Privacy Policy
- Information for customers
- Information for suppliers, sole proprietorships, and professionals
- Information for persons working at customers or suppliers
- Information for email recipients
- Cookies and website navigation policy (with traffic analyzers)
- Short cookie policy (site with Analytics)
- Information for those filling out online forms
- Website registration policy
Information for customers
This information is provided to the customers of the Data Controller, pursuant to Art. 13 of GDPR 679/16 – “European General Data Protection Regulation”.
Identity of the Data Controller
The Data Controller for the processing activities indicated below is Farma Idà International Research S.L. with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain), in the person of its legal representative pro tempore.
Source of data
The personal data processed are those provided by the data subject on the occasion of:
- visits or phone calls;
- direct contacts;
- formulation of proposals and quotes;
- transmissions and transactions following the order.
Purposes of processing
Personal data are processed for the execution of the necessary pre-contractual activities, the definition and acceptance of the service agreement regulating the performance, and the correct execution of all planned activities.
In particular, they are processed for the following purposes:
- forwarding communications of various kinds and through different means of communication (telephone, mobile phone, SMS, email, fax, paper mail);
- formulating requests or processing requests and proposals received;
- exchanging information aimed at the execution of the service relationship, including pre- and post-contractual activities;
- managing and monitoring the correct delivery of the service;
- managing the consequent civil and fiscal obligations.
They will also be processed specifically for: Fiscal compliance, organizational management, and bureaucratic compliance of the requested services. Management of negotiations and pre-contractual relationships. Management of commercial activities related to the business activity.
Legal basis for processing
The data collected for the achievement of the indicated purposes are processed lawfully for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Data recipients
The personal data processed by the Controller are not disseminated, meaning they are not disclosed to indeterminate subjects, in any possible form, including making them available or simple consultation. They may, however, be communicated to workers operating under the Controller, to external subjects collaborating with it designated as Data Processors or authorized to process data as they operate under the authority of the Data Controller.
They may also be communicated, within the strictly necessary limits, to subjects who, for the purpose of processing your requests, must provide goods or perform services or tasks on behalf of the Controller. Finally, they may be communicated to subjects entitled to access them by virtue of provisions of law, regulations, and EU regulations.
In particular, based on the roles and work duties performed, workers have been legitimized to process your personal data, within the limits of their competencies and in accordance with the instructions given to them by the Data Controller.
External subjects operating under the authority of the Controller have also been appropriately authorized based on the type of service provided, the processing carried out, and the nature of the processed data.
External subjects to whom the Controller has entrusted a processing of personal data have been designated as Data Processors.
Data transfer
The Data Controller does not transfer personal data to third countries or international organizations. It reserves the right to use cloud services; in which case, the service providers will be selected from those who provide adequate guarantees, as provided for by Art. 46 GDPR 679/16.
Data retention
The Data Controller stores and processes personal data for the time necessary to fulfill the indicated purposes. Specifically, customer data is stored until administrative prescription.
Rights of the data subject
With reference to Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, the data subject exercises their rights by writing to the Data Controller at the address above, or via email, specifying the subject of their request, the right they intend to exercise, and attaching a photocopy of an identity document attesting to the legitimacy of the request.
The Controller specifically reminds that every data subject may exercise the right to object in the forms and ways provided for by Art. 21 GDPR.
Withdrawal of consent
With reference to Art. 7 of GDPR 679/16, the data subject can withdraw any consent given at any time. However, the processing covered by this policy is lawful and permitted, even in the absence of consent, as it is necessary for the performance of a contract to which the data subject is party (the supply relationship of products and services).
Refusal to provide data
The data subject cannot refuse to provide the Controller with their personal data necessary for the civil and fiscal obligations connected with the supply or performance.
The provision of further personal data, while optional, is necessary for a correct and efficient management of the contractual relationship. Therefore, any refusal to provide such data may compromise the contractual relationship in whole or in part.
Automated decision-making processes
In no case, regarding the processing indicated below, does the Controller carry out processing consisting of automated decision-making processes on the data of natural persons.
Information for suppliers, sole proprietorships, and professionals
This information is provided to sole proprietorships and professional suppliers of the Controller in any capacity, pursuant to Art. 13 of GDPR 679/16 – “European General Data Protection Regulation”.
