PRIVACY

Privacy Notice for the Processing of Customers’ Personal Data

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

1. INTRODUCTION

GERIT SYSTEMS S.r.l., with registered office at Via Giotto 15 – 39100 Bolzano (Italy), Tax Code and VAT No. 03323060214, in the person of its legal representative pro tempore, as Data Controller, hereby informs you, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (hereinafter also the “GDPR”) and in compliance with Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, that your personal data will be processed in the manner and for the purposes set out in this privacy notice.

2. DATA SUBJECTS CONCERNED

This notice is addressed to customers, including prospective customers who are natural persons, as well as to contact persons, employees and collaborators of companies, entities or organisations that maintain, or intend to maintain, pre-contractual, contractual and commercial relationships with GERIT SYSTEMS S.r.l., whose personal data are processed in connection with the management of such relationships.

The separate privacy notice provided to the end users of the PoolAgent application and the DashPool platform remains applicable where relevant.

3. DATA CONTROLLER

The Data Controller is GERIT SYSTEMS S.r.l., with registered office at Via Giotto 15 – 39100 Bolzano (Italy), Tax Code and VAT No. 03323060214, in the person of its legal representative pro tempore.

The Data Controller can be contacted using the following details:

  • e-mail: info@geritsystems.com
  • Certified e-mail (PEC): geritsystems@altoadigepec.it.

4. CATEGORIES OF PERSONAL DATA PROCESSED

For the purposes indicated in this notice, GERIT SYSTEMS S.r.l. may process the following categories of personal data:

  • identification and personal details, such as first name, surname, tax code, VAT number, corporate role or position;
  • contact details, such as e-mail address, telephone number, address of the premises or office, or other contact details provided by the data subject;
  • administrative, accounting and tax data necessary for the management of the pre-contractual, contractual and commercial relationship;
  • data relating to the contractual and commercial relationship, such as requests for information, quotations, offers, orders, contracts, correspondence, invoicing and payment data;
  • data relating to the products, services or activities requested by the customer, to the extent necessary for the management of the relationship with GERIT SYSTEMS S.r.l.;
  • data relating to the technical management of products, systems, installations, support interventions, configurations, repairs, maintenance, technical history and activities connected with the services requested by the customer;
  • where the customer or its contact persons use reserved areas, platforms or digital services made available by GERIT SYSTEMS S.r.l., account and access data, such as username, user ID, authorisation profile, technical logs and information necessary for the security and proper functioning of the systems;
  • any further personal data provided by the data subject in connection with the requests submitted to GERIT SYSTEMS S.r.l.

In the context of relationships with customers, GERIT SYSTEMS S.r.l. processes ordinary personal data. Special categories of personal data within the meaning of Article 9 GDPR and data relating to criminal convictions and offences within the meaning of Article 10 GDPR are not processed, unless required by specific legal provisions.

5. PURPOSES AND LEGAL BASIS OF THE PROCESSING

Personal data will be processed for the following purposes, on the basis of the relevant legal bases:

 

Purpose of the processing Legal basis
Handling of requests for information, quotations and offers submitted by the customer in relation to the products, components, systems and services offered by GERIT SYSTEMS S.r.l. Performance of pre-contractual measures taken at the data subject’s request – Art. 6(1)(b) GDPR.
Performance and management of the contractual relationship with the customer, including the handling of orders, supplies, deliveries, support and activities related to the requested products or services. Performance of the contract – Art. 6(1)(b) GDPR.
Management, cataloguing and retention of the technical history relating to products, components, supplies, installations, repairs and support interventions, including by means of IT tools or company platforms. Performance of the contract, where the processing is necessary for the management of the relationship with the customer, and legitimate interest of the Controller in product traceability, in managing the technical history and in organising/improving support services – Art. 6(1)(b) and (f) GDPR.
Administrative, accounting and tax management of the relationship. Compliance with legal obligations – Art. 6(1)(c) GDPR.
Management of communications with the customer and its contact persons for operational, technical, commercial, administrative and organisational needs connected with the relationship. Performance of the contract and legitimate interest of the Controller – Art. 6(1)(b) and (f) GDPR.
Handling of any disputes, debt recovery or protection of the Controller’s rights. Legitimate interest of the Controller – Art. 6(1)(f) GDPR.
Sending, by e-mail, of commercial communications relating to products or services similar to those already covered by the relationship with the customer, within the limits permitted by applicable law. Article 130(4) of Legislative Decree No. 196/2003 and legitimate interest of the Controller, subject to the data subject’s objection – Art. 6(1)(f) GDPR.
Sending of commercial, promotional or marketing communications relating to products or services not similar to those already covered by the relationship, or by means other than those falling within the scenario referred to in Article 130(4) of Legislative Decree No. 196/2003. Consent of the data subject – Art. 6(1)(a) GDPR.
[…] […]

 

 

 

6. PROFILING AND AUTOMATED DECISION-MAKING

GERIT SYSTEMS S.r.l. does not carry out processing based on automated decision-making, nor profiling activities within the meaning of Articles 4(4) and 22 GDPR.

Any use of IT tools for the management, cataloguing and retention of the technical history relating to products, components, installations, repairs and support interventions serves organisational, technical and management purposes and does not entail any evaluation, analysis or prediction concerning natural persons, nor does it produce any automated effects on data subjects.

7. NATURE OF THE PROVISION OF DATA

The provision of the data necessary for handling the data subject’s requests, for the pre-contractual and contractual relationship, and for administrative, accounting and tax obligations is necessary. Failure to provide such data may make it impossible for GERIT SYSTEMS S.r.l. to act on the requests received, to establish or manage the relationship with the customer, to carry out the requested activities or to comply with the applicable legal obligations.

The provision of data for any further promotional or marketing purposes is optional, and the related processing will be carried out on the basis of the data subject’s consent, which may be withdrawn at any time.

The data subject remains entitled to object at any time to the sending of commercial communications relating to products or services similar to those already covered by the relationship, carried out within the limits permitted by applicable law.

8. METHODS OF PROCESSING

Personal data will be processed in paper, electronic and telematic form and entered into the relevant company databases, which may be accessed solely by persons authorised to process the data pursuant to Article 29 GDPR, duly instructed in relation to the tasks performed and the activities permitted on the collected data.

The processing may also be carried out by external parties that provide administrative, accounting, IT, technical, cloud, hosting, maintenance, support, digital preservation, communication or other services instrumental to the purposes indicated in this notice; such parties will act, as the case may be, as Data Processors pursuant to Article 28 GDPR or as independent Data Controllers.

The Controller adopts appropriate technical and organisational measures to ensure that processing operations are carried out in a manner that guarantees the security, integrity, confidentiality and availability of personal data.

9. RECIPIENTS OF PERSONAL DATA

Personal data may be disclosed to:

  • banks and credit institutions;
  • companies providing digital preservation, archiving and document management services;
  • platforms and providers of IT, management, cloud, hosting, maintenance and technical support services;
  • installers, technical partners, maintenance providers and parties entrusted with configuration, support, technical intervention or operational management of the products, systems or services requested by the customer;
  • payment providers and parties involved in the management of subscriptions, collections, invoicing and transactions;
  • platforms providing DEM (direct e-mail marketing) or newsletter services;
  • public and/or private bodies to which disclosure is necessary in order to comply with legal obligations;
  • consultants and independent professionals, including in associated form;
  • insurance companies, including for trade credit insurance services;
  • debt collection companies;
  • forwarders, carriers, logistics companies, postal services and other parties involved in the operational management of the commercial relationship.

The parties referred to above may act, as the case may be, as Data Processors pursuant to Article 28 GDPR or as independent Data Controllers.

Personal data will not be disseminated to the public.

10. TRANSFER OF DATA TO THIRD COUNTRIES

The processing and storage of personal data will take place on servers located within the European Union.

Should it become necessary to transfer personal data to countries located outside the European Economic Area, including through the use of IT services or cloud platforms, the transfer will take place in compliance with Articles 44 et seq. GDPR and on the basis of the safeguards provided for by applicable law.

11. RETENTION PERIOD

Personal data will be retained for the time necessary to pursue the purposes for which they were collected and, thereafter, for the periods possibly required by applicable law or necessary for the protection of the Controller’s rights.

 

Purpose Retention period
Pre-contractual requests, quotations and offers For the time necessary to handle the request and, thereafter, for the period possibly necessary to protect the Controller’s rights.
Management of the contractual relationship For the entire duration of the relationship and, thereafter, for the applicable limitation period.
Administrative, accounting and tax obligations For 10 years, in accordance with the legal obligations regarding the retention of accounting and tax records.
Management and retention of the technical history of products, components, installations, repairs and support interventions For the entire duration of the contractual relationship and, thereafter, for a maximum period of 36 months, save for legal obligations or documented technical support, security or rights-protection needs that make further retention necessary.
Commercial communications relating to products/services similar to those already covered by the relationship Until any objection by the data subject.
Newsletters, mailing lists and further promotional or marketing communications Until withdrawal of consent or a request to be removed from the mailing list, by means of the dedicated function included in the communication received or by writing to the Controller’s contact details.

 

12. RIGHTS OF THE DATA SUBJECT

The data subject may exercise, in the cases and within the limits provided for by the GDPR, the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing, pursuant to Articles 15 to 22 GDPR.

Where processing is based on consent, the data subject may withdraw it at any time, pursuant to Article 7 GDPR, without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise these rights, the data subject may contact GERIT SYSTEMS S.r.l. by sending a communication to the details indicated in this notice, including the certified e-mail (PEC) address: geritsystems@altoadigepec.it.

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), pursuant to Article 77 GDPR, should they consider that the processing of personal data is carried out in breach of applicable law.

13. UPDATES

This notice may be updated or amended over time. The updated version will be made available through the channels ordinarily used by GERIT SYSTEMS S.r.l.

Last updated: 10/08/2026

Warning: some page functionalities could not work due to your privacy choices: