Privacy Notice pursuant to Article 13 of EU Regulation No. 679/2016 Website Users

Dear website user,

DIESSE Diagnostica Senese S.p.A. (hereinafter “DIESSE”), Tax Code and VAT No. 05871140157, represented by its Chief Executive Officer and legal representative, Dr. Massimiliano Boggetti, with registered office at Viale Decumano 26, Milan, and DIESSE INC., with registered office at 1139 Fairway Gardens NE, Atlanta, GA 30319, USA, acting as joint controllers (hereinafter the “Joint Controllers”) pursuant to Article 26 of EU Regulation No. 679/2016 (hereinafter also the “GDPR”), wish to inform you that, pursuant to Article 13 GDPR, they need to process the personal data you provide while browsing the DIESSE INC. website (e.g., for the creation and management of personal accounts), using landing pages and/or online forms (e.g., to request information), and submitting requests through the website or the channels indicated therein, in compliance with applicable laws and as further specified below.

Aving stated the above, the Joint Controllers identify within this document the purposes and means of processing your Personal Data. In accordance with Article 26(2) GDPR, the essential elements of the joint controllership agreement entered into between the Joint Controllers are set out below: DIESSE Diagnostica Senese S.p.A. and DIESSE INC. act as joint controllers with regard to the data of users of the DIESSE INC. website, as well as for the creation and management of a shared “US customers/prospects” database — also created through contacts and personal information acquired via this website — and for carrying out marketing and business development activities. Processing activities carried out independently by each company, for its own purposes and by its own means (including, among others, the management of orders and purchases by US customers, which shall be managed by DIESSE INC. as independent controller), are excluded from the agreement.

Within the scope of the joint controllership agreement, DIESSE Diagnostica Senese S.p.A. operationally coordinates the handling of data subjects’ requests relating to the joint processing activities. DIESSE INC. cooperates with DIESSE Diagnostica Senese S.p.A. by providing the information and support necessary to properly respond to data subjects’ requests.

Without prejudice to Article 26(3) GDPR, data subjects may exercise their rights against each joint controller independently, regardless of the internal allocation of responsibilities provided for in the agreement.

1. SUBJECT MATTER OF THE PROCESSING AND CATEGORIES OF DATA PROCESSED

The Joint Controllers process the following personal data (hereinafter also referred to as the “Data”) for the purpose of providing the services and/or activities requested by you, including but not limited to:

  • identification data: personal data enabling the direct identification of the data subject (first name, last name, personal details, address, business references, telephone number, email address, etc.);
  • data accessible through IT systems and software procedures used for the operation of the Website itself (so-called “navigation data”), and in any case all information that must be acquired in order to monitor the functioning and use of the website, for security and maintenance reasons, as well as for relations with supervisory authorities and compliance with any other legal and contractual obligations. The Joint Controllers do not knowingly collect data from persons under 18 years of age. The Data are provided directly by the data subject.

2. PURPOSES, LEGAL BASIS OF THE PROCESSING AND CONSEQUENCES OF FAILURE TO PROVIDE DATA

Your Data are processed lawfully and fairly for the purposes described below.

A. Compliance with legal obligations Such necessity constitutes the legal basis legitimizing the related processing, as the Joint Controllers are required to comply with legal, accounting, tax, administrative, and contractual obligations connected to the provision of the requested services, as well as to properly manage relations with authorities, supervisory bodies, and third-party public entities for purposes related to specific requests, compliance with legal obligations, or other procedures. Providing the data necessary for these purposes constitutes a legal obligation. Failure to provide such data may make it impossible for the Joint Controllers to establish the contractual relationship and may require them to make reports or notifications.

B. Marketing and commercial communications Only with your specific and separate consent (pursuant to Article 7 GDPR), which you are free to grant or withhold, the Joint Controllers may carry out market research and analyses aimed at assessing your level of satisfaction with the quality and type of services provided and initiatives aimed at improving the services offered, as well as send promotional material and/or informational, commercial, and marketing communications regarding new services offered by the Joint Controllers or by other group companies (“Direct Marketing”):

  • B.1. Through traditional means – paper mail or telephone calls through operators and/or sales agents;
  • B.2. Through automated systems – automated calling systems without operator intervention, email (e.g., newsletters, DEMs, etc.), and/or SMS. Providing Data for these purposes is optional. You may therefore decide not to provide any data or subsequently deny the possibility of processing data already provided: in such case, you will not receive commercial communications and promotional material relating to the services offered by the Joint Controllers.