Identity of the Data Controller
The Data Controller for the processing activities indicated below is Farma Idà International Research S.L. with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain), in the person of its legal representative pro tempore.
Source of data
The personal data processed are those provided by the data subject on the occasion of:
- visits or phone calls;
- direct contacts;
- proposal of offers;
- transmissions and transactions following the order.
Purposes of processing
Personal data are processed for the execution of the necessary pre-contractual activities, the drafting and signing of the service contract regulating the performance or supply, and the correct execution of all activities provided for by the contract.
In particular, they are processed for the following purposes:
- forwarding communications of various kinds and through different means of communication (telephone, mobile phone, SMS, email, fax, paper mail);
- formulating requests or processing requests and proposals received;
- exchanging information aimed at the execution of the contractual relationship, including pre- and post-contractual activities;
- managing and monitoring the correct processing of orders;
- managing the consequent civil and fiscal obligations.
Legal basis for processing
The data collected for the achievement of the indicated purposes are processed lawfully for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Data recipients
The personal data processed by the Controller are not disseminated, meaning they are not disclosed to indeterminate subjects, in any possible form, including making them available or simple consultation. They may, however, be communicated to workers operating under the Controller, to external subjects collaborating with it designated as Data Processors or authorized to process data as they operate under the authority of the Data Controller.
They may also be communicated, within the strictly necessary limits, to subjects who, for the purpose of processing your requests, must provide goods or perform services or tasks on behalf of the Controller. Finally, they may be communicated to subjects entitled to access them by virtue of provisions of law, regulations, and EU regulations.
In particular, based on the roles and work duties performed, workers have been legitimized to process your personal data, within the limits of their competencies and in accordance with the instructions given to them by the Data Controller.
External subjects operating under the authority of the Controller have also been appropriately authorized based on the type of service provided, the processing carried out, and the nature of the processed data.
External subjects to whom the Controller has entrusted a processing of personal data have been designated as Data Processors.
Data transfer
The Data Controller does not transfer personal data to third countries or international organizations. It reserves the right to use cloud services; in which case, the service providers will be selected from those who provide adequate guarantees, as provided for by Art. 46 GDPR 679/16.
Data retention
The Data Controller stores and processes personal data for the time necessary to fulfill the indicated purposes. Specifically, data of suppliers, sole proprietorships, and professionals are stored until administrative prescription.
Rights of the data subject
With reference to Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, the data subject exercises their rights by writing to the Data Controller at the address above, or via email, specifying the subject of their request, the right they intend to exercise, and attaching a photocopy of an identity document attesting to the legitimacy of the request.
The Controller specifically reminds that every data subject may exercise the right to object in the forms and ways provided for by Art. 21 GDPR.
Withdrawal of consent
With reference to Art. 7 of GDPR 679/16, the data subject can withdraw any consent given at any time. However, the processing covered by this policy is lawful and permitted, even in the absence of consent, as it is necessary for the performance of a contract to which the data subject is party (the supply relationship of products and services).
Refusal to provide data
The data subject cannot refuse to provide the Controller with their personal data necessary for the civil and fiscal obligations connected with the supply or performance.
The provision of further personal data, while optional, is necessary for a correct and efficient management of the contractual relationship. Therefore, any refusal to provide such data may compromise the contractual relationship in whole or in part.
Automated decision-making processes
In no case, regarding the processing indicated below, does the Controller carry out processing consisting of automated decision-making processes on the data of natural persons.
Information for persons operating at customers or suppliers
The management of the contractual relationship with customers and suppliers who are legal entities necessarily involves the processing of personal data (identification data, telephone numbers, emails) relating to the persons with whom contact is made. This information is therefore provided pursuant to Art. 13 of GDPR 679/16 – “European General Data Protection Regulation” to natural persons operating at customers and suppliers. Given the difficulty of providing it directly to the data subjects, the information is made available to them on the Data Controller’s website, with a request to notify the data subjects.
Identity of the Data Controller
The Data Controller for the processing activities indicated below is Farma Idà International Research S.L. with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain), in the person of its legal representative pro tempore.
