Tinext Group SA, as the Data Controller (hereinafter “Controller”), considers privacy and the protection of personal data to be an important aspect of its business. For this reason, it processes personal data in accordance both with the Swiss Federal Data Protection Act (FADP, 25 September 2020) and with the provisions of Regulation (EU) 679/2016, General Data Protection Regulation (hereinafter “GDPR”).
We therefore invite you, before providing any personal data to the Controller, to carefully read this Privacy Policy as it contains important information on the protection of your personal data.
This Privacy Policy:
applies to the website https://group.tinext.com (hereinafter “Site”) and to all cases in which reference is made to or there is a link to this policy;
forms an integral part of the Site and the services we offer;
is addressed to those who interact with the Site's web services, pursuant to Art. 13 of the GDPR and Art. 19 of the FADP.
The processing of your personal data will be based on the principles of good faith and proportionality, fairness, lawfulness, transparency, limitation of purposes and retention, minimization and accuracy, integrity and confidentiality, as well as the principle of accountability. Your personal data will therefore be processed in accordance with legislative provisions and confidentiality obligations.
We inform you that the personal data processed may consist – depending on how you use the services – of textual information, photographic images, or any other information suitable to identify or make the data subject identifiable, depending on the type of services requested.
1. DATA CONTROLLER
The Data Controller is Tinext Group SA, with registered office in Sorengo and business address at Viale Serfontana 7, 6834 Morbio Inferiore (hereinafter “Controller”).
2. DATA PROCESSED AND PURPOSES OF PROCESSING
To allow you to use the Site and its services, the Controller needs to collect and process certain personal data. By personal data we mean information relating to an identified or identifiable natural person, such as, for example, name, contact details, and IP addresses. For simple navigation of the Website, the types of data processed and the relevant cookie policy are specified below.
We inform you that the personal data processed may consist – also depending on how you choose to use the services – of identifiers such as name, identification number, or one or more elements characteristic of your identity that make you identifiable, depending on the type of services requested (hereinafter “personal data”).
The personal data processed through the Site are as follows:
a. Browsing data
In the course of their normal operation, the computer systems used to operate the Site acquire certain personal data, the transmission of which is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified individuals, and the Controller will not attempt to link the data in server logs with individuals visiting the site. However, such data, through processing and association with data held by third parties, could make users identifiable.
Such data includes IP addresses or domain names of the computers used by users connecting to the Site, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numeric code indicating the server response status, and other parameters relating to the user's operating system.
These data are used solely to obtain anonymous statistical information on Site usage, to ensure its proper functioning, to detect anomalies and/or abuse, and to improve the structure of the Site. Data may be used to establish liability in the event of cybercrimes against the Site or third parties.
Purpose of processing: browsing the Site. Data provision is mandatory, as it is automatically collected to enable site navigation.
Legal basis: Overriding legitimate interest of the Controller.
Retention period: session duration.
b. Data provided by the user for information requests
Unless otherwise specified in dedicated notices, this Privacy Policy also applies to the processing of data voluntarily provided by you through the Site. In particular, you may provide data through the contact form (hereinafter “Form”) for requesting information about services and products, or by sending an email.
Please do not include in the Site Forms or emails any information that falls under the special categories of personal data as per Art. 9 GDPR (e.g., your political opinions, religious beliefs, or health status) or data requiring special protection under Art. 5, para. 1(c) FADP.
Purpose of processing: to respond to the data subject’s request. Providing name, surname, email, company, and how you heard about Tinext is mandatory to send the request. Job title is optional.
Legal basis: performance of pre-contractual and contractual measures.
Retention period: contact data collected for handling requests are retained for 2 years.
d. Cookies
Information on cookies used by the Site is available at the following link.
3. RECIPIENTS OF PERSONAL DATA
Tinext does not sell, transfer, or otherwise disclose your data. Personal data may be shared with recipients who process the data as data processors, for the purposes indicated in section 2 of this Privacy Policy. In particular, data may be shared with:
individuals, companies, or professional firms that provide the Controller with assistance and consultancy in accounting, administrative, legal, tax, and financial matters;
entities responsible for technical maintenance, IT system management, or supporting the Controller in managing the website;
companies providing newsletter services;
parent, subsidiary, and affiliated companies of the Controller, limited to administrative-accounting purposes or related to organizational, commercial, administrative, financial, and accounting activities;
entities to whom data must be disclosed pursuant to legal obligations or orders from authorities.
4. TRANSFERS OF PERSONAL DATA
Your personal data is processed in the country where the Controller is established.
In case of data transfers to other EU countries, in accordance with Art. 16 et seq. of the FADP and Art. 8 et seq. of the OFADP, the destination country must be listed in Annex 1 of the OFADP, i.e., countries whose legislation is recognized by the Federal Council as ensuring adequate data protection.
In the absence of such adequate safeguards, transfers are permitted only in compliance with Art. 17 of the FADP and Art. 8 et seq. of the OFADP. Such transfers will be specifically communicated to the data subject.
5. RIGHTS OF THE DATA SUBJECT
The data subject is granted the following rights:
1) right of access: to obtain confirmation from the Controller whether or not personal data is being processed and to receive information on the purposes and methods of processing, recipients, retention criteria, data source (if not collected from the subject), and the existence of any automated decision-making; the Controller provides a copy of the processed personal data;
2) right to rectification and completion of incomplete personal data, including by submitting a supplementary statement;
3) right to erasure; this right may be limited if processing is necessary for the establishment, exercise, or defense of legal claims;
4) right to restrict processing;
5) right to withdraw consent, without affecting the lawfulness of processing based on consent before withdrawal;
6) right to object, on legitimate grounds, to the processing of personal data, including for direct marketing purposes;
7) right to data portability;
8) right to object to automated decision-making concerning natural persons, including profiling;
9) right to lodge a complaint with a supervisory authority.
The data subject may also take actions to protect personal rights by requesting the prohibition of certain data processing, the prohibition of disclosing personal data to third parties, or the deletion or destruction of data, as provided under Art. 32, para. 2 of the FADP.
These rights may be exercised by sending an email to: [email protected].
The Controller will seek to provide the requested information within 30 days (or will inform you of the timeframe within which the information will be provided) and free of charge, unless the request imposes a disproportionate cost.
6. CONSENT OF MINORS FOR INFORMATION SOCIETY SERVICES
To access services provided through the Site, users must be over sixteen years of age. Consent for processing the personal data of a minor under sixteen is lawful only if given by the holder of parental responsibility.
7. AUTOMATED DECISION-MAKING
The Controller does not use automated decision-making processes, including profiling.
8. REPRESENTATIVE OF THE CONTROLLER
To provide a contact person based in an EU Member State for matters relating to processing, the Controller has appointed the following EU representative pursuant to Art. 27 GDPR:
Tinext Italia S.r.l.
Via Borghi 8, Gallarate
Email: [email protected]
9. CHANGES
The Controller reserves the right to amend or simply update this Privacy Policy, in part or in full, due to changes in applicable law. Before using the Site or related resources (email, phone, social media accounts, etc.), users must check the current version of the policy.
10. CONTACT
For any inquiries, please email: [email protected]