Procedure regarding the rights of data subjects
Procedure regarding Data Subjects’ rights
The General Data Protection Regulation (EU Regulation 2016/679) (hereinafter also “Regulation” or “GDPR”) grants Data Subjects the exercise of the following rights towards the Data Controller:
- Right of access Art. 15 GDPR: in order to request confirmation whether or not a processing of personal data is taking place;
- Right to rectification Art. 16 GDPR: in order to request rectification or integration of the provided data, if inaccurate;
- Right to erasure Art. 17 GDPR: in order to request that processed data be erased (for example if they are no longer necessary for the purposes for which they were collected; or in case of withdrawal of consent; or even if processing is unlawful);
- Right to restriction of processing Art. 18 GDPR: so that the data processed by the Data Controller are marked in such a way as to limit their processing in the future;
- Right to data portability Art. 20 GDPR: in order to obtain the receipt of personal data or the transmission of data to another Data Controller, in a structured, commonly used and machine-readable format;
- Right to object Art. 21 GDPR: to oppose at any time the processing of data, unless there are legitimate and prevalent reasons for processing (for example for the exercise or defense in court).
Data Subjects’ categories
For the purposes of this procedure, the Data Subjects’ categories, whose data are processed by Qura S.r.l., are grouped below by area of competence, as identified in the Register of Processing drawn up pursuant to Art. 30 of the GDPR:
- Data Subjects attributable to the HR Area: candidates, employees, family members of employees and former employees of Qura S.r.l. as well as freelancers who work for the Company and employees of third parties who provide services for the Company;
- Data Subjects attributable to the Administration Area: customers, suppliers, professionals, consultants, in relation to the contracts entered into with them and the related completion of all related activities, instrumental and/or complementary to the relationship;
- Other Data Subjects: web users as well as all individuals external to Qura S.r.l. and in general any natural person whose personal data are controlled by Qura S.r.l. as Data Controller and who does not belong to the previous categories.
Exercise of the right by the Data Subject and receipt of the request by Qura S.r.l.
- The exercise of rights is free of charge;
- The exercise of rights is subject to prior identification of the Data Subject. Therefore, the Data Subject must attach a copy of a valid identification document to the request;
- It may also be submitted by means of a proxy with a specific authorization;
- To exercise your rights, you can send a request by certified email to email@example.com or by registered letter with return receipt to Qura S.r.l. via di Mezzo 23, Mirandola, (MO).
- Following receipt of the request, Qura S.r.l. will verify the identity of the Data Subject as well as the submitted request;
- Within 30 days from the request (extendable to 60 days for complex cases), the Data Controller will respond to the request submitted by the Data Subject.
Please note that Qura S.r.l. has appointed a Data Protection Officer pursuant to Art. 37 of EU Regulation 679/2016 who can be contacted at any time by Data Subjects at the email address firstname.lastname@example.org