Privacy Policy
Information Notice pursuant to Article 13 ex EU REG. 2016/679 (‘GDPR’)
Pursuant to Article 13 of Regulation (EU) 2016/679 ('the Regulation' or 'GDPR'), we would like to inform you about how and for what purposes we process the personal data of those who interact with our website: https://www.tinextadefence.it/
This information does not apply to other websites that may be consulted via links present on the domain websites of the owner, who is not liable in any way for the websites of third parties
Data controller
The Data Controller of personal data collected through this site is Tinexta Defence S.p.A. Benefit Corporation and Group companies: DONEXIT, FORAMIL, NEXT Ingegneria dei Sistemi e Innovation Design S.r.l., all co-processorswith registered office in Rome, to the street Giacomo Peroni, 452, VAT NUMBER 11065701002, in the person of the l.r.p.t., Tel: (+39) 0645752720; E-mail: privacy@defencetech.it; PEC: dth@pec.defencetech.it
Data Protection Officer
Pursuant to the General Data Protection Regulation (Art. 37 c.7 GDPR EU Regulation 2016/679), the company has appointed a Data Protection Officer, Dr. Ernesto Barbone, contacted as follows:
Purpose of processing, legal basis, nature of conferment
For the purposes expressed in this information notice, they will be processed, as a rule:
- personal data (e.g. name, surname, address, tax code, company name);
- contact details (e.g. telephone numbers, e-mail address);
- browsing data (e.g. IP addresses, domain names of computers used by users connecting to the site).
- special categories of data ('sensitive data') pursuant to Article 9 GDPR, i.e. data concerning health (membership of so-called protected labour categories, in case of application on our website).
The data will be processed in compliance with the conditions of lawfulness under Art. 6 of the Regulation, in order to:
- allow navigation on this website and the technical management of connections to it
The computer systems responsible for the functioning of the websites acquire, during their normal operation and for the sole duration of the connection, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes, for example: IP addresses or the names of the computers used by users who connect to the websites, the URI (Uniform Resource Identifier) notation addresses of the resources requested, the characteristics of the browser used for browsing, the resolution of the screen on which the browser is running on the device being used, and other parameters relating to the user's operating system and computer environment. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the sites and to check their correct functioning, and is deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes to the detriment of the sites.
Legal basis for processing: Processing is necessary for the pursuit of the legitimate interest of the holder of the
processing pursuant to Article 6(1)(f) of EU Reg. 2016/679.
- following up information or contact requests and other types of requests made by customers/users concerning the services offered by the Controller.
The voluntary sending of e-mails to the e-mail addresses indicated on the above-mentioned websites entails the subsequent acquisition of the sender's e-mail address and first name and surname, which are necessary in order to respond to requests, as well as any other personal data included in the message. This also applies in the context of handling and responding to complaints submitted by users.
Legal basis for processing: The processing is necessary for the performance of a contract to which the data subject is a party, pursuant to Art. 6(1)(b) of EU Reg. 2016/679. The data requested for the purposes indicated are necessary in order to be able to follow up on the data subject's requests. Failure to provide the data has the sole effect of making it impossible to send and/or receive and/or acknowledge the data subject's requests.
- manage the selection process when applying and sending a CV
The user is also free to provide his or her personal and special data (exclusively for the above-mentioned purposes) by means of the
section of the site 'Work with us', to send your CV and submit your application.
Legal basis for processingthe performance of pre-contractual or contractual obligations (Art. 6(1)(b) GDPR) and the
consent for special data (Art. 9 lett a GDPR).
The data requested for the purposes indicated are necessary in order to initiate the personnel selection procedure. Any
failure to provide the data has the effect of making it impossible to include you in the selection and consequently to assess the
its recruitment.
Personal data will not be processed using automated decision-making processes as referred to in Article 22 of the GDPR and collection for marketing purposes is excluded in any case.
Modalities of data processing
Il trattamento sarà effettuato con strumenti informatici e telematici nel rispetto delle norme in vigore e dei principi di correttezza, liceità, trasparenza, pertinenza, completezza e non eccedenza, esattezza e con logiche di organizzazione ed elaborazione strettamente correlate alle finalità perseguite e comunque in modo da garantire la sicurezza, l’integrità e la riservatezza dei dati trattati, nel rispetto delle misure organizzative, fisiche e logiche previste dalle disposizioni vigenti.
Data retention period
In compliance with the provisions of Article 5 paragraph 1 letter e) of EU Reg. 2016/679, the personal data collected will be stored in a form that allows the identification of the data subjects for a period of time not exceeding the achievement of the purposes for which the personal data are processed. The retention of data of a personal nature provided depends on the purpose of the processing:
– per richiesta di contatto e informazioni, maximum 1 year;
– processo di candidatura online and personnel selection: maximum 1 year
- for the technical profilesthe data you send concerning your application and curriculum vitae will be kept until 5 years;
- for profiles genericsthe data you send concerning your application and curriculum vitae will be kept until 2 years.
- tax obligations, up to 10 years.
After these terms, the data will be deleted or made anonymous, unless their further retention is necessary to fulfil contractual obligations that have arisen, legal obligations or to comply with orders issued by public authorities.
Nature of data provision
L’utente è libero di fornire i propri dati personali. Il mancato conferimento dei dati può comportare l’impossibilità di ottenere quanto richiesto o di usufruire dei servizi web del Titolare del trattamento.
