Information on the processing of personal data
Pursuant to Italian Legislative Decree no. 196/2003, EU Regulation 2016/679 (GDPR), and Italian Legislative Decree no. 101/2018 laying down provisions for the protection of individuals and other subjects with regard to the processing of personal data, we hereby inform you that the personal data you provide will be processed in compliance with the above-mentioned regulations.
1. Data Controller
The Data Controller is Piusi S.p.A., with registered office at Via Pacinotti 16/A, 46029 Suzzara (MN), Italy. The updated list of data processors may be requested by letter or email at marketing@piusi.com.
2. Subject of Processing
The Data Controller processes the personal and identification data provided by you (such as company name, address, telephone number, email address, banking and payment details, names of legal representatives, attorneys, or your employees for the management of procedures) — hereinafter referred to as “personal data” or simply “data”.
3. Purpose of Processing
All data are collected and processed to fulfill mandatory administrative and tax obligations related to the management of our contractual relationship or to respond to your requests.
The provision of data is mandatory for compliance with legal obligations and contractual requirements; therefore, failure to provide such data may prevent the establishment, continuation, or full or partial execution of pre-contractual or contractual relationships, or the ability to respond to your requests.
Additional data may include commercial and legal information provided to or by leading specialized companies, with particular reference to creditworthiness ratings and reliability in payments and commercial transactions.
4. Methods of Data Processing
Data are processed lawfully and in accordance with principles of fairness and confidentiality, in full compliance with Italian Legislative Decree 196/2003 and EU Regulation 679/2016, using both electronic and paper-based tools, and in any case with instruments suitable to ensure data security and confidentiality.
In accordance with the principles of lawfulness, purpose limitation, and data minimization pursuant to Article 5 of GDPR 679/2016, your personal and identification data will be retained for a maximum period of ten years.
The Company informs that, in providing its services, it may use Artificial Intelligence (AI) systems exclusively as support tools for operational and assistance activities, always ensuring compliance with the principles of transparency, fairness, security, confidentiality, and non-discrimination required by applicable legislation. Such systems do not generate binding decisions or automatic legal effects concerning data subjects.
Data subjects may request further information at any time regarding the use of Artificial Intelligence by contacting the address indicated in this privacy notice.
These systems do not make autonomous decisions and do not produce direct effects on the rights or interests of data subjects, pursuant to EU Regulation 1689/2024 and Law no. 132/2025. Personal data processed through AI are limited to what is necessary for the stated purposes and, where possible, are anonymized or pseudonymized.
The use of AI does not replace human decision-making and does not independently affect the rights of data subjects. Users are clearly informed about the use of AI and retain all rights provided under the GDPR, including access, rectification, objection, and erasure of data.
The Company adopts appropriate technical and organizational measures to protect data processed through AI and to prevent risks to data subjects. The use of Artificial Intelligence does not involve surveillance systems, behavioral profiling, or automated evaluations of natural persons. All outputs generated by AI systems are subject to human review and validation.
5. Scope of Data Communication and Disclosure
We also inform you that the collected data will never be disclosed and will not be communicated without your explicit consent.
Data may be communicated, in addition to all members of our internal organization (administrative, commercial, marketing, headquarters and branch offices, etc.), to external parties such as subsidiaries or affiliated companies or other entities performing services on behalf of the Company (e.g., tax compliance, sales network, shipping services, archiving, IT services, external consulting, transport and communication services, etc.), as well as to parties required or authorized by law.
Data may also be transmitted to commercial information companies for the assessment of creditworthiness and payment behavior.
6. Transfer of Personal Data
No transfers of data outside the European Union are carried out. Should the need arise to transfer personal data abroad, the Data Controller undertakes to ensure the existence of adequate safeguards for the protection and security of personal data in accordance with applicable legislation.
7. Existence of Automated Decision-Making Processes, Including Profiling
No automated decision-making processes, including profiling, as referred to in Article 22, paragraphs 1 and 4, of EU Regulation 679/2016, are adopted.
8. Rights of Data Subjects
At any time, pursuant to Italian Legislative Decree 196/2003 and Articles 15 to 22 of EU Regulation 679/2016, you may exercise the right to:
- obtain confirmation as to whether or not personal data concerning you exist;
- obtain information about the purposes of processing, the categories of data, the recipients or categories of recipients t
- whom personal data have been or will be disclosed, and, where possible, the data retention period;
- obtain rectification and erasure of data;
- obtain restriction of processing;
- obtain data portability, i.e., receive your data from a data controller in a structured, commonly used, and machine-readable format and transmit them to another controller without hindrance;
- object at any time to the processing, including processing for direct marketing purposes
- object to automated decision-making processes concerning natural persons, including profiling;
- request access to personal data and the rectification or erasure thereof, or restriction of processing concerning you, or object to their processing, in addition to the right to data portability;
- withdraw consent at any time without affecting the lawfulness of processing based on consent given before its withdrawal;
- lodge a complaint with a supervisory authority.
You may exercise your rights by sending a request to marketing@piusi.com.
Suzzara, 20/07/2021