CYBER 4.0 – PRIVACY POLICY SECURE PROJECT
Data Controller
Cyber 4.0 Association
Via Ardito Desio 60 – 00131 Rome
Owner’s email address: privacy@cyber40.it
Contact details of the Data Protection Officer (DPO-Data Protection Officer).
Pursuant to Article 37 of Regulation 2016/679, Association Cyber 4.0 has appointed the Personal Data Protection Officer as lawyer Tiziana Pica, who can be contacted at the following email addresses:
E-mail: dpo@cyber40.it and PEC: tizianapica@ordineavvocatiroma.org
Types of Data Collected
In the context of the Secure Cyber Resiliences for Smes Call (hereafter also just the “Secure Project”) Cyber 4.0 acts as the Data Controller of personal data for the purposes better stated in this policy.
The Data Controller collects and processes the following types of personal data: (i) common personal identification data (including first name, last name, place and date of birth, social security number, telephone contact, email address, residential address) of the legal representative of the registering company and of any collaborators and/or employees of the same entity who are active in the registered team; (ii) any special categories of data (possibly pertaining to ethnic/racial origin); (iii) any judicial data of the legal representative of the registered company.
The Data Subject assumes responsibility for the Personal Data of third parties obtained, published or shared through the channels active on this platform.
Method and place of processing of collected Data
Mode of treatment
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
The processing is carried out by means of computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes. In addition to the Data Controller, in some cases, other subjects involved in the organization, in the management of the Data Controller’s activities (administrative staff, lawyers, system administrators) and/or external subjects (such as third party technical service providers, hosting providers, IT companies, communication agencies) appointed if the conditions pursuant to art. 28 of the GDPR are met as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.
Location
The Data are processed at the Holder’s operational offices and at any other location where the parties involved in the processing are located. For more information, please contact the Data Controller.
The Personal Data of the Data Subject may be transferred to a country other than the country where the Data Subject is located. To obtain more information about the location of processing, the Data Subject may refer to the section on Personal Data Processing Details.
Retention period
Personal Data are processed and kept for as long as strictly necessary or for a duration equal to that required by the purposes of verification, accounting and administration activities proper to the Secure Project for which they were collected and may be kept for a longer period due to any legal obligations.
At the end of the retention period, the Personal Data will be deleted. Therefore, at the expiration of this period the right of access, deletion, rectification and the right to Data portability can no longer be exercised by the individual Data Subject.
Purpose and Legal Basis of Processing
The Data Controller processes Personal Data described above to execute the activities of management and proper conduct of the individual company’s participation in the Secure Project Call.
The Controller processes the Personal Data of the Data Subject only if there is at least one of the following legal bases for processing:
- the processing is necessary for the execution of the individual Enterprise’s enrollment relationship with the Secure Project Application and the management of all financing and reporting relationships arising therefrom;
- processing is necessary to fulfill a legal obligation to which the Controller is subject;
- the processing is necessary for the performance of a task of public interest or the exercise of public authority vested in the Controller;
- processing is necessary for the pursuit of the legitimate interest of the Controller or third parties.
Transmission of Your Data to Third Parties
The Data Controller, as part of the proper and full execution of the existing Convention between the proponents of the Secure Project, may transmit some of your data to third parties such as: the member organizations of the Secure Consortium (INSERT LIST), organizations or individuals supporting the Data Controller for the management of the administrative acts of the proceedings, etc.
Rights of the Data Subject under the General Data Protection Regulation (GDPR)
Data Subjects may exercise certain rights with respect to the Data processed by the Data Controller and, specifically, the right to:
- Revoke consent at any time (Art. 7, para. 3 GDPR).
- Object to the processing of one’s Data. The Data Subject may object to the processing of his or her Data when it takes place under a legal basis other than consent (Art. 21 GDPR).
- Access to one’s own Data. The Data Subject has the right to obtain information about the Data processed by the Data Controller, about certain aspects of the processing and to receive a copy of the Data processed (Art. 15 GDPR).
- verify and request rectification. The Data Subject may verify the correctness of his or her Data and request that it be updated or corrected (Art. 16 GDPR).
- obtain restriction of processing. The Data Subject may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation (Art. 18 GDPR).
- Obtain the deletion or removal of their Personal Data. The Data Subject may request the deletion of his/her Data by the Data Controller (Art. 17 GDPR).
- Receive their Data or have it transferred to another data controller. The Data Subject has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred unhindered to another data controller (Art. 20 GDPR).
- propose complaint. The Data Subject may bring a complaint to the relevant data protection supervisory authority or take legal action.
How to exercise rights
Any requests to exercise the rights of the Data Subject may be addressed to the Data Controller through the e-mail addresses provided in this document. The request is free of charge and the Data Controller will respond as soon as possible, in any case within one month, providing the Data Subject with all the information required by law. Any rectification, deletion or restriction of processing will be communicated by the Controller to each of the recipients, if any, to whom the Personal Data has been transmitted, unless this proves impossible or involves a disproportionate effort. The Data Controller shall notify the Data Subject of such recipients if he or she so requests.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying the Data Subjects through the “News & Events” section active on this website as well as, if technically and legally feasible, by sending a notification to the Users through one of the contact details it has. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Controller will collect consent from the Data Subject, if necessary.
Last updated: January 27, 2026