Recipients of the data or categories of recipients
For the pursuit of the purposes described, or where this is indispensable or required by law or by authorities with the power to impose it, the Data Controller reserves the right to communicate the data to recipients belonging to the following categories:
- subjects that provide services for the management of the information system used by the Data Controller and telecommunications networks, including e-mail and website management;
- the data may also be made known, in connection with the performance of assigned tasks, by the Controller's staff, including workers and consultants, all of whom are specifically authorised to process the data;
- Public Bodies or Public Security Authorities in fulfilment of legal obligations.
Data transfer abroad
Tinexta Defence S.p.A. Società Benefit si impegna a circoscrivere gli ambiti di circolazione e trattamento dei Dati Personali (es. memorizzazione, archiviazione e conservazione dei dati sui propri server) ai Paesi facenti parte dell’Unione Europea, con espresso divieto di trasferirli in paesi extra UE che non garantiscano (o in assenza di) un livello adeguato di tutela, ovvero, in assenza di strumenti di tutela previsti dal Regolamento UE 2016/679 (Paese terzo giudicato adeguato dalla Commissione europea, BCR di gruppo, clausole contrattuali modello, consenso degli interessati, etc.).
Data Dissemination
User data will not be disseminated.
Using Social Networks
Dal sito internet è possibile collegarsi alla pagina aziendale presente su LinkedIn, attraverso la rispettiva icona.
As is well known, social networks autonomously regulate privacy for those who surf, post and communicate through them, being in this case the main data controllers.
You are therefore invited to visit the following links for more information:
However, when the user is on social pages managed by LinkedIn and communicates, in various ways, his or her personal data (e.g. through a private message or by commenting on a post or leaving a review), or when the social network provides certain statistics on the use of the pages in a non-anonymous way (and thus traceable to the activity carried out on the page by the specific person), it is Tinexta Defence S.p.A. Benefit Corporation to become a data controller.
The data processing that is carried out is exclusively for the ordinary administration of the pages (e.g. if a comment is posted in which you insult other users Tinexta Defence S.p.A. Benefit Corporation may decide to remove it from the page as unlawful) and to answer user questions (both public and private) about the characteristics of the products of Tinexta Defence S.p.A. Società Benefit.
In this case, the legal basis for the processing is the legitimate interest of Tinexta Defence S.p.A. Benefit Corporation to propose to the user and illustrate their products and their characteristics, as well as on the need to answer any possible user queries.
The processing of the user's personal data will take place by means of the tools made available by the Social Network itself.
At this stage of simple contact, Tinexta Defence S.p.A. Benefit Corporation will not transfer or disclose the user's personal data to other parties. The user is always free to decide when to remove a like, delete a comment, review, etc., simply by going back to the relevant Social Network page and deleting it directly.
As for private messages, these are kept for a maximum of 6 months after the last contact, after which they are deleted.
L’utente è sempre libero di fornire i propri dati personali. Il mancato conferimento dei dati può comportare l’impossibilità di ottenere quanto richiesto o di usufruire dei servizi del Titolare.
Rights of the data subject
Articles 15, 16, 17, 18, 20, 21 of the GDPR confer on the data subject the exercise of specific rights that may be exercised vis-à-vis the Data Controller.
In particular, as a data subject, you may, under the conditions laid down in the GDPR, exercise the following rights:
- right of access: diritto di ottenere conferma che sia o meno in corso un trattamento di dati personali che La riguardano e, in tal caso, ottenere l’accesso ai Suoi dati personali, compresa una copia degli stessi;
- right of rectificationThe right to have inaccurate personal data concerning you corrected and/or incomplete personal data supplemented;
- right to erasure (right to be forgotten): the right to obtain the deletion of personal data concerning you, if they are no longer necessary for the purposes pursued by the Controller, in case of revocation of your consent (and if there is no other legal basis for the processing) or your objection to the processing, in case of unlawful processing, or if there is a legal obligation to delete.
The right to erasure does not apply insofar as the processing is necessary for the fulfilment of a legal obligation or the performance of a task carried out in the public interest or for the establishment, exercise or defence of legal claims;
- right of restriction of processing: the right to obtain the restriction of processing when: a) the data subject contests the accuracy of the personal data; b) processing is unlawful and the data subject objects to the erasure of the personal data and requests instead that their use be restricted; c) the personal data are necessary for the establishment, exercise or defence of legal claims;
- right to data portabilityThe right to receive, in a structured, commonly used and machine-readable format, the personal data concerning you that you have provided to the Controller and the right to transmit them to another controller without hindrance, where the processing is based on consent and is carried out by automated means;
- right of opposition: the right to object, at any time, to the processing if personal data are processed for purposes other than those for which you have consented to the processing.
Pursuant to Article 77 of the Regulation, you have the right to lodge a complaint with a supervisory authority, namely in the Member State where you habitually reside, work or where the alleged infringement has occurred, which in Italy corresponds to the Italian Data Protection Authority, whose references can be found at www.garanteprivacy.it.
In addition, the GDPR gives you the right to withdraw your consent at any time and as easily as if it had been given.
The exercise of your rights as a data subject is free of charge pursuant to Article 12 GDPR. However, in the case of requests that are manifestly unfounded or excessive, including due to their repetitiveness, the Data Controller may charge you a reasonable fee, in light of the administrative costs incurred in handling your request, or deny satisfaction of your request.
You may exercise your rights by using the attached form which must be sent in hard copy to the Controller's address, or by e-mail or fax to the addresses given in this notice.
This Policy was updated on 2.4.2025
Any updates will always be published on this page.
The Data Controller
Tinexta Defence S.p.A. Benefit Corporation