C. Dati di navigazione. With regard to the navigation data of websites attributable to the Joint Controllers, the processing of such information is necessary:

a) to allow the Joint Controllers to obtain anonymous statistical information on website use and to verify its proper functioning;

b) for security reasons (anti-spam filters, firewalls, and virus detection), in order to block attempts to damage the website or harm users, and in any case to prevent harmful or criminal activities;

c) to carry out any other function necessary or instrumental to the operation of the website, including the installation of technical cookies to improve website functionality, for which reference is made to the Cookie Policy.

Such information will be acquired by the Joint Controllers pursuant to Article 6(1)(b) GDPR in order to allow proper navigation on the website, for the reasons partially described above.

Should the user access the Website through a social profile (e.g., Facebook or Instagram), the Joint Controllers will receive from the social network provider certain Personal Data necessary for authentication. Such data are collected from third parties pursuant to Article 14 GDPR. Before proceeding with access through social login, the data subject may review this Privacy Notice, which is always available on the Website.

3. PROCESSING METHODS

Your Data are processed through the operations referred to in Article 4(2) GDPR, namely: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Data.

Your Data are processed both in paper and electronic and/or automated form.

The Data collected are processed in full compliance with the law and with the principles of lawfulness, fairness, transparency, proportionality, and protection of your confidentiality and rights.

4. DATA RETENTION PERIOD

The Controller retains the Data in compliance with local laws and internal company policies and procedures for the time necessary to fulfill the purposes described above and satisfy its legitimate business interests, legal obligations, or to establish, exercise, or defend legal claims. Once the need to retain the Data for such purposes has ceased, the Data will be securely deleted.

More specifically, data collected for marketing purposes shall be processed by the Joint Controllers for no longer than 2 years from their collection. With regard to navigation data, please refer to the Cookie Policy.

This is without prejudice to any retention requirements imposed by law and/or binding provisions applicable to the Joint Controllers.

5. CATEGORIES OF RECIPIENTS OF PERSONAL DATA

Your Data may be made accessible for the purposes described above:

  • to employees and collaborators of the Joint Controllers — in Italy and, where applicable, abroad — acting as persons authorized to process data pursuant to Article 29 GDPR and/or persons entrusted with specific functions and tasks pursuant to Article 2-quaterdecies of Italian Legislative Decree No. 196/2003, or processors and/or sub-processors pursuant to Article 28 GDPR;
  • to other companies connected in any capacity (parent companies, subsidiaries, and/or affiliates) to the Joint Controllers, both in Italy and abroad where applicable, and to their employees and collaborators (for example for administrative and accounting purposes);
  • to public authorities, bodies, and entities competent in supervision and control matters, as well as to any other public entity entitled to receive them pursuant to applicable laws;
  • to third-party companies or other entities (including, by way of example only, banks, credit insurance institutions, professional firms, consultants, etc.) that carry out outsourced activities on behalf of the Joint Controllers, acting as data processors, including suppliers or entities entrusted with carrying out ancillary or instrumental services related to the purposes indicated above, with whom the Joint Controllers enter into appropriate agreements.

The Joint Controllers also reserve the right to make personal data accessible to certain third parties, including: IT providers for system development and technical support purposes; auditors and consultants to verify compliance with external and internal requirements; legal entities, law enforcement agencies, and litigating parties in accordance with legal disclosure obligations or claims; any successors or business partners of the Joint Controllers or companies related thereto (parent companies, subsidiaries, and/or affiliates) in the event of sale, transfer, or other extraordinary transactions; police forces, armed forces, and other public administrations, in order to comply with obligations imposed by laws, regulations, or EU legislation.

