DATEV KOINOS Srl processes data provided by users in accordance with the provisions of European Regulation 679/2016 (“GDPR”). This document constitutes an information notice pursuant to Article 13 of the GDPR, for those who interact with the website owned by DATEV KOINOS Srl, login.datev.it, during Internet browsing.
This privacy policy applies solely to this website and does not concern any external websites that may be accessed via links on this site; in such cases, a specific notice will be provided.
Following consultation of this site, data relating to identified or identifiable persons may be processed.
The Data Controller is DATEV KOINOS Srl, Milano, Corso Garibaldi 86 - Taxpayer’s Code number: 03336420967.
2(a) Browsing data
The IT systems and software procedures responsible for the operation of this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes IP addresses, domain names of the computers used by users connecting to the site, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request, and other technical parameters relating to the user’s operating system and IT environment.
Such data are processed exclusively for the purpose of ensuring the proper functioning, maintenance, and security of the website and its associated IT systems.
2(b) Data provided for user account creation, access to software and services, and processing of purchase orders
Users wishing to access the software and services provided by the Data Controller and/or purchase them must log in after registering their profile on the site.
The data processed for registration purposes include: first name, last name, and email address, username and password.
The personal data referred to in point 2(a) are processed solely for the purpose of obtaining anonymous statistical information on the use of the site and to ensure its proper functioning also to ascertain possible responsibility in the event of hypothetical cybercrimes against the site.
The data referred to in point 2(b) are processed to allow registration and creation of the customer account, particularly creating and managing the user’s digital identity and enabling access (Single Sign-On) to other platforms connected to the Controller’s services.
The personal data referred to in point 2(a) are processed by the Controller for the performance of contractual measures pursuant to Article 6(1)(b) of the GDPR, to ensure the proper functioning of the site and on the basis of its legitimate interest pursuant to Article 6 (1) (f) of the GDPR, in relation to the possible activities aimed to keep its IT systems secure, preventing unauthorized access or cyberattacks).
The personal data referred to in point 2(b) are processed by the Controller for the performance of pre-contractual measures adopted at the data subject’s request (such as profile registration) and/or to fulfill contractual obligations, pursuant to Article 6(1)(b) of the Regulation.
No data derived from the site are transferred outside the European Union.
Personal data are processed within the European Union and are not transferred outside the European Economic Area.
Should the Controller transfer personal data outside the European Economic Area in the future, such transfers will be carried out in compliance with Articles 44 et seq. of Regulation (EU) 2016/679 and, where applicable, on the basis of appropriate safeguards, including adequacy decisions adopted by the European Commission, Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs).
Browsing data (including system logs) are retained for a period not exceeding 30 days, unless further retention is necessary to investigate security incidents or comply with legal obligations.
Personal data relating to user accounts are retained for as long as the account remains active, except where the user requests deletion; in such cases, the data will be erased.
Apart from what is specified for browsing data, the provision of personal data is necessary for the creation and management of a user account and for enabling access to the Controller’s digital services through the Single Sign-On system.
Failure to provide such data will make it impossible to complete the registration process and to access the connected platforms and services.
Personal data may be accessed by duly authorized personnel of the Controller who are involved in the management and operation of the website and related services, as well as by third-party service providers acting on behalf of the Controller and appointed as Data Processors pursuant to Article 28 of Regulation (EU) 2016/679.
Such access is limited to what is strictly necessary for the performance of the respective tasks and is granted in accordance with the principles of data minimization and confidentiality. All individuals authorized to process personal data are subject to appropriate confidentiality obligations.
In providing the Service, Datev Koinos will entrust the processing to Datev International GmbH, appointed as sub-processor for the hosting, development, management and maintenance of the technological and systems infrastructure of the Service, as well as for the statistical and technical analysis and for optimizing early problem resolution processes, and Datev.it S.r.l., appointed as sub-processor by Datev Koinos in relation to the assistance services related to https://www.dkcare.it provided to the Client and/or to its end users, and as sub-processor by Datev International GmbH for the technological support and management of the Service.
To obtain and consult an updated list of appointed Data Processors, you may contact: privacy@datevkoinos.it.
The processing of personal data is carried out in accordance with the principles of fairness, lawfulness, and transparency.
Personal data are processed using automated tools for the time indicated in paragraph 6.
Specific security measures are implemented to ensure, among other things, the security, confidentiality, integrity, and availability of systems and services, and to prevent the risk of data loss, unlawful or improper use, and unauthorized access.
Pursuant to Article 37 of the GDPR, Datev Koinos shall designate and appoint a Data Protection Officer (DPO).
The Data Protection Officer is Eng. Paolo Pesarin, domiciled for the purposes of the appointment at the Controller’s registered office.
Data subjects may exercise, at any time, the rights provided for under Articles 15 to 22 of Regulation (EU) 2016/679, including:
Where processing is based on consent, the data subject also has the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Data subjects also have the right to lodge a complaint with a supervisory authority, in the Member State of their habitual residence, place of work, or place of the alleged infringement.
You may exercise your rights at any time by sending: