Eclexia Platform - Data Protection Conditions

Use of personal data and cookies

(last update: 25.01.2019)

Welcome

The "Eclexia" video distribution platform is owned and managed by Vetrya S.p.A. (hereafter Vetrya), which is solely responsible for its development and operation from a technical point of view. With this document, Vetrya wants its Customers to know the way in which their data and Personal Data / information relating to the use of the Eclexia platform (hereafter only the Platform) are collected, used, shared and stored by the end users (hereafter referred to as Spectators) who view the videos of the Customer through the Platform.

Roles and Responsibilities of the Data Processor and the Data Controller

The Customer and Vetrya accept that the Customer is the Data Controller and that Vetrya is the Data Processor, except for the cases in which (a) the Customer acts as Data Processor, in that case, Vetrya will be another Data Processor.

Regarding the use of the Platform, the Customer who uses it for the management of multimedia content within its websites or apps, therefore, configures itself, except in the case (a), as Data Controller, while Vetrya as Data Processor.

Vetrya does not have a direct relationship with the Spectators. The Spectators information / data collected on the websites or on the Customers' applications are subjected to the Customer's privacy policies.

Data security

Provided that no data transmission over the Internet or data storage system can be guaranteed 100% in terms of security, Vetrya implements and ensures appropriate organizational and technical measures to protect Customer Data and Personal Data on the Platform. These measures comply with the requirements established by the ISO 27001 standards. The Eclexia platform is ISO / IEC 27001: 2013 certified - Certification for the management, development and maintenance of the VOD service.

Personal data processed with the Platform

Vetrya, in addition to the processing of customer data necessary for the access to the platform (e.g. surname, name, userid, psw) and all data voluntarily entered by the same through the inclusion / publication of multimedia content (such as video, img, audio, live streaming, etc.) for which the same Customer assumes that they refer to himself or to third parties from whom he has received express authorization to confer them on the basis of an appropriate legal basis that legitimizes the treatment in question, processes the following personal data:

1. Data relating to the Spectators

Personal Data collected by Vetrya in relation to the supply of the Eclexia platform include Spectators data.

The information that can be collected when videos are viewed through Eclexia include:

1.1 Navigation data

Computer systems and software procedures used for the functioning of Eclexia acquire, during the normal operation, some personal data that are transmitted implicitly in the use of internet communications protocols.

This information is not collected to be associated with identified interested parties, but due to its nature could, through processing with data held by third parties, allow the identification of users / visitors (e.g. IP address, the code indicating the status of data response from the server, browser type, etc.). The platform also collects data related to the views (e.g.: number of views, minutes displayed, percentage of content displayed, new viewers, unique viewers, geographical origin, language preference, search terms and other similar information used only at the statistical level (so they are anonymous), to check the correct functioning of the Eclexia platform and to return anonymous reports to the Customer through Microsoft Power BI.

This information is aggregated and anonymized, it is not connected to a single Spectator.

2. Cookies and other tracking technologies

Vetrya and its third-party service providers may use technologies such as cookies to quantify usage, analyze the display and duration of videos viewed using the Eclexia platform, in order to conduct benchmarking, generate metrics, reporting and evaluate the quality of services offered through the Platform.

Cookies - A cookie is a small text file stored on the user's computer for archiving purposes. We may link the information we store in cookies to any personal information obtained from the use of the Eclexia platform. The Platform uses both session and permanent cookies. A session cookie expires when the browser is closed. A persistent cookie remains on the Spectator's hard disk for a long period of time. It is possible to control the use of cookies at the individual browser level, but disabling cookies may limit the use of certain features or functions of the Eclexia platform. Each customer within his website or app could then use different cookies for which reference is made to the privacy and cookie law of the customer related to his website / application.

HTTP Headers - are information transmitted each time a Web page is viewed and contain technical information necessary for the communication between a navigation device and a website server. Other electronic communication protocols (such as those used for e-mails) also use headers to transmit information. The information can be transmitted through the HTTP headers (or other electronic communication protocols) to Eclexia by the interaction of the Spactator with the video published by the Customer. This may include information on the device browser, the requested web page and the computer or device used.

Analytics - We may use third-party analytics services, such as but not limited to Google Analytics, to track the use of Eclexia services by our Customers. For information on how Google collects and processes information and how to disable Google's information collection, click here.

