P R I V A C Y

PRIVACY NOTICE (GDPR)

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

1. Data Controller

Plenum S.r.l., with registered office at Via San Quintino 26/A, 10100 Turin (TO), Italy (email: plenum@plenum.it; phone: +39 011 81224705; VAT No.: 08809900015), in its capacity as Data Controller (the “Controller”), hereby informs you that your personal data shall be processed in accordance with Regulation (EU) 2016/679 (the “GDPR”).

2. Principles of Processing

The Controller shall process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.

3. Purposes and Legal Basis

The personal data provided shall be processed for the following purposes:

(a) compliance with legal and regulatory obligations (including tax and accounting);

(b) management of customer relationships;

(c) performance of contractual obligations, including purchase and post-sale assistance;

(d) customer satisfaction analysis and invoicing history.

The legal basis for such processing is Article 6(1)(b) and (c) GDPR.

Subject to your prior consent pursuant to Article 6(1)(a) GDPR, your data may also be processed for:

(i) sending newsletters;

(ii) marketing communications, market research and promotional activities.

Provision of data for contractual and legal purposes is mandatory. Failure to provide such data may result in the impossibility of performing the contract.

4. Methods of Processing

Personal data shall be processed by electronic and manual means and may be outsourced to third-party processors, in compliance with Articles 6 and 32 GDPR and appropriate security measures.

5. Disclosure of Data

Personal data may be disclosed to authorised personnel and to third parties acting as processors or independent controllers, including:

(a) postal service providers;

(b) consultants and professionals;

(c) suppliers;

(d) insurance companies;

(e) public authorities;

(f) hosting and IT service providers.

6. International Transfers

Personal data may be stored on cloud platforms (e.g., OneDrive, Dropbox). Such transfers shall comply with the GDPR and ensure an adequate level of protection.

7. Data Retention

Personal data shall be retained for a period of ten (10) years pursuant to Article 2220 of the Italian Civil Code, and for any longer period necessary to protect the Controller’s legal rights.

8. Data Subject Rights

Under Articles 15–22 GDPR, you have the right to access, rectify, erase, restrict processing, object to processing, and request data portability.

9. Right to Lodge a Complaint

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

10. Contact Details

Any requests concerning the processing of personal data may be addressed to: plenum@plenum.it