With this document, we wish to inform you that in accordance with the Italian legislation applicable pro tempore on the protection of personal data and with EU Regulation 679 – 2016 – General Data Protection Regulation (GDPR), we recognize the importance of the protection of personal data and consider their protection one of the main objectives of our business.

In compliance with and in accordance with the provisions of the GDPR and the Italian legislation in force on the matter, the processing of data will therefore be based on the principles of correctness, lawfulness and transparency, minimization, accuracy and integrity, in strict compliance with the fundamental rights and freedoms as well as the dignity of the interested party, with particular reference to confidentiality, personal identity and the right to data protection.

Pursuant to articles 13 and 14 of the GDPR, our company, as “data controller”, provides you, as “data subject”, with the following information regarding the processing of your data.

1. Data controller

The Data Controller is the Amateur Sports Association for Social Promotion OVER2000RIDERS in the person of the legal representative Mr. Mario Guerra, with registered office in Corso Galileo Ferraris 118, 10129 Turin, VAT number 10784290016 and Tax Code 97716620014; email address: info@over2000riders.com ; telephone +393357260239.

To exercise your rights and to receive any information relating to them and/or this information, you may therefore write to the email address indicated above.

The Data Controller, also through its specifically designated and duly trained representatives, will take charge of your request and provide you with the information as soon as possible.

We inform you that if the Data Controller has doubts about the identity of the natural person submitting the request, he/she may carry out the appropriate investigations necessary to confirm the identity of the interested party.

2. The data we process

“Personal data” means any information relating to an identified or identifiable natural person with particular reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, mental, economic, cultural or social identity of that natural person.

The personal data that we process are those provided directly and voluntarily by you, as the interested party, such as name, surname, date of birth, telephone number, e-mail address, home address, tax code, nationality, payment information.

Among the data provided by you there may also be some personal data defined as "special" by the GDPR and, specifically, those that reveal racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, as well as genetic data, biometric data intended to uniquely identify a natural person, data relating to health or sexual life or sexual orientation.

Such data will be processed in compliance with the applicable legislation, only for the purposes indicated below, assuming that they are referred by you or by third parties who have expressly authorized you to provide them on the basis of an appropriate legal basis that legitimises the processing of the data in question. With respect to this hypothesis, you act as an independent data controller and assume all legal obligations and responsibilities, granting us the broadest indemnity with respect to any dispute, claim or request for compensation for damages that may be received by us from third parties whose personal data have been processed by you in violation of current legislation.

3. Purpose and legal basis of the processing

Your personal data are collected and processed for the following purposes:

  1. Purpose: marketing, direct marketing, and specifically:

-send informative material or other advertising and commercial communications aimed at informing you about our initiatives (e.g. information on events organised by OVER 2000);

respond to your requests regarding events organised by OVER 2000;

– send the periodic newsletter and/or the information material and/or the desired white papers/reports;

– inform interested parties about developments or new editions of newsletters, white papers, reports, events,

as well as on initiatives connected to them, including promotional or commercial ones;

  • allow you to register for events we organize;

  • send you informative and promotional communications relating to services and/or products offered by us.

Indirect marketing, specifically:

  • Send informative and advertising communications regarding goods and/or services of

third parties belonging mainly to the tourism and motorcycling sectors.

Profiling activities, i.e. analysis, including through the administration of satisfaction questionnaires and with fully or partially automated methods, of your travel preferences and consumer habits, as well as market research for the purpose of improving the offer of services and commercial information presented by us or our commercial partners, making them more in line with your interests.

Legal basis: art. 6.1 lett. a) GDPR (consent).

Nature of the provision: optional.

Processing methods: Your data may be processed both using automated methods (for example, e-mail, direct e-mail marketing systems, text messages, instant messaging applications, etc.) and using non-automated methods (for example, postal mail, telephone, etc.).

3 Rights of the interested party:

You have the possibility to oppose such processing at any time, initially or on the occasion of subsequent communications, easily and free of charge also by writing to the email address indicated in the previous art. 1, as well as to obtain an immediate response confirming the interruption of such processing (art. 15 of the Regulation).

