Personal Data Processing Notice (FEA)

 

Non-biometric advanced electronic signature service using an OTP

Notice provided pursuant to Article 13 of Regulation (EU) 2016/679

 

1. Joint Data Controllers

DUCATI MOTOR HOLDING S.p.a. and DIAMANT S.r.l. are Joint Data Controllers, by virtue of the arrangement entered into pursuant to Article 26 of Regulation (EU) 2016/679. The information provided in this notice and any consents given by the user when providing their data apply to both Data Controllers.
Each Data Controller has appointed a Data Protection Officer (DPO).


DUCATI MOTOR HOLDING S.p.a.
Via Cavalieri Ducati 3 – 40132 Bologna
The Data Controller and the DPO can be contacted at privacy@ducati.com.

 

DIAMANT S.r.l.
Viale del Lavoro 8 – 37060 Zona Industriale Bonferraro (VR) For information.
The Data Controller can be contacted through the Privacy Service at privacy@diamantdmt.com.
The DPO can be contacted at dpo@diamantdmt.com.

 

2. Data Protection Officer
The Joint Data Controllers have each appointed a Data Protection Officer (“DPO”), who can be contacted using the details provided above or any additional contact details supplied by the respective Joint Data Controller.
The DPO can be contacted regarding the processing of personal data and the exercise of the rights granted under Regulation (EU) 2016/679.


3. Subject matter and scope of the processing
This notice relates exclusively to the processing of personal data required to enable the data subject to sign, using a non-biometric AES authenticated by means of an OTP code, documentation relating to participation in a free test ride of a newly manufactured bicycle organised at a trade fair stand operated by one or both of the Joint Data Controllers.
The same procedure may be used to sign documents relating to the test ride, declarations, release forms and declarations of intent. The conditions of participation, the liability waiver and any optional processing activities, including marketing, profiling and the use of photographs or video footage, are governed by separate documents and data processing notices.
The solution described in this notice does not use biometric data relating to handwritten signatures, facial recognition or any other biometric technology.


4. Categories of personal data processed
The following data may be processed for the purposes of managing the AES:

  • identification and personal details, such as first name, surname, place and date of birth and tax code, where required;
  • contact details, such as e-mail address and mobile telephone number;
  • details and a copy of the identity document used for identification;
  • documents submitted for signature and signed documents;
  • the date and time of each operation and identifiers relating to the procedure and signing session;
  • the telephone number or e-mail address used to receive the OTP, evidence that it was sent and the outcome of the verification;
  • the IP address and technical data relating to the device, browser and session;
  • the certificate of completion and any further technical evidence required to document the procedure and the integrity of the document.

 

The OTP code is used for a single signing operation or session. Evidence that it was sent and successfully validated may be retained to the extent necessary to document the authentication of the signatory.


5. Purposes of the processing
Personal data are processed in order to:

  1. reliably identify the signatory and verify their identity document;
  2. activate and manage the advanced electronic signature procedure;
  3. send and verify the OTP code;
  4. link the signature to the signatory and the relevant documents;
  5. ensure the integrity, immutability and verifiability of the signed documents;
  6. produce and retain technical evidence relating to the procedure;
  7. allow subsequent verification of the validity and authenticity of the signature;
  8. comply with the obligations laid down by the applicable legislation governing electronic documents and AESs;
  9. prevent misuse, fraud, unauthorised access and security incidents;
  10. establish, exercise or defend the rights of the Joint Data Controllers or the data subject.


6. Legal basis of the processing
The processing is based on:

  • the performance of pre-contractual measures taken at the request of the data subject and the performance of the contractual relationship relating to participation in the test ride, pursuant to Article 6(1)(b) of the Regulation;
  • compliance with the legal obligations applicable to the management of AESs and electronic documents, pursuant to Article 6(1)(c) of the Regulation;
  • the legitimate interests of the Joint Data Controllers in ensuring the security, integrity, traceability and legal enforceability of the procedure, preventing fraud and protecting their rights, pursuant to Article 6(1)(f) of the Regulation.


Acceptance of the terms and conditions governing the use of the AES service constitutes an expression of contractual intent and not consent to the processing of personal data. Any consent relating to other purposes is obtained separately on the basis of the relevant data processing notices.


7. Nature of the provision of data
The provision of the data required for identification and management of the AES is necessary in order to use the electronic signing method.
Failure to provide the requested data, refusal to present an identity document, failure to provide a personal telephone number or e-mail address, or failure to accept the conditions governing the AES service may prevent completion of the electronic procedure. This is without prejudice to the possibility of using a different signing method made available by the Joint Data Controllers.


8. Identification and signing procedure
The identity of the data subject is verified by authorised personnel through the presentation of a valid identity document and in accordance with the procedure adopted by the Joint Data Controllers.
The data subject must provide a personal mobile telephone number or e-mail address to which they have access. During the procedure, an OTP code is sent for use in the individual signing operation or session. The code must not be disclosed to third parties.
At the end of the procedure, the signed document and the related technical evidence are generated and retained.


