Privacy Policy

Privacy Policy

Information and request for consent for the processing of personal data

Dear User/Data Subject,
This Privacy Notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter also referred to as the “GDPR”).

We hereby inform you that the personal data provided in connection with your use of this website will be processed by Abacus Group S.r.l., in its capacity as Data Controller (hereinafter also referred to as “Abacus Group” or the “Data Controller”), in compliance with the data protection principles laid down in the GDPR, as well as with all applicable European and national legislation and/or measures issued by the competent Supervisory Authorities.

The following Privacy Notice applies solely to the Abacus Group website and does not apply to any other websites that may be accessed by the User via links contained therein.

We inform you that the optional, explicit and voluntary sending of electronic mail messages to the addresses indicated on this site, as well as the filling in of contact forms involves the acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message.

Finally, please be informed that Abacus Group may, by email — where you have provided us with your email address and given your consent — offer you products or services similar to those you have previously requested. In such cases, we will always remind you of your right to opt out of receiving further similar communications.
We also inform you that, while you browse the pages of this website, Abacus Group may place technical cookies on your browser in order to improve your user experience.

You will find more details about these cookies and related processing in the section “COOKIES”.

A. Purpose of processing

The processing of data voluntarily provided by the User while browsing the website electronically, through the completion of contact request forms, is carried out by Abacus Group for the following purposes:

a. to enable us to respond to the requests you submit. For this purpose, the following data are required: first name, last name, company, email address and telephone number (the latter being optional);
b. subject to your prior consent, to establish and manage commercial relationships effectively, particularly for promotional, advertising and marketing purposes relating to products and services provided by Abacus Group;
c. subject to your prior consent, to analyse your habits and preferences in order to send you marketing materials that are more relevant to your characteristics and interests.

The processing carried out for the purpose referred to in point a) is necessary in order to respond to the User’s request and, therefore, for the performance of pre-contractual measures taken at the User’s request (Article 6(1)(b) of the GDPR). The processing carried out for the purposes referred to in points b) and c) is based on the User’s consent (Article 6(1)(a) of the GDPR), which may be withdrawn at any time, without affecting the lawfulness of processing based on consent given prior to its withdrawal.

B. Type of data collected and processed

Without prejudice to the Data Subject’s freedom of choice and to the provision of browsing data, the provision of the data referred to in Section A, point a), is mandatory. Failure to provide, even in part, the data expressly indicated as necessary will make it impossible to process the request submitted. Mandatory data are marked with an asterisk (*). The provision of the data referred to in Section A, points b) and c), is optional. Failure to provide such data for these purposes will make it impossible to keep Users informed about sales and promotional initiatives.

C. Data Controller, Data Protection Officer and Authorised Persons

The Data Controller is Abacus Group S.r.l., represented by its legal representative pro tempore.
Registered Office: Centro Direzionale Milanofiori, Strada 1, Palazzo F1, 20057 Assago (MI), Italy
Email: privacy@abacusgroup.io

Please be informed that you may contact the Data Controller using the Company’s contact details provided above.

Please be informed that the data provided will be processed by Abacus Group personnel who have been expressly authorised to process personal data and duly instructed in accordance with Article 29 of the GDPR.

D. Method of treatment.

The personal data provided will be processed at Abacus Group’s premises, including by means of automated procedures, in the manner and within the limits necessary to achieve the purposes set out above. Please also be informed that the personal data provided will be processed using computerised procedures, in the manner and within the limits necessary to achieve the aforementioned purposes.

E. Retention period

Please be informed that the personal data provided will be processed and retained by the Data Controller for purposes strictly related to those set out in Section A, point a), and will be kept by the Data Controller only for the period strictly necessary to handle the requests submitted by the User. Personal data processed for the purposes referred to in Section A, points b) and c), will be retained until the User withdraws his or her consent, without prejudice to the Data Controller’s commitment to periodically assess whether the consent given remains valid and current over time. At the end of the applicable retention period, the personal data will be deleted or destroyed.

F. Recipients of the Data

Personal data may be disclosed, to the extent strictly necessary to pursue the purposes set out in Section A, to entities providing ancillary services to the Data Controller (such as IT, hosting and email service providers), which act as data processors pursuant to Article 28 of the GDPR, as well as to public authorities where required by law.
An up-to-date list of data processors is available upon request using the Data Controller’s contact details.
Personal data will not be disseminated.

Subject to your specific consent pursuant to Section A, point d), the contact details you provide (first name, last name, email address and, where applicable, telephone number) may be disclosed to companies controlled by Abacus Group. The recipient companies will process the personal data as independent data controllers, exclusively for the purpose of sending promotional and commercial communications relating to their own products and services, and will provide you with their own privacy notice no later than at the time of the first communication. You may withdraw your consent at any time by writing to privacy@abacusgroup.io or directly to each recipient company. Abacus Group will communicate any resulting erasure requests to the recipient companies in accordance with Article 19 of the GDPR.

G. Transfer of Data to Third Countries

Personal data are processed within the European Economic Area (EEA). Where, in connection with the services provided by data processors, it becomes necessary to transfer personal data to third countries, such transfer will be carried out in compliance with Chapter V of the GDPR, on the basis of an adequacy decision adopted by the European Commission (Article 45) or appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission (Article 46). A copy of the safeguards adopted may be requested using the Data Controller’s contact details.

