Car/Privacy Policy B2B

PRIVACY POLICY (B2B)

What does this Privacy Policy apply to?

This Privacy Policy is understood as information notice pursuant to [article 13 of Regulation (EU) 2016/679 (so-called General Data Protection Regulation or “UK GDPR”)] and it applies to the personal data collected and processed by Pirelli UK Tyres Limited with offices at Derby Road Burton on Trent Staffordshire DE13 0BH and Dalston Road Carlisle CA2 6AR – in its quality of data controller – (hereinafter “Pirelli”, “we”, “us” or “our”, as appropriate) about your enterprise, more specifically, its representatives, employees, collaborators and contact persons, when they interact with us.

You expressly acknowledge that it is your responsibility to inform your representatives, employees, collaborators and contact persons, of the processing of the personal data referred to in this Privacy Policy and obtain their consent, if necessary.

What personal data do we collect?

We may collect the following categories of personal data:

(1) Identifiers and contact details of contact persons of the company such as name and surname, email, direct phone;

(2) Any other information voluntarily provided by you when you interact with us.

From which sources do we collect your personal data?

You provide us with most of the data we collect. We may also collect your data from other Pirelli Group companies operating in your country or any open sources such as Internet, public registers, etc.

For which purposes do we process your personal data and what is the legal basis for our processing?

We may process your personal data to:

(1) Consider the possibility of engaging in a business/contractual relationship with you, including answering your questions and fulfilling your information requests. Legal basis: processing is necessary in order to take steps at your request prior to entering into a contract with you (if you are the enterprise having the agreement with us) and for our legitimate interest in communicating with you (if you are a representative, employee, collaborator and/or contact person of the enterprise having the agreement with us).

(2) Establish and manage the business/contractual relationship with you, including (i) the invitation to join initiatives, courses, events and/or contests organized, promoted or sponsored by us, aimed at describing our new products and/or obtaining a possible increase of the sales of our products made by you/in your point(s) of sales and (ii) the invitation to attend surveys on your degree of satisfaction in your relationship with us, after a certain degree of business interactions with us. Legal basis: processing is necessary for the performance of a contract to which you are a party (if you are the enterprise having the agreement with us) and for our legitimate interest in fulfilling the purposes described in this section (2), including communicating and improving the relationship with you and/or your employer (if you are a representative, employee, collaborator and/or contact person of the enterprise having the agreement with us).

(3) Allow you to log in to our B2B platform (subject to the conditions set forth in separate agreements with us) and/or test our digital products and services. Legal basis: processing is necessary for (i) the performance of a contract to which you are party (if you are the enterprise having the agreement with us) and (ii) our legitimate interest of fulfilling the purpose described in this section (3) (if you are a representative, employee, collaborator and/or contact person of the enterprise having the agreement with us).

(4) Publish your contact details in our Dealer Locator (subject to the conditions set forth in separate agreements with us). Legal basis: processing is necessary for (i) the performance of a contract to which you are party (if you are the enterprise having the agreement with us) and (ii) our legitimate interest of fulfilling the purpose described in this section (4) (if you are a representative, employee, collaborator and/or contact person of the enterprise having the agreement with us).

(5) Comply with legal or regulatory obligations to which we are subject. Legal basis: processing is necessary to comply with legal obligations (by way of example accounting and tax obligations) to which we are subject.

(6) Exercise or defend legal claims in judicial, administrative or arbitration procedures. Legal basis: processing is necessary for our legitimate interest of legal protection.

(7) Carry out activities connected to the execution of extraordinary transactions. Legal basis: processing is necessary for our legitimate interest connected to the execution of extraordinary transactions.

How and where do we store your personal data?

We securely store your personal data at ours and our service providers’ data centers in the European Union, adopting all reasonable necessary measures to keep it safe.

How long do we keep your personal data?

Your personal data will be kept for:

(1) a period of 2 (two) years from your last active interaction with us, in case of considering the possibility of engaging in a business/contractual relationship with your enterprise/the enterprise you belong to (active interaction meaning the last visit to your enterprise, which date is registered in our systems);

(2) the duration of the business and/or contractual relationship with your enterprise/the enterprise you belong to, in case a business/contractual relationship is established.

The above without prejudice to the possibility to keep your personal data for the mandatory period of time required by the applicable laws concerning the retention of data and documents for administrative, accounting, tax and defensive purposes (in compliance with the applicable statute of limitations).

We will delete your personal data upon your request, if permitted, in accordance with the data protection laws applicable to you.

With whom your personal data is shared?

We may need to share your personal data with:

(1) Other Pirelli Group companies in order to pursue legitimate interests related to the performance of technical and organizational activities functional to the purposes described in section: “For which purposes do we process your personal data?

(2) Third party service providers (e.g. IT providers, logistic providers, marketing agencies, travel agencies, events organizers, suppliers that carry out organizational, administrative and/or technical activities in the context of the business/contractual relationship and of the prize contests – including those suppliers delegated by us to fulfill the legal and administrative obligations relating to such prize contests) and, in case of credit recovery needs, with credit insurance companies and law firms.

(3) Potential partners involved in business transactions, in the event we intend to sell or transfer ownership or control of any or all of our business, operations or services to a third party.

Both other Group Pirelli companies and third party service providers, which act in most cases as data processors, are bound by data protection obligations aimed at ensuring an adequate level of protection to your personal data. In case of events which entail the existence of insurance policies, the data may be acquired by the insurance companies involved, which will act as autonomous data controllers.

We may also disclose your personal data to courts, law enforcement agencies, governmental authorities, or authorized third parties, if and to the extent we are required or permitted to do so by law or by court orders.

We inform you that some the service providers to which we may disclose your personal data might be established outside the [European Economic Area (“EEA”)]. If your personal data is transferred outside the EEA, we will ensure that your personal data continue to be protected in compliance with this Privacy Policy, subject to the applicable laws there.

Your rights under the data protection law

Under the GDPR, you have the right to ask us to:

(1) be informed on the purposes and methods of the processing of your personal data;

(2) access to your personal data;

(3) rectify incomplete, inaccurate or out-of-date data;

(4) delete your personal data, restrict the processing of your personal data, object to the processing, wholly or partly, for reasons linked to your specific situation or if such processing is made for marketing purposes, obtain the portability of your personal data, where applicable under the GDPR.

(5) You may exercise any of the rights above by writing to the contacts indicated in the section “How can you contact us?

(6) You have also the right to lodge a complaint with the competent national data protection authority.

Links to other websites

In the event this Privacy Policy applies to a website or an app, such website or app may contain links to external websites. If you click on any of these links, you will be directed to a website not covered by this Privacy Policy.

Changes to the Privacy Policy

We may review this Privacy Policy at our own discretion. Make sure to check the latest version available regularly.

How can you contact us?

You can contact us and write to our Data Protection Officer at dpo_pirelliuktyres@pirelli.com.