Source of data
The personal data processed are those provided by the data subject on the occasion of:
- visits or phone calls;
- direct contacts;
- receipt/proposal of offers;
- transmissions and transactions following the order.
Purposes of processing
The personal data of the natural contact persons are processed to:
- forward communications of various kinds and through different means of communication (telephone, mobile phone, SMS, email, fax, paper mail);
- formulate requests or process requests and proposals received;
- exchange information aimed at the execution of the contractual relationship, including pre- and post-contractual activities.
Legal basis for processing
The legal basis consists of the need to follow up on pre-contractual, contractual, and post-contractual obligations.
Data recipients
The personal data processed by the Controller are not disseminated, meaning they are not disclosed to indeterminate subjects, in any possible form, including making them available or simple consultation. They may, however, be communicated to workers operating under the Controller, to external subjects collaborating with it designated as Data Processors or authorized to process data as they operate under the authority of the Data Controller.
They may also be communicated, within the strictly necessary limits, to subjects who, for the purpose of processing your requests, must provide goods or perform services or tasks on behalf of the Controller. Finally, they may be communicated to subjects entitled to access them by virtue of provisions of law, regulations, and EU regulations.
In particular, based on the roles and work duties performed, workers have been legitimized to process your personal data, within the limits of their competencies and in accordance with the instructions given to them by the Data Controller.
External subjects operating under the authority of the Controller have also been appropriately authorized based on the type of service provided, the processing carried out, and the nature of the processed data.
External subjects to whom the Controller has entrusted a processing of personal data have been designated as Data Processors.
Data transfer
The Data Controller does not transfer personal data to third countries or international organizations. It reserves the right to use cloud services; in which case, the service providers will be selected from those who provide adequate guarantees, as provided for by Art. 46 GDPR 679/16.
Data retention
The Data Controller stores and processes personal data for the time necessary to fulfill the indicated purposes. Specifically, the data of contact persons are stored for two years following the termination of the job function or employment relationship with their employer.
Rights of the data subject
With reference to Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, the data subject exercises their rights by writing to the Data Controller at the address above, or via email, specifying the subject of their request, the right they intend to exercise, and attaching a photocopy of an identity document attesting to the legitimacy of the request.
The Controller specifically reminds that every data subject may exercise the right to object in the forms and ways provided for by Art. 21 GDPR.
Withdrawal of consent
With reference to Art. 7 of GDPR 679/16, the data subject can withdraw any consent given at any time. However, the processing covered by this policy is lawful and permitted, even in the absence of consent, as it is necessary for the performance of a contract to which the data subject is party (the supply relationship of products and services).
Refusal to provide data
The data subject can refuse to provide the Controller with their personal data.
However, the provision of personal data is necessary for a correct and efficient management of the contractual relationship. Therefore, any refusal to provide such data may compromise the contractual relationship in whole or in part.
Automated decision-making processes
In no case, regarding the processing indicated below, does the Controller carry out processing consisting of automated decision-making processes on the data of natural persons.
Information for email recipients
The content of e-mails is to be considered confidential. Therefore, the information contained in them or in any attachments is reserved exclusively for the recipients. Persons or subjects other than the recipients themselves, also pursuant to Art. 616 of the Criminal Code, are not authorized to read, copy, modify, or disseminate the message to third parties. Anyone who receives a communication from us by mistake should not use it and should not bring it to anyone’s attention, but delete it from their mailbox and notify the sender. The authenticity of the sender and the contents are not guaranteed, with the exception of digitally signed documents.
Furthermore, pursuant to Art. 13 of GDPR 679/16, we inform you that our archives include email addresses relating to natural persons, companies, and entities with whom previous communications have taken place via email, or by other means of communication, or who have spontaneously provided their email address on the occasion of direct contacts. Such addresses are used by us in compliance with the will and willingness of the data subjects to receive communications via email from our company. We also inform you that all mailboxes of the domain “…..@farmaidainternational.es” are corporate mailboxes and, as such, are used for work-related communications. Therefore, for needs connected with operational activity, any message, both outgoing and incoming, could be read by subjects other than the sender and/or the recipient.
In the event that the data subjects wish their email address to be removed from our archive, or for the exercise of the rights referred to in Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, they can write to the Data Controller identified in the legal representative pro tempore of the company Farma Idà International Research S.L. with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain).
