Notice · Articles 13 and 14 GDPR
Visitor privacy notice
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), ATC s.r.l. informs you about the processing of the personal data collected when you visit its premises.
1. Data controller
The data controller is ATC s.r.l. (VAT no. 11001120960), Via dei Tigli n°7/9, 20853 Biassono (MB), Italy, represented by its legal representative ("Controller"), who can be contacted at info@atc.srl or +39 039 9000393.
2. Data processed
- Identification and visit data: first and last name, company or organisation (optional), person you are meeting, reason for the visit, date and time of check-in and check-out, visitor pass number.
- Confirmations given: acknowledgement of this notice and acceptance of the confidentiality undertaking and safety rules, with the version of the accepted text.
- Signature: made with your finger on the reception tablet and stored as a graphic trace (sequence of coordinates). No biometric parameters (pressure, speed or rhythm of the stroke) are recorded and the signature is not used to identify you by automated means.
- Pre-registration: if an ATC employee registers you in advance as an expected guest, your name, company and the expected date and time of the visit. In this case the data are collected from the employee expecting you.
3. Purposes and legal bases
- a) Site security and access control, including check-in/check-out and escort by your host: legitimate interest of the Controller in the security of people, assets and systems (Art. 6(1)(f) GDPR), particularly relevant given the Controller's activity.
- b) Protection of confidential information through the signed confidentiality undertaking: legitimate interest of the Controller in protecting its know-how and technical and commercial information (Art. 6(1)(f) GDPR).
- c) Emergency and evacuation management, to know at any time who is on site: compliance with legal obligations on health and safety at work (Art. 6(1)(c) GDPR and Italian Legislative Decree 81/2008).
- d) Establishment, exercise or defence of legal claims of the Controller: legitimate interest (Art. 6(1)(f) GDPR).
4. Provision of data
Providing your data, signature and confirmations is necessary to access the premises: otherwise access cannot be granted. Indicating your company is optional.
5. Retention
Data are kept for 1 (one) year from the date of the visit and then automatically deleted. Pre-registrations are deleted 7 days after the expected date of the visit. In case of litigation, the necessary data may be kept until it is resolved.
6. Processing methods and security
Processing is carried out electronically with appropriate technical and organisational measures: access restricted to authorised staff with personal credentials and two-step verification for administrators, activity log (audit), record integrity chain, encrypted communications. On the kiosk, the check-out search shows only the first name and the initial of the surname, after typing at least two letters.
7. Recipients
Data are processed by authorised employees and collaborators of ATC s.r.l. and may be disclosed, where necessary, to public authorities and law enforcement as required by law. The service is hosted by Cloudflare, Inc., acting as data processor; the database is located in the European Union. Any technical access from the United States is covered by the Standard Contractual Clauses and the EU-US Data Privacy Framework. The system was built by Boneway, which does not access visitor data in ordinary operation.
8. Your rights
You may exercise your rights under Articles 15-22 GDPR at any time (access, rectification, erasure, restriction, objection to processing based on legitimate interest) by writing to info@atc.srl. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
9. Updates
This notice may be updated; the version in force is always available on the reception tablet and at this address. Each registration keeps the version of the notice and of the confidentiality text accepted.