PRIVACY POLICY PURSUANT TO ARTICLES 13
and 14 OF REGULATION (EU) 2016/679 (“GDPR”)
Dear
Customer,
In
accordance with articles 13 and 14 of EU Regulation No. 2016/679 on the
protection of natural persons with regard to the processing of personal data
(hereinafter referred to as “GDPR”), this Privacy Policy provides you with
information on the processing of your personal data in relation to the use of
the BTicino App “MyHome_Up”.
DATA CONTROLLER
BTicino S.p.A.
Viale Borri, 231
21100 Varese - Italy
Fax: +39 0332 423675
E-mail: privacy@pec.bticino.it
Joint
Controller
Legrand
SNC
SIRET
No. 389 290 586 000 12
APE
Code 4669A
Registered
with the Limoges Trade and Companies Register under No. 3898290586
VAT ID No. FR 15 389 290 586
128, av. Du Maréchal de
Lattre de Tassigny
87045 Limoges Cedex (France)
DATA PROTECTION OFFICER (DPO)
E-mail: dpo@pec.bticino.it
PERSONAL DATA WE PROCESS
The personal
data in the possession of BTicino S.p.A.,
Data Controller, are:
1.
provided by you or learnt by us during
the performance of contractual activities;
2.
acquired from third parties;
3.
acquired from publicly-accessible
databases.
Data
collected during app use
During
their normal operation, the computer systems and software procedures that are
involved in the functioning of this app acquire certain personal data whose
transmission is implicit in the use of Internet communication protocols. This
information is not collected for the purpose of being associated with any
identified data subjects but, because of its nature, could, if processed and
combined with other data held by third parties, lead to the identification of
the concerned data subjects.
These
data include IP address, unique device identifier (UDID, UID), operating system
installed on the device, model and make of the device, technical details that
can help identifying errors, as well as data relating to network connectivity
and the applications running on the device.
Data
provided directly by the user
In order to be able
to use the service via the app, you will be requested to provide the following
personal data: name, surname, e-mail address, password, country.
Provision of
registration data is mandatory, as these identify the customer in the
performance of the agreement to which the customer is a party. A failure to
provide registration data makes it impossible to register and use the app.
Push
notifications
This app may send both service-related push notifications
and, subject to approval by the data subject, “commercial” push notifications.
If enabled, notifications may be received when the app is
active.
Push notifications may be disabled by accessing the push
notifications section in the operating system running on the device (Android or
iOS). The choice to disable push notifications is not irreversible.
Data
provided by the system
The app collects the following data:
o
system name
o
system address: street + post code +
country
o
MacAddress
o
IP address
o
firmware version
o
hardware version
o
lights status: on/off, light adjustment (percentage
value), colour adjustment for coloured lights
o
controlled sockets status: on/off
o
automated elements status: up/down/stop
o
system plan, including, in particular, a
list of floors, rooms and related names, a list of lights, sockets and other automated
elements and a list of scenarios with related descriptions.
PURPOSES OF PROCESSING – LEGAL GROUNDS
– STORAGE PERIODS
Personal data are
processed as part of BTicino S.p.A.’s
regular activities for the following purposes:
1.
To
register the App/create the account;
Legal basis for processing: performance of a contract to
which you are a party;
Storage
period: until request for account deletion.
2.
To
enable use of app services:
· technical management of the app;
· analysis of errors generated by the app;
· use of app functions;
· sending of service-related push notifications;
Legal basis for processing: performance of a contract to
which you are a party;
Storage
period: until request for account deletion.
3.
To
manage the data automatically provided by the system:
Legal basis for processing: performance
of a contract to which you are a party;
Storage period: until request
for account deletion.
4.
To send
commercial, advertising or promotional communications regarding the
products/services offered by the Company via automated means (e.g.: e-mail, SMS,
App notifications etc.) or traditional means (e.g.: operator telephone call). Personal
data may also be processed through questionnaires to measure the level of your
satisfaction on the quality of the services supplied and the activities
conducted by BTicino S.p.A.
Legal
basis for processing: your consent
at the time of registration;
Storage period: until withdrawal of consent.
5.
To
analyse your preferences/interests for the purpose of offering personalised
content in the app or via push notifications;
Legal
basis for processing: your
consent at the time of registration;
Storage period: until withdrawal of consent, except for details regarding
app use which will be stored, in any case, for a maximum of 24 months from
recording.
6. To collect data via GrayLog for the purpose of improving the services offered; data
are collected upon specific choice by the customer (subject to request by the
user).
Legal basis for processing: your consent; consent may be changed directly from the app;
Storage period: 48 months.
Once the above
storage periods have elapsed, personal data will be destroyed, erased or
anonymised, compatibly with technical erasure and backup procedures.
MANDATORY/VOLUNTARY NATURE OF DATA PROVISION
Provision of the data for the purposes
under items (1), (2) and (3) is mandatory. Failure to provide the data makes it
impossible to register the app and use the related services.
Provision of the data is voluntary for
all other purposes. Failure to provide the data does not affect the app
functions.
AUTHORISED PERSONS AND DATA RECIPIENTS
The data may be processed by employees
in the company departments responsible for pursuing the above purposes who have
been expressly authorised to process the data and have received
adequate operating instructions from the Controller and/or from the Joint
Controller.
Your data may also be processed by other companies -
including companies that are part of the Legrand Group – who conduct specific
activities on our behalf, including, without limitation, technical management
and maintenance of the system on which the data are stored, user database
hosting services, provision of registration and authentication procedures and
cloud services. These companies are designated as Data Processors under Article
28 GDPR. A detailed list of these companies is also available from our offices.
Your data may also be disclosed to external parties acting
as Data Controllers, including, without limitation, supervisory
and monitoring bodies and authorities and/or public and private entities in
general who are entitled to request disclosure of your data.
The data will not be transferred to countries that are not
member states of the European Union.
RIGHTS
OF THE DATA SUBJECT AS PER CHAPTER III GDPR
With regard to the processing of your personal data, you
shall have the right:
· to request from the Controller access to the data concerning
you (article 15 GDPR);
· to request from the Controller rectification and completion
of any incomplete data (article 16 GDPR);
· to request from the Controller erasure of the data (article
17 GDPR);
· to request from the Controller restriction of processing
(article 18 GDPR);
· to object to processing in cases where the Controller has
legitimate grounds (article 21 GDPR);
· to receive the data in a structured, commonly used and
machine-readable format and, if technically feasible, to transmit those data to
another controller without hindrance (“Right to data portability”, article 20
GDPR);
· to withdraw consent at any time. (article 7 GDPR).
Please be also informed that you have a right to lodge a
complaint with the competent supervisory authority (article 13 GDPR).
The above rights may be exercised by sending a written
notice to the address below or an email to: privacy@pec.bticino.com.