Cookies and website navigation policy
(with traffic analyzers)
This information is provided to natural persons who access and consult the website of Farma Idà International Research S.L., pursuant to Art. 13 of GDPR 679/16 – “European General Data Protection Regulation”.
Identity of the Data Controller
This WEB site is managed by Farma Idà International Research S.L. in the person of its legal representative pro tempore, Data Controller with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain). The Data Controller guarantees the security, confidentiality, and protection of the personal data in their possession, at any stage of the data processing process. The personal data collected are used in compliance with GDPR 679/16.
Purposes of processing
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users who connect to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error ..) and other parameters relating to the operating system and the user’s IT environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning and are deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site.
Legal basis for processing
The use of technical cookies is a processing carried out in the legitimate interest of the Controller; the use of analytical cookies is carried out with the consent of the data subject.
Data recipients
The Data Controller does not communicate any personal identification data or information to third parties unless, possibly and as strictly necessary, to those who intervene as suppliers for the provision of services inherent to the management of the website and for the consequent management of the contractual relationship and related administrative obligations.
Data transfer
The Data Controller does not transfer personal data to third countries or international organizations.
Data retention
The Data Controller retains data for the time necessary to obtain anonymous statistical information on the use of the site and to check its correct functioning. The data are deleted immediately after processing.
Rights of the data subject
With reference to Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, the data subject exercises their rights by writing to the Data Controller at the address above, or via email, specifying the subject of their request, the right they intend to exercise, and attaching a photocopy of an identity document attesting to the legitimacy of the request.
Withdrawal of consent
With reference to Art. 7 of GDPR 679/16, the data subject can withdraw consent at any time.
Lodging a complaint
The data subject has the right to lodge a complaint with the supervisory authority of the state of residence.
Refusal to provide data
The data subject can refuse to provide the Controller with their navigation data. To do this, they must disable cookies by following the instructions provided by the browser in use. Disabling cookies may worsen navigation and the use of the site’s features.
Automated decision-making processes
The Controller does not carry out processing consisting of automated decision-making processes.
Types of Cookies
Cookies are information placed on the user’s browser when they visit a website or use a social network with their PC, smartphone, or tablet. Each cookie contains different data such as, for example, the name of the server it comes from, a numerical identifier, etc. Cookies can remain in the system for the duration of a session (i.e., until the browser used for web browsing is closed) or for long periods and can contain a unique identification code.
Technical cookies
Some cookies are used to perform computer authentication, session monitoring, and storage of specific information about users accessing a web page. These cookies, so-called technical cookies, are often useful because they can make web browsing and use faster and quicker, because for example they intervene to facilitate some procedures when you make online purchases, when you authenticate to restricted access areas, or when a website automatically recognizes the language you usually use. A particular type of cookie, called analytics, are then used by website managers to collect information, in aggregate form, on the number of users and on how they visit the site itself, and then process general statistics on the service and its use.
Profiling cookies
Other cookies can instead be used to monitor and profile users during browsing, study their movements and habits of web consultation or consumption (what they buy, what they read, etc.), also for the purpose of sending advertising of targeted and personalized services (so-called Behavioural Advertising). We speak in this case of profiling cookies. It may happen that a web page contains cookies from other sites and contained in various elements hosted on the page itself, such as advertising banners, images, videos, etc. These are so-called third-party cookies, which are usually used for profiling purposes. Given the particular invasiveness that profiling cookies (especially third-party ones) can have within the private sphere of users, European and Italian legislation provide that the user must be adequately informed about the use of the same and express their valid consent to the insertion of cookies on their terminal.
Cookies used
The site https://www.pernalife.com/en uses cookies to make the site’s services simpler and more efficient for the user viewing the web pages. Users accessing the site will receive very small amounts of information in their devices in use, whether they are computers or mobile devices, in the form of small text files, the “cookies” precisely, stored in the directories used by their browser. The cookies used by https://www.pernalife.com/en allow to:
- store browsing preferences,
- avoid re-entering the same information multiple times,
- analyze the use of services and content provided by the site to optimize the browsing experience.
