Privacy Policy

The following Privacy Policy is referred exclusively to the website https://www.metra.eu/ (hereinafter “Website”) and does not apply to any other websites that may be accessed through links to external websites or pages. It is provided pursuant to the European Regulation on the protection of personal data (hereinafter the “GDPR”) and the relevant Italian data protection legislation (hereinafter, jointly, the “Applicable Law”) to the users who interact with the Website by browsing its pages. With regard to cookies, please refer to the Cookie Policy, which shall be deemed an integral part of this Privacy Policy.

Table of contents

  1. DATA CONTROLLER AND CONTACT DETAILS1
  2. TYPE AND ORIGIN OF PERSONAL DATA COLLECTED
  3. PURPOSE OF DATA PROCESSING
  4. NATURE OF THE PROVISION OF PERSONAL DATA
  5. METHODS OF PROCESSING AND DATA SECURITY
  6. RECIPIENTS OF PERSONAL DATA
  7. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANIZATIONS
  8. RETENTION PERIOD
  9. DATA SUBJECT RIGHTS
  10. EXERCISE OF DATA SUBJECT RIGHTS
  11. UPDATES OF PRIVACY POLICY

1.  DATA CONTROLLER AND CONTACT DETAILS

Metra S.p.A. with registered office in Via Stacca, 1 – 25050 Rodengo Saiano (BS), Tax Code and VAT IT00285030177, hereinafter “Data Controller”.

For every need connected to data processing the Data Controller can be reached here: tel. +39 030 68191, e-mail privacy@metra.it,  PEC amministrazione@pec.metra.it.

2.  TYPE AND ORIGIN OF PERSONAL DATA COLLECTED

The personal data collected by or through the Website (hereinafter the “Data”) are those indicated below.

browsing data
The IT systems used to operate the Website collect, during their normal operation, certain personal data in aggregated form and not immediately identifying the data subject, the transmission of which is implicit in the use of Internet communication protocols.

Such information is not collected in order to be associated with identified data subjects but may allow users to be identified through processing activities and associations with data held by third parties.

This technical/IT data may be processed for the following purposes:

  • obtaining statistical information on the use of the Website;
  • monitoring the proper functioning of the services provided through the Website;identifying anomalies and/or misuse.

personal data voluntarily provided by the user
By using the Website, users may voluntarily provide personal data, such as:

  • personal data provided through the voluntary sending of emails to the Data Controller’s contact details indicated on the Website, which imply the subsequent collection of the sender’s address, including email address, and/or telephone number necessary to respond to requests, as well as any other personal data included in the relevant communications;
  • personal data (in particular, name, surname, email address, telephone number, city and country) provided through the completion of the contact form available in the “CONTACTS” section of the Website, for any requests for information and/or clarification and, subject to the user’s consent, for marketing purposes;
  • any personal data collected through the restricted area of the Company’s Extranet, accessible exclusively to authorized users through credentials provided by the Data Controller, dedicated to the management and use of company services and applications functional to the performance of employment relationships, as well as commercial and contractual relationships with customers, suppliers, partners and collaborators. Within the scope of such services, the following data may be processed, such as: identification and contact data, company-related data, authentication credentials, data related to accesses and logs of the user, administrative, accounting and contractual data, data relating to technical support and support tickets, as well as any further information provided or managed through the services available on the platform (such as CRM, HR portal, document management systems, Office 365, supplier portal, corporate communication systems, and reporting and assistance tools).

The Data Controller shall process the user’s data according to the Applicable Law, assuming that such data refers to the user or to third parties who have expressly authorized the user to provide them, or whose personal data the user is otherwise entitled to provide. In relation to such circumstances, the user undertakes to indemnify and hold harmless the Data Controller from any objections, claims, demands or requests for compensation for damages arising from the processing of personal data that may be submitted by such third parties.

Please help us keep your personal data updated by informing us of any changes concerning such data.

Cookies and other tracking technologies
For information regarding the types of cookies used by the Website, please refer to the cookie policy available in the relevant section of the Website.

3. PURPOSE OF DATA PROCESSING

In light of the above, the Data collected will be processed for the purposes and on the basis of the legal bases indicated below.

PURPOSE OF PROCESSING:

  • To answer requests submitted by users through the voluntary sending of messages to the Data Controller’s contact details indicated on the Website;
  • To answer any requests for information and/or clarification submitted through the contact form available in the CONTACTS” section of the Website.

