Why this notice?
This page describes the methods of management of the Websites of UniCredit S.p.A., with reference to the processing of the personal data of users who consult it. This is a disclosure made also under the terms of Art. 13 and 14 of Regulation EU 2016/679 to those who interact with the web services of UniCredit S.p.A., accessible by electronic means via the addresses:
corresponding to the homepages of the UniCredit S.p.A. websites. The disclosure is made only for the UniCredit S.p.A. websites and not also for any other websites consulted by the user through links.
The disclosure is based also on Recommendation No 2/2001 which the European Personal Data Protection Authority, meeting as the Working Party established by Art. 29 of Directive 95/46/EC, adopted on 17 May 2001 to identify certain minimum requirements for the on-line gathering of personal data and, in particular, the methods, times and nature of the information that Data Controllers must provide to users when they visit web pages, irrespective of the purposes of the visit.
The "Data Controller"
Following consultation of this website, data on identified or identifiable persons may be processed. The "data controller" is UniCredit S.p.A., whose Registered Office is in Piazza Gae Aulenti, 3, Tower A - 20154 Milan.
In case of data processing running, within the various sections of the website will be pointed out the relevant Data Processors.
Place of data processing
The processing of data connected with the web services of this site takes place at the above Headquarters and also at the office in Via Livio Cambi, 1, in Milan and is performed only by the personnel of UniCredit S.p.A., in charge of the processing, or by employees of UniCredit Services S.C.p.A., the "Data Processor" designated by the controller UniCredit S.p.A.
No personal data deriving from the web service is disseminated.
The personal data provided by users are used for the sole purpose of performing the service or task requested and are communicated to third parties only when necessary for this purpose.
Types of data processed
During their normal operation, the information systems and software procedures used for the functions of this websites acquire certain personal data the transmission of which is implicit in the use of the Internet, which is based on the TCP/IP protocol.
This is information which is not gathered to be associated with identified data subjects, but which by its very nature could, through processing and association with data held by others, enable the users to be identified.
This category of data includes the "IP addresses" or domain names of the computers used by users who visit the website, the addresses in URI (Uniform Resource Identifier) format of the resources requested, the time of the request, the method used in submitting, the request to the web server, the dimensions of the file obtained in response, the numerical code indicating the state of the response given by the web server (success, error, etc...) and other parameters relating to the user's operating system and IT environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the websites and to check the correct operation of the UniCredit S.p.A. websites.
It should be noted that the above data could be used to ascertain responsibility in the case of computer crime which harms the UniCredit S.p.A. website or the structures of the data processor UniCredit Services S.C.p.A., or other websites connected or linked to it: except in this case, the navigation data are deleted immediately after the related statistical processing and in any case, they are kept for 24 months from the time of collection.
Data provided voluntarily by the user
Requests to send e-mail to the addresses indicated in the relevant section of the UniCredit S.p.A. website entail the subsequent acquisition of certain personal data of the applicant, including the applicant's e-mail address, necessary to respond to the requests.
Specific summary disclosures will be progressively contained or displayed on the pages of the website prepared for these particular services on request
Call CenterThe systems and procedures arranged for operation of the Bank's Call Center acquire certain data in relation to customers' calls. This category includes the caller's remote number (if not hidden), the navigation data in the IVR call flow (that is the actions/key pad inputs that the customer performs to gain access to the various services), duration of the call, and, only in the cases expressly envisaged and after notifying the caller, audio recording of the call.
The above data are processed in order to obtain anonymous statistical information on the use of the Call Center, to check that it is operating correctly and to ensure its security, as well as for the aware of responsibility in the event of any crimes that damage the Bank or its customers.
Optionality of conferment of personal dataApart from the details provided for navigation data, users are free to provide their personal data included in the specific electronic request forms, in the sections of the website prepared for the particular services on request.
It should be noted, however, that failure to provide such information may make it impossible to fulfil the request.
Processing method and security measuresThe personal data are processed with automated and non-automated instruments, only for the time strictly necessary to achieve the purposes for which they have been gathered. Specific security measures are observed to prevent loss of data, illegal or incorrect uses and unauthorized access.
In particular, in the sections of the website prepared for particular services, where personal data are requested from users navigating the site, the channel through which the data transit is encrypted by means of a security technology entitled Secure Sockets Layer & Transport Layer Security, abbreviated as SSL/TLS. The SSL/TLS technology makes available an encrypted channel in which information transits before it is exchanged via the Internet between the user's computer and the UniCredit S.p.A. central systems, making it incomprehensible to unauthorized persons and thus guaranteeing the confidentiality of the information transmitted.
The use of SSL/TLS requires however a compatible browser capable of "swapping" a security key with a minimum length of 128 bits, necessary to establish the said secure connection with the UniCredit S.p.A. central systems.