In any case, you will have the right to: a) obtain human intervention to review the automated decision; b) express your opinion on this automated decision and, in the event of a dispute, we will take care of recording your dispute.

Consequences of refusal:

Your refusal to process your data for these purposes will prevent us from offering you our services and from learning about our commercial offers.

Your personal data are collected and processed for the following purposes.

  1. Purpose: contractual performance

Your personal data will be processed for:

  • acquire the preliminary information necessary for the conclusion of the contract that you intend to stipulate with us, having as its object your participation in one of the events that we organize;

– fulfill our contractual obligations and perform the requested services;

– send you service communications.

Legal basis: art. 6.1 letter b) and art. 9.2. lit. a) GDPR.

Nature of the provision: necessary.

Consequences of refusal: Your refusal to process your personal data for these purposes will prevent the conclusion of the contract and will not allow us to perform our service and, therefore, will prevent you from participating in the requested event. It could also expose you to possible liability for breach of contract.

Special data: our processing of your so-called “special” data for these purposes always requires your express consent (art. 9.2 lett. a) GDPR). However, in the absence of such consent, we may not be able to fulfill certain contractual obligations and guarantee you the specific assistance you have requested.

  1. Purpose: legal obligation and protection of vital interests

Your personal data, including sensitive data, may also be processed for:

  • to execute obligations established by laws, regulations, national and/or community standards and/or deriving from provisions issued by authorities responsible for this which we are in any case obliged to comply with;

  • to ascertain, exercise and/or defend our rights in court;

  • to protect your vital interests or those of another natural person.

Legal basis: art. 6.1 letter c) and d) and art. 9.2. lit. b) and c) GDPR.

Nature of the provision: necessary.

4. Categories of recipients

Your data will not be disclosed and may be communicated and shared exclusively for the purposes specified above to the following categories of subjects:

  1. our internal staff, duly trained and authorized to process personal data pursuant to art. 29 GDPR, according to specific instructions given by the Data Controller.

  2. entities that typically act as data controllers pursuant to art. 28 GDPR, namely:

  • people, companies or professional firms that provide assistance and consultancy services to us in the organisation and implementation of events (including organisational secretariat);

  • people, companies, associations or professional firms that provide services or assistance and consultancy activities in our favour to protect our rights and/or legitimate interests (for example: accountants, lawyers, tax consultants, auditors, etc.);

  • our external suppliers who provide services related to the management and/or storage of data and/or technical maintenance (including maintenance of IT equipment), in order to guarantee compliance with the security requirements set out in the legislation;

  • people, companies or agencies that provide marketing, market analysis and research services, credit card payment management;

  • persons whose right to access your data is recognised by provisions of law and/or secondary regulations and/or by provisions issued by authorities authorised to do so by law.

The list of subjects to whom the data is communicated is available at our company.

5. Processing methods

The methods and criteria for data processing will be those naturally connected and necessary to the pursuit of the indicated purposes.

The processing may be carried out not only manually and with paper supports, but also by means of electronic or otherwise automated, computerised and telematic tools, or by means of manual processing with logic strictly related to the purposes for which the data are collected and, in any case, in such a way as to guarantee their security in any case.

Personal data may also be processed and stored through a partially or fully automated decision-making process.

Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.

  1. Transfers of personal data

Your personal data may be transferred abroad to third-party companies belonging or not to the European Union, always within the scope of the protection of your rights and exclusively for the purposes indicated above.

With regard to any transfer of data to third countries outside the European Union, the processing will take place according to one of the methods permitted by current law, such as the consent of the interested party, the adoption of Standard Clauses approved by the European Commission, the selection of subjects adhering to international programs for the free circulation of data (e.g. EU-USA Privacy Shield) or operating in countries considered safe by the European Commission.

7. Data retention and protection measures

Your personal data will be stored for a period of time not exceeding that necessary to achieve the purposes for which they were collected and subsequently processed in compliance with the principles of minimization and limitation of storage pursuant to art. 5.1. letter e) GDPR.