LEGAL BASIS FOR PROCESSING: to take steps at the request of the data subject prior to entering into a contract or necessary to the performance of a contract to which the data subject is party [cfr. art. 6, par. 1, lett. b), GDPR].

PURPOSE OF PROCESSING:

  • to comply with obligations arising from laws or regulations, including the obligation to answer any requests made by the user to exercise the rights granted to them as a data subject under the applicable data protection legislation.

LEGAL BASIS FOR PROCESSING: to comply with obligations arising from laws or regulations to which the Data Controller is subject [art. 6, par. 1, lett. c), GDPR].

PURPOSE OF POCESSING:

  • to verify any fraudulent or otherwise unlawful use of the Website and ensure its security and functionality in the interest of users and the Data Controller;
  • to carry out research/statistical analyses on aggregated or anonymous data, which therefore do not allow the user to be identified, as well as to measure traffic and assess the usability of and interest in the Website;
  • to carry out the storage, hosting and management of the Website’s backend infrastructure;
  • to establish, exercise or defend a right in judicial or extrajudicial proceedings, or whenever judicial authorities perform their functions.

LEGAL BASIS FOR PROCESSING: the legitimate interest of the Data Controller and of the users themselves in preventing or detecting any fraudulent or otherwise unlawful use of the Website; the legitimate interest of the Data Controller in assessing the usability and attractiveness of the Website and managing its infrastructure; the legitimate interest of the Data Controller, where applicable, in establishing, exercising or defending a right in judicial or extrajudicial proceedings, or whenever judicial or administrative authorities perform their functions [art. 6, par. 1, lett. f), GDPR].

PURPOSE OF PROCESSING:

  • management of the employment relationship, including the organization of company activities, personnel administration, internal communication, and the use of company tools and services;
  • management of contractual and commercial relationships with customers, suppliers, partners and collaborators, including the management of orders, supplies, technical support, and commercial and administrative documentation;
  • management of IT services and technical support, including the opening and management of support tickets, system maintenance, and monitoring of the proper functioning of the platform;
  • management of documentation, technical support and application services available through the platform.

LEGAL BASIS FOR PROCESSING: to perform a contract to which the data subject is party and legitimate interest of the Data Controller [art. 6, par. 1, lett. b) and f), GDPR].

4. NATURE OF THE PROVISION OF PERSONAL DATA

The provision of Data by the user is optional. However, failure to provide such Data, either in whole or in part, may result in the inability to respond to any requests for information and/or clarification and/or requests to exercise data subject rights.

The provision of any optional Data within the contact forms available on the Website (fields without an asterisk) is entirely voluntary and does not affect the ability to use the services.

5. METHODS OF PROCESSING AND DATA SECURITY

The Data is processed using manual and/or IT tools, in any event through methods suitable to ensure their security and confidentiality.

For this purpose, the Data Controller has adopted and implemented appropriate technical and organizational security measures commensurate with the level of risk associated with the processing activities carried out.

In particular, the functionalities of the Website are provided through an encrypted HTTPS connection, and personal data are collected, stored and retained on secure servers protected by firewalls and physically located within the European Union.

6. RECIPIENTS OF PERSONAL DATA

The Data may be shared, for the purposes of processing stated hereinabove, with:

  • Persons authorized by the Data Controller to process personal data pursuant to Article 29 of the GDPR and Article 2-quaterdecies of the Italian Privacy Code, who have received specific instructions regarding the methods for processing personal data in compliance with the Applicable Law;
  • Companies belonging to the Group, if and only to the extent necessary to take steps prior to entering into a contract at the user’s request or to perform a contract to which the user is a party and/or upon the user’s request;
  • Companies, consultants or professionals appointed, where applicable, to install, maintain, update and, generally, manage the Data Controller’s hardware and software, including hosting provider and cloud computing service providers, companies providing Website management and development services, and companies providing marketing and information/communication services, all of which typically act as Data Processors pursuant to Article 28 of the GDPR;
  • Entities, bodies or authorities which, acting as independent data controllers, are required to receive the user’s personal data pursuant to legal provisions or orders issued by authorities, or in order to prevent and/or detect any fraudulent activities or misuse of the Website and the services offered by the Data Controller;
  • Law firms, professional associations, consultants or professionals (such as legal, administrative and/or tax advisors) appointed, where applicable, to assist the Data Controller in: properly fulfilling the legal obligations to which it is subject; establishing, exercising or defending a right in judicial or extrajudicial proceedings, or whenever judicial or administrative authorities perform their functions.

7. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANIZATIONS

The servers of the Data Controller’s hosting provider are located within the European Union. However, certain suppliers of the Data Controller, or the servers used by such suppliers, may be located in countries outside the European Economic Area (EEA). In such cases, the Data Controller ensures that any transfer will be carried out in compliance with Chapter V of the GDPR.

In particular, where transfers are made to countries that do not ensure an adequate level of protection, the Data Controller undertakes to adopt one of the appropriate safeguards provided for under the GDPR and in accordance with the provisions issued by the competent authorities.

Further information is available from the Data Controller by writing to the following address: privacy@metra.it.

8. RETENTION PERIOD

The Data processed for the pre-contractual and/or contractual purposes indicated above will be retained for the time necessary to achieve the purposes for which they are collected or for any other related legitimate purpose, and in any event no longer than the expiry of the statutory limitation periods for the protection of rights and/or compliance with legal obligations.

Where, following requests for information and/or clarification, a contract is entered into, the retention period of the Data shall be the one indicated in the Privacy Notice applicable to customers and suppliers, namely ten years from the date of execution of the contract, in order to allow the Data Controller to demonstrate the proper fulfilment of its contractual obligations, as well as to ensure any judicial or extrajudicial protection of its legal position.

The Data processed to comply with legal obligations will be retained for the period necessary to fulfil such obligations and in compliance with the minimum retention periods provided for by the applicable legislation from time to time in force or, where no statutory retention period is provided, for the period necessary to demonstrate compliance with such obligations.

9. DATA SUBJECT RIGHTS

The user, as a data subject, has the right to:

  • Obtain confirmation as to whether or not personal data concerning the user are being processed and, where applicable, obtain access to such data and a range of relevant information, including, by way of example, information relating to: (a) the purposes of the processing; (b) the categories of personal data processed; (c) the recipients or categories of recipients to whom the personal data have been or will be disclosed; (d) the retention period of the personal data or, where this is not possible, the criteria used to determine such period; (e) the source of the personal data, where such data have not been provided by the user;
  • Request and obtain the updating of the Data, the rectification of inaccurate Data or, where relevant, the completion of incomplete Data;
  • Request and obtain the erasure of the Data where: (a) the Data is no longer necessary in relation to the purposes for which they were collected or otherwise processed; (b) the user objects to the processing carried out on the basis of the Data Controller’s legitimate interest and there are no overriding legitimate grounds for continuing the processing; (c) the Data has been unlawfully processed; or (d) the Data must be erased in order to comply with a legal obligation to which the Data Controller is subject;
  • Request and obtain restriction of processing in the following cases: (a) the accuracy of the Data is contested, for the period necessary for the Data Controller to carry out the required checks; (b) the processing of the Data by the Data Controller is unlawful and the user objects to the erasure of the Data and requests restriction of their use instead; (c) the user needs the Data for the establishment, exercise or defense of a right in judicial proceedings, although the Data Controller no longer needs the Data for processing purposes; (d) pending verification of whether the legitimate interests of the Data Controller override those of the data subject;
  • Where the processing is based on a contract and is carried out by automated means, request and receive the Data concerning the user in a structured, commonly used electronic form and, where technically feasible, obtain the direct transmission of such Data from the Data Controller to another controller;
  • Object in whole or in part, on grounds relating to the user’s particular situation, to the processing of the Data concerning the user, even where such Data is relevant to the purpose of the processing;
  • Where the processing is based on the user’s consent, withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
  • Lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) pursuant to Article 77 of the GDPR and Articles 140-bis et seq. of the Italian Privacy Code, in case the user considers that their rights under data protection legislation have been infringed.

The Data Controller shall communicate any rectification, erasure or restriction of processing carried out to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves a disproportionate effort.

10. EXERCISE OF DATA SUBJECT RIGHTS

As a data subject, you may exercise the rights referred to above at any time by sending an email to the following email address: metra@privacy.it.

To file a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), you may use the forms available on its website.

11. UPDATES OF PRIVACY POLICY

This Privacy Policy may be subject to changes and/or additions and/or updates, including as a result of updates to the Applicable Law.

In such cases, the Data Controller will inform you of any changes and/or additions and/or updates affecting this Privacy Policy by publishing the updated version on the Website.