Pursuant to the contents of EU Regulation 2016/679, updated to the corrigenda published in the Official Journal of the European Union 127 of 23 May 2018, transposed in Italy by Law no. 163 of 2017 (European delegation law 2016-2017), article 13,
the Data Controller declares to adopt:
- physical security measures aimed at preventing access by unauthorised parties to the Infrastructure within which the data is stored;
- identity and access controls using an authentication system and a password management policy;
- an access management system that limits access to the facilities to those for whom it is indispensable in the performance of their duties and within their responsibilities;
- a system that physically and logically isolates clients from one another;
- authentication procedures for users and administrators, and to protect access to administrator functions;
- an access management system for support and maintenance activities that operates on the principles of minimum privilege and the need for communication;
- procedures and measures to track actions performed on its information system;
- adequate security measures to ensure a level of security appropriate to the risks to the data, pursuant to Article 32, such as backup and disaster recovery procedures;
- internal rules on document management and Internet and e-mail use for data processors;
- training procedures for data processors;
- an information notice for data subjects complete with consent in the cases provided for;
- a Processing Register pursuant to Article 30, periodically updated;
- a list of Data Processors designated pursuant to Article 28.
Privacy policy customers/suppliers GDPR EU 679/2016
BDS Srl, in its capacity as personal data controller pursuant to Articles 13 and 14 of the EU Regulation 679/2016 - General Data Protection Regulation ("GDPR"), in compliance with the obligations dictated by the legislator to protect privacy, hereby wishes to inform you in advance, both of the use of your personal data and of your rights, by communicating the following:
About us
BDS Srl
Registered Office: Regione Noce 84 - 12050 Feisoglio, (CN) PI 03285210047
Administrative and Operational Headquarters: Via Frua 14, 20146 Milan - P.I. 03285210047
privacy@britishschool-italia.it
The "data controller" is BDS Srl and the legal representative is Fabrizio Borghi.
What personal data we collect and why we collect it
SOURCE OF CONTACT:
The source of the data is provided directly by the data subject
FORM
We will not use your contact form data for marketing purposes, but only to contact you for contractual purposes.
The data collected includes only the following mandatory data: first name, last name, email, telephone;
SERVICE PERFORMANCE:
Following any contractual services performed we will identify your language level and situations where you have language needs.
In the case of contracts with you, we will process accounting records of services rendered, financial information, debtors, due dates, requests, etc. -
Personal data (identification, accounting, financial, etc.)
Duration: Information maintained for the duration of the contract. At the end, only information required by legal obligations will be kept for 10 years
- Main purpose: to perform the tasks under the contract
- Legal Basis: processing is necessary for the performance of a contract to which the data subject is party or the performance of pre-contractual measures taken at the data subject's request
AREAS OF SERVICE PERFORMANCE
- information relating to services in the field of training
- information relating to translation and interpreting services
With whom we share your data.
The data we collect directly through the site is not shared with anyone. Only persons within our organisation, appointed as data processors, will have access to your data for the purposes described above.
For purposes of performing contractual services, some of your data may be disclosed to companies within the British School-SPIKE Group consisting of British School-SPIKE Srl, with registered office in Regione Noce 84 - 12050 Feisoglio (CN) and administrative and operational headquarters in Via Frua 14, 20146 Milan, PI 03285210047,
( 100% parent company of British School Global Srl, with registered office and administrative and operational headquarters in Via Santi Giacomo e Filippo 19-21 R, 16122 Genova, PI 01965580994) to collaborators, consultants or external suppliers appointed to provide services determined by contract.
.
The data communicated are exclusively those necessary for the provision of the service.
These subjects are appointed as data processors pursuant to Article 28 of EU Regulation 679/16.
- members of corporate bodies;
- third parties with servers located within the European Union; The full list of data processors can be requested at the addresses indicated in this notice.
This is without prejudice to the obligation to communicate the data to the judicial authorities in the event of a specific request.
How long we keep your data.
For users who register on our website (if any), we also store the personal information they provide in their user profile.
All users can see, change or delete their personal information at any time (except their user name, which they cannot change).
Website administrators can also view and edit this information.
Please note that you can contact us at any time at #mail# to assert your rights under Articles 15,16,17,18,19,20,21 of the GDPR.
What rights do you have over your data.
If you have an account on this site you can request #mail# to receive an exported file from the site with the personal data we have about you, including the data you have provided to us.
You can also request that we delete all personal data about you.
This does not include data that we are obliged to keep for administrative, legal or security purposes.
Additional information.
HOW WE PROTECT YOUR DATA:
The data on this site is protected by an SSL certificate installed on the server.
In addition to the SSL certificate, the site is constantly maintained by us and our technical partners. We also have an antivirus/antispam service to prevent hacker attacks.