Privacy notice for customers and suppliers
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”)
Version 1.0 – October 2026
Valli Granulati S.r.l. processes the personal data of the people it deals with in the course of its business relationships. This notice explains which data we process, for what purposes, how long we keep them and which rights the data subjects have.
1. Who this notice is for
- customers and suppliers, including prospective ones, who are natural persons, sole traders or self-employed professionals;
- owners, legal representatives, employees, contractors and contact persons of customers and suppliers that are companies or other organisations;
- drivers, carriers and staff of contractors or suppliers who access our plant;
- people who contact us or leave us their business contact details at trade fairs, meetings or when requesting information.
2. Data controller and contact details
The data controller is VALLI GRANULATI S.R.L., Via Selva 20, 24060 Zandobbio (BG), Italy, VAT and Tax Code IT 01624170161, tel. +39 035 940249, certified e-mail (PEC) valligranulati@pec.it.
For any matter concerning personal data, please write to our internal privacy contact at privacy@valligranulati.it.
The controller has not appointed a Data Protection Officer (DPO), as none of the cases in which an appointment is mandatory applies (Art. 37 GDPR).
3. Data we process
- Identification and contact data: first name and surname, company, role or position, address, telephone, e-mail.
- For sole traders, professionals and private individuals: tax code, VAT number, business or home address, bank and payment details, invoicing data, registration in professional registers where applicable.
- Data relating to the business relationship: requests, quotations, orders, contracts, transport documents, customs documents, invoices, payments, correspondence.
- For vehicles entering the plant: vehicle registration number, weighing data and, where it appears on the transport documents, the driver’s name.
- For contractors and suppliers working at the plant: the documents required by occupational health and safety law, for example the social security compliance certificate (DURC), list of staff employed, training certificates and, where required, only the fitness-for-work assessment, without any diagnostic information.
- Images recorded by the video surveillance system, for anyone entering monitored areas (section 10).
- Technical data of electronic communications exchanged with us (for example e-mail addresses, date and time of messages), processed by our e-mail security and archiving systems.
We do not process data relating to criminal convictions and offences, unless required by law and within the limits set by it.
4. Where the data come from
The data are provided directly by the data subject or by the customer or supplier they work for, for example when it names a contact person, a driver or the staff who will work at our premises. They may also come from publicly available sources (company register, professional registers, company websites) and from parties involved in performing the supply, such as carriers and freight forwarders.
5. Purposes, legal bases and retention periods
| Purpose | Legal basis | Retention |
|---|---|---|
| A. Pre-contractual and contractual relationship: requests for quotation, quotations, orders, production and deliveries, loading, unloading and weighing of vehicles, customer service and complaints, supplier qualification and evaluation under our quality management system. | Performance of a contract or pre-contractual steps (Art. 6(1)(b)) where the data subject is the customer or supplier. Otherwise, the controller’s legitimate interest in managing its relationship with the organisation the data subject works for (Art. 6(1)(f)). | Duration of the relationship plus 10 years after it ends. |
| B. Administrative, accounting, tax and customs obligations: invoicing, including e-invoicing through the Italian exchange system (SdI), accounting, payments, document retention, customs and export formalities, checks by statutory auditors and the board of auditors. | Legal obligation (Art. 6(1)(c)). | 10 years from the last entry (Art. 2220 Italian Civil Code) or any longer period required by tax or customs law. |
| C. Health and safety in contracted work and plant access: verification of technical and professional suitability, cooperation and coordination, interference risk assessment (DUVRI), access management. | Legal obligation (Art. 6(1)(c); Art. 26 Italian Legislative Decree 81/2008). For fitness-for-work assessments: Art. 9(2)(b). | Duration of the contract plus 10 years after it ends. |
| D. Protection of rights: unpaid invoices and payment reminders, debt collection, disputes and litigation. | Legitimate interest in protecting the controller’s rights (Art. 6(1)(f); for any special category data, Art. 9(2)(f)). | Until the matter is settled; in case of litigation, for its whole duration and until the time limits for appeal have expired. |
| E. Marketing communications to customers: e-mails about products and services similar to those already purchased. | Legitimate interest (Art. 6(1)(f)) and Art. 130(4) Italian Legislative Decree 196/2003. Customers may object at any time, including via the link in every message. | Until the customer objects and in any case no longer than 24 months after the last order. |
| F. Prospective customers and suppliers: replying to requests for information and following up with people met at trade fairs or meetings who have given us their contact details. | Pre-contractual steps at the data subject’s request (Art. 6(1)(b)) or legitimate interest in developing business relationships (Art. 6(1)(f)). Newsletters and promotional messages are sent to prospects only with their consent (Art. 6(1)(a)), which may be withdrawn at any time. | 24 months after the last contact; where consent was given, until it is withdrawn. |
| G. Security of IT systems and company assets: protection of e-mail from spam and malware, security event logging, backups, archiving of correspondence, video surveillance. | Legitimate interest in the security of systems and the protection of company assets (Art. 6(1)(f)); obligation to implement appropriate security measures (Art. 32 GDPR). | Business correspondence: 10 years (Art. 2220 Italian Civil Code). Logs and backups: as set by internal procedures. Images: as stated in the video surveillance notice. |
When the retention periods expire, the data are deleted or anonymised.
