(pursuant to art. 13 of EU Regulation 2016/679)
In accordance with Article 13 of Regulation (EU) 2016/679 (hereinafter “GDPR”), HANTECH MEDICAL ITALY SPA provides this information to describe how it processes the personal data of its customers and suppliers.
It is essential to clarify the scope of this document. The GDPR protects the personal data of "natural persons." Therefore, this notice is specifically addressed to the following categories of individuals (hereinafter "Data Subjects"):
Data processing will be based on the principles of lawfulness, fairness, and transparency, to protect the privacy and rights of interested parties.
The Data Controller, or the entity that determines the purposes and means of processing personal data, is:
HANTECH MEDICAL ITALY SPA
Please be informed that, as of the date of publication of this notice, the Data Controller has not designated a Data Protection Officer (DPO), as the mandatory requirements set forth in Article 37 of the GDPR do not apply.
The personal data of the Data Subjects are processed exclusively for the purposes described below and in accordance with the corresponding lawfulness conditions set forth in Article 6 of the GDPR. To ensure maximum clarity and transparency, the information relating to each processing activity is summarized in the following table.
|
For the processing referred to in Purpose 4 (Video Surveillance), express reference is made to the extended Information on the Processing of Personal Data through the Video Surveillance System, which can be requested at the address HR.Italy@hantechmedical.com .This document, drafted in accordance with the European Data Protection Board (EDPB) Guidelines 3/2019 and the indications of the Italian Data Protection Authority (Garante Privacy), provides full details on the processing methods, the areas monitored, and the safeguards adopted, also pursuant to the trade union agreement signed on July 22, 2021.
The provision of personal data for the purposes set out in points 1 (Management of the contractual relationship) and 2 (Fulfillment of legal obligations) of the previous table is mandatory. It constitutes a necessary requirement for the establishment and continuation of the business relationship. Failure to provide the requested data would make it impossible for HANTECH MEDICAL ITALY SPA to execute the contract and fulfill the related legal obligations.
Data processing for the purpose referred to in point 3 (Exercising and defending legal claims) does not require specific provision, as it pursues the Data Controller's legitimate interest by using data already collected for other purposes. Processing for the purpose referred to in point 4 (Video surveillance) is intrinsically linked to physical access to company premises.
The personal data of the Data Subjects will not be disseminated, i.e., will not be disclosed to unspecified parties. However, they may be disclosed, for the purposes described above, to specific categories of parties who will act as independent Data Controllers or Data Processors pursuant to Art. 28 of the GDPR, based on specific contractual agreements. These categories include:
Furthermore, please note that aggregated and anonymized data relating to business flows with customers and suppliers, which do not constitute personal data pursuant to Regulation (EU) 2016/679 as they do not allow the identification of natural persons in any way, even indirectly, may be shared with the parent company, HANTECH MEDICAL DEVICE CO. LTD, based in China, for statistical analysis and internal reporting purposes. The processing of personal data outside the European Economic Area is not foreseen.
In relation to the processing of their personal data, each Data Subject may exercise the rights provided for in Articles 15 to 22 of the GDPR at any time. Specifically, the Data Subject has the right to:
The exercise of these rights is free of charge. To exercise their rights, the Data Subject may send a written communication to the Data Controller using the contact details provided in Section 2 of this policy. The Data Controller will respond within one month of receiving the request.
If the data subject believes that the processing of their personal data violates the provisions of the GDPR, they have the right to lodge a complaint with the competent supervisory authority. In Italy, the supervisory authority is the Italian Data Protection Authority (Garante per la protezione dei dati personali). The contact details for the Authority are as follows:
Address: Piazza Venezia n. 11, 00187 - Rome, Italy
Telephone switchboard: (+39) 06.696771
Email: protocollo@gpdp.it
Certified electronic mail (PEC): protocollo@pec.gpdp.it (enabled to receive only communications from certified email)
Institutional website: www.gpdp.it or www.garanteprivacy.it
Further information and the forms required to submit a complaint are available on the Guarantor's website.
(pursuant to art. 13 of Regulation (EU) 2016/679)
The Data Controller, i.e. the legal entity that determines the purposes and means of processing your personal data, is:
HANTECH MEDICAL ITALY SPA
The personal data you provide by submitting your CV or by filling out forms on recruiting portals will be processed exclusively for the following purposes:
a) Research, selection and evaluation of personnel, for the position for which you have applied or for other open positions compatible with your professional profile.
b) Managing communications with you throughout the selection process.
The legal basis for this processing is Article 6, paragraph 1, letter b) of the GDPR, as the processing is necessary for the implementation of pre-contractual measures taken at your request (evaluation of your application for a potential job).
The processing will concern the common personal data you entered in your CV, such as, for example: personal details, contact details, information relating to your educational background and professional experience, as well as any other information you freely decide to provide.
We ask you not to include in your CV any data belonging to special categories (pursuant to Article 9 of the GDPR), such as data relating to health, political opinions, racial or ethnic origin, trade union membership, etc. If the inclusion of such data is required by law (e.g., belonging to protected categories pursuant to Law 68/99), please limit yourself to providing only strictly relevant information.
Your data will be processed using manual and electronic means by specifically authorized and trained internal personnel of HANTECH MEDICAL ITALY SPA (e.g., Human Resources and line managers involved in the selection process). Your data will not be disseminated or shared with third parties, with the exception of any external companies that support the Company in the recruiting process, which will act as Data Processors pursuant to Article 28 of the GDPR.
Your personal data will be retained for the time strictly necessary to manage the selection process for the position for which you have applied. If you are unsuccessful in the selection process, or if you submitted a speculative application, your data will be retained for a maximum of 24 months from the date of collection, in order to consider you for future job opportunities that match your profile. After this period, the data will be deleted or irreversibly anonymized. If the selection process is successful, your data will be processed in accordance with the employee privacy policy.
Providing your personal data is optional but necessary to evaluate your application. Failure to provide it would make it impossible for the Company to consider your request and, therefore, include you in the selection process.
As a data subject, you have the right to exercise at any time the rights provided for in Articles 15 to 22 of the GDPR, including:
To exercise your rights, you can send a written communication to the email address: HR.Italy@hantechmedical.com .
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In Italy, this authority is the Italian Data Protection Authority (Garante per la protezione dei dati personali). The Authority's contact details are available on its official website: www.gpdp.it