Diatech Pharmacogenetics S.r.l
In compliance with the legal obligations to protect privacy (1, 2), our Company wishes to inform you in advance regarding the conditions of use of your personal data and rights in relation to their treatment.
In this Policy the term “personal data” means any piece of information that can identify a person, either as a single data subject or together with other data, such as name, surname, telephone number, e-mail address, information on respective studies and other personal information made available by sending a curriculum vitae and/or completing the “Personal Selection Questionnaire”.
1. SCOPE OF THE INFORMATION ON THE PROTECTION OF PERSONAL DATA
2. DATA CONTROLLER
The Data controller of your data is Diatech Pharmacogenetics S.r.l. a Socio Unico, with registered office in Via Ignazio Silone, 1/b – 60035 Jesi (AN), which determines the purposes and methods of processing in full compliance with current legislation on the protection of personal data. The Data Controller can be contacted by e-mail at firstname.lastname@example.org or by sending the communication to the address of the company headquarters. In the following Diatech Pharmacogenetics S.r.l. a Socio Unico will also be indicated as the “Company”, “Diatech” or the “Data controller”.
The Data Protection Officer (DPO) is the person appointed by the Data Controller to monitor compliance with the GDPR Regulations, and is available to respond to your requests for any information on the processing of your personal data, as well as your rights, and can be contacted by e-mail at: email@example.com
3. PROCESSED DATA AND PURPOSES
– Data provided voluntarily by the data subject “off-line” (outside the company website)
Personal data and / or curriculum vitae sent by the person concerned by mail, e-mail or delivered directly to the headquarters, exclusively for selection purposes or self-application for employment.
– Data acquired “on-line” through the Company website (www.diatechpharmacogenetics.com)
Voluntary submission of personal data associated with the presentation of your curriculum vitae, in cases where the user is interested in participating in one of the open selections for hiring new staff on the page “Work with us”. The processing of such data is solely constrained to the selection process.
Whatever method the data was collected, its handling always takes place in compliance with the principles of lawfulness, fairness and relevance, moreover, it will not be exceeded meaning that for each activity in which the management of personal data is planned, only strictly necessary data will be processed.
4. LEGAL BASIS FOR PROCESSING
Candidates can give their consent voluntarily for the selection of new staff, after having read this notice.
5. NATURE OF THE PROVISION
The allocation of data on the page of the site “Work with us” associated with the submission of your curriculum vitae is optional, as well as the sending of said CV through the “offline” mode, but in any case, necessary for the acquisition and management by the system of self-application for participation in the selection of personnel for the professional figure of your interest.
The processing of data for this purpose requires the stated consent of the person concerned, collected at the same time as the registration on the data site, or at the bottom of the form “Questionnaire personal selection” in case of conferment of data “off-line”.
If sensitive data is included in the curriculum vitae (e.g. belonging to protected categories, disabilities, etc.), candidates give their consent strictly to the processing of sensitive data communicated for exclusive selection purposes, by means of a declaration signed at the end of the curriculum vitae. In the absence of such a declaration, the curricula will be discarded.
For any questions about the legal basis on which the Company collects and uses your personal data, please contact our Data Protection Officer (firstname.lastname@example.org).
6. METHODS OF DATA HANDLING AND TIME LIMITS FOR DATA RETENTION
The data collected for personnel selection purposes will be entered in our databases and kept for as long as required for the duration of the evaluation. If the candidate does not present characteristics of interest for the selection, the relevant data will be deleted or destroyed. In any case, the data will be kept for a period which doesn’t exceed the legal time limits (maximum two years from the date of the transfer of data).
7. PEOPLE AUTHORISED TO HANDLE, RESPONSIBLE FOR AND COMMUNICATE THE DATA
The handeling of the collected data is carried out by Company staff identified and authorized for this purpose according to specific instructions given in compliance with current regulations.
The data collected, if it is necessary or key for the performance of the purposes indicated above, may also be processed by third parties appointed as external data processors, or, depending on the case, communicated to the third parties as independent data controllers, and precisely:
• companies that are part of our corporate group;
• persons, companies, associations or professional firms that provide assistance and consultancy to our Company;
• companies or other entities that carry out on behalf of Diatech Pharmacogenetics services necessary for the implementation of the purposes considered above (for example: technicians for the operation and maintenance of computer systems;
In any case, personal data will never be disclosed.
Diatech Pharmacogenetics has adopted specific physical, electronic and organizational measures in order to guarantee the security of personal data in its archives, in particular to prevent unauthorized access to its information systems, as well as to prevent the loss, alteration or unauthorized forwarding of data to third parties.
9. RIGHTS OF THE DATA SUBJECT
The person concerned may at any time access his/her data, oppose its processing or request the cancellation, correction or updating of all personal information concerning him/her collected by Diatech Pharmacogenetics, furthermore, exercising the right to limit the processing and the right to data portability.
In particular, it is in your right:
b. require to amend without undue delay, inaccurate personal data concerning him/her;
c. taking into account the purposes of the processing, obtain the completion of incomplete personal data provided through an additional statement;
d. obtain the deletion without undue delay of your personal data if they are no longer necessary with respect to the purposes of the processing or if your consent to the processing for marketing purposes is revoked;
e. issue a complaint with the competent supervisory authority (Data Protection Supervisor);
f. obtain the deletion of personal data if their unlawful use is detected;
g. obtain a limitation of the handling of the data during the period of verification of the allegedly inaccurate data;
h. object to the deletion of your personal data if such data is necessary to establish, exercise or defend legal rights.
The Data Controller that you will have to contact to exercise these rights or for any other information relating to the management of the privacy of data concerning you is Diatech Pharmacogenetics S.r.l. a Socio Unico, which you can contact by one of the following means:
• Communication to the e-mail address ( email@example.com )
• a letter addressed to the respective address: Via Ignazio Silone, 1/b – 60035 Jesi (AN)
For any information regarding the processing of your personal data and the exercise of your rights, you may contact the Data Protection Officer (DPO) by e-mail at: firstname.lastname@example.org
Last updated: 15 October 2018
Reason for revision: Publication of the contact details of the Data Protection Officer (DPO) pursuant to Art. 37 (p.to 7) of Regulation (EU) 2016/679
(1) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
(2) Legislative Decree no. 196 of 30 June 2003 – CODE IN PROTECTION OF PERSONAL DATA