Dear Madam/Sir,
pursuant to art. 13 of the EU General Data Protection Regulation no. 679/2016, containing provisions on the processing of personal data (hereinafter, RGPD), we hereby inform you that BV TECH S.p.A., as the Data Controller of the data you have provided, will use this information concerning you and, qualified as "personal data" by the RGPD. The regulation states that anyone who processes personal data must inform the person concerned of what data is processed and of certain elements qualifying the processing, which must in any case be carried out in a lawful, correct and transparent manner, protecting your confidentiality and guaranteeing your rights.
The Data Controller is BV TECH S.p.A., with registered office at Piazza Diaz 6, 20123, Milan - Italy
The Data Protection Manager can be contacted at the following email address: dpogruppo@bv-tech.it.
The information and personal data indicated below will be processed for the following purposes
to fulfil the execution of the contract with you for the supply and management of the following Apps:
and/or related services requested by you, namely:
optional data:
The personal data referred to in point 3) of the information notice will be processed lawfully because the following conditions are met:
The provision of data is necessary for the establishment and management of the contractual relationship. We inform you that, in the absence of such data, it will be impossible for our Company to fulfil the obligations of the contract in place with you. Therefore, failure to provide such data will make it impossible to establish or continue the contractual relationship to the extent that such data are necessary for us to correctly fulfil the obligations related to the management of the contract.
Personal data in the rendez-vous cloud solution will be stored in the PrivateWave infrastructure in compliance with the conservation limitation principle provided for by the RGPD and/or for the time necessary to pursue the purpose of the service and for legal and / or contractual obligations.
Encrypted messages and their attachments are temporarily queued on the server to be delivered to recipient devices that are temporarily offline. PrivateWave cannot access end-to-end encrypted user messages in any way. The personal data for the on-premise solution are within the customer's infrastructure and therefore in the responsibility of the latter.
We comply with all industry standard measures aimed at eliminating the risk of damage and unauthorized access or use of personal information, ensuring that we have implemented adequate technical and organizational policies to apply the security measures established by the RGPD.
PrivateWave uses open protocols and IETF standards and complies with the NSA mobility capability package for the protection of National Security Systems (NSS).
All data is transmitted using the HTTPS protocol encrypted with TLS stack at the highest certification level (ECDHE-AES256-SHA384-GCM). PrivateWave encrypts in end-to-end (ZRTP ECDH 384/512) or end-to-site (SDES) mode even all data (Voice, messages and attachments) before they leave the phone, with a key that only the other recipient phone knows.
The content of calls and messages cannot be revealed to anyone except the sender and recipient. Any communication between client and server is also encrypted.
Privatewave immediately realizes if a man-in-the-middle attack attempt is in progress, warning the user and immediately closing any type of communication. All data on the mobile device is stored in an encrypted database with an access PIN chosen by the user and which not even PrivateWave knows. The data is kept for the period of time that the user deems appropriate.
Your personal data will be processed both by the Company's staff, authorised to process them using electronic and paper-based instruments, and by external parties (collaborators and service providers) called upon to carry out specific tasks on behalf of the Data Controller, in their capacity as Data Processors, pursuant to art. 28 RGPD, subject to our letter of appointment imposing on them the duty of confidentiality and security in the processing of personal data, and with the adoption of suitable security measures to prevent loss and/or unlawful and incorrect use of the data and/or unauthorised access, in compliance with the provisions in force on the protection of personal data.
Below is a list of our service providers:
For more information, visit their privacy policy: https://www.vonage.com/legal/privacy-policy/?icmp=footer_legalpolicy_privacy
For more information, visit their privacy policy: https://www.swisscom.ch/en/business/footer/data-protection.html
For more information, visit their privacy policy: https://firebase.google.com/support/privacy
For more information, visit their privacy policy: https://www.apple.com/ca/legal/privacy/en-ww/
Instead, for the sake of brevity, the detailed list of authorized subjects and collaborators designated as Data Processors is available at the headquarters of the Data Controller and is at your disposal.
The processed data will not be transferred to third countries or international organizations, will not be disseminated, and will not be communicated to third parties except, where necessary, for legal and/or contractual obligations.
As envisaged by the RGPD, in relation to your data you are entitled to exercise the rights envisaged by articles 15 et seq. of the RGPD, as set out below, and more precisely
provided for by law;
Please note that there may be conditions or limitations to the rights of the data subject. It is therefore not certain that, for example, you can exercise your right to data portability in all cases. This depends on the specific circumstances of the processing activity, or, if you decide to object to the processing of your data, the Data Controller has the right to evaluate your request, which may not be accepted if there are compelling legitimate grounds to proceed with the processing that override your interests, rights and freedoms.
11. METHODS OF EXERCISING YOUR RIGHTS
Without any formality, the data subject may at any time exercise his/her rights in a clear and explicit manner by sending:
Last update: Milan 14 March 2021