Privacy Policy
PRIVACY POLICY REGARDING THE PROCESSING OF PERSONAL DATA BY KIRANTONI S.R.L. (www.kirantoni.com)
Thank you for your interest in KIRANTONI S.R.L. Protecting the personal data you provide is especially important to us. The confidentiality of your personal data is equally important to us.
In accordance with the provisions of LAW No. 195 of July 25, 2024 on the protection of personal data, KIRANTONI S.R.L. processes personal data in accordance with the principles set out below, for legitimate purposes.
Personal data is processed using mixed methods (manual and automated), in accordance with legal requirements and under conditions that ensure security, confidentiality, and respect for the rights of data subjects.
1. PERSONAL DATA COLLECTION
The purpose of this security policy is to ensure an adequate level of protection for the personal data of data subjects through the proper application of national legislation regarding data protection and communications privacy.
2. PRINCIPLES OF PERSONAL DATA PROCESSING
Lawfulness:
Personal data is processed fairly and in accordance with legal provisions;
Clear Purpose:
Any processing of personal data is carried out for clearly defined, explicit, and legitimate purposes that are appropriate, relevant, and not excessive in relation to the purpose for which they are collected and subsequently processed;
Disclosure:
This information informs individuals that their personal data will be processed;
Storage Location:
Personal data will not be stored longer than is necessary to achieve the purposes for which they were collected;
Protection of Data Subjects:
Personal data will be processed by authorized persons within KIRANTONI S.R.L. or by other authorized persons in accordance with the law.
Security:
Technical and organizational security measures for personal data are in place to protect personal data from accidental or unlawful destruction, loss, alteration, disclosure, or unauthorized access (access to user databases is based on a username and password and is governed by roles and access rights).
3. PERSONAL DATA PROCESSING POLICY
In accordance with the provisions of LAW No. 195 of July 25, 2024, on the protection of personal data, KIRANTONI S.R.L. is obligated to manage the personal data provided to it securely and solely for the purposes set out below.
KIRANTONI S.R.L. undertakes to maintain the confidentiality of personal data provided through the website www.kirantoni.com, in accordance with the provisions of LAW No. 195 of July 25, 2024, as subsequently amended, on the protection of personal data.
4. PERSONAL DATA SECURITY REQUIREMENTS
The following categories of personal data processing operations pose particular risks to human rights and freedoms:
1) adaptation, modification, disclosure by transfer, dissemination, or any other means of personal data related to racial or ethnic origin, political or religious beliefs, membership in a political party or religious organization, personal data of personnel on their health or intimate life, as well as personal data on criminal records, coercive measures, disciplinary or unlawful sanctions;
2) operations involving the processing of genetic and biometric data and data enabling the determination of the geographic location of individuals via electronic communication networks;
3) operations involving the processing of personal data by electronic means aimed at assessing certain aspects of an individual, such as professional competence, trustworthiness, behavior, etc.;
4) Electronic processing of personal data in evidence systems for the purpose of analyzing solvency, financial and economic status, and facts that may lead to disciplinary, misconduct, or criminal liability of individuals;
5) Processing the personal data of minors for commercial purposes (direct marketing activities);
6) Processing the personal data specified in subparagraphs 1) and 2) of this Appendix, as well as the personal data of minors collected via the Internet or electronic communications.
The requirements for ensuring the security of personal data when processed in personal data information systems (hereinafter referred to as the Requirements) are aimed at establishing minimum rules for the implementation by personal data holders of technical and organizational measures necessary to ensure the security, confidentiality, and integrity of personal data processed in personal data information systems and/or manually maintained registries.
These Requirements provide the necessary basis for the application of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data
I agree Regarding the requirements for ensuring the security of personal data when processed in personal data information systems, measures to protect personal data are an integral part of the creation, development, and use of the Personal Data Information System and will be implemented continuously by all personal data holders. The protection of personal data in personal data information systems is ensured by a set of technical and organizational measures to prevent the illegal processing of personal data. Measures to protect personal data processed in personal data information systems must be implemented taking into account the need to ensure the confidentiality of these measures. It is prohibited to carry out any activities or work using the information resources of the personal data holder if appropriate measures to protect personal data have not been adopted and implemented.
"KIRANTONI" S.R.L." confirms that it meets the minimum requirements for personal data security.
