Privacy Policy - Information pursuant to articles 13 and 14 of EU Regulation no. 2016/679 ("GDPR") Last update: 06.03.2019 The data controller is: • GSW Srl, with registered office in Via Guido Rosato N 56 Lanciano CHIETI; • - Italian Company, hereinafter referred to individually as "Owner". The Owner has appointed a person responsible for the protection of personal data ("Data Protection Officer" or "DPO"), which you can contact to exercise your rights, as well as to receive any information relating to them and / or this information, writing to gruppogsw@live.it. The protection and respect of your personal data are important for the owner. This information (together with the Terms of use of our platform and any other document to which reference is made) indicates the bases under which any personal data collected from you or supplied by you will be treated by us. We invite you to carefully read the following in order to understand our vision and our practices regarding your personal data and the related processing methods. By visiting the sites www.arriva.it and estore.arriva.it or providing the information and personal data in the cases described below, you are acknowledging and, where appropriate, consenting to the treatments described in this statement. 1. What personal data do we collect? • Data provided by you. By filling in the forms available on our website. (the "Sites") or by contacting us by phone, e-mail or other means, you will provide us with your personal data. In addition, you will also provide us with your personal data on other occasions such as, for example, when you register for use of the Sites, to download and use our App, subscribe to our services, purchase tickets, use the Wi- service Fi present on our vehicles, participate in a competition, promotion or survey, report a problem concerning our sites or make a complaint, propose your candidacy in the "work with us" section, or propose other reports in the appropriate area (ex .: lost objects). The personal data you provide to us on such occasions could include your name, date of birth, address, e-mail address and telephone number, your origin (understood as a nationality, including the Region), financial information such as, for example, credit card information, your photo, geographic location, IP or MAC address or other details regarding the use of your mobile device or laptop computer. • Data collected by us. Whenever you access or visit our Sites, like the App, we may automatically collect the following information about you: • technical information, such as the IP address used to connect your mobile device or computer to the Internet , your login information, browser type and version, time zone settings, browser plug-in type and version, system and operating platform; 2 • information about your access, including the entire URL, clicks flows to, through and from our sites (including date and time); products that you have viewed or searched for; page response times, download errors, duration of visits to certain pages, information on page interaction (such as scrolling, clicking and mouse-over) and methods used to navigate from the page and any phone number used to contact the service customers. • Information we receive from other sources. We may receive information about you if you use any other site that we manage or use other services we provide. We also work closely with third parties (including, but not limited to, business partners, sub-providers of technical, payment and delivery services, analytical providers, research information providers, credit agencies) and we may receive information from you on you. • Data belonging to particular categories (so-called sensitive data). We will not intentionally or systematically attempt to collect, store or otherwise use information about you qualified as "special categories of data" or "sensitive data" (for example, information relating to joining a trade union, ethnic origin or information relating to health status). 2. Cookies Our Sites use cookies in order to be able to distinguish you from other users of our Sites. This allows us to provide you with an optimal browsing experience when you visit our Sites and to improve our sites. For more information on the cookies we use and the purposes for which we use them, we invite you to read our Cookie policies saved on the Sites. 3. Purpose and legal basis of the treatments You provide: we use the information you provide for the following purposes and by virtue of the legal bases of treatment set out below: Aims of treatment Legal basis of processing a) Fulfillment of obligations under national or community laws, regulations and / or regulations, or by supervisory and control bodies or by judicial authority or by other legitimate authorities. Fulfillment of a legal obligation on our part. b) Satisfaction of the requests formulated by you from time to time by filling in the appropriate forms available on the Sites. Execution of the contract / satisfaction of the request of the interested party. c) Satisfaction of your request for registration to the Sites and provision of related services (eg: purchase of travel documents). Execution of the contract / satisfaction of the request of the interested party. d) Sale of the ticket (s) for the trip selected by you. Execution of the contract / satisfaction of the request of the interested party. e) Management of applications and curricula vitae, for the purposes of the possible selection and conclusion of a work or collaboration contract Execution of the contract / satisfaction of the request of the interested party. 3 f) Sending communications of a commercial nature (including newsletters) on the activities and services of the Data Controller's legitimate interest g) Geolocation of your position in order to allow us to provide you with more accurate information regarding the means and routes available Consent. h) Profiling for statistical or marketing purposes (for the purpose of carrying out market research, for sending commercial communications, for subscribing to newsletters) in order to provide information for a customized offer of products and services (our or our business partners). Consent. Data collected by us. The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified interested parties, but by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the Sites, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (successful, error, etc. ) and other parameters relating to the operating system and the user's IT environment. These data constitute the register of connections. This data is used by Arriva Italia for the sole purpose of obtaining anonymous statistical information on the use of the Sites and to check its correct functioning. The register of connections is then kept available to the Judicial Authority and exhibited only upon explicit request. Legal basis of the processing and nature of the