EDiM / Privacy policy for suppliers

Privacy notice for suppliers

1 July 2023

PRIVACY NOTICE FOR SUPPLIERS

EDiM S.p.A. a socio unico, with legal office in Villasanta (MB) via Saragat n. 1, acting as Data Controller (hereinafter also, the “Company”), wishes to inform you, pursuant to Articles 13 and 14 of the EU Regulation No.679/2016 (GDPR), about the purpose and manner of the processing of your personal data for the performance of the contractual relations with the Company and for the performance of the relevant pre-contractual measures.

1. SOURCE OF PERSONAL DATA

For purposes described in the following paragraphs, the Company will process the personal data you provide in the context of the performance of the business relationship or of the relevant pre-contractual measures and for the fulfillment of related legal obligations, including fiscal or accounting, or for the purposes of judicial defense.

In addition, and in order to carry out preliminary contractual checks, the Company may receive data relating to your economic and financial situation from external suppliers who professionally provide services of exchange of commercial information pursuant to art. 134 of the T.U.L.P.S. and D.M. 269/2010, and that process your personal data as autonomous data controllers.

2. PURPOSES OF PROCESSING

Your data will be processed for the following purposes:

i. performance of the contractual relationship or of the relevant pre-contracted measures;

ii. performance of preliminary checks on your financial solidity, solvency and reliability;

iii. claims management, debt collection or litigation;

iv. fulfillment of related legal obligations including taxing or accounting obligations.

3. LEGAL BASIS AND NATURE OF PROVISION OF DATA

Processing for the purpose described in the previous paragraph (i) is necessary for the execution of the contract of which you are part, under art. 6 paragraph 1 lett. b) of the GDPR.

Processing for the purposes referred to in the previous points ii) and iii) are carried out on the basis of the legitimate interest of the Company acting as Data Controller, under art. 6 paragraph 1 lett. (f) of GDPR.

Processing for the purpose referred to in the previous paragraph iv) is necessary in order to comply with the legal obligations to which the Company is subject, under art. 6 paragraph 1 lett. c).

The provision of your data is optional, but necessary for the performance of the contractual relationship with you.

To the extent that, for the pursuit of the above mentioned purposes, the Data Controller processes personal data of employees or partner of the supplier or consultant, this privacy notice is also addressed to these employees and/or partner. It is the responsibility of the supplier to inform these subjects of this privacy notice on the processing of their personal data.

4. DATA COMMUNICATION

Your personal data will not be disclosed. They will be communicated to third parties who need to process your data for the performance of the contractual relationship (where these third parties do not act as Data Processors on behalf of EDiM S.p.A. a socio unico such as:

i. consultants – professionals acting as supplier for services above descripted;

ii. third parts that offers services for the fulfillment of legal obligations;

iii. the holding Company of the Bosch Group.

5. MODALITIES OF PROCESSING

Personal data is processed in paper and/or automated format and can be processed in order to take decisions based on automated processing. In such cases, however, there will always be a human intervention in the evaluation process.

6. RETENTION PERIODS

Your personal data will be stored for the duration of the contractual relationship and the related services (such as warranty, warranty extension) plus any additional period required by the law in relation to the product.

7. TRANSFERS OUTSIDE THE EUROPEAN UNION

Personal data is processed and stored at the Data Controller’s office and in any other place where the parties involved in the processing are located.

For the purposes described above, there will be no transfers of personal data outside the European Economic Area.

8. DATA CONTROLLER

The Data Controller is EDiM S.p.A. a socio unico, based in Villasanta (MB), via Saragat n. 1. In relation to this activity, the Data Controller uses service providers that have been duly appointed as “Data Processors”. The full list of Data Processors can be requested in writing at the following e-mail address: info@edim-it.com.

9. DATA SUBJECTS’ RIGHTS

You may, at all times and free of charge, request the Data Controller to exercise the rights provided by art. 15 and ss. of the GDPR, including the right to:

  • receive confirmation of the existence of your personal data, understand the purpose of the processing or their scope of circulation and access your personal data;
  • update, modify and/or correct your personal data;
  • request deletion, transformation in anonymous form, blocking of data unlawfully processed or request limitation of processing;
  • where applicable, object to the processing of your personal data carried out on the basis of the Data Controller’s legitimate interests. In particular, according to art. 22 of the GDPR and in relation to decisions based solely on automated processing having legal effects, you have the right to request from the Data Controller the human intervention in the process, to express your opinion or to challenge the decision;
  • receive a copy of the data you provided and request that this data is transmitted to another data controller;
  • revoke previous consents, effective for the future.

For additional information on the processing activities described in this document, to exercise the additional rights listed in art. 15 and following of GDPR n. 679/2016, as well as to report cases of privacy violation, please use the following link: https://request.privacy-bosch.com.

If you believe that a violation of your rights has occurred, you may also contact the relevant authority under art. 77 GDPR or you can bring your claim to the competent judicial authorities.

In case of any need or request regarding the processing of your personal data, please contact the Data Privacy Officer (DPO) at the following e-mail address: DPO@bosch.com.

 

Edition 3.2 valid from july 2023