6. DATA TRANSFER

The Data are stored on servers and storage tools located within the European Union. With reference to the processing carried out under joint controllership, please note that certain personal data may be collected directly by DIESSE INC., established in the United States of America, through websites, landing pages, online forms, or other channels attributable thereto, and subsequently shared with DIESSE for the purposes described in this Privacy Notice. In such cases, since the data flow takes place from the United States to Italy, it does not, in itself, constitute a transfer of personal data to a third country pursuant to Chapter V GDPR. It is understood, however, that DIESSE, where necessary, may transfer data also to countries outside the European Union or the European Economic Area recognized by the European Commission as providing an adequate level of protection for personal data or, failing that, only where an adequate level of protection equivalent to that of the European Union is contractually guaranteed and the exercise of data subjects’ rights is ensured. In such cases, DIESSE hereby guarantees that transfers of Data outside the EU will take place in compliance with applicable legal provisions, applying all necessary safeguards.

7. RIGHTS OF THE DATA SUBJECT

As a data subject, you have the rights referred to in Articles 13(2)(b), (c), and (d), 15, 16, 17, 18, 19, and 21 GDPR (where compatible with each relevant processing activity), namely the right to:

  • obtain confirmation as to whether or not personal data concerning you exist, even if not yet recorded, and communication thereof in intelligible form;
  • obtain information regarding: a) the source of the Data (where not collected from the data subject); b) the purposes and methods of processing, as well as the legal basis thereof; c) the logic applied in case of processing carried out with electronic tools; d) the identification details of the Controller, processors, Data Protection Officer, and any representative designated pursuant to Article 13(1) GDPR; e) the entities or categories of entities to whom the Data may be communicated or who may become aware of them as processors or designated representatives within the territory of the State;
  • obtain: a) updating, rectification, or, where interested therein, integration of the Data; b) erasure, anonymization, or blocking of personal data processed unlawfully, including data whose retention is unnecessary in relation to the purposes for which they were collected or subsequently processed; c) certification that the operations referred to in points a) and b) have been notified, including their content, to those to whom the Data were disclosed or disseminated, unless this proves impossible or involves a manifestly disproportionate effort compared to the protected right;
  • object, in whole or in part, on legitimate grounds, to the processing of Data concerning you, even if relevant to the purpose of collection;
  • where applicable, exercise the rights under Articles 16–21 GDPR (right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority;
  • withdraw at any time any consent previously given, without affecting the lawfulness of processing based on consent before its withdrawal. With regard to the right to data portability, the data subject may request to receive or transfer personal data held by the Joint Controllers in a structured, commonly used, and machine-readable format for further personal use or to provide them to another controller.

With reference to the contractual relationship, the data subject may generally request portability of identification and contact data.

8. METHODS FOR EXERCISING RIGHTS

You may exercise your rights or submit a request at any time by sending:

  • a registered letter with return receipt to DIESSE Diagnostica Senese S.p.A., Tax Code and VAT No. 05871140157, represented by its Chief Executive Officer and legal representative, Dr. Massimiliano Boggetti, with registered office at Viale Decumano 26, Milan;
  • or an email to: privacy@diesse.it.

The response period is one month. This period may be extended by two additional months in particularly complex cases: should this occur, DIESSE will provide notice of the reasons for the extension within one month. DIESSE has the right to request information necessary to identify the requester. In general, exercising rights is free of charge, except in the case of manifestly unfounded or excessive requests, for which DIESSE may reserve the right to request a reasonable fee based on the administrative costs incurred.

9. CONTROLLERS, DATA PROTECTION OFFICER (DPO), AND CATEGORIES OF PROCESSORS

The Joint Controllers are DIESSE Diagnostica Senese S.p.A., Tax Code and VAT No. 05871140157, represented by its Chief Executive Officer and legal representative, Dr. Massimiliano Boggetti, with registered office at Viale Decumano 26, Milan, and DIESSE INC., with registered office at 1139 Fairway Gardens NE, Atlanta, GA 30319, USA.

DIESSE’s Data Protection Officer may be contacted at: privacy@diesse.it. The list of categories of processors is kept at DIESSE’s registered office.