provision. As you can see, the legal basis of the treatments described above depends on the personal data collected and processed from time to time as well as the specific context in which they are collected. Except for the purpose of sending commercial communications and geolocation, as well as profiling, indicated in the previous table respectively under letters f) g) and h), the provision of personal data for the purposes indicated in the previous table in letters a), b), c), d) and e) is mandatory. Therefore, your refusal to provide your personal data will not allow us to provide you with the information, services and, in any case, the response to your request made through the Sites. Otherwise, for the purpose of sending commercial communications of referred to in letter f) of the previous table, the provision of personal data is optional, with the consequence that your refusal will not prevent us from following up the request you formulated through the Sites. Similarly, for the purpose of geolocation ( letter g) of the previous table), the provision of personal data is not mandatory. Therefore, any refusal to provide your personal data for this purpose will not prevent us from satisfying your request through the Sites in any case but only to provide you with 4 more accurate information regarding the means and routes available. With reference to geolocation - which is based on your consent, we inform you that, at any time, you have the right to revoke the consent given. In the same way, you have the right at any time to also revoke the consent given for the profiling purposes referred to in letter h): also for this case, your refusal to provide personal data will not prevent us from running your request via the Sites, but will imply the impossibility of providing you with information for a customized offer of products and services. With regard to commercial purposes, the Owner informs you that the treatment is inspired by the philosophy of permission marketing: our commercial communications (non-invasive) will be sent, subject to your express consent and will be targeted to your interests; they will not be invasive. 4. Sharing Your Information In order to achieve the aforementioned purposes, we may communicate your personal data to the following categories of recipients: • public authorities, supervisory and control bodies, as well as competent judicial authorities, government agencies or other third parties also for the purpose to exercise, establish or defend our rights in court; • Group companies • parties that carry out tasks of a technical and organizational nature on behalf of geniwit Italia; • subjects that perform acquisition services, processing and processing of data necessary for the use of customer services; • subjects that provide services for the management of the Sites and their information system; • parties that provide customer assistance; • studios and companies that provide services to geniwit in the area of assistance and consulting; • subjects that carry out operations of control, revision, certification of the activities carried out by geniwit.com Italia also in the interest of its customers and users; • companies and consultants specialized in conducting informative interviews, in performing psycho-aptitude tests and in evaluating their results; • companies for the supply of functional services for recruitment / selection (such as, for example, IT or archiving services); • companies with which Arriva Italia Srl and / or its subsidiaries have partnerships, with particular reference to those in whose favor transport services are provided. We may also communicate your personal data to a buyer or potential buyer (and their agents and consultants) in relation to any reorganization, restructuring, merger or sale, or other transfer of assets, provided that, in these cases, we will inform any recipient of your personal data who must use them exclusively for the purposes indicated in this statement. 5 The subjects belonging to the categories listed above operate as distinct Data Controllers or as data controllers appointed for this purpose by Arriva Italia. Personal data may also, be known by the employees / consultants of geniwit.com Italia who have been specifically appointed as subjects authorized to process them. 5. Period of storage of personal data We will not process your personal data for a period exceeding that necessary to pursue the purposes for which the personal data were collected and, subsequently, we will keep them exclusively for the period necessary to comply with current legislation (including the statute of limitations on rights). The following table sets out in more detail the period for which Arriva Italia will retain the different types of personal data: Purpose of the processing Personal data retention period Fulfillment of obligations under national or community laws, regulations and / or regulations, or by supervisory and control bodies or judicial authorities and other legitimized authorities. The personal data will be processed for the period strictly necessary to fulfill the obligation imposed by the law and kept for the next one eventually established by the law. Satisfaction of the requests formulated by you from time to time by filling in the appropriate forms available on the Sites. Personal data will be processed for the time strictly necessary to satisfy your request formulated through the Sites and, in any case, will be canceled 6 months later fulfillment of the request Satisfaction of your request for registration to the Sites and provision of related services. Personal data will be stored for the period of time in which you decide to remain registered on the Sites. Sale of the ticket (s) for the trip selected by you. Personal data will be processed for the time strictly necessary for the execution of the contract and until the end of the trip. Beyond this date, they will be kept exclusively for the period of time necessary to comply with the regulations in force (including the provisions on statute of limitations). Management of applications and curricula vitae, for the purposes of possible selection and conclusion of a work contract or collaboration Personal data will be processed for the time strictly necessary to satisfy your request formulated through the Sites and, in any case, will be deleted 6 months after processing the request except in the event of termination of the employment relationship or collaboration. Sending communications of a commercial nature (including newsletters) on the activities and services of the Data Controller The personal data will be processed by the Data Controller until your decision to terminate the processing. Geolocation of your location in order to allow us to provide you with more accurate information regarding the means and routes available. The personal data collected for this purpose will be processed exclusively to satisfy your request and will be kept for the time necessary to improve your experience on the Sites and the best use of our services. Profiling for statistical or marketing use (with the aim of carrying out market research, to send the personal data will be processed for the time strictly necessary to satisfy your request formulated through the Sites and, in any case, will be canceled 6 months after the processing of the request. 