LANGUAGE: IT | EN -
 

Information pursuant to art. 13 eu regulation no. 679/2016 on the protection of personal data

Connected to the Coordinated Vulnerability Disclosure (CVD) required by the Cyber Resilience Act (EU Reg. 2024/2847

The information is provided pursuant to Article 13 of EU Regulation no. 679/2016 on personal data protection (hereinafter also "GDPR").

  1. Identity and contact details of the Personal Data Controller
    The Personal Data Controller of your personal data is Walvoil S.P.A. with registered office in Via Adige 13/D – 42124 – Reggio Emilia (RE, Italy) who can be contacted at the e-mail address: privacy@walvoil.com. The Personal Data Controller has appointed its own Data Protection Officer ("DPO") who can be contacted at the e-mail address: dpo@walvoil.com.
     
  2. Data processed
    The data processed are those collected for the purpose of managing the Coordinated Vulnerability Disclosure (CVD) required by the Cyber Resilience Act (European Regulation 2024/2847), hereinafter referred to as “CRA,” which you voluntarily provided as a reporter at the time of the report or at a later time.
    This data typically consists of the information contained in a report, including personal identification details and email addresses, as well as any additional data provided during the reporting process. The data will be processed manually or using electronic, automated, computer-based, or telecommunications tools.
    Unless strictly necessary, reporting parties are asked to omit from their report or from any subsequent communications with the Data Controller any information or data not strictly relevant to the report.
     
  3. Purpose and lawfulness of the processing
    The collection and processing of personal data provided by the reporting party are carried out exclusively for the purposes of investigating, evaluating, managing, and resolving the reported issue, as well as for any other purposes requested by the CRA.
     
  4. Nature of the provision and consequences of any refusal
    The provision and updating of certain personal data, as well as the provision of data and its processing, are optional; however, any refusal to provide the data (or your request to have it deleted) may make it impossible for the Data Controller to initiate or continue the Coordinated Vulnerability Disclosure (CVD) process required by the CRA.
     
  5. Recipients and data transfer
    Your personal data, for the exclusive pursuit of the purposes specified above, may be shared with:
    - subjects within the Company who act as authorised by the Personal Data Controller;
    - external parties who carry out specific tasks on behalf of the Personal Data Controller and functional to the purposes indicated above (e.g. technical consultants.);
    - third parties appointed by the Company to provide electronic components or Information Technology strictly connected to the purposes indicated above;
    - public bodies in compliance with regulatory obligations or specific requests.

    The subjects belonging to the categories to which the data may be communicated will use them as "Personal Data Processors" specifically appointed by the Company pursuant to art. 28 of the GDPR or autonomous "Personal Data Controllers".
    Apart from the above cases, your Personal Data will not be disclosed, nor will they be transferred to third parties outside the territory of the European Union. If, for the purposes indicated, the Company should in any case need to transfer your Personal Data outside the European Union, to countries not considered adequate by the European Commission, the Company will take the necessary measures to protect your Personal Data.
     
  6. Data retention times
    Your personal data are stored by the Company only for the period necessary for the purposes for which they are processed or within the terms provided for by applicable national and EU laws, rules and regulations.
     
  7. Rights of the data subject
    With regard to the processing of personal data carried out by the Personal Data Controller, it is possible, at any time, to exercise the rights provided for by the GDPR and in particular: the right to access personal data and to obtain a copy thereof (art. 15 GDPR); the right to rectification of personal data (Art. 16 GDPR); the right to erasure of personal data (Art. 17 GDPR); the right to restriction of the processing of personal data (Art. 18 GDPR); the right to data portability (art. 20 GDPR); the right to object to processing (art. 21 GDPR); (where applicable) the right to withdraw the consent freely given at any time without prejudice to the lawfulness of the processing based on the consent given before the withdrawal (art. 7 GDPR).

    You may exercise your rights by sending a specific request to the Personal Data Controller by e-mail to the addresses above.

    Requests relating to the exercise of your rights will be processed without undue delay and, in any case, within 30 days of receipt of the request.

    In any case, you always have the right to lodge a complaint with the competent supervisory authority pursuant to Article 77 GDPR if you believe that the processing of your data is contrary to the applicable data protection legislation. For Italy, the supervisory authority is the Guarantor for the protection of personal data, which can be contacted following the indication of the following link: https://www.garanteprivacy.it/home/footer/contatti