Privacy Notice

(pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 – GDPR)

With this privacy notice (the “Privacy Information Notice”), Serco Italia S.p.A., with registered office at Viale dell’Astronomia 13, Rome 00144, Italy, tax code 06293370588 (the “Controller” or the “Platform Provider”), in its capacity as data controller, hereby informs the individuals accessing and using the digital interface, website, infrastructural services or application operated by the Platform Provider accessible at the address postmaster@nadireo.com (the “Platform”) of the processing of their personal data in connection with the activities carried out through the Platform, including pre-contractual activities, in accordance with Legislative Decree No. 196/2003, as subsequently amended and supplemented (the “Italian Privacy Code”), and Regulation (EU) 2016/679 (the “GDPR”) as subsequently amended and/or integrated.

1. DATA CONTROLLER

The Controller may be contacted for any information relating to the processing of personal data at the following contact details:

  • email: [postmaster@nadireo.com]
  • postal address: by sending a written communication to the address indicated above (Viale dell’Astronomia 13, Rome 00144, Italy).

The Controller has appointed a Data Protection Officer (“DPO”), who can be contacted at the following email address: postmaster@nadireo.com.

2. SCOPE OF THE PRIVACY INFORMATION NOTICE

This Privacy Information Notice describes the processing of personal data carried out by the Controller in in connection with the provision of the Platform and the geospatial data services, the provision of geospatial data and all related digital services made available through the Platform (the “Services”).

This Privacy Information Notice applies, in particular, to:

  • any individual or corporate entity that intends to register on the Platform to purchase or obtain a license for Services supplied by Content Providers or by the Controller itself through the Platform (the “Customer”);
  • any employee, contractor, affiliate, agent or any other authorized natural person permitted to access the Services on behalf of the Customer (the “End Users”);
  • any employee, contractor or representative of Customers and/or of parties supplying Geospatial Data, Geospatial Data Services and associated content through the Platform (the “Content Providers”) operating on the Platform;
  • individuals interacting with the Controller in the context of onboarding, registration or negotiation of the Services offered through the Platform;
  • any individuals or entities accessing the Services through the rights of access and use granted to the Customer;

(hereinafter collectively referred to as the “Data Subjects”).

3. SOURCE OF PERSONAL DATA

The personal data processed by the Controller may be collected from the following sources:

  • directly from the Data Subjects (for instance, during registration on the Platform, account creation, service requests or interactions with the Controller);
  • automatically collected during the use of the Platform, through IT systems and software procedures required for its operation, including, by way of example, access logs, information relating to the use of Services, device-related data and other technical data;
  • from third parties, such as employers of End Users, Customers on whose behalf they operate, Content Providers or other commercial partners, who may provide the data necessary to enable access to the Platform, manage user accounts or allow the provision of the requested Services.

4. CATEGORIES OF PERSONAL DATA PROCESSED

The Controller processes the following categories of personal data relating to Data Subjects:

  1. Identification and contact data (name, surname, email address, telephone number, company, role and function);
  2. Account-related data (login credentials such as username, account identifiers, registration information and data required to manage access authorizations to the Platform);
  3. Platform and Services usage data (such as access logs, information relating to activities carried out, data relating to operations performed, IP address, information on the device used (device, browser, operating system), date and time of access, specific metrics relating to the use of Services and applications available on the Platform (API call volumes, frequency and duration of access to specific services, and usage data volumes) to the extent necessary for the functioning of the Platform and management of contractual relationships). The Controller may also collect Data Subjects’ browsing data through cookies or similar tracking technologies present on the Platform. Further information on the cookies used by the Controller is available in the Cookie Policy accessible at the following https://www.nadireo.com/cookie-notice/;
  4. Administrative and payment data (billing data, tax information, bank details and data relating to payments and transactions carried out through the Platform);
  5. Service-related data (information relating to orders placed, transaction history, data relating to access to and use of specific services or applications, including those provided by Content Providers, as well as user preferences and configurations);
  6. Compliance and regulatory data (information processed for the purpose of carrying out compliance checks under applicable export control regulations and international trade sanctions laws, including data relating to the nationality, country of establishment or residence, and the results of screening against applicable restricted-party lists and sanctioned-country lists)

(hereinafter collectively referred to as the “Data”).

