clauses
In view of the current state of development of the legislation on the protection of personal data, we inform you that this privacy policy may be subject to updates.

Concesio (BS), April 2019