You are using an outdated browser. For a faster, safer browsing experience, upgrade for free today.

Aegis UK - Privacy Policy

FOR CLIENTS top

INFORMATION NOTICE PURSUANT TO SECTIONS 13 AND 14 GDPR


Dear Data Subject,
In accordance with the provision set forth by the European Regulation 2016/679 of the EU Parliament and of the Counsel dated April 27, 2016, concerning the protection of natural persons with regard to processing of personal data (hereinafter, the “GDPR” or the “Regulation”), Aegis S.r.l., having its legal offices in Milan, via Settala 10, 20124, VAT number 03516140963, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative as controller of your personal data (hereinafter, the “Controller”), and, where applicable, Aegis UK – Recruiting & Consulting Ltd. having its legal offices in 21 Lombard Street, EC3V 9AH - London, United Kingdom, VAT number 255 7676 63, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative as processor of your personal data, provide you with the present information notice, pursuant to Sections 13 and 14, GDPR, in relation to the processing of your personal data communicated to us by you or by third parties (hereinafter, the “Information Notice”).


1. Identity and Contact details of the Controller
Aegis S.r.l., having its legal offices in Milan, via Settala 10, 20124, VAT number 03516140963, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative
2. Purposes of the processing for which the personal data are intended and related legal basis
Personal data will be processed:
(i) without your consent (Section 6, items b, c, f, GDPR), for the following purposes:
a) performance of pre-contractual and contractual obligations deriving from the execution of a possible contract (service provision);
b) compliance with legal obligations, as provided for by a regulation or a law (national or EU), or perform an order of public or judicial Authority or controlling Authority to which the Controller is subject;
c) exercise the rights of the Controller, with particular reference to judicial defensive rights.

(ii) with your consent (Section 7, GDPR), for the following purposes:
a) marketing, promotional events and commercial and/or professional activities;
b) organization of events of promotional nature;
c) distribution of information / promotional materials, sending out of commercial newsletters and publications;
d) management of surveys and customers’ satisfaction questionnaires;
e) storage of information related to these activities

For the purposes under par. (i) above, the collection of your personal data is necessary. Any express refusal of consent to process such data, may cause the impossibility to the Controller to perform the contractual services and to comply with obligations to which the Controller is subject.

For the purposes under par. (ii) above, the collection of your personal data is made on voluntary basis; consequently, you may decide not to provide us with any consent or to waive it in any moment.

3. Processed Categories of Personal Data
Pursuant to Section 4, n. 1, GDPR, for “personal data” and within the purposes of processes mentioned under par. 2) above, we shall exclusively process those personal data concerning, by way of example, your name and family name, tax code, date of birth, VAT number, residence, domicile, number of passport and/or ID, work address, email, certified email address, phone and fax numbers, and, possibly, employer company, business role and/or position.

Pursuant to principle of “data minimization” stated by section 5, n.1, GDPR, you will not to send your personal data to the Controller, except where personal data are strictly necessary to perform contractual and / or commercial activities. In such a case, personal data should be transferred to the Controller anonymously or under pseudonyms, as expressly stated by GDPR.
Should it be necessary to process more data in addition to the ones of legal representative and/or contact persons, for the purpose of executing contractual relationship with a customer (legal entity, hereinafter, the “Client”), and if these personal data could not be obtained in anonymous form or under pseudonyms, the Client declares and guarantees that the processing of personal data will be in compliance with GDPR for all data that will be communicated to the Controller during the performance of the contract. In particular, the Client declares that it has been provided to any Data Subject an adequate information notice in which it is expressly mentioned the possibility to provide personal data to third entities and to have obtained the necessary consents for the purpose.
The Client undertakes to indicate to its employees and/or collaborators that the present Information Notice is also available on the website www.aegishcgroup.com, so that the Information Notice can be provided by the Controller to the data subject, pursuant to Sections 13 and 14, GDPR.

4. Categories of Personal Data Recipients
Your personal data you will submit to us for the purposes mentioned under par. 2, above, could be transferred to:

(i) employees and collaborators of the Controller or other entities belonging to the same companies’ group to which the Controller is party thereof (Aegis UK), in their capacity of persons authorized or data processors;
(ii) any third party (such as provider for management and maintenance of website, providers, credit institutions, professional firms), performing outsourced activities on behalf of the Controller, in their capacity of data processors;
(iii) any judicial or controlling Authority, public entities (whether national or foreign ones);
The updated list of Processors and persons who are authorized to process personal data is available by Controller’s seat.