H. Rights of the Data Subject

As a Data Subject, you may exercise your rights under the GDPR against the Data Controller at any time, as set out below:

I. Right of Access by the Data Subject – Article 15 GDPR

The Data Subject may ask the Data Controller whether or not personal data concerning him or her are being processed. Where such processing is taking place, the Data Subject may obtain access to his or her personal data and receive information on the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed, including any recipients located in third countries or international organisations.

The Data Subject may also receive information, where possible, on the envisaged period for which the personal data will be stored or, where it is not possible to specify that period precisely, on the criteria used to determine it.
The Data Subject may also be informed of the existence of the right to request from the Data Controller the rectification or erasure of personal data, the restriction of processing of personal data concerning him or her, or to object to such processing.

The Data Subject also has the right to lodge a complaint with a supervisory authority. Where the personal data have not been collected directly from the Data Subject, he or she may obtain any available information as to their source.

Finally, the Data Subject may receive information on the existence of any automated decision-making, including profiling as referred to in Article 22(1) and (4), and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the Data Subject.

II. Right to Rectification – Article 16 GDPR

The Data Subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the Data Subject also has the right to have incomplete personal data completed, including by providing a supplementary statement.

III. Right to Erasure (the “Right to Be Forgotten”) – Article 17 GDPR

The Data Subject may request that the Data Controller erase personal data concerning him or her where, for example, such data are no longer necessary in relation to the purposes for which they were collected, where consent is withdrawn and there is no other legal ground for the processing, where the processing is unlawful, or where erasure is required in order to comply with a legal obligation.

This right also includes the so-called “right to be forgotten”, namely the possibility, in the cases provided for by law, to request that personal data no longer be made available or associated with the Data Subject, particularly where such data have been published or disseminated online. Where the Data Controller has made the personal data public and is required to erase them, it shall take reasonable steps to inform any other data controllers processing such data of the Data Subject’s request to erase any links to, or copies or replications of, those personal data.

The Data Controller shall erase the personal data without undue delay, unless the processing must continue because it is necessary, for example, to comply with a legal obligation, to exercise the right to freedom of expression and information, for reasons of public interest, or for the establishment, exercise or defence of legal claims.

IV. Right to Restriction of Processing – Article 18 GDPR

The Data Subject may request that the Data Controller restrict the processing of personal data concerning him or her where, for example, the Data Subject contests the accuracy of the data, considers the processing to be unlawful but does not wish the data to be erased, or where the data are required for the establishment, exercise or defence of legal claims.

Restriction of processing means that, as a rule, the personal data are only stored and are not further processed, unless such processing is carried out with the Data Subject’s consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another person, or for reasons of important public interest.

The Data Controller shall inform the Data Subject before lifting the restriction on processing.

V. Right to Data Portability – Article 20 GDPR

The Data Subject may request that the Data Controller provide the personal data concerning him or her in a structured, commonly used and machine-readable format, so that such data may be used or transmitted to another Data Controller.

This right may be exercised where the processing is based on the Data Subject’s consent or on a contract and is carried out by automated means. Where technically feasible, the Data Subject may request that the personal data be transmitted directly by the Data Controller to another data controller.

The exercise of this right shall not affect the right to erasure of personal data and shall not adversely affect the rights and freedoms of others.

VI. Right to Object – Article 21 GDPR

The Data Subject may object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her where such processing is based on the performance of a task carried out in the public interest or on the legitimate interests pursued by the Data Controller, including any related profiling.

In the event of an objection, the Data Controller shall cease processing the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or where the processing is necessary for the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, the Data Subject may object at any time to such processing, including any profiling related to direct marketing. In such cases, the personal data will no longer be processed for those purposes.

The Data Subject may also exercise the right to object by automated means, where available.
Where personal data are processed for scientific or historical research purposes or for statistical purposes, the Data Subject may object to such processing on grounds relating to his or her particular situation, unless the processing is necessary for the performance of a task carried out in the public interest.

VII. Right to Lodge a Complaint with a Supervisory Authority – Article 77 GDPR

Without prejudice to any other administrative or judicial remedy, a Data Subject who considers that the processing of personal data concerning him or her infringes the GDPR has the right to lodge a complaint with the supervisory authority of the Member State in which he or she has his or her habitual residence or place of work, or of the place where the alleged infringement occurred. In Italy, the competent supervisory authority is the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it).

General rules for exercising rights

Please be informed that the rights set out in the preceding sections may be exercised at any time by sending an email to the following address: info@abacusgroup.io, together with a digital copy of a valid identity document.
Please note that, if you request the cessation of all processing of your personal data, we may no longer be able to continue providing you with the services requested. In any event, we may retain certain personal data where such retention is necessary for the establishment, exercise or defence of legal claims.

Cookie Policy

Abacus Group uses cookies to improve its website and to provide services and functionalities to Users. You may restrict or disable the use of cookies through your web browser settings. However, if you do so, certain website functionalities may become unavailable.

Navigation data

The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is inherent in the use of Internet communication protocols. Such information is not collected for the purpose of being associated with identified Data Subjects; however, by its very nature, it may, through processing and association with data held by third parties, make it possible to identify Users. This category of data includes:

  • the IP addresses or domain names of the computers used by Users connecting to the website;
  • the Uniform Resource Identifier (URI) addresses of the requested resources; the time of the request; the method used to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the response returned by the server (successful, error, etc.); and other parameters relating to the User’s operating system and IT environment.

This data is used for the sole purpose of obtaining anonymous statistical information about the use of the site and to check its correct operation and is deleted immediately after processing. Il relativo trattamento si fonda sul legittimo interesse del Titolare a garantire la sicurezza e il corretto funzionamento del sito (art. 6, par. 1, lett. f) del GDPR).

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.