Privacy Policy

Cambi Casa d’Aste srl, with its registered headquarters at Mura di San Bartolomeo, 16 - 16122 Genova (GE) - Italy, in its capacity as data controller, wishes to inform you on how your personal data will be treated, as provided by Art. 13 of European Regulation No. 679/2016 ("GDPR") on the protection of personal data.

1. Data controller and data processors
The data controller is Cambi Casa d’Aste srl, with its registered headquarters at Mura di San Bartolomeo, 16 - 16122 Genova (GE) - Italy (hereinafter also referred to as Controller or Data controller).

2. Purposes of processing
A) The personal data you have provided us with are processed without your explicit consent to:
- perform services for you (asset estimates, sales services, mediation services);
- carry out the sales mandate;
- allow you to take part in physical or online Auctions;
- execute contracts in which you are a party;
- issue invoices;
- comply with legal obligations or regulations;
- comply with any other obligation foreseen by the law, by Community legislation as well as provisions issued by authorities legitimated by the law;
- exercise the Controller’s rights, such as the defense of legal claims.
B) Exclusively with your prior specific and distinguishable consent (articles 23 and 130 Privacy Code and art. 7 GDPR):
- for the purpose of sending you emails, text messages, mms, phone calls, social media, instant messages, mobile applications, banners, fax, mail and telephone, for the promotion and/or sale of products and/or services and advertising material regarding products or services offered by the Controller;
- to subscribe to the newsletter for the data controller’s marketing purposes.

3. Collected personal data
The data controller, in accordance with this policy, processes general data and identifiable data, including:
a) personal information and contact details, fiscal data and accounting information;
b) identity documents required to participate in the auctions;
c) online identification data for accessing web platforms owned by the Controller and/or by third parties in their capacity as data processors;
d) bank details for any business transactions; Such data are only processed insofar as they are necessary to achieve the purposes described in paragraph 2 of this policy.

4. Methods for processing
Your data is processed through the operations stated in art. 4 GDPR, namely: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Your personal data are processed in paper and electronic form both. Personal data in electronic form are stored on local or remote servers, within the EU or within Countries on which the Commission (pursuant to Art. 29 95/46/EC) has adopted an adequacy decision, protected by appropriate security measures, and copies of such data will be stored in encrypted format, protected on local devices and/or cloud servers for security purposes (backup copies).

5. Lawful basis for processing
The processing of personal data for the purposes of performing the services as stated in section 2A is mandatory as it is required for the use of specific services offered by the Controller. The collection of personal data for the purpose of law is mandatory as it is required under the applicable laws. If the Client objects to the processing for the purposes stated in section 2A, he or she shall not be able to use the services provided by the Controller. Pursuing its legitimate interest, the Controller may send notices relating to services already used by the Client. The processing of personal data for marketing purposes is optional and subject to explicit consent as stated in section 2B.

6. Data communication
Your data may be made available for the purposes stated in sections 2A and 2B to the Controller’s employees and collaborators, in their capacity as data processors and/or system administrators. Without the need for express consent, the Controller may only communicate your data for the purposes set out in section 2A to supervisory authorities, judicial authorities and to those subjects towards whom such communication is required for the fulfillment of the above mentioned purposes. These subjects will process the data in their capacity as independent data controllers. Your data shall not be disclosed to third parties whom you have not authorized in writing.

7. Data transfer
The Controller guarantees that data shall not be transferred outside the EU unless such transfer is required in accordance with the provisions of applicable law, provided that the standard contractual provisions established by the European Commission have been agreed upon, or, if it is necessary for the use of particular services, the Controller shall have the right to transfer any data to structures that are hosted in countries outside the EU; in such case the Controller guarantees from this moment that such data will be processed in accordance with the applicable law, namely on servers residing in States for which the Commission (pursuant to article 29 95/46/EC) has adopted an adequacy decision, protected by appropriate security measures.

8. Rights of the data subject
In his or her capacity, the data subject is entitled to exercise the rights established in Art. 7 Privacy Code and Art. 15 GDPR and namely:
I. the right to obtain from the Controller confirmation as to whether or not personal data concerning him or her are being processed, albeit not yet stored, and to request their transmission in intelligible form;
II. the right to obtain information: a) on how the personal data was collected; b) on the purposes and methods of processing; c) on the logic applied in case of processing with electronic tools; d) on the identity of the Data Controller, the Data Processors and the DPO pursuant to Art. 5, comma 2 Privacy Code and Art. 3, comma 1, GDPR; e) on the subjects or categories of subjects to whom the personal data may be communicated or made available;
III. the right to obtain a) an update, rectification, or integration of the data; b) the erasure or restriction of unlawfully processed data; c) a certification that the operations under letters a and b have been notified (data breach), also with regards to their content, to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort;
IV. the right to object, in whole or in part: a) for legitimate reasons, to the processing of personal data concerning him or her, though pertinent for collection purposes; b) to the processing of personal data for direct marketing purposes such as sending quotations and purchase offers.
Where applicable, the data subject is also entitled to the rights established in articles 16-21 GDPR (right to rectification, right to be forgotten, right to restriction of processing, right to data portability, right to object), and the right to complain to the Supervisory Authority.

9. Duration of the processing
The Controller will process personal data for as long as needed to fulfill the above purposes, and also: • with regards to the obligation to store documents for accounting purposes, storage shall be subject to the general regulations relating to the ordinary terms of contractual actions and therefore data relating to the contractual relationship shall be deleted once the ten year term provided by law expires; • data shall no longer be processed if the data subject has expressly requested that such processing be restricted, interrupted or erased for the purposes of art 2. B.

10. Procedures for the exercise of the rights of the data subjects
To obtain the rectification, update, restriction, certification for letters A or B, the data subject may at any time exercise his or her rights by specifically requesting this to the Controller, without any excessive formalities, or by sending an email to the address privacy@cambiaste.com. The right to erasure and the right to data portability shall instead be expressed in clear, explicit and signed written form.

11. Data controller and processors
Cambi Casa d’Aste srl is the Data controller. Your data may be made available for the purposes stated in sections 2A and 2B to the Controller’s employees and collaborators, in their capacity as data processors and/or system administrators; to third-party companies such as credit institutions, firms, consultants that carry out outsourcing activities on the Controller’s behalf, in their capacity as external processors. An updated list of external processors is kept at the Controller’s headquarters and may be requested by sending an e-mail to the address privacy@cambiaste.com.