5. Storage and Transfer of Personal Data to Third Countries
Your personal data will be processed, managed and stored on servers located within EU, and, unless are fulfilled specific requirements, they will not be transferred to non EU-countries.
Should it be necessary to use third party’s activities which have their seats outside EU-countries, we inform you, here and now, that:
- the Controller has arranged to appoint these subjects as data processors pursuant to Section 28, Regulation and
- The transfer of your personal data to these subjects is performed in strict compliance with provisions of Section 44 et seq of the Regulation.

This ensure you that will be adopted all necessary measures to guarantee you the complete personal data protection, because the transfer will be based on standard contractual clauses or other legal basis drafted to safeguard your rights and interests.

Your personal data will not subject to dissemination.

6. Personal Data Storage Period
Your personal data provided for the purposes indicated under par. 2, section (i) above, are processed and stored for the entire duration of the executed contract; as of the termination of such contractual relationship, for whichever reason or cause, personal data will be stored as long as time-barring legal terms will be elapsed.
Personal data provided for the purposes indicated under par. (2), section (ii) above, are processed and stored for the time necessary for the performance of the same purposes and, anyhow, no later than 5 years from the date in which the Controller will receive the consent of the data subject.

7. Exercisable Rights
In compliance with the provisions under Chapter III, Section I, GDPR, you may exercise the rights therein indicated and in particular:
(i) right of access;
(ii) obtain the rectification or the erasure of personal data or the limitation to processing from Controller. In case of the request of erasure, the data subject has the right to obtain that Controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data;
(iii) right to object to the processing of personal data;
(iv) right to data portability;
(v) right to withdraw the consent at any time; the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal;
(vi) right to lodge a complaint with the Supervisory Authority.

You may exercise such rights by means of a request to be sent by email to the following certified email address: privacy@aegishcgroup.com

8. Processing Operations
Your personal data are processed through the operations indicated in section 4, n.2), GDPR. Performed by not automated means – in particular: collection, recording, organization, structuring, update, storage, adaptation or alteration, retrieval and analysis, consultation, use, disclosure by transmission, alignment or combination, restriction, erasure or destruction of data.
Personal Data of data subject will be processed through traditional (modules, forms, etc.) or computer tools.
Whichever the way, it will guaranteed their security, logical and physical, and overall their confidentiality.



FOR CANDIDATES top

 

Privacy notice for the acquisition of CV and information about candidates (by web site or other means) pursuant to Section 13, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data (hereinafter, respectively, the “Information Notice” and the “Regulation” or the “GDPR”)

In accordance with the provision set forth by the Regulation, Aegis S.r.l., having its legal offices in Milan, via Settala 10, 20124, VAT number 03516140963, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative as controller of your personal data (hereinafter, the “Controller”), and, where applicable, Aegis UK – Recruiting & Consulting Ltd. having its legal offices in 21 Lombard Street, EC3V 9AH - London, United Kingdom, VAT number 255 7676 63, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative as processor of your personal data provides you with the present information notice, pursuant to Section 13, GDPR, in relation to the processing of your personal data communicated to us by you or by third parties.


1. Identity and Contact details of the Controller
Aegis S.r.l., in person of its pro tempore legal representative, having its legal offices in Milan, via Settala 10 20124, VAT number 03516140963, certified e-mail address: aegishr@legalmail.it (hereinafter, the “Controller”).
2. Purposes of the processing for which the personal data are intended and related legal basis
Your personal data will be processed:
(i) without your consent (Section 6, items b, c, f, GDPR), for the following purposes:
- personnel recruitment and selection, for open or future job positions, to be included in the organization of companies or other entities for which the Controller operates;
- compliance with legal obligations, as provided for by a law (Italian or UE), collective labor agreement or other binding legal provisions (in particular, on tax, social security, health and safety at work, public order and security);
(ii) with your consent (Section 7, GDPR)
- communication of your personal data, including special categories of personal data pursuant to Sections 9 and 10, GDPR, in addition to those belonging to sheltered group that are eventually provided by the data subject to third party which make use of the Controller’s services, for the personnel recruitment and selection;
The transfer of personal data for the purposes indicated above under sec. (i) will be compulsory. Any lack of the data and/or any express refusal of consent to process such data, may cause the impossibility to the Controller to perform the selection process and to comply with obligation related to management of potential employment relationship.

The transfer of personal data for the purposes indicated above under sec. (ii) will be on voluntary basis; consequently you may decide to not provide any consent or to waive it in any moment. With reference to such case, the Controller will not perform, however, most of the services that normally provides to the candidates.

