Customer Information

INFORMATION ON THE PROCESSING OF PERSONAL DATA
CUSTOMERS AND POTENTIAL CUSTOMERS

(Information pursuant to art. 13 and art. 14 of Reg. (EU) 679/2016, so-called GDPR)

Below, we provide you with some information that you need to know, not only to comply with legal obligations, but also because transparency and fairness towards data subjects are a fundamental part of our business.
This information is intended for customers and potential customers of T2 WELDING SRL.

Who is the data controller?
The Data Controller of your personal data is TECNODUE SRL (VAT number 00161710280), with registered office in Via Bacchiglione, 22/1 – 35030, Cervarese Santa Croce (PD) – Italy, responsible for the legitimate and correct use of your personal data and which you can contact for any information or request at the following addresses: info@tecnodue.eu, tecnodue-srl@pec.it

Where is the data collected?
The data processed is communicated by you and/or by third parties, such as authorities and public bodies (e.g., the Chamber of Commerce) and/or collected from publicly accessible sources.

What data processing is carried out?
Your personal data is collected and processed, using both automated and non-automated methods, as specified below.

Sale and pre-sale business activity

Purpose and legal basis – Promotional activities, based on the Execution of a contract and/or pre-contractual measures, Legitimate interest
– Offer of products and services, based on the Execution of a contract and/or pre-contractual measures, Legitimate interest
Data categories Personal data, Contact data, Address data, Data relating to purchases or use of services
Shelf life* 10 years from the year of competence
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), other entities for whom the communication of data is necessary for the purposes stated by the data controller, Authorities and public administrations with respect to which there is a legal obligation to communicate.

Customer Management

Purpose and legal basis Follow up on customer or potential customer requests and manage pre-contractual or contractual obligations, based on the Execution of a contract and/or pre-contractual measures
Data categories Personal data, Contact data, Address data, Payment data, Data relating to purchases or use of services
Shelf life* 10 years from the year of the contract or from the cessation of the effects of the last contact
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), other entities for whom the communication of data is necessary for the purposes stated by the data controller, Banks, Authorities and public administrations with respect to which there is a legal obligation to communicate.

Customer Service

Purpose and legal basis Allow the exercise of the right of guarantee, on the basis of the Execution of a contract and/or pre-contractual measures, Legal obligation
Data categories Personal data, Contact data, Data relating to purchases or use of services
Shelf life* 10 years from the year of exercise of the right
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), and other entities for whom data disclosure is necessary for the purposes stated by the data controller.

Warranty

Purpose and legal basis Allow the exercise of the right of guarantee, on the basis of the Execution of a contract and/or pre-contractual measures, Legal obligation
Data categories Personal data, Contact data, Data relating to purchases or use of services
Shelf life* 10 years from the year of exercise of the right
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), and other entities for whom data disclosure is necessary for the purposes stated by the data controller.

Planning and control of activities

Purpose and legal basis Planning of activities, based on the legitimate interest of the owner in carrying out the business activity
Data categories Personal data, Contact data, Data relating to work activity, Data relating to purchases or use of services
Shelf life* 10 years from the year of data acquisition
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), and other entities for whom data disclosure is necessary for the purposes stated by the data controller.

Quality of service

Purpose and legal basis Verify the quality of the service, on the basis of legitimate interest to verify compliance with internal procedures
Data categories Personal data, Contact data, Address data, Data relating to purchases or use of services
Shelf life* 10 years from the year of termination of the effects of the last contract
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), and other entities for whom data disclosure is necessary for the purposes stated by the data controller.

Accounting

Purpose and legal basis – Keeping of accounting records, based on a legal obligation
– Tax obligations, based on a legal obligation
Data categories Personal data, Contact data, Address data, Payment data, Data relating to work activity, Data relating to purchases or use of services
Shelf life* 10 years from the year of termination of the effects of the last contract
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Authorities and public administrations with a legal obligation to communicate, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), other entities for whom data communication is necessary for the purposes stated by the data controller, Banks

Management control

Purpose and legal basis Internal management control, based on the legitimate interest in carrying out business activities
Data categories Personal data, Contact data, Work-related data
Shelf life* 10 years from the year of competence
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, banks, data processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), and other entities for whom data disclosure is necessary for the purposes stated by the data controller.