5. PURPOSES OF PROCESSING

The Data are processed for the following purposes:

  1. in order to establish and manage the contractual relationship between the Controller and the Data Subjects, as well as to carry out pre-contractual activities requested by them pursuant to Article 6(1)(b) GDPR including for the purposes to:
  • enable registration on the Platform, the creation and management of user accounts, and the assignment and management of access rights and authorization levels;
  • allow access to the Platform and the use of the Services and functionalities available;
  • manage orders, service requests and related transactions, as well as administrative, accounting and billing activities;
  • provide technical assistance and support, including handling requests and reports relating to the operation of the Platform and the Services;
  • track and measure the utilization of the Services and applications by Customers, for the purposes of calculating revenue share amounts due to Content Providers in accordance with the applicable collaboration agreements and providing Content Providers with the relevant usage reports; and
  • carry out all activities necessary or related to the proper provision of the Services and management of the contractual relationship.

(jointly, the “Contractual Purposes“);

  • to comply with legal or regulatory obligations pursuant to Article 6(1)(c) GDPR, including for the purposes to:
  • comply with tax, accounting and administrative obligations, including those relating to transactions carried out through the Platform;
  • fulfill obligations under laws, regulations or EU provisions, including those relating to digital services and geospatial data; and
  • perform compliance checks required under applicable export control regulations and international trade sanctions laws, including the verification of Customer and End User identity against applicable restricted-party lists and sanctioned-country lists, in connection with the geospatial and satellite data distributed through the Platform;

(jointly, the “Legal Purposes“);

  • for the pursuit of legitimate interests of the Controller, adequately balanced with the rights and freedoms of Data Subjects pursuant to Article 6(1)(f) GDPR. In particular, the Controller processes on the basis of legitimate interest Data to:
  • ensure the security of the Platform and IT systems;
  • improve the performance and functionality of the Platform;
  • defend the interest of the Controller, its group entities and officers and manage claims, disputes and pre-litigation activities; and
  • carry out corporate transactions (mergers, acquisitions, etc.) and activities functional to them;

(jointly, the “Legitimate Interest Purposes“).

6. LEGAL BASIS OF PROCESSING

The processing of the Data for Contractual Purposes is necessary, pursuant to Article 6(1)(b) of the GDPR, for the performance of a contract to which a Data Subject is a party or to take steps at the request of the Data Subject prior to entering into a contract. Such processing is therefore mandatory, as, in its absence, the Controller would be unable to fulfill the Data Subject’s requests.

The processing of the Data for Legal Purposes is necessary, pursuant to Article 6(1)(c) of the GDPR, to comply with legal and regulatory obligations to which the Controller is subject. Such processing is also mandatory, and, in its absence, the Controller would be unable to fulfill the Data Subject’s requests.

The processing of the Data for Legitimate Interest Purposes is carried out, pursuant to Article 6(1)(f) of the GDPR, for the pursuit of the legitimate interests of the Controller, as identified in paragraph 5(c) above, which have been subject to appropriate assessment and balancing against the rights and freedoms of the Data Subjects. Such processing is not mandatory, and the Data Subject may object to it at any time in accordance with the procedures indicated in paragraph 11 of this Privacy Information Notice. In the event of objection, the Controller shall cease processing the Data for Legitimate Interest Purposes, unless it demonstrates the existence of compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or the processing is necessary for the establishment, exercise or defense of legal claims.

7. METHODS OF PROCESSING

The Data are processed by electronic and automated means and, where necessary, also in paper form, in compliance with the principles of lawfulness, fairness and transparency.

The Controller implements appropriate technical and organizational measures pursuant to Article 32 of the GDPR to ensure a level of security appropriate to the risk, including protection of the Data against unauthorized or unlawful processing and against accidental loss, destruction or damage.

8. RECIPIENTS OF PERSONAL DATA

For the purposes indicated above, the Controller may disclose the Data to the following categories of recipients:

  • authorized personnel of the Controller, acting within the scope of their respective duties and in compliance with applicable law;
  • providers of technical and infrastructural services necessary for the management and operation of the Platform (such as, by way of example, IT service providers, hosting, cloud computing, maintenance and application support providers);
  • providers of administrative, accounting and payment services, including entities managing invoicing systems and financial transactions related to the Services offered through the Platform, as well as payment service providers;
  • consultants and professionals, such as legal, tax and administrative advisors;
  • public authorities and supervisory bodies, as well as other public or private entities to whom the Data must be disclosed pursuant to legal provisions or orders of competent authorities;
  • companies belonging to the Controller’s corporate group, for internal administrative, accounting and organizational purposes; and
  • entities acquiring the Controller’s business or part thereof, as well as companies resulting from mergers, demergers or other corporate transformations.