"KIRANTONI" S.R.L." utilizes security methods and technologies, as well as policies applicable to participants and operational procedures, to protect personal data collected in accordance with applicable legal provisions. Personal data protection in personal data information systems is ensured for the following purposes:
1) preventing the leakage of information containing personal data by eliminating unauthorized access;
2) preventing the destruction, modification, copying, and unauthorized blocking of personal data in telecommunications networks and information resources;
3) compliance with the regulatory framework for the use of information systems and personal data processing programs;
4) ensuring the completeness, integrity, and accuracy of personal data in telecommunications networks and information resources;
5) maintaining the ability to manage the processing and storage of personal data.
Personal data processed in information systems is protected by the following methods:
1) preventing unauthorized connections to telecommunications networks and the interception of personal data transmitted over these networks using technical means;
2) eliminating unauthorized access to processed personal data;
3) preventing special technical and software actions that could lead to the destruction or modification of personal data or defects in the operation of the technical and software system;
4) preventing intentional and/or unintentional actions by internal and/or external users, as well as other employees of the personal data holder, that could lead to the destruction or alteration of personal data or to defects in the operation of the hardware and software system. Automated means are used to ensure the detection of unauthorized access and the initiation of actions to block access.
Protection against malware penetration into the software used for processing personal data is ensured, which enables automatic and timely updating of anti-malware protection tools and virus signatures.
5. RIGHTS OF INTERESTED PARTIES
In accordance with the provisions of LAW No. 195 of July 25, 2024, the personal data subject has the following rights:
• Right to information: this is the right of the individual to obtain from the operator, upon request and free of charge, confirmation that the data concerning him or her is or is not being processed by "KIRANTONI" S.R.L.;
• Right of access to personal data: every data subject has the right to obtain from the controller, upon request, without delay and free of charge, any information concerning his or her personal data;
• Right to intervene on personal data: every data subject has the right to obtain from the controller, upon request and free of charge, the rectification, updating, blocking or deletion of personal data the processing of which contravenes the above-mentioned Law;
• Right of objection by the data subject: the right of the data subject to object at any time, free of charge, for compelling and legitimate reasons relating to his or her particular situation, to the processing of personal data directed at the object of processing, unless otherwise provided by law. If the objection is justified, the processing carried out by the controller may no longer target these data;
• Right not to be subject to an individual decision: anyone has the right to request the annulment, in whole or in part, of any individual decision which produces legal effects on his or her rights and freedoms, based solely on automated processing of personal data intended to evaluate certain aspects of his or her personality, such as professional competence, credibility, conduct, etc.;
• Right to appeal to the CNPDCP or to the courts: any person who has suffered damage as a result of the unlawful processing of personal data or whose rights and interests are guaranteed
If the provisions of this law have been violated, you have the right to seek compensation for material and moral damages.
Any information you provide will be reviewed and constitute your explicit consent to the use of your personal data by KIRANTONI S.R.L. in accordance with the purposes specified below.
If you would like your personal data updated or deleted from the database, or if you have any questions about data privacy, you can contact us at any time using the contact information on the website.
If you do not want your data collected, please do not provide it to us.
6. PURPOSE OF PERSONAL DATA COLLECTION
KIRANTONI S.R.L. processes the personal data of its clients and other persons associated with or in contact with them, which are provided while browsing the website www.kirantoni.com, for the purpose of promoting products and services related to computer equipment and laboratory equipment. Personal data (identification data, address, personal identification number, telephone number, age, or any other similar data provided) may be processed and used by "KIRANTONI" SRL for the purposes of marketing products and services, laboratory equipment ordered on the company's website, and for the purpose of compiling databases and using them in the operator's future operations and activities, in accordance with the provisions of LAW No. 195 of July 25, 2024 for the protection of individuals with regard to the processing of personal data.
"KIRANTONI" SRL will not disclose any of your data (personal information or additional information) to third parties without your consent, unless we believe in good faith that the law requires us to do so or that it is necessary to protect the rights or property of our company.
7. SECURITY AUDIT OF PERSONAL DATA INFORMATION SYSTEMS
"KIRANTONI" SRL regularly, at least once a year, verifies the implementation of technical and/or organizational measures taken to detect malfunctions in the use of telecommunications systems during the processing of personal data and/or implement improvements where necessary. To verify the level of protection of personal data information systems, as well as to prevent possible cases of illegal or accidental access to these information systems and to identify weaknesses in their protection mechanisms, "KIRANTONI" SRL periodically conducts security audits, including the implementation of special technical measures to simulate the access model to personal data information systems.
For further details and information, any interested party may contact us by email at office@kirantoni.com or by phone at any number listed in the "Contacts" section of the company's website: www.kirantoni.com