Go back

This policy is drafted in compliance with art. 13 of Regulation (EU) 2016/679 (GDPR) - Privacy Policy on the processing of personal data collected from the Data Subject*


* This policy is not valid for websites that may be accessed through links on the APP or in the areas in the site’s domain name of the Data Controller.


1. Data Controller (Articles 4 and 24 GDPR)

DUFERCO ENERGIA S.p.A., with registered office in Via Paolo Imperiale no. 4, 16126 Stradario 31820 Genoa (Italy), represented by its pro tempore legal representative. You can contact the Data Controller by sending a fax to +39 010.275.60200, an e-mail to privacy@dufercoenergia.com, or by calling the phone number +39 010 275 601.

Data Protection Officer (DPO)is a staff member of the organisation/company pursuant to Articles 37 to 39 of GDPR. You can contact the DPO by calling the phone number +39 010 275 601 or by sending an e-mail to dpo@dufercoenergia.com.

2. Categories of Personal Data processed

Personal data: means any information relating to an identified or identifiable natural person («data subject»); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (Art. 4, paragraph 1 no. 1 - C26, C27, C30 of GDPR).

3. Purpose of Processing/Lawfulness of processing - Data retention period and nature of data provision

PURPOSE OF DATA PROCESSING LAWFULNESS: DATA RETENTION PERIOD NATURE OF DATA PROVISION
Creation of a personal account to allow access to services and products provided by Duferco Energia S.p.A. – through the Data Controller’s website and/or APP – and establishment of a contractual relationship. After filling in the form You will receive an e-mail to confirm the registration process. Once You have completed the registration process, Your account will be active. The APP may also have access to the following data: App history; phone; photos/multimedia items/files on device, external device memory; camera; connection information; device ID; login credentials. Art. 6 (1)(b) GDPR Contract - adoption of pre-contractual measures taken at the request of the Data Subject Data for the creation and subsequent use of the account: until the account is deactivated. Necessary in order to proceed with account creation. Failure to provide the requested Personal Data will make it impossible to register and, as a consequence, to access the services provided by the Data Controller.

4. Cookies

For additional information on the cookies used in this website please refer to cookies policy.

5. Data Recipients/Recipient categories

The Personal Data provided by the Customer may be transferred to recipients, who shall process them in their capacity as Data Processors (Art. 28 GDPR) and/or as individuals operating under the authority of the Data Controller and Data Processor (Art. 29 GDPR), or operating in a completely autonomous way as Data Controllers in their own right, in order to fulfil the purposes pursued by Duferco as stated above. The list of the appointed Data Processors is constantly updated and is available by contacting the Data Controller at the e-mail addresses and numbers specified herein above.

More specifically, personal data may be transferred to recipients in the following categories: - Parent companies/subsidiaries/affiliated undertakings of Duferco Energia S.p.A.; - Individuals/companies who provide services for the management of the information system and communication networks of Duferco Energia S.p.A. (including e-mail and hosting service) and of the telecommunications networks and APP development; - Companies within the scope of assistance and consulting relationships in the marketing industry; - Competent authorities who enforce the law and/or regulations by public bodies, upon request.

6. Data transfer to third countries

As regards the transfer of Personal Data to non-EU countries, more particularly to countries that according to the European Commission do not ensure an adequate level of protection, Duferco Energia will take all necessary security measures to protect Personal Data and will provide adequate safeguards for Data Subjects in accordance with applicable law and, in particular, with Articles 45 and 46 of Regulation EU 2016/679.

This is without prejudice to the Customer's right to know the guarantees adopted, the means used to obtain copies of such Personal Data and the place where Personal Data were transferred.

7. Rights of the Data Subjects

You shall be able to exercise Your rights under Regulation EU 2016/679 by sending an e-mail to the Data Controller to the e-mail address privacy@dufercoenergia.com or by contacting the DPO by e-mail at the e-mail address dpo@dufercoenergia.com. You shall have the right to obtain from the Data Controller, at any moment, access to Your Personal Data (Art. 15), their rectification (Art. 16) or erasure (Art. 17), as well as the restriction of their processing (Art 18). You shall also exercise Your right to data portability, where applicable, (Art. 20): if You so wish, the Data Controller shall provide You with the Personal Data concerning You in a structured, commonly used and machine-readable format. Moreover, You have the right to object to the processing of Your Personal Data (including automated processing, such as profiling). More specifically, to object to profiling, You may at any time write an e-mail to the following address privacy@dufercoenergia.com with the "no profiling" subject line.


Without prejudice to any other administrative and jurisdictional recourse, if You believe that the processing of Your Personal Data violates the provisions of Regulation (EU) 2016/679, Art. 15 (f), You have the right to lodge a complaint with the Data Protection Authority, namely the Italian Data Protection Authority (https://www.garanteprivacy.it/) and, with reference to Art. 6(1)(a), You shall have the right to withdraw the consent previously given at any time by writing to the Data Controller and/or to the DPO to the above mentioned e-mail addresses and numbers.


Updated on: 28 May 2021


Go back