PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
pursuant to article 13 of Regulation (EU) 2016/679 (“GDPR”)
With this notice, the Data Controller, as defined below, would like to illustrate the purposes for which your personal data are processed, which data categories are processed, what rights you are attributed by regulations related to personal data protection and how to exercise them.
1. WHO IS THE DATA CONTROLLER?
MCZ Group S.p.A., in the person of its legal representative pro tempore, with registered office in via La Croce 8, Fontanafredda (PN), hereinafter “MCZ”.
The Controller has appointed a Data Protection Officer (DPO), who may be contacted by the Data Subject in writing at the following email address: dpo@mcz.it
2. WHICH DATA CATEGORIES ARE PROCESSED, WHY IS YOUR DATA PROCESSED AND THE RELATIVE LEGAL BASIS?
When supplying the APP and any product assistance activities, pursuant to the general conditions (EULA) and connected, instrumental activities, MCZ collects and processes the following Data categories referable to you:
• personal and identification data (i.e.: name*, surname*, country*, sex, age, address, postal code, municipality and province);
• contact details (i.e.: phone number, e-mail address*);
• APP login data (i.e.: username* and password*);
• any other data communicated by phone during assistance activities.
Data marked by an * are to be considered mandatory.
The Data referred to you is processed for the following purposes:
a) Registration with the MAESTRO APP
Your data will be used to create an identification profile in the application supplied by MCZ. Among other things, this will enable you to set stove use profiles, remote control of lighting and shutdown, to establish any users connected to you, etc…
b) Purchase of further services and/or use of assistance services
By choosing to do so voluntarily, you may use the other services offered through the APP or open technical assistance tickets. For that purpose, case by case, it might be necessary to collect further data concerning you.
The app collects location data to activate the 'Follow-me' functionality (automatic operation of the MCZ product when leaving or re-entering the house) even when the app is closed or not in use.
That data could possibly be requested applying the minimisation principle.
c) Marketing by electronic mail
With your prior consent, your data (e-mail address) could be processed by MCZ to send - promotional and commercial communications by automated contact mode, related to services/products offered by the Data Controller, as well as market surveys and for statistical purposes.
***
For the purposes indicated in letters a) and b) any refusal to provide data will make it impossible for you to use the services included in the application supplied by MCZ or the connected assistance services; consequently, the legal basis can be considered as contractual compliance (EULA).
The legal basis for processing your data for the purposes indicated under letter c) is consent. In any case consent for the processing of Data is free and may be revoked at any time from the APP profile or by notifying the following e-mail address dpo@mcz.it.
3. WHO DO WE COMMUNICATE YOUR DATA TO?
The Data Controller may communicate your Data to the parties used to manage the infrastructure or perform maintenance on any information systems. They will process data referred to you as Processors.
The list of Processors is updated by the Controller and may be consulted c/o the latter’s offices.
Your Data may also be communicated to internal persons, (employees and collaborators) authorised to process them for their respective jobs and to subjects that the Controller uses to perform activities
4. WHERE DO WE TRANSFER YOUR DATA TO?
Your data will not be transferred outside Europe.
5. HOW LONG DO WE STORE YOUR DATA?
MCZ will store your Data for as long as you use the APP or the assistance services, after your termination where needed to fulfil legal obligations, for the time established by fiscal and civil regulations or to protect its rights before the law.
In particular, the APP security mechanisms, through automatic control systems will deactivate your user profile if you should not access the APP for 730 days and will cancel your profile completely after a further 365 days.
Any data related to assistance tickets requested or commercial transitions related to the purchase of any services will be stored in compliance with terms established by the law, fiscal and civil regulations.
Any consent provided for marketing purposes will remain valid for a period of no longer than 24 months from the last communication sent by the Controller.
6. WHAT RIGHTS DOES THE DATA SUBJECT PROCESSED HAVE?
During the period in which MCZ holds or processes your Data, as the data subject of that processing, you may exercise the following rights at any time:
· Right of access – You have the right to confirmation about whether processing regarding your Data is being performed or not, and the right to receive all the information on that processing;
· Right to rectification – Your have the right to rectify the Data held by us, if that data is incomplete or inexact;
· Right to erasure – in some circumstances, you have the right to request that your data present in our archives be erased if they are not important for continuation of the contractual relationship in force;
· Right to portability – You have the right to have your Data held by us transferred to another controller;
· Right to restrict processing – if certain conditions occur, you have the right to restrict the processing of your Data, if they are not important for continuation of the contractual relationship in force;
· Right to revoke consent – You have the right to revoke your consent to the processing of your Data at any time, without prejudice to the lawfulness of processing based on consent prior to revocation;
· Right to lodge a complaint with the privacy Authority – if you wish to lodge a complaint on how your Data are processed by MCZ, or on the management of a complaint lodged by you, you may lodge a complaint with the privacy Authority directly (the form needed to lodge a compliant is available at the following link: https://www.garanteprivacy.it/documents/10160/0/Modello+di+reclamo.pdf/46f18fed-08b1-767a-c856-a59d5a814533?version=1.10).
Right to object
Right to object – You have the right to object, at any time for grounds connected to your specific situation, to the processing of Data concerning you based on the condition of the legality of the legitimate interest or execution of a task of public interest or the exercising of public powers, including profiling; unless the Controller has legitimate reasons for continuing to process that prevail over the interests, rights and liberties of the data subject or the processing of Data is needed to ascertain, exercise or defend a right in court.
The above indicated rights may be exercised with the Controller by writing to the e-mail address dpo@mcz.it