IT EN

Privacy Policy on the Processing of Personal Data

The protection of personal data is a fundamental value for Fideiussioni Digitali and for Surety Shield S.r.l. (a company controlled by Cetif Advisory S.r.l. and owner of the Fideiussioni Digitali platform). This Privacy Policy clearly and comprehensively describes how we collect, use, store and protect our users’ personal data, ensuring that all processing activities are carried out in compliance with individuals’ fundamental rights and freedoms.

1. Data Controller and Contact Information

The Data Controller is SURETY SHIELD SRL, VAT Number 13827730964, with registered office at Via Santa Maria Valle, 5, Milan – 20123.

2. Types of Personal Data Processed

The Company minimizes the collection and processing of personal data strictly to what is necessary for the purposes pursued. The data collected include:

  • Identification and contact data: Surname and First Name, telephone contact details, email address.
  • Administrative and financial data: Tax data and banking details necessary for the organization and management of the contractual relationship.
  • Images and audiovisual recordings: Photographic images and videos that may be collected during events or courses organized by Surety Shield S.r.l.
3. Purposes of Processing and Legal Basis

In order to provide our services and manage the Fideiussioni Digitali platform effectively, we process your data only where there is a valid legal basis (the so-called “legal basis”). Specifically, processing activities are divided into two main categories:

Processing activities necessary for the provision of the service (Mandatory)

  • Managing the contract and the platform: to establish and manage the contractual relationship, allowing you to use all the features of Fideiussioni Digitali. The legal basis is the performance of pre-contractual and contractual measures.
  • Compliance with legal obligations: for administrative, accounting and tax management, as well as audit activities related to the contract. The legal basis is compliance with a legal obligation to which Surety Shield S.r.l. is subject.

Note: refusal to provide data for these purposes will result in the impossibility of establishing the relationship and receiving the service.

Processing activities based on your consent (Optional)

  • Marketing activities: for sending commercial and promotional communications relating to our services. The legal basis is your explicit consent.
  • Publication on social media and the web: to publish on our website or social media channels (e.g. LinkedIn) images or videos collected during events or courses organized by Surety Shield S.r.l., for the purpose of promoting the event itself. The legal basis is your explicit consent. In the case of group recordings during events, where it is not possible to blur your image, refusal to provide consent may limit participation in the event itself.
  • Statistics and quality control: to carry out analyses aimed at improving our services and assessing your satisfaction. This processing is carried out based on the Company’s legitimate interest in anonymous form; if the data collected is not anonymous and allows you to be identified, we will request your specific consent.
4. Processing Methods and Security

Data may be processed in paper-based, electronic and through systems using artificial intelligence, always in compliance with applicable legislation.

Surety Shield S.r.l. plans and adopts the necessary technical and organizational measures to minimize the risks of loss of confidentiality, availability and integrity, ensuring the continuity of the services provided. The Company adopts a privacy and compliance management system aligned with the following international standards:

  • ISO 27001 (Information Security Management System) to protect data from unauthorized processing, loss or accidental destruction.
  • ISO 37301 (Compliance management systems).
  • ISO 31000 (Risk Management).
  • ISO/IEC 29134 (Guidelines for privacy impact assessment – PIA).
5. Scope of Communication and Data Recipients

SURETY SHIELD SRL does not disclose or communicate personal data to third parties for purposes other than those described above. For the performance of its activities, the Data Controller may use third-party entities that will be appointed as External Data Processors (Article 28 GDPR), and instructed to process data in compliance with appropriate security measures:

  • Providers of administrative services (e.g. accountants);
  • Providers of technical assistance for IT systems and software providers;
  • CETIF ADVISORY SRL (controlling company);
  • Banking and insurance institutions.

Company employees and collaborators are appropriately trained and appointed as authorized persons/data processors pursuant to Article 29 of the GDPR. A system administrator has also been appointed in accordance with the provisions issued by the Italian Data Protection Authority.

6. Data Retention Period

Personal data are stored according to the following criteria:

  • For the entire duration of the existing contractual relationship;
  • Until the termination of the contractual activity and the fulfilment of the administrative and tax requirements provided by law (e.g. 10 years for accounting documentation);
  • For a longer period in relation to specific requests from public authorities;
  • Within the limits of the statutory limitation period of rights, for purposes related to exercising the right of defense in the event of disputes.
7. Data Subject Rights

As a data subject, the GDPR (Articles 15 and following) grants you specific rights that you may exercise at any time by contacting the Data Controller at the contact details indicated in Section 1:

  • Right of access: to know whether or not processing of your personal data is taking place;
  • Right to rectification or erasure (right to be forgotten): to correct inaccurate data or request its deletion;
  • Right to restriction of processing: in the cases provided for by Article 18 of the GDPR;
  • Right to data portability: to receive your personal data in a structured and machine-readable format;
  • Right to object: to object at any time to processing for legitimate reasons or for marketing purposes;
  • Right to lodge a complaint with a supervisory authority (in Italy, the Italian Data Protection Authority – www.garanteprivacy.it).