ACCESS REQUEST MANAGEMENT POLICY
POLICY FOR MANAGING REQUESTS FOR ACCESS, MODIFICATION, AND DELETION OF PERSONAL DATA
Last update: [publication date]
1. PURPOSE
This Policy describes how data subjects can exercise the rights granted by applicable personal data protection laws in relation to data processed by ZEROTRACCE.
This Policy supplements the Privacy Policy published on the website and does not replace it.
2. DATA CONTROLLER
The entity indicated as the data controller is:
Amerion Group LLC
30 N Gould St #36862
Sheridan, WY 82801
USA
Contact email:
sirius.amerion@gmail.com
3. WHO MAY EXERCISE RIGHTS
Rights may be exercised by the natural person to whom the personal data refers.
Requests may also be submitted by an authorized representative, provided that authorization to act on behalf of the data subject can be adequately verified.
4. HOW TO SUBMIT A REQUEST
Requests regarding personal data can be sent to:
sirius.amerion@gmail.com
Recommended subject line:
PRIVACY RIGHTS REQUEST – [TYPE OF REQUEST]
The request should contain sufficient information to allow for the identification of the data subject and the proper handling of the request.
5. RECOMMENDED INFORMATION
To facilitate the processing of the request, the data subject may provide:
- first and last name;
- email address used on the site;
- order number, if applicable;
- right intended to be exercised;
- description of the request;
- any information useful for identifying the relevant data.
The data subject should not provide information that is excessive relative to what is necessary.
6. RIGHT OF ACCESS
The data subject may request confirmation as to whether or not personal data concerning them is being processed and, in cases provided for by applicable law, obtain access to the personal data and information regarding their processing.
7. RIGHT TO RECTIFICATION
The data subject may request the correction of inaccurate personal data concerning them.
They may also request the completion of incomplete personal data, within the limits provided by applicable law.
8. RIGHT TO ERASURE
The data subject may request the deletion of their personal data in cases provided for by applicable law.
The right to erasure is not absolute.
ZEROTRACCE may be required to retain certain data when necessary to comply with a legal obligation, to exercise or defend a legal claim, or for other purposes provided for by applicable law.
9. RIGHT TO RESTRICTION OF PROCESSING
In cases provided for by applicable law, the data subject may request the restriction of the processing of their personal data.
During the period of restriction, data may only be processed in cases permitted by applicable law.
10. RIGHT TO OBJECT
The data subject may object to the processing of their personal data in cases provided for by applicable law.
When processing relates to direct marketing activities, the data subject may object to such processing in accordance with applicable law.
11. RIGHT TO PORTABILITY
In cases provided for by applicable law, the data subject may receive the personal data provided to the controller in a structured, commonly used, and machine-readable format.
When technically feasible and required by law, the data subject may also request that such data be transmitted directly to another controller.
12. WITHDRAWAL OF CONSENT
When processing is based on the data subject's consent, such consent may be withdrawn at any time.
The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
13. MARKETING AND NEWSLETTER
The data subject may stop receiving marketing communications by using the unsubscribe link included in the communications received.
They may also send a request to:
sirius.amerion@gmail.com
Unsubscribing from marketing communications does not necessarily imply the deletion of all personal data, if other data must be retained for legal, contractual, or other applicable legal bases.
14. COOKIES AND TRACKING TECHNOLOGIES
Preferences regarding cookies and similar technologies can be managed through the tools made available on the site.
For further information, please refer to the Cookie Policy and the cookie preference management page.
15. REQUESTS REGARDING ORDERS
When a request concerns an order, the data subject may indicate the relevant order number.
This allows for faster identification of data linked to the transaction.
The request to exercise privacy rights does not alter obligations related to order management or the retention of documents that must be kept by law.
16. IDENTITY VERIFICATION
To protect personal data and prevent it from being disclosed to unauthorized persons, ZEROTRACCE may take reasonable measures to verify the identity of the requester.