3. Processed Categories of Personal Data
Pursuant to Section 4, no. 1, GDPR, with “personal data” we mean any information relating to a natural person, identified or identifiable, directly or indirectly, by reference to an identifier such as a name, an identification company number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the natural person- that was collected by the Controller, with regard to the candidates.
In order to reach the abovementioned purposes of the data processing, pursuant to principle of “data minimization” in accordance with Section 5, no 1, items c), GDPR, there is no need for the Controller to process yours or, if necessary, your family members special categories of personal data, as defined by Sections 9 and 10, GDPR (hereinafter, the “Data”), except the only confidential data relating to the belonging or not to sheltered group. Therefore, we invite you not to send to the Controller any additional personal data, if those data are not necessary to perform the selection process; if you send such data, the Controller will have the power to remove and/or obscure them, and, in any case, not to process those data for any purposes indicated above under par. 2.
We highlight that this potential personal data processing will also take place in compliance with Section 8, Workers’ Statute (Law no. 300/1970 and further adjustments and integrations), which sets forth the obligation of the employer, for the purpose of recruitment and during the employment relationship, to avoid to conduct any investigation about employees’ political, religious or trade-unions opinion, as well as about any circumstance not relevant for the evaluation of professional skills.

4. Categories of Personal Data Recipients
The personal data you will submit to us for the purposes mentioned under par. 2, above, could be transferred to:

(i) Employees and collaborators of the Controller and / or other entities belonging to the same companies’ group to which the Controller is party thereof (Aegis UK), in their capacity of persons authorized to process personal data or data processor: in particular, with reference to activities relating to management of staff and administrative aspects, your personal data will be process by subjects expressly authorized by the Controller;
(ii) Professionals and professional offices empowered by the Controller, eventually, banks and companies specialized in handling of payments, law and consulting firm, service companies;
(iii) Public authorities for legal requirements and supervisory purposes, public administrations, public entities (national and UE).

The updated list of processors and persons who are authorized to process personal data is available at Controller’s offices.

5. Processing operations
The processing of personal data of the Employee is realized through the operations indicated in section 4, n. 2, GDPR – whether or not by automated means – and in particular: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, alignment or combination, restriction, erasure or destruction of data.

Personal data will be processed and stored through traditional (form, questionnaire, etc.) or computer tools. Whichever the way, it will be guaranteed data security, logical and physical, and overall data confidentiality.

6. Transfer of Personal Data to Third Countries
Your personal data will be processed, managed and stored on servers located within EU, and, unless are fulfilled specific requirements, they will not be transferred to non-EU-countries.

Should it be necessary to use third party’s activities which have their seats outside EU-countries, we inform you, here and now, that:
- the Controller has arranged to appoint these subjects as data processors pursuant to Section 28, Regulation and
- The transfer of your personal data to these subjects is performed in strict compliance with provisions of Section 44 et seq of the Regulation.

This ensure you that will be adopted all necessary measures to guarantee you the complete personal data protection, because the transfer will be based on standard contractual clauses or other legal basis drafted to safeguard your rights and interests.

Your personal data will not subject to dissemination.

7. Personal Data Storage Period
Your personal data will be stored no later than 5 years from the date in which the Controller will receive the last update of your consent.

8. Exercisable Rights
In compliance with the provisions under Chapter III, Section I, GDPR, you in your quality of data subject, may exercise the rights therein indicated, and in particular:
(i) right of access;
(ii) right to obtain the rectification or the erasure of personal data or the limitation to processing from Controller. In case of the request of erasure, the data subject has the right to obtain that Controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data;
(i) right to object to the processing of personal data;
(ii) right to data portability;
(iii) right to withdraw the consent at any time; the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal;
(iv) right to lodge a complaint with the Supervisory Authority.

The data subject may exercise such rights by means of a request to be sent by email to the following email address: privacy@aegishcgroup.com

 

 

 

 

FOR SUPPLIERS top

 

INFORMATION NOTICE PURSUANT TO SECTIONS 13 AND 14 GDPR

Dear Data Subject,
In accordance with the provision set forth by the European Regulation 2016/679 of the EU Parliament and of the Counsel dated April 27, 2016, concerning the protection of natural persons with regard to processing of personal data (hereinafter, the “GDPR” or the “Regulation”), Aegis S.r.l., having its legal offices in Milan, via Settala 10, 20124, VAT number 03516140963, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative as controller of your personal data (hereinafter, “Aegis” or the “Controller”), and, where applicable, Aegis UK – Recruiting & Consulting Ltd. having its legal offices in 21 Lombard Street, EC3V 9AH - London, United Kingdom, VAT number 255 7676 63, certified e-mail address: aegishr@legalmail.it, in person of its pro tempore legal representative as processor of your personal data, provide you with the present information notice, pursuant to Sections 13 and 14, GDPR, in relation to the processing of your personal data communicated to us by you or by third parties (hereinafter, the “Information Notice”).
Your personal data will be processed to the following condition.
a) Identity and Contact details of the Controller

Aegis S.r.l., in person of its pro tempore legal representative, having its legal offices in Milan, via Settala 10, 20124, VAT number 03516140963, email address: privacy@aegishcgroup.com, certified e-mail address: aegishr@legalmail.it,
b) Purposes of the processing for which the personal data are intended and related legal basis

Your personal data will be processed without your consent (pursuant to section 6, items b, c, f, GDPR), for the following purposes:

• performance of pre-contractual and contractual obligations deriving from the execution of the contract between you and the Controller;
• compliance with provisions of a law or a regulation (national or EU), or perform an order of public or judicial Authority or controlling Authority to which the Controller is subject;
• exercise the rights of the Controller, with particular reference to judicial defensive rights.