The Services available on the Platform may also be provided by Content Providers, which act as independent data controllers with respect to the personal data processed for their own purposes and by their own means. In this case, the data processing will occur in compliance with the privacy information notice provided by the relevant Content Provider.

Without prejudice to the independence of the respective processing activities, no systematic transfer of personal data from the Controller to the Content Providers is generally envisaged in the context of the use of the Platform.

9. TRANSFERS OF PERSONAL DATA OUTSIDE THE EEA

The Data of the Data Subjects may be transferred to countries outside the European Economic Area (“EEA”).

In such cases, the Controller ensures that the transfer is carried out in compliance with the conditions and safeguards set out in Articles 44 et seq. of the GDPR, to ensure a level of protection of personal data that is substantially equivalent to that guaranteed within the EEA.

In particular, where applicable, such transfers may be carried out based on:

  • adequacy decisions adopted by the European Commission;
  • standard contractual clauses approved by the European Commission;
  • or other appropriate safeguards provided for under applicable data protection laws.

10. DATA RETENTION PERIOD

The Data are retained for a period not exceeding that necessary to achieve the purposes for which they were collected, as identified in paragraph 5 above.

In particular:

  • Data processed for Contractual Purposes are retained for the entire duration of the contractual relationship and for 10 years following its termination, without prejudice to cases where retention for a longer period is required for the management of disputes, requests from competent authorities or under applicable law;
  • Data processed for Legal Purposes are retained for the period established by the applicable legal or regulatory provisions, including, by way of example, obligations in the field of taxation and accounting relating to transactions carried out through the Platform;
  • Data processed for Legitimate Interest Purposes are retained for different periods depending on the specific purpose pursued and, in particular:
    • for purposes relating to security of the Platform and IT systems, including the prevention of unauthorized access and fraudulent activities, for a maximum period of [12 months] from collection;
    • for purposes relating to monitoring and improvement of the services, including the analysis of the use of the Platform, for a maximum period of [12 months], after which the data will be anonymized or aggregated;
    • for the purposes of establishing, exercising or defending legal claims are retained for the entire duration of the relevant proceedings and any further term necessary to claim and defend the rights of the Controller and/or its group entities and officers.

11. DATA SUBJECTS’ RIGHTS

The Data Subject may, at any time and free of charge:

  1. obtain confirmation as to whether or not personal data concerning them exist and access such data;
    1. obtain information on the origin of the data, the purposes and methods of processing, as well as the logic applied in the event of processing carried out by electronic means;
    1. request the updating, rectification or, where relevant, integration of personal data;
    1. obtain the erasure of personal data, anonymization or restriction of processing in the cases provided for by applicable law;
    1. withdraw any consent previously given, without affecting the lawfulness of processing based on consent before its withdrawal;
    1. obtain from the Controller the restriction of processing in cases where:
    1. the Data Subject contests the accuracy of the data, for the period necessary for the Controller to verify such accuracy;
    1. the processing is unlawful and the Data Subject opposes the erasure of the data, requesting instead that their use be restricted;
    1. the Controller no longer needs the data for the purposes of processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims;
    1. the Data Subject has objected to processing pursuant to Article 21(1) GDPR, pending verification of whether the legitimate grounds of the Controller override those of the Data Subject;
    1. object at any time to the processing of personal data concerning them carried out for Legitimate Interest Purposes;
    1. receive the personal data concerning them in a structured, commonly used and machine-readable format and transmit such data to another controller.

The Data Subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures available at www.garanteprivacy.it, if they believe that the processing of their personal data is in violation of applicable law.

Requests for the exercise of the above rights may be submitted to the Controller by sending a written communication to the following email address: postmaster@nadireo.com .

12. CHANGES TO THIS NOTICE

This Notice is effective as of the date indicated above. The Controller reserves the right to amend or update it at any time, including in light of changes to applicable law.

Any changes will be made available through the Platform or by other appropriate means of communication.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.