1. Identity and contact details of the Controller
The Controller is Trans Tunisian Pipeline Company SpA, with registered office in San Donato Milanese, Piazza Ezio Vanoni, 1 , 20097 San Donato Milanese (MI), which can be contacted through the following email address: firstname.lastname@example.org.
2. Contact details of the Data Protection Officer
The Company has appointed a Data Protection Officer, who can be contacted at the email address DPO@eni.com.
3. Purposes and legal basis of the processing
a. Necessary legal and contractual purposes – processing is necessary for compliance with a legal obligation to which the controller is subject or to execute a specific request of the data subject
User’s personal data may be processed without his/her consent in cases where this is necessary in order to comply with obligations deriving from laws, regulations, codes or procedures approved by authorities or other competent institutions.
User’s personal data will also be processed for purposes relating and/or connected to the provision by the Company of services for the navigation of the Website. Given that providing data for these purposes is necessary to maintain and deliver all the services connected to navigating the Website, failure to provide such data will make it impossible to provide the specific services in question.
During normal use by Users, the Website acquires through its IT systems and software procedures for the functioning some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes IP addresses or domain names of computers and terminals used by users, URI/URL (Uniform Resource Identifier/Locator) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.) and other parameters relating to the operating system and computer environment.These data, necessary for the use of web services, are also processed for the purpose of:
- obtain statistical information on the use of the services (most visited pages, number of visitors per time slot or day, geographical areas of origin, etc.);
- check the correct functioning of the services offered.
4. Recipients of the personal data
n pursuit of the purposes indicated above, the Controller may communicate User’s personal data to third parties, such as those belonging to the following organisations or categories of organisations:
- police forces, armed forces and other public authorities, to comply with obligations set out by law, regulations or EU legislation. In such cases, there is no obligation under applicable data protection legislation to obtain the data subject’s prior consent to these communications.
- other companies contractually linked to the Data Controller that provide consultancy, support for the provision of services, etc.
The Controller warrants that the utmost care will be taken to ensure that the communication of User’s personal data to the aforementioned recipients only involves the data necessary to achieve the specific purposes for which they are intended. User’s personal data is stored in the Controller’s database and will be processed exclusively by authorised personnel. Said personnel will be given specific instructions on the methods and purposes of the processing. The data will not be disclosed to third parties except as provided above and, in any case, within the indicated limits.
Finally, we remind that User’s personal data will not be disseminated, except in the cases described above and/or the cases required by law.
5. Data storage period
The data will be stored for a period not exceeding the time necessary to fulfil the purposes for which it was collected or subsequently processed in accordance with legal obligations.
6. Rights of data subjects
As a data subject, User has the following rights over the personal data collected and processed by the Controller for the purposes indicated above: (i) the right of access, in particular to request at any time confirmation of the existence of his/her personal data in the Company’s archives and the making available of this information in a clear and intelligible form, and the right to know the origin, logic and purpose of the processing with express and specific indication of the data supervisors and processors and the third parties to which User’s data may be communicated; (ii) the right to have his/her data updated and rectified (except for subjective data), to have superfluous data erased or anonymised, and to block processing and to have his/her data definitively erased in the event of unlawful processing; and (iii) where the conditions are met, to restrict processing and data portability. The law also grants data subjects the right to complain to the Supervisory Authority for Personal Data Protection if they become aware of a violation of their rights under applicable personal data protection legislation.