The site https://www.pernalife.com/en/ uses Google Analytics or ShinyStat. In this case, the information generated by the cookie on the use of the site is transmitted to Google Inc. or to Triboo Data Analytics srl and deposited on their servers. These data recipients use this information for the purpose of producing reports on site activities, intended for the Controller or subjects appointed by it. It is possible to refuse the provision of navigation data by selecting the appropriate setting on the browser. In this regard, please refer to the policies published on the Google site https://www.google.it/intl/en/policies/privacy/ and to the browser add-on for deactivating Google Analytics https://tools.google.com/dlpage/gaoptout?hl=en or to https://www.shinystat.com/it/informativa_privacy_generale_app.html.
However, this choice could prevent you from using all the features of the site. On the contrary, by accepting the use of cookies as described above and continuing navigation, the user gives free and unconditional consent to the processing of personal data by the Committee and by Google or Inc. Triboo Data Analytics srl with the methods and for the purposes indicated above. From the moment the user clicks on any icons of Facebook, Twitter, YouTube, Instagram etc., they are directed to the respective sites and receive cookies from them that are not under the control of the Controller. Finally, if the user arrives on the site after clicking on a banner published on another site, they must know that the advertising network manager has assigned cookies necessary to detect the throughput and the amount of any purchases made. The responsibility for the management of these cookies lies with the advertising network manager whose policy is normally available on their institutional site.
Short cookie policy
(site with Analytics)
This site does not use profiling cookies, neither its own nor from other sites. Technical cookies are used to allow you easier use of some site features and Google Analytics (or ShinyStat or other web traffic analyzers) to improve site functionality. Detailed information on browsing this site can be consulted by pressing the “privacy policy” button. By following the links in the policy, you can learn how to deactivate Google Analytics (or ShinyStat or other web traffic analyzers). Detailed information on browsing this site can be consulted by pressing the “privacy policy” button. To deactivate technical cookies, follow the instructions of the browser in use. By pressing the “OK” button, you explicitly express consent to the use of the indicated cookies and the communication of navigation data to third parties (Google, ShinyStat, or others).
Information for those filling out online forms
Identity of the Data Controller
The Data Controller for the processing activities indicated below is Farma Idà International Research S.L. with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain), in the person of its legal representative pro tempore.
Source of data and type of data collected
The personal data processed are those provided by filling out the form, possibly integrated with data derived from public lists or already known, ensuring, in any case, the consistency of the processing.
Purposes of processing
Personal data are processed to process requests made by filling out online forms. Furthermore, the data, including email addresses, will be entered into the archives and used (also seeing the General Provision of the Guarantor G.U. 1st July 2008 n° 188/C, formulation 6, points a, b, c) for sending, also via email, technical, promotional, and commercial communications concerning products and services similar to those for which the requests were made.
Legal basis for processing
The legal basis for the processing consists of the execution of a contract to which the data subject is party, or the processing of their requests.
Data recipients
The personal data processed by the Controller are not disseminated, meaning they are not disclosed to indeterminate subjects, in any possible form, including making them available or simple consultation. They may, however, be communicated to workers operating under the Controller, to external subjects collaborating with it designated as Data Processors or authorized to process data as they operate under the authority of the Data Controller.
They may also be communicated, within the strictly necessary limits, to subjects who, for the purpose of processing your requests, must provide goods or perform services or tasks on behalf of the Controller. Finally, they may be communicated to subjects entitled to access them by virtue of provisions of law, regulations, and EU regulations.
In particular, based on the roles and work duties performed, workers have been legitimized to process your personal data, within the limits of their competencies and in accordance with the instructions given to them by the Data Controller.
External subjects operating under the authority of the Controller have also been appropriately authorized based on the type of service provided, the processing carried out, and the nature of the processed data.
External subjects to whom the Controller has entrusted a processing of personal data have been designated as Data Processors.
Data transfer
In no case does the Data Controller transfer personal data to third countries or international organizations.
However, it reserves the right to use cloud services; in which case, the service providers will be selected from those who provide adequate guarantees, as provided for by Art. 46 GDPR 679/16.
Data retention
The Data Controller stores and processes personal data for the time necessary to fulfill the indicated purposes. Specifically, data entered in online forms are stored for two years.
