This page describes how the site is managed for processing users' personal data.
This policy on the protection of personal data is also provided pursuant to Article 13 of EU Regulation 2016/679 (the GDPR) for anyone interacting with the web services of IPZS from:
https://www.portaleunicovalori.ipzs.it/bollini
which is the starting page of the official web site Portale Unico Valori - Bollini.
This policy is only for Portale Unico Valori - Bollini, not for any other web site consulted by the user through any links.
This policy is also based on Recommendation No. 2/2001 that the European authorities for the protection of personal data in the Group established by Article 29 of directive No. 95/46/CE, adopted on 17 May 2001. The Group identified minimum requirements for collecting personal data online and, in particular, the methods, times and nature of information that the data controller must provide to users when they connect to web pages, regardless of the purpose for connecting.
The purpose of this privacy policy is to transparently provide information on data collected from the above site and how it is used.
By consulting this site a user gives information which is personal data. The data controller is Istituto Poligrafico e Zecca dello Stato S.p.A., whose registered office is in Rome (Italy), Via Salaria 691, in the person of the CEO pro-tempore.
A user's personal data is handled by people authorised by the controller and by processing managers specially appointed and trained by Poligrafico as the controller, or by independent "Owners", authorised to access it by provisions of the law and regulations.
Users' personal data are also processed by designated system administrators within the meaning of the Guarantor for the Protection of Personal Data of 27 November 2008 and modifications.
Personal data will be processed by computerised/telematic tools for purposes strictly necessary to consult the site https://www.portaleunicovalori.ipzs.it/bollini as well as for purposes related and/or instrumental to the consultation itself.
These data are automatically processed and aggregated to check the site functions properly, as well as for security.
Data are processed using instruments and procedures designed to ensure the security and confidentiality of data per Articles 32 onwards of the GDPR and in conformity with national legislation.
Specific safety measures prevent the loss of data, illicit or incorrect use and unauthorised access.
Processing personal data for the above purposes does not require consent as this is necessary to consultation of the site www.portaleunicovalori.ipzs.it/bollini.
Personal data provided by users who ask for information (cds, newsletters, publications, etc.) are used only to perform the service or provision requested.
Processing related to the services on this web site are at the above premises and are handled only by technical personnel of the data processing management or by any persons authorised to carry out occasional maintenance.
No data from the web service is communicated or disseminated to third parties.
The computer systems and software procedures used for this website acquire, during their normal operations, some personal data which is implicitly provided when using internet communication protocols.
This information is not collected so it can be associated with identified interested parties, but by its very nature could, through elaborations and associations with data held by third parties, enable users to be identified.
This category of data includes IP addresses or domain names of the computers used to connect to the site, addresses in the URI (Uniform Resource Identifier) of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file in reply, the numerical code indicating the status of the response given by the server (done, error, etc.) and other parameters related to the operating system and the computer environment of the user.
These data are processed only to obtain anonymous statistical information on the use of the site and to check its correct functioning.
The data could be used to ascertain responsibility for any computer crimes against the site. Otherwise web contact data are not held for more than 180 days.
The optional, explicit and voluntary sending of electronic mail to the addresses indicated on this site involves the subsequent acquisition of the sender's address, which is essential for any response, as well as any other personal data inserted in the communication. These data are kept for the time needed to fulfil the request.
After this, the data is disguised or deleted, unless it needs to be kept for other and different objectives expressly provided by the law (e.g. archiving).
Cookies
No user personal data is acquired by the site.
The cookies do not transmit personal information, and there are no persistent cookies of any kind, nor systems for tracking users.
The use of session cookies (which are not stored persistently on the user's computer and vanish when the browser closes) is strictly limited to sending session identifiers (which are random numbers generated by the server) needed to enable safe and efficient exploration of the site.
The session cookies on this site do not use other IT techniques potentially prejudicial to the confidentiality of user navigation and do not allow the acquisition of personal data identifying the user.
For more information about the type of cookies used, as well as the purposes and methods of disabling them please see the specific section.
TYPE OF TRANSMISSION AND CONSEQUENCES OF REFUSAL
Apart from navigation data, the user is free to provide Poligrafico with personal data in the request forms or in contacts with Poligrafico to ask for informative material or other communications.
Refusing to transmit such data makes it impossible to process the request.
Notably in some cases (not for ordinary management of this site) the Authority may request information to control personal data processing. In these cases, an answer is required under penalty of administrative sanctions.
RIGHTS OF THE INTERESTED PARTY
As per the GDPR, anyone can exercise the following rights in respect of Poligrafico:
a) a) the right to obtain from the controller, confirmation whether or not ongoing personal data processing concerns them and, if it does, to obtain access to personal data and information as provided for by Article 15 of the GDPR. In particular this refers to processing, categories of personal data, recipients or categories of recipients to whom the personal data have been or will be communicated, the retention period, etc.;
b) the right to for incorrect personal data to be corrected, as well as supplemented when incomplete always for the purpose of processing (Article 16);
c) the right to cancellation of data ("right to oblivion"), for circumstances referred to in Article 17;
d) the right to limit processing, in the cases provided for by Article 18;
e) the right of portability of data within the meaning of Article 20;
f) the right to oppose processing within the meaning of Article 21;
g) the right to revoke consent at any time without affecting the legality of processing based on the consent given before revocation, solely for purposes where the legal basis is the consent (Article 7).
These rights can be exercised with a request sent by registered letter with return receipt to the Data Protection Manager or Data Protection Officer to the following address:
Via Salaria, 691 – 00138 Roma, or by email to the following email addresses:
privacy@ipzs.it or rpd@pec.ipzs.it by using the form on the website for the Privacy Manager www.garanteprivacy.it
In addition, you can lodge a complaint to the Privacy Manager or other authorities within the meaning of Article 13 (2) (d) of the GDPR
This policy may change. Regularly monitoring this section is therefore recommended www.ipzs.it/ext/privacy.html.
Last update: 22 May 2018