Billing and delivery notes

Purpose and legal basis Shipping of documents and goods, based on the execution of a contract and/or pre-contractual measures
Data categories Personal data, Contact data, Address data
Shelf life* 10 years from the year of termination of the effects of the last contract
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), other entities for whom the communication of data is necessary for the purposes stated by the data controller, Banks, Authorities and public administrations with respect to which there is a legal obligation to communicate.

Creation and subsequent publication/dissemination of multimedia content

Purpose and legal basis Creation, use and publication/dissemination of multimedia content, in whole or in part, based on the consent of the interested party**
Data categories Personal data, contact details, multimedia content (including photos and videos)
Shelf life* The data will be retained, subject to disclosure, until consent is revoked or an explicit request for deletion is accepted. In any case, once the purpose for which it was collected no longer applies, the data will be deleted.
Data recipients Authorized data processors appointed pursuant to art. 29 of EU Regulation 2016/679, Data Processors appointed pursuant to art. 28 of EU Regulation 2016/679 (see register of data processors), and other entities for whom data disclosure is necessary for the purposes stated by the data controller.

**Providing consent is always optional and can be revoked at any time. You can contact the Data Controller using the contact information above.

*In addition to the time required for the statute of limitations to accrue in relation to mutual rights and the time for keeping backups.
In addition to the above, as part of activities aimed at the proper management of the organization, your personal data will also be processed by duly authorized internal or external personnel for:
1) management and maintenance of the network and IT systems, when processing occurs even through partially automated methods (for example, when data transits through TECNODUE SRL's IT systems), based on the legitimate interest in protecting the data and for information security obligations; the data is stored in compliance with security implementations and with the provisions for the primary processing of reference among those described above;
2) manage compliance activities, including personal data protection obligations, as required by law, in accordance with the retention periods established for the primary processing in question;
3) to prevent and detect abuse and to defend the rights and interests of the Data Controller, retaining them until the expiration of the limitation periods, except in the case of disputes (in which case, the data will be retained until the matter of the dispute has been definitively resolved), based on the legitimate interest of the Data Controller in protecting his rights and interests;
4) verify compliance with procedures and quality standards based on the owner's legitimate interest in pursuing control and efficiency within the Organization, in accordance with the retention periods established by applicable regulations, including voluntary ones, and internal procedures.

Are there automated processes?
The processing is not based on automated decision-making.

Is it mandatory to provide data?
Except for any purposes based on consent, providing your data is a necessary requirement: failure to provide the data indicated as mandatory may have legal and contractual consequences. Therefore, failure to provide the data may result in the desired outcome being lost or only partially achieved.

Is data transferred outside the European Union?
The processing of personal data (e.g., storage, archiving, and retention of data on our servers or in the cloud) will be limited to the areas of circulation and processing of personal data in countries within the European Economic Area. We are expressly prohibited from transferring personal data to non-EU countries that do not guarantee (or lack) an adequate level of protection, or in the absence of the protection measures provided for by EU Regulation 2016/679 (third country deemed adequate by the European Commission, group BCRs, model contractual clauses, data subject consent, etc.).

What rights are recognized?
● You have the right, pursuant to articles 15 et seq. of EU Regulation 2016/679, to request from the Data Controller access to your personal data, as well as their rectification, deletion or oblivion;
● You also have the right to request data portability or limitation of processing;
● You have the right, for reasons relating to your particular situation, to object to the processing of personal data concerning you based on the legitimate interest;
● You have the right to view the essential contents of any joint ownership agreements signed;
● For processing based on consent, you have the right to withdraw your consent at any time, without prejudice to the lawfulness of the processing based on the consent given before the withdrawal;
● You can also lodge a complaint with the Italian Data Protection Authority, located in Piazza Venezia 11, 00187 – Rome – protocollo@pec.gdpd.it.
To exercise your rights or to request additional information, you can contact the Data Controller using the contact information above.

Can the information in this policy change?
We reserve the right to update our Privacy Policy. We will communicate any changes as appropriate, and we will update the date in this Privacy Policy. Therefore, we recommend periodically reviewing our Privacy Policy, including requesting a copy from the Data Controller.

Last updated: December 30, 2025

Torna in alto