Refusal to provide data
The data subject can refuse to provide the Controller with their data.
However, failure to provide data could compromise or make impossible the response or processing of requests.
Rights of the data subject
With reference to Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, the data subject exercises their rights by writing to the Data Controller at the address above, or via email, specifying the subject of their request, the right they intend to exercise, and attaching a photocopy of an identity document attesting to the legitimacy of the request.
The Controller specifically reminds that every data subject may exercise the right to object in the forms and ways provided for by Art. 21 GDPR.
Withdrawal of consent
With reference to Art. 7 of GDPR 679/16, the data subject can withdraw any consent given at any time.
However, the processing covered by this policy is lawful and permitted, even in the absence of consent, as it is necessary for the performance of a contract to which the data subject is party, or for the processing of their requests.
Lodging a complaint
The data subject has the right to lodge a complaint with the supervisory authority of the state of residence.
Automated decision-making processes
In no case, regarding the processing indicated below, does the Controller carry out processing consisting of automated decision-making processes on the data of natural persons.
Website registration policy
This information is provided to natural persons who access and consult the website of Farma Idà International Research S.L., pursuant to Art. 13 of the GDPR 679/16 – “European General Data Protection Regulation”.
Identity of the Data Controller
This WEB site is managed by Farma Idà International Research S.L. in the person of its legal representative pro tempore, Data Controller with registered office at Plaza Alfonso el Magnánimo 3 4B – 46003 Valencia (Spain). The Data Controller guarantees the security, confidentiality, and protection of the personal data in their possession, at any stage of the data processing process. The personal data collected are used in compliance with GDPR 679/16.
Data subjects
This information is provided to natural persons who fill out the online registration form proposed by the site of Farma Idà International Research S.L.
Purposes of processing
The personal data of natural persons who have filled out the online registration form are processed for the following purposes: Registration in order to be able to make online purchases.
Legal basis for processing
The personal data of natural persons who fill out the online registration form are lawfully processed based on the following conditions:
- execution of a contract to which the data subject is party or execution of pre-contractual measures adopted at the request of the same (the free request for registration);
- pursuit of the legitimate interest of the data controller (promotion of commercial activity and pursuit of statutory purposes);
- acquisition of consent.
Data recipients
The personal data processed by the Controller will not be disseminated, meaning they will not be disclosed to indeterminate subjects, in any possible form, including making them available or simple consultation. They may be communicated, within the strictly necessary limits, to subjects who, for the purpose of processing your request, must provide goods and/or perform services or tasks on our behalf. Finally, they may be communicated to subjects entitled to access them by virtue of provisions of law, regulations, and EU regulations.
In particular, based on the roles and work duties performed, some workers of Farma Idà International Research S.L. have been legitimized to process personal data, within the limits of their competencies and in accordance with the instructions given to them by the Controller.
Data transfer
The Data Controller does not transfer personal data to third countries or international organizations.
However, it reserves the right to use cloud services; in which case, the service providers will be selected from those who provide adequate guarantees, as provided for by Art. 46 GDPR 679/16.
Data retention
The Data Controller stores and processes personal data for the time necessary to fulfill the indicated purposes. Subsequently, they will only be stored for the time established by the provisions in force on the matter.
Rights of the data subject
With reference to Artt. 15 – right of access, 16 – right to rectification, 17 – right to erasure, 18 – right to restriction of processing, 20 – right to data portability, 21 – right to object, 22 – right to object to automated individual decision-making of the GDPR 679/16, the data subject exercises their rights by writing to the Data Controller at the address above, or via email, specifying the subject of their request, the right they intend to exercise, and attaching a photocopy of an identity document attesting to the legitimacy of the request.
Withdrawal of consent
With reference to Art. 7 of GDPR 679/16, the data subject can withdraw consent at any time.
Lodging a complaint
The data subject has the right to lodge a complaint with the supervisory authority of the state of residence.
Refusal to provide data
The data subject can refuse to provide the Controller with their personal data as the provision is optional.
However, filling in the fields indicated as mandatory is essential to register and have access to the reserved area. Any refusal to provide such data will therefore block the registration.
Automated decision-making processes
The Controller does not carry out processing consisting of automated decision-making processes.