Therefore, if personal data is processed for two different purposes, we will retain such data until the purpose with the longest term ceases to exist, however we will no longer process the personal data for that purpose whose retention period has expired.

Your personal data that is no longer necessary, or for which there is no longer a legal basis for its retention, is irreversibly anonymised (and may be retained in this way) or securely destroyed.

Direct and indirect marketing purposes, including profiled marketing:

personal data may be retained for 24 months from the date on which we obtained your last consent for this purpose (except for opposition to receiving further communications).

Contractual purposes or those arising from legal obligations: personal data will be retained for the time necessary to fulfill all obligations set forth in the contract as well as for the legal obligations established by current legislation, including secondary legislation, and in any case within 10 years from the termination of the contract or, if subsequent, from a binding decision issued by an administrative or judicial authority. In any case, any obligations to retain data for longer periods of time remain in place if prescribed by law in relation to particular categories of data, or if this is necessary to protect the rights of our company, as Data Controller, in the event of any disputes arising.overare linked to the provision of the service.

The personal data collected to evaluate the conclusion of the contract, in case of failure to complete the same, will be deleted within 12 months.

In any case, if you decide to withdraw your consent or to oppose the processing, your data will be deleted within 30 days of your request, if the conditions exist.

We also specify that we will store your data using operating systems and hardware infrastructures located within the European Union, as well as software capable of guaranteeing high levels of integrity, availability and confidentiality of information, adopting adequate technical and organizational measures, in compliance with the provisions of art. 32 of the GDPR.

Any data provided and/or processed on paper will be stored in rooms and cabinets equipped with suitable devices.

8. Rights of the interested party

In relation to the processing described in this document, pursuant to articles 15 to 22 of the GDPR, you as the interested party have the following rights:

  • right of access: the right to obtain confirmation as to whether or not personal data concerning you are being processed and, where that is the case, to obtain access to your data (including a copy of the same) and to have information on: a) the purposes of the processing; b) the recipients or categories of recipients to whom your personal data have been or will be communicated, in particular whether your data are or will be transmitted to recipients in third countries or to international organisations, as well as on the existence of appropriate guarantees; c) the period for which the personal data will be stored; d) available information as to their source if the data are not collected from you.

  • right of rectification: right to obtain the rectification and/or correction of inaccurate personal data concerning you or the integration of incomplete data.

  • right to be forgotten: the right to obtain the erasure of your personal data if one of the hypotheses specified in art. 17 GDPR applies.

  • right to restriction of processing: right to obtain restriction of processing where one of the hypotheses specified in art. 18 GDPR applies.

  • right to data portability: the right to receive your personal data in a structured, commonly used and machine-readable format, as well as to transmit them to another data controller without hindrance, where the processing has been carried out by automated means.

  • right to object: right to object, at any time, for reasons related to your particular situation, to the processing of personal data concerning you even if the same is based on the condition of lawfulness of legitimate interest, without prejudice to the right of the Data Controller to continue the processing where this prevails over your interests, rights and freedoms or when it is necessary for the ascertainment, exercise and defense of a right in court.

You may also object at any time to the processing of your data if they are processed for marketing purposes, by selecting “unsubscribe” at the bottom of the email containing communications related to marketing activities or by sending a specific request to our email address indicated in art. 1.

  • right of withdrawal: the right to withdraw your consent to the processing of your personal data at any time (except where the processing is necessary to comply with a legal obligation to which the data controller is subject).

  • right to complain:

For any complaints or reports on how we process your data, we will make every effort to respond to your concerns. However, if you wish, you may forward your complaints or reports to the data protection authority, using the relevant contact details: Garante per la protezione dei dati personali:

  • Montecitorio Square No. 121

– 00186 ROME

– Fax: (+39) 06.69677.3785

– Telephone: (+39) 06.696771

– Email: garante@gpdp.it

– Certified mail: protocollo@pec.gpdp.it

You may exercise these rights and/or obtain further information on the processing of personal data by sending a communication to the email address specified in art.1.

If you exercise any of the above rights, we will verify that you are entitled to exercise them and will respond, as a rule, within one month.