6. Whether providing data is mandatory
Providing the data for purposes A, B and C is necessary: without them we cannot enter into or perform the relationship or comply with our legal obligations. Consent to receive promotional messages (purpose F) is optional and refusing it has no consequences for the relationship.
7. How we process the data
Data are processed on paper and electronically, with technical and organisational measures appropriate to the risks (Art. 32 GDPR). They are handled by staff authorised and instructed by the controller, each within their own remit: sales, administration, purchasing, logistics and shipping, quality, health and safety, and IT.
No decisions are taken based solely on automated processing, including profiling (Art. 22 GDPR).
8. Who we share the data with
For the purposes above, the data may be disclosed to:
- tax authorities, the Italian Customs and Monopolies Agency, other public bodies and authorities, including judicial authorities, where required by law;
- banks and payment institutions, for collections and payments;
- carriers, couriers, freight forwarders and customs brokers, chosen by the controller or by the customer depending on the agreed Incoterms;
- tax, legal and employment advisers, statutory auditors and the board of auditors, the quality system certification body, insurance companies;
- other customers or suppliers, occasionally and only where needed to perform the supply, for example a driver’s contact details to coordinate a delivery;
- parties involved in extraordinary corporate transactions (mergers, demergers, contributions or transfers of business), to the extent necessary.
These recipients process the data as independent controllers.
The controller also uses suppliers that process data on its behalf as processors (Art. 28 GDPR), bound by a written agreement: providers of management software, e-mail and cloud services, e-mail security and archiving, certified e-mail (PEC), website hosting, and IT support and maintenance. The up-to-date list of processors is available on request at privacy@valligranulati.it.
The data are not made public.
9. Transfers outside the European Economic Area
Where the customer or supplier is established outside the European Economic Area (EEA), the data needed to perform the contract are disclosed to that party and, where necessary, to carriers, freight forwarders and customs authorities in the country of destination. If there is no European Commission adequacy decision for that country, the transfer takes place because it is necessary for the performance of the contract with the data subject or with the organisation they work for (Art. 49(1)(b) and (c) GDPR).
Some IT service providers may process data outside the EEA. In that case the transfer is based on an adequacy decision, including the EU-U.S. Data Privacy Framework for participating companies, or on the standard contractual clauses adopted by the European Commission (Art. 46 GDPR). Information on these safeguards is available at privacy@valligranulati.it.
10. Video surveillance
Some areas of the plant are under video surveillance to protect company assets and the safety of people. These areas are marked by signs. The full video surveillance notice is available at our premises and on request.
11. Data subjects’ rights
Data subjects may exercise the following rights:
- access to their data (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction of processing (Art. 18);
- portability of the data they provided (Art. 20), where processing is based on contract or consent and carried out by automated means;
- objection (Art. 21) to processing based on legitimate interest, on grounds relating to their particular situation, and to marketing communications, at any time and without giving reasons;
- withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Requests can be sent to privacy@valligranulati.it or by registered letter to the controller’s address. We reply within one month; this may be extended by two further months for complex requests (Art. 12 GDPR).
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of their EU country of residence or workplace, or to apply to the courts.
12. Informing the staff of customers and suppliers
We ask customers and suppliers that provide us with data about their staff or contractors to make this notice available to them.
13. Updates
This notice may be updated. The current version is published at www.valligranulati.it. In case of discrepancy between language versions, the Italian version prevails.