For the purposes above mentioned, the collection of your personal data is necessary. Any lack of the data and/or possible express refusal to process such data, may cause the impossibility to the Controller to perform the contractual services or the possible violation of requests of the controlling Authority.

 

c) Processed Categories of Personal Data

Pursuant to Section 4, no. 1, GDPR, the “personal data” which may be processed by the Controller, for the above purposes, concerning, by way of example, name and family name, tax code, copy of ID, VAT number, residence, domicile, work address, email or certified email address, phone and fax numbers and, eventually, bank, financial or insurance data, etc.

You will not to send your personal data to the Controller, except where personal data are strictly necessary to perform contractual and / or commercial activities. In all other cases, personal data should be transferred to the Controller anonymously or under pseudonyms, pursuant to principle of “data minimization” as stated by Section 5, par. 1, GDPR.
In the event that, during the performance of the contractual relationship, the supplier (legal entity, hereinafter, the “Supplier”), communicate to the Controller (not anonymously or not under pseudonyms) more data in addition to the ones of legal representative and/or contact persons, the same Supplier declares and guarantees to process all above personal data lawfully and in compliance with GDPR, furthermore, the Supplier declares that it has been provided to any Data Subject an adequate information notice, in which it is expressly mentioned the possibility to provide personal data to third entities and to have obtained the necessary consents for the purpose. Furthermore, the Supplier undertakes to indicate to its employees and/or collaborators that the present Information Notice is available on the website www.aegishcgroup.com, so that the Information Notice can be provided by the Controller to the data subject, pursuant to Sections 13 and 14, GDPR.
d) Categories of Personal Data Recipients
For the purposes mentioned under par. 2 above, the personal data you will submit could be transferred to:

1) employees and collaborators of the Controller or other entities belonging to the same companies’ group to which the Controller is party thereof (Aegis UK), in their capacity of person authorized to process personal data;
2) any third party (such as provider for management and maintenance of website and/or management information systems, providers, credit institutions, professional companies, etc.), performing outsourced activities on behalf of the Controller, in their capacity of data processors;
3) controlling Authority, public entities and institutions (whether national or foreign ones).

e) Storage and Transfer of Personal Data to Third Countries
The Controller declares that the process and the storage of the personal data take place on servers located within UE, belonging to and/or in the possession of the Controller and/or third party companies, as duly appointed as processors. Where necessary, the transfer to non EU-countries will be performed, anyhow, in compliance with the provisions under par. V, GDPR (Section 46), adopting standard contractual clauses drafted pursuant to versions no. 2004/915/EC e n. 2010/87/EU, as adopted by the European Commission. The Controller may transfer servers in non-EU countries.
Your personal data will not subject to dissemination.
f) Personal Data Storage Period
Personal Data provided for the purposes indicated under par. (b), above will be processed and stored for the entire duration of the executed contract. As of the termination of such contractual relationship, for whichever reason or cause, personal data will be stored as long as time-barring legal terms will be elapsed.

g) Exercisable Rights

In compliance with the provisions under Chapter III, Section I, GDPR, you may exercise the rights therein indicated and in particular:
(i) right of access;
(ii) obtain the rectification or the erasure of personal data or the limitation to processing from Controller. In case of the request of erasure, the data subject has the right to obtain that Controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data;
(iii) right to object to the processing of personal data;
(iv) right to data portability;
(v) right to withdraw the consent at any time; the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal;
(vi) right to lodge a complaint with the Supervisory Authority.

You may exercise such rights by means of a request to be sent by email to the following certified email address: privacy@aegishcgroup.com.

h) Processing Operations

Your personal data are processed through the operations indicated in section 4, n.2), GDPR. Performed by not automated means – in particular: collection, recording, organization, structuring, update, storage, adaptation or alteration, retrieval and analysis, consultation, use, disclosure by transmission, alignment or combination, restriction, erasure or destruction of data.

Whichever the way, it will guaranteed their security, logical and physical, and overall their confidentiality, implementing all the appropriate technical and organizational measures to ensure their security.