Rights of data subjectsThe data subjects to whom the personal data - which may be collected in the aforementioned specific sections - refer, have the right, pursuant to art. 15 and following of the above mentioned Regulation, to know at any time what personal data are held by UniCredit S.p.A. and how these data are used (Right of access), to obtain updating, correction or, if there is interest, integration, as well as cancellation, anonymization or limitation and may at any time revoke, where issued, consent to the processing of data: for purposes of sending commercial and advertising material, for direct sales or market research (i.e. direct marketing) and for profiling and marketing enrichment purposes.
Any such requests must be sent to:
Via Del Lavoro, 42
Tel.: +39 051.6407285
Fax: +39 051.6407229
MinorsUniCredit S.p.A. does not knowingly use its website to request data from persons of less than 18 years of age.
Data processors appointed by UniCredit
Lists are available at the following link (Destinatari o categorie di destinatari dei dati personali section):
SOCIAL MEDIA MONITORING ACTIVITY MADE BY UNICREDIT S.P.A.
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
1 Data Controller and Data Protection Officer
The Data Controller is UniCredit S.p.A., with registered office in Milan, Piazza Gae Aulenti n. 3, Tower A, 20154 Milan (UniCredit).
You can contact the Data Protection Officer at:
Data Protection Office
Piazza Gae Aulenti n. 3
Tower A, 20154 Milan (MI)
2.PURPOSES AND LEGAL BASIS OF THE PROCESSING
UniCredit wishes to understand the public sentiment towards its brand and to monitor the perception of its products, services or campaigns, through research carried out on information in the public domain. UniCredit, in the pursuit of this interest, may process some personal data referring to online users and users of Social Media, Forums, Blogs, other digital sites or digital media (the "Data Subjects").
The legal basis of the processing is the legitimate interest of UniCredit to understand the public sentiment about its brand and to monitor the perception of its products, services or campaigns, through research carried out on information in the public domain.
The processing is carried out according to logic strictly related to the purposes described above and, in any case, in such a way as to guarantee the security and confidentiality of the data concerned.
3.CATEGORIES OF DATA PROCESSED
UniCredit collects and analyses data present in social media and in various online sources, including forums, blogs and online news sites, intentionally made public by the Data Subjects, among which there could be personal data referring to the Data Subjects themselves. Therefore, only information in the public domain will be processed. Such information may also include individual quotes or personal data such as personal details (e.g. name, surname, address, etc.). Such personal data are processed mainly in an aggregate manner for the purposes described above. No personal data referring to a specific Data Subjects are intentionally processed, nor is any monitoring of a specific Data Subjects carried out. However, it is possible that individual quotations are taken and used to understand a general attitude towards UniCredit.
4.RECIPIENTS OR CATEGORIES OF RECIPIENTS OF PERSONAL DATA
For the purposes of the processing activities described above and necessary to analyze the public sentiment towards UniCredit, UniCredit may make use of platforms and analysis activities of external suppliers, who will act as autonomous data controllers or as data processors appointed by UniCredit.
The topics to be monitored have been strictly circumscribed and it is also ensured that the persons acting under the authority of UniCredit and having access to the personal data of the Data Subjects follow precise instructions and obligations of confidentiality.
Further to that, only a limited number of persons authorised by UniCredit may access to the personal data referring to the Data Subjects.
5.DATA SUBJETCS' RIGHTS
The GDPR grants individuals, sole proprietorships and/or freelancers the rights referring to in articles from 15 to 22 of GDPR, including the right to know what personal data is held by UniCredit and how it is used (Right of Access), to obtain the updating, rectification or, if interested, integration of such data, as well as their erasure, transformation into anonymous form or limitation.
5.1. PERIOD OF DATA STORAGE AND RIGHT TO ERASURE (i.e. RIGHT TO BE FORGOTTEN)
UniCredit will keep the personal data referring to the Data Subject per the period strictly necessary to achieve the purposes specified above and, in any case, for a maximum period of six months.
6.HOW EXERCISE YOUR RIGHTS
In order to exercise the rights, set forth in the previous paragraph, each Data Subject may apply to:
Group Brand Management & Communication Intelligence
Group Media Relations
Piazza Gae Aulenti n. 3
Tower A - 20154 Milano (MI)
Tel. +39 02 88623569
The deadline for the reply is one (1) month, which may be extended by two (2) months in particularly complex cases; in these cases, UniCredit will provide at least one interim communication within one (1) month.
The exercise of the rights is, in principle, free of charge; UniCredit reserves the right to charge a fee in the event of manifestly unfounded or excessive requests (including repetitive ones).
UniCredit has the right to request information necessary for the identification of the applicant
7.COMPLAINT OR REPORT TO THE PERSONAL DATA PROTECTION AUTHORITY
UniCredit informs the Data Subjects about the right to file a complaint or a report to the Italian Data Protection Authority or alternatively to appeal to the Judicial Authority. The contacts of the Italian Data Protection Authority are available on the websit: http://www.garanteprivacy.it.