9. Processing methods and security measures
Processing is carried out mainly using electronic means, in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, integrity and confidentiality.
The Joint Data Controllers adopt technical and organisational measures appropriate to the level of risk, including authentication and authorisation systems, protection of communications, encryption where applicable, logging of operations, protection of documents and logs, access restrictions, backup and recovery measures and procedures for managing personal data breaches.


10. Authorised persons and data recipients
The data may be processed by personnel of the Joint Data Controllers who have been expressly authorised and instructed, particularly personnel responsible for participant registration, identification, stand management, information systems and administrative and legal functions.
The data may also be disclosed, to the extent necessary, to:

  • providers of IT, cloud, authentication and messaging services;
  • providers of the electronic signature platform;
  • technical and legal advisers;
  • public, administrative or judicial authorities, where required by law;
  • any other parties to whom disclosure is necessary in order to comply with legal obligations or protect rights.

 

Providers that process data on behalf of the Joint Data Controllers are appointed as processors pursuant to Article 28 of the Regulation, where the relevant conditions are met.


11. Management of the service using Docusign
The Joint Data Controllers use the Docusign platform to manage the advanced electronic signature process. The platform is configured in accordance with the relevant contractual arrangements.
On behalf of the Joint Data Controllers and within the limits of the instructions received, Docusign processes the data required to prepare and transmit documents, authenticate the signatory, send and verify the OTP, produce evidence of the signature and store the documents and related technical data.
For the activities carried out on behalf of the Joint Data Controllers, Docusign acts as a processor pursuant to Article 28 of the Regulation, on the basis of a specific agreement. Docusign may engage other companies in its group and sub-processors to provide infrastructure, cloud, security, authentication, messaging and technical support services, in accordance with the applicable contractual terms.
An up-to-date list of sub-processors and further information about the service may be obtained from the Joint Data Controllers or accessed as indicated in Docusign’s contractual documentation.


12. Location and transfer of data
Signed documents and other contractual data uploaded to the platform are stored in the European region, provided that the account used by the Joint Data Controllers has been correctly configured and the relevant contract provides for European data residency.
Certain technical, transactional or support data, such as identification data, contact details, IP addresses, transaction identifiers, authentication data and logs, may also be processed or accessed by Docusign group companies or sub-processors located outside the European Economic Area.
Any transfers to third countries are carried out in accordance with Articles 44 et seq. of the Regulation, on the basis of adequacy decisions, binding corporate rules, standard contractual clauses or other safeguards provided for under the applicable legislation. Further information on the safeguards adopted may be requested from the Joint Data Controllers.


13. Retention periods
The copy of the identity document, the declaration accepting the conditions governing the AES service and the information required to demonstrate compliance with the procedure are retained for at least twenty years from the date on which they are obtained, without prejudice to any longer period required under the applicable legislation.
Signed documents are retained for the period laid down by the legislation applicable to the relevant type of document and, in any event, for the time required to comply with legal obligations and protect the rights of the Joint Data Controllers and the data subject.
The technical evidence relating to the signature, including the certificate of completion and the logs required to demonstrate the authenticity and integrity of the signature, is retained for at least twenty years, unless a longer period is required by law or made necessary by the existence of disputes.
Data relating to signing procedures that have been initiated but not completed are deleted within thirty days, unless further retention is necessary to document anomalies, attempted fraud, security incidents or disputes.


14. Rights of the data subject
In the circumstances provided for by law, the data subject may exercise the rights granted under Articles 15 to 22 of the Regulation and, in particular, may request:

  • access to their personal data;
  • rectification of inaccurate data and completion of incomplete data;
  • erasure of the data, where permitted;
  • restriction of processing;
  • data portability, where applicable;
  • objection to processing based on legitimate interests;
  • information concerning recipients and the safeguards applicable to transfers;
  • a copy of the data and documentation required under the legislation governing AES.


Requests may be addressed to either Joint Data Controller or to the contact point indicated above. The internal allocation of responsibilities under the joint controllership agreement does not restrict the data subject’s rights in relation to either Joint Data Controller.
The data subject may also lodge a complaint with the Italian Data Protection Authority or bring proceedings before the competent court.


15. Copy of the AES documentation
The data subject may request the following from the Joint Data Controllers free of charge, using the contact details provided in this notice:

  • a copy of the declaration accepting the conditions governing the AES service;
  • a copy of the signed document;
  • a copy of the information and evidence retained, within the limits laid down by the applicable legislation.


16. Withdrawal from the AES service
The data subject may request that the advanced electronic signature method no longer be used for any future signatures. Withdrawal from the service does not affect the validity of documents already signed and does not result in the deletion of data that the Joint Data Controllers are required to retain in order to comply with legal obligations or protect their rights.


DECLARATION OF ACKNOWLEDGEMENT
I, the undersigned, hereby declare:

  • that I have received and read this notice;
  • that I have received or had the opportunity to consult the conditions governing the use of the advanced electronic signature service;
  • that I have been informed of how my data is processed and of the existence of the joint data controller agreement;
  • that I have been informed of how to obtain a copy of the documentation;
  • that I have been informed of the possibility of withdrawing from the service in relation to future signatures.

 

Acknowledgement of this notice does not constitute consent for any further purposes, such as marketing, profiling or the use of images, which are governed by separate documents.