Privacy Policy

Privacy Policy pursuant to art. 13 of European Regulation 2016/679 (GDPR – General Data Protection Regulation)

We hereby inform you that, pursuant to art. 13 of EU Reg. 2016/679, the Personal Data collected will be subject to Data Processing by our Company for the purposes of the personnel selection procedure and the resulting legal and contractual obligations According to the aforementioned Regulation:

  • Tesisquare S.p.A., with with registered office in Via Mendicità Istruita, 24 – 12042 Bra (CN) and operational
    headquarters in Via Savigliano, 48 – 12062 Roreto di Cherasco (CN) Tel. (+39) 0172 476301 – Fax (+39)
    0172 476399 – www.tesisquare.com – info@tesisquare.com is the “Data Controller”;
  • You, as a natural person (including sole proprietorships or professionals), are the “Data Subject” and your data will be processed as indicated below. You hold the rights illustrated further below;
  • If you are a legal entity (company, organization, etc.), you are NOT a “Data Subject”, your data are NOT Personal Data, and the regulation in question does NOT apply to the relevant processing. In any case, any of your directors/representatives/employees/collaborators/officials—whose Personal Data may be incidentally provided or communicated due to contact with the Data Controller on your behalf—are “Data Subjects”; their data will be processed as indicated below and they will have the rights illustrated further below. You are therefore required to communicate this information to such Data Subjects.

This processing will always be based on the principles of correctness, lawfulness, transparency, and the protection of confidentiality and the rights of the Data Subjects pursuant to art. 5 of the GDPR.

DATA PROTECTION OFFICER. Pursuant to art. 37 of the GDPR, the Data Controller has appointed a Data Protection Officer (DPO) who can be contacted at the following email address: dpo@tesisquare.com.

DESCRIPTION OF DATA PROCESSING. Your Personal Data are processed in both hard copy and electronic format by the Data Controller for the purposes described below and disclosed to third parties exclusively for the same purposes, in accordance with this policy. The Data Processing of the data provided by you is carried out through all or some of the operations indicated in art. 4 no. 2) of the GDPR (“collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”).

DATA PROCESSED. The following data will be collected and processed:

DATA PROCESSED
Personal and/or identifying information entered into the internal historical access log to track and identify the individual in possession of an access badge to the company’s headquarters, which must be linked to the name of their internal contact at Tesisquare
Contact details
Personal Data relating to education and training, such as diplomas, training certificates, professional qualifications, etc.
UNILAV data relating to the employment contract (including, by way of example but not limited to, biographical data, place of residence, data concerning professional qualifications or residence permits, and employee remuneration).
When external consultants and personnel from outside companies enter the company’s premises for maintenance work, etc., the Data Controller requires that the data subject be issued an access badge bearing only the company name of the organization to which they belong—thus excluding any other identifying information about the individual—and that this identification badge be clearly visible on the company premises.


PURPOSES AND LEGAL BASIS.
The processing will take place for the following purposes:

PURPOSELEGAL BASISRETENTION PERIOD OR CRITERIA
Performance of the contract between the Supplier and TESISQUARE S.p.a.(art. 6.1.b of the GDPR) – Performance of a contract or precontractual measures.10 years (contractual limitation period for rights), unless a different term is required by law or for the exercise of rights in judicial/extrajudicial disputes.
Compliance with legal storage obligations(art. 6.1.c of the GDPR) – Compliance with a legal obligation to which the Data Controller is subject.10 years from the expiration of the contract
Corporate security management and access control, including the recording of the badge holder’s identity in the system and linking it to the internal Tesisquare contact person(art. 6.1.f of the GDPR) – Legitimate interest of the data controller.Access logs are retained for the time strictly necessary for security and monitoring purposes, and in any case for no longer than 90 days.
 

VOLUNTARY OR OBLIGATORY NATURE. The communication of your data to the Data Controller is a mandatory requirement for the fulfillment of the purposes set forth above; any refusal to provide such data may result in the total or partial failure to perform the contractual obligations.

RECIPIENTS OR CATEGORIES OF RECIPIENTS. Personal Data will be processed by the Data Controller and by persons strictly authorized by them.

The data may be communicated to the following categories of subjects: (i) other companies belonging to the TESISQUARE group (i.e., those participated in and controlled by TESISQUARE S.p.a.); (ii) external parties trusted by the Data Controller who perform certain processing activities on behalf of the Data Controller itself, acting as Data Processors (bound by a specific contract pursuant to art. 28 GDPR) or as independent Data Controllers (e.g., State administrations, insurance companies, local authority associations, banking institutions, consultants and freelancers also in associated form, financial intermediaries, national health service bodies, trade union or patronal bodies, Group companies, DIG42 Foundation). The data will NOT be subject to dissemination.

RIGHTS OF THE DATA SUBJECTS. Data Subjects may, at any time, exercise their rights of access to Personal Data, rectification or erasure, restriction of processing, objection, and portability as set out in Articles 15-20 of European Regulation 2016/679 by sending an email request to: privacy@tesisquare.com. The exercise of these rights may be delayed, limited, or excluded in cases provided for by applicable law.

RIGHT TO FILE A COMPLAINT WITH A SUPERVISORY AUTHORITY. The Data Subject has the right to file a complaint with the Supervisory Authority (Garante per la protezione dei dati personali).

EXISTENCE OF AN AUTOMATED DECISION-MAKING PROCESS. The processing does NOT involve an automated decision-making process.

TRANSFER OF DATA TO A THIRD COUNTRY OR TO AN INTERNATIONAL ORGANIZATION. Collected Personal Data may be transferred to countries outside the European Union, including the United States. Such transfers shall be carried out in compliance with Articles 44–49 of the GDPR.

Rev. dated 18/02/2026

Below are all the privacy policies that TESISQUARE S.p.a. adopts and makes public.

Scroll to Top