6 6. Security information We adopt appropriate technical and organizational security measures in order to protect your personal data processed by us from access, collection, use, disclosure, copying, modification or unauthorized transfers. All personal data provided or collected is stored on secure servers. Arriva Italia is part of the GSW Group, which, in addition to carrying out training courses for its employees concerning the policies and procedures internally adopted on privacy, has implemented an access system for which it is allowed exclusively to authorized employees, based on the need to learn about it in accordance with the role covered, to access personal data. We also act in order to ensure that all service providers who process personal data on our behalf adopt appropriate technical and organizational measures in order to safeguard such personal data. 7. Updating this information We may update this information from time to time, in consideration of regulatory changes, techniques or commercial developments. Should we update this information, we will take appropriate measures to inform you, consistent with the relevance of the changes made. We will ask for your consent for any substantial change to the information if and where this is required by the applicable personal data protection legislation. It is possible to check the latest update of this information by displaying the "last update" date shown at the beginning of the same. 8. Your rights regarding the protection of personal data In relation to the treatments described in this Notice, as an interested party you may, under the conditions provided by the GDPR, exercise, in particular, the following rights: • right of access: right to obtain confirmation that your personal data is being processed and whether or not, and in this case, gain access to your personal data - including a copy of the same - and communication, among others, of the following information: a) purpose of the processing; b) categories of personal data processed; c) recipients to whom these have been or will be communicated; d) data retention period or criteria used; e) rights of the data subject (correction, deletion of personal data, limitation of processing and right to object to processing; f) the right to lodge a complaint; g) the right to receive information on the origin of my personal data if they have not been collected from the data subject; h) the existence of an automated decision-making process, including profiling; • right of rectification: the right to obtain the rectification of inaccurate personal data concerning you and / or the integration of incomplete personal data; commercial communications, for subscription to newsletters) in order to provide you with information for a customized offer of products and services (our or our business partners). 7 • right to cancellation (right to be forgotten): the right to obtain the cancellation of the personal data concerning you, when: a) the data are no longer necessary with respect to the purposes for which they were collected or otherwise processed; b) You have withdrawn your consent and there is no other legal basis for processing; c) You have successfully opposed the processing of personal data; d) the data have been unlawfully processed, e) the data must be deleted to fulfill a legal obligation; f) personal data was collected in relation to the offer of information society services referred to in Article 8, paragraph 1, GDPR. The right to cancellation does not apply to the extent that the processing is necessary for the fulfillment of a legal obligation or for the performance of a task performed in the public interest or for the verification, exercise or defense of a right in court; • right to limitation of treatment: the right to obtain the limitation of the processing, when: a) the data subject disputes the accuracy of the personal data; b) the processing is unlawful and the data subject opposes the deletion of personal data and requests instead that its use be limited; c) personal data are necessary for the interested party to ascertain, exercise or defend a right in court; • right to object: right to object to the processing of personal data concerning you, unless there are legitimate reasons for the Data Controller to continue processing; • right to data portability: the right to receive, in a structured format, commonly used and readable by an automatic device, the personal data concerning you provided to the Owner and the right to transmit them to another holder without impediment, if the processing is based on consent and is carried out by automated means. Furthermore, the right to have your personal data transmitted directly from GENIWIT Italia to another owner if this is technically feasible; • lodge a complaint with the Guarantor Authority for the protection of personal data, GSW SRL Via Guido Rosato n 56 Lanciano CH 66034 commonly used and readable by an automatic device, the personal data concerning you provided to the Owner and the right to transmit them to another holder without impediment, if the treatment is based on consent and is carried out by automated means. Furthermore, the right to have your personal data transmitted directly from GENIWIT Italia to another owner if this is technically feasible; • lodge a complaint with the Guarantor Authority for the protection of personal data, GSW SRL Via Guido Rosato n 56 Lanciano CH 66034 commonly used and readable by an automatic device, the personal data concerning you provided to the Owner and the right to transmit them to another holder without impediment, if the treatment is based on consent and is carried out by automated means. Furthermore, the right to have your personal data transmitted directly from GENIWIT Italia to another owner if this is technically feasible; • lodge a complaint with the Guarantor Authority for the protection of personal data, GSW SRL Via Guido Rosato n 56 Lanciano CH 66034 the right to obtain that your personal data is transmitted directly from GENIWIT Italia to another owner if this is technically feasible; • lodge a complaint with the Guarantor Authority for the protection of personal data, GSW SRL Via Guido Rosato n 56 Lanciano CH 66034 the right to obtain that your personal data is transmitted directly from GENIWIT Italia to another owner if this is technically feasible; • lodge a complaint with the Guarantor Authority for the protection of personal data, GSW SRL Via Guido Rosato n 56 Lanciano CH 66034