The verification will be proportionate to the risk associated with the request.
ZEROTRACCE will not request information that is unnecessary for verification.
17. REQUESTS SUBMITTED BY THIRD PARTIES
When a request is submitted by another person on behalf of the data subject, it may be necessary to demonstrate the existence of valid authorization.
Information regarding representation will be processed solely to the extent necessary to manage the request.
18. MINORS' REQUESTS
When a request concerns a minor's personal data, additional identity checks may be required, and where relevant, verification of authority to submit the request.
Processing is carried out in accordance with applicable law.
19. NO CHARGE
Exercising these rights is generally free of charge in cases provided for by applicable law.
If a request is manifestly unfounded or excessive, particularly due to its repetitive nature, measures permitted by applicable law may be applied.
20. RESPONSE TIMES
Requests are handled within the timeframes provided by applicable law.
Where permitted, the timeframe may be extended taking into account the complexity and number of requests.
In case of an extension, the data subject will be informed within the timeframes required by law.
21. INCOMPLETE REQUESTS
If the information provided is insufficient to understand or properly handle the request, ZEROTRACCE may request clarification or additional information reasonably necessary.
The requester is invited to respond by providing only the necessary information.
22. IMPOSSIBILITY OF FULFILLING A REQUEST
If a request cannot be granted, in whole or in part, the data subject will receive a response containing, within the limits of applicable law, the reasons for the decision.
The response does not limit the data subject's right to exercise further rights provided by law.
23. DATA RETENTION
Exercising the right to erasure does not automatically imply the deletion of all data.
Some data may be retained when necessary to:
- comply with legal obligations;
- prove the execution of a transaction;
- manage tax and accounting obligations;
- prevent or detect fraud;
- exercise or defend legal claims;
- fulfill other obligations provided by applicable law.
24. SECURITY OF REQUESTS
Requests regarding personal data are handled by adopting reasonable measures to avoid unauthorized access, improper disclosure, or other forms of unauthorized processing.
25. LOGGING OF REQUESTS
Information necessary to manage privacy rights requests may be logged and retained to document:
- the request received;
- the verification performed;
- the activities carried out;
- the response provided;
- any subsequent obligations.
Retention occurs in accordance with applicable law and the Privacy Policy.
26. DISCLOSURE OF DATA TO THIRD PARTIES
When necessary to fulfill a request, parties processing data on behalf of the controller or other authorized recipients may be involved, in compliance with the conditions provided by applicable law.
27. SUPERVISORY AUTHORITY
A data subject who believes that the processing of their personal data violates applicable law may, in cases provided for by law, lodge a complaint with the competent supervisory authority.
For data subjects in the European Union, this may be the data protection authority competent for the specific situation.
28. ITALIAN DATA PROTECTION AUTHORITY (GARANTE)
For matters falling under Italian jurisdiction, the reference authority is:
Garante per la protezione dei dati personali
Official information regarding how to submit complaints and the authority's powers is available on the Garante's official website.
29. NO WAIVER OF RIGHTS
This Policy does not limit or exclude the rights granted to the data subject by applicable personal data protection laws.
Any provision must be interpreted in accordance with applicable law.
30. UPDATING THE POLICY
This Policy may be updated when necessary, including following:
- regulatory changes;
- changes to processing processes;
- introduction or modification of technological tools;
- changes in service providers;
- Privacy Policy updates;
- changes in internal procedures.
The version published on the site is the one applicable from the date indicated in the update.
31. CONTACTS
To exercise rights regarding personal data:
Amerion Group LLC
Email:
sirius.amerion@gmail.com
Recommended subject line:
PRIVACY RIGHTS REQUEST
32. RELATIONSHIP WITH THE PRIVACY POLICY
This Policy must be read in conjunction with the Privacy Policy, the Cookie Policy, and the Cookie Preference Management published on the site.
In the event of a conflict with a mandatory provision of applicable law, the latter shall prevail.
33. UPDATE DATE
Last update: [publication date]