Privacy Notice

Regarding the processing of personal data of individuals submitting reports through the internal Node channel, in compliance with Legislative Decree of March 10, 2023, No. 24, implementing Directive (EU) 2019/1937 of the European Parliament and of the Council of October 23, 2019, on the protection of persons who report breaches of Union law, and containing provisions regarding the protection of persons who report breaches of national regulations.

Privacy Policy

Pursuant to Article 13 of Legislative Decree No. 196/2003 (the “Privacy Code”) and Article 13 of the European Regulation No. 679/2016 (the “GDPR”), we provide this privacy notice concerning the processing of personal data contained in reports submitted via the Node software platform (hereinafter, “Report”).

DATA CONTROLLER

Top Service Coop Società Cooperativa, with registered office at Via Albert Einstein 2/A, Verona (VR), represented by its legal representative pro tempore, Biagio Palmieri, born in Foggia (FG) on 13/07/1963 and residing at Via dei Poeti 52, Valeggio sul Mincio (VR).

PLACE OF DATA PROCESSING

The data processing activities take place in Italy or in other EU countries. There is no transfer or dissemination of data abroad or to non-EU countries. No data is communicated or disclosed, except for statistical purposes and in any case only in anonymous and/or aggregated form.

PURPOSE OF DATA PROCESSING

The personal data you provide is used solely to manage the Report submitted via the Node platform.

PROCESSED DATA

The personal data processed includes exclusively:

  • First name;

  • Last name;

  • Email address;

  • Data provided to describe the alleged unlawful conduct subject of the Report.

Providing personal data is mandatory, as failure to do so would make it impossible for the Cooperative to fulfill the specific legal obligations regarding the management of Reports and, consequently, would prevent the implementation of protective measures provided by the Decree for the benefit of the data subjects.

LEGAL BASIS FOR PROCESSING

The legal basis for the processing of personal data is the legal obligation arising from Article 6 of Legislative Decree No. 231 of 2001, as amended by Law No. 179 of 2017 (“Provisions for the protection of whistleblowers who report crimes or irregularities of which they became aware within the context of a public or private employment relationship”), and subsequently by Legislative Decree No. 24 of March 10, 2023, Articles 4 and 13.

DATA RETENTION PERIOD

The personal data you provide will be stored for the time strictly necessary to process the Report and, in any case, no longer than five years from the date of the communication of the final outcome of the Report procedure, in accordance with Article 14, paragraph 1, of Legislative Decree 24/2023 and subsequent amendments.

DATA SHARING

Your personal data may be accessed by employees tasked with handling Whistleblowing reports and, if present, members of the Supervisory Body pursuant to Legislative Decree 231/2001. Since Whistleblowing reports are submitted through the Node software, your personal data may also be accessed by the software provider or other contractors appointed as data processors or sub-processors pursuant to Article 28 of the GDPR.

It is understood that, in accordance with the confidentiality obligations of the whistleblower established by Law 179/2017 and Legislative Decree 24 of March 10, 2023, Article 12, paragraph 2, data sharing will be strictly limited to what is necessary to ensure the whistleblower’s confidentiality.

DATA PROCESSING METHODS

Personal data is processed using both automated and manual tools for the purposes indicated above. Specific security measures are applied to prevent data loss, unlawful or incorrect use, and unauthorized access.

DATA SUBJECT RIGHTS

The data subject (i.e., the individual to whom the personal data refers) has the right to:

  1. a) Access and request a copy of their personal data;
  2. b) Request rectification of their personal data;
  3. c) Request deletion of their personal data where applicable under Article 17 of the GDPR;
  4. d) Obtain restriction of processing under the conditions set out in Article 18 of the GDPR;
  5. e) Object, for legitimate reasons, to the processing of their personal data;
  6. f) Request the transfer of their personal data to another data controller (so-called data portability);
  7. g) Lodge a complaint with the Data Protection Authority.

These rights may be exercised, within the limits and in the manner provided for by the GDPR, by contacting the Data Controller at the following email address: .

The exercise of these rights is subject to certain exceptions aimed at safeguarding the public interest (e.g., prevention or identification of crimes) and our interests (e.g., maintaining legal professional privilege).

However, if you wish, you may submit complaints or reports to the competent data protection authority pursuant to Article 77 of the GDPR, using the contact details below:

Garante per la protezione dei dati personali
Piazza Venezia 11 – 00186 ROME
Phone: (+39) 06.696771
Email:
Certified Email: