Data Subjects: clients and suppliers, including prospective ones (natural persons)
This notice is issued by Resitape s.r.l. and sets out the methods and purposes of the processing of your personal data carried out in the context of your client/supplier relationship with Resitape S.r.l., as well as any further information required by law, including information about your rights and how to exercise them.
1. Data Controller
Your personal data will be processed by Resitape S.r.l., with registered office in Italy, Via Senato 15, 20121 – Milan, e-mail: info@resitape.com, PEC: resitape@legalmail.it, website: www.resitape.com, acting as data controller (hereinafter also the “Controller” o “Company”) with the aim of clearly and transparently describing the methods and purposes for which your personal data will be processed. Such processing will be carried out in accordance with the principles of fairness, lawfulness, transparency and protection of your privacy and rights as laid down by the GDPR.
2. Categories of Data Processed
In the course of carrying out its business activities, the Controller may process common personal data, such as identification and personal details (e.g. first name, surname, place and date of birth), contact details (e.g. telephone number, e-mail address and/or certified e-mail (PEC)), tax and financial information (including tax identification number and VAT number, bank account details and information relating to the role and function held within the data subject’s organisation).
The processing of special categories of personal data (so-called sensitive data) pursuant to Art. 9 GDPR is not envisaged.
3. Purposes of Processing
The processing of your personal data is carried out primarily to enable the management of your contractual/pre-contractual relationship with the Company, as well as to fulfil legal and fiscal obligations. The data may be used to ensure effective management of the commercial and financial relationship. Processing may also be aimed at pursuing any further legitimate interest of the Controller (e.g. for the exercise and/or defence of a right in judicial, administrative or arbitration and conciliation proceedings) and in any event to fulfil legal obligations to which the Controller is subject, in particular in civil, tax and accounting matters, as well as to implement provisions issued by tax authorities or by supervisory authorities or bodies duly empowered by law.
4. Legal Basis
The processing of personal data for the purposes referred to in Section 3 above is based on legal grounds such as the performance of a contract or pre-contractual measures and does not require the expression of explicit consent by the Data Subject, as such processing will be necessary to implement the pre-contractual measures/contractual relationship between the Company and you as a Client/Supplier of Resitape S.r.l., of which you are the reference person, and to enable the mutual fulfilment of the resulting obligations, as well as to enable the Company to fulfil its legal obligations and/or pursue the Company’s legitimate interest in carrying out its business activities.
5. Processing Methods
In accordance with Article 5 of the GDPR, the personal data subject to processing will be processed by means of IT, electronic and, where necessary, paper-based tools, in compliance with the principles of fairness, transparency, data minimisation and security set out by the GDPR.
In particular, they will be:
- processed in a lawful, fair and transparent manner in relation to the Data Subject;
- collected and recorded for specified, explicit and legitimate purposes and subsequently processed in a manner compatible with those purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- accurate and, where necessary, kept up to date;
- processed in a manner that ensures an adequate level of security;
- stored in a form that permits identification of the Data Subject for no longer than is necessary for the purposes for which they are processed.
The Controller adopts adequate technical and organisational measures to prevent unauthorised access, data loss, destruction or unlawful use of your data.
Automated decision-making processes pursuant to ex Art. 22 GDPR will not be employed.
6. Provision of Personal Data
The provision of your personal data is necessary for the establishment and management of the contractual relationship. Any refusal to provide such data would make it impossible for the Controller to proceed with the relationship or to fulfil the obligations connected thereto.
7. Personal Data Retention Period
Your personal data will be retained for the time strictly necessary to pursue the purposes indicated above and for the reasons for which they were collected, or for the time necessary to properly perform the contract and, thereafter, for the period provided for by applicable legislation. In tax and accounting matters, they will be kept for the time necessary to protect the Controller’s rights.
8. Communication, Disclosure and Transfer of Personal Data
Within the scope of the purposes indicated above, your personal data will be accessible, within their respective functions, to the Controller’s employees and collaborators duly designated for the performance of specific tasks and/or functions as authorised persons, to external collaborators and service providers for the Controller, designated as data processors, to whom specific written instructions have been given, to the extent strictly necessary for the pursuit of the aforementioned purposes.
Your data may be communicated to third parties such as banking and financial institutions, professional consultants (e.g. accountants or lawyers), transport or logistics companies, insurance companies and public bodies, to the extent necessary.
Such parties act as data processors or independent data controllers, as the case may be.
Your data will not be disclosed to the public and will not be transferred outside the European Union.
9. Rights of the Data Subject
As a Data Subject, you are entitled to exercise directly with the Controller the following rights:
- right of access, i.e. the right to obtain from the Company confirmation as to whether or not personal data concerning you are being processed and, if so, to obtain access thereto (Art. 15 GDPR);
- right to rectification, i.e. the right to obtain the rectification of inaccurate data and/or the completion of incomplete data (Art. 16 GDPR);
- right to erasure, i.e. the right to obtain the erasure, anonymisation or blocking of data processed in violation of law, including data whose retention is not necessary in relation to the purposes for which the data were collected (Art. 17 GDPR);
- right to receive confirmation that the operations referred to in points b) and c) have been brought to the attention of those to whom the data have been communicated or disclosed, except where such fulfilment proves impossible or involves a disproportionate effort relative to the right being protected;
- right to restriction of processing, i.e. the right to object to processing or to obtain restriction of the processing of personal data as provided by law (Art. 18 GDPR);
- right to be informed of rectifications, erasures and restrictions of the processing of personal data (Art. 19 GDPR);
- right to data portability, i.e. the right to receive personal data in a structured, commonly used and machine-readable format, as well as the right to transmit the data to another data controller (Art. 20 GDPR);
- right to object, i.e. the right to object to the processing of data where legitimate grounds exist (Art. 21 GDPR);
- right to withdraw consent, at any time, without prejudice to the lawfulness of processing based on consent given prior to withdrawal (Art. 7 GDPR);
- right to compensation, i.e. the right to obtain from the Controller and/or the Processor full and effective compensation for any material or non-material damage suffered, if caused by the processing of personal data in breach of the Regulation (Art. 82 GDPR);
- right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali – Piazza Venezia, 11 – 00187 Rome – PEC: protocollo@pec.gpdp.it) in the event of unlawful processing (Art. 77 GDPR).
10. Personal Data Breaches
In the event of a personal data breach entailing a risk to your rights, we inform you that the Controller will:
- notify any DATA BREACH, i.e. security violations that accidentally or unlawfully result in the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, to the Italian Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art. 33 GDPR);
- communicate any breach to the Data Subject without undue delay where such breach is likely to result in a high risk to the rights and freedoms of natural persons, except in the cases provided for by Art. 34 GDPR.
11. Contact Details of the Data Controller
The contact details of the Data Controller are as follows: Resitape S.r.l., Tax Code/VAT No. 11024940154, with registered office at Via Senato 15, 20121 – Milan, reachable at the following addresses:
– E-mail / P.E.C.: resitape@legalmail.it
– Website: www.resitape.com
– Postal address: Resitape S.r.l., Via Senato 15, 20121 – Milan
12. Communications and Exercise of Data Subject Rights
For any request relating to the processing of personal data or to exercise the rights referred to in Section 9, you may submit a written request, without formality, to the Controller by sending a communication to the following e-mail address: resitape@legalmail.it
Resitape S.r.l. – Data Controller