3. Data provided voluntarily by the Customer relating to the Spectator or other natural person

Vetrya may also collect other personal information of a natural person / Spectator, perhaps included in multimedia content that Customers upload to Eclexia.

Purpose, legal basis and compulsory or optional nature of processing

To the extent permitted by applicable law, as Data Processor for contracts in place with our Customers relating to the use of the Platform, Vetrya uses the above data concerning Spectators / Customers for the following purposes:

a) Purposes related to the execution of a contract that the Customer is a part of, therefore more simply to provide all the services of the Eclexia platform requested by our Customers;

b) Purposes related to the execution of the possible registration service of the Spectator concerning the visualization of video content on the websites or on the apps of the Customers;

c) Provide our Customers with analytical data and reports on video viewing activity;

d) Provide assistance to Customers;

e) Use of software / algorithms for machine learning, to optimize the user experience or provide analyses requested by the Customer.

f) Purposes of statistical research / analysis on aggregated or anonymous data, without the possibility of identifying the user, aimed at measuring the operation of the Platform, measuring traffic, evaluating usability and improving the performance of the Platform;

g) Purposes related to the fulfillment of a legal obligation to which Vetrya is subjected;

h) Purposes necessary to ascertain, exercise or defend a right in court or whenever the jurisdictional authorities exercise their jurisdictional duties.

The legal basis of the processing of Personal Data for the purposes referred to in points a), b), c), d) e) is the contract and the privacy agreement (Article 28 of the GDPR) stipulated between the Customer and Vetrya, the latter by virtue of its role as Data Processor; the purpose of point e) does not involve the processing of personal data, while points f) and g) represent a legitimate interest once the personal data have been provided, the processing is indeed necessary to fulfill a legal obligation to which Vetrya is subjected or exercise its right to defense in court.

Processing methods

The processing is carried out through IT and telematic tools for the time strictly necessary to achieve the purposes for which the data were collected and in any case, in compliance with the provisions in force on the subject and as per contracts with the Customer.

Data retention

Vetrya will process data until the validity of the contract with the Customer, usually until the Customer account on the platform is active. The processing will also lasts until all Personal Data will be deleted or returned in accordance with the instructions given by the Customer. To the extent permitted by applicable law, Vetrya may retain anonymous or pseudonymised aggregate data indefinitely. It will also retain information as reasonably necessary to fulfill its contractual and / or legal obligations, to resolve any disputes and enforce the agreements.

Without prejudice to the foregoing, Vetrya will process Personal Data up to the time allowed by Italian law to protect its interests (arts. 2946 and 2947 (1) (3) c.c.).

Recipients / sub-responsible

To the extent permitted by applicable law on privacy and as per contractual agreements with the Customer, Vetrya may share, disclose and transfer information, including personal data with:

a) Third-party service providers that use them to support Eclexia services and its business, such as companies that provide cloud hosting services, data analysis, infrastructure provision, IT services, customer service, analysis, and email delivery services;

b) Current and future Vetrya S.p.A. subsidiaries or affiliates;

c) A buyer, an investor, a new affiliate or other third party in the event that Vetrya, or any portion, group or business unit, undergoes a business transition, such as a merger or acquisition, or during the contemplative phases of such activities (e.g. negotiations and due diligence);

d) Public and government authorities, according to applicable law, to respond to any requests or exercise or defend a right in court.

Subcontractors

Customer agrees that for Vetrya Platform services he makes use of other suppliers to support Eclexia services, such as companies that provide cloud hosting services, data analysis, infrastructure provision, IT services, customer service, analytics and email delivery services; Vetrya is responsible for the compliance of the other Data Processors. Vetrya provides the list of subcontractors upon explicit request.

Data transfer

Eclexia services use servers located in Europe. Accesses outside Europe to the data on the Platform are contemplated in the cases provided for and duly authorized by the same Customer, who will provide for the issuance of the appropriate authorizations.

Rights of the interested parties; Assistance with requests

Vetrya will provide to the Customer, in accordance with the functionality of the Eclexia platform and its role as Data Processor, the Personal Data on its behalf treated in accordance with the GDPR, conforming to the Customer reasonable assistance requests.

Customer's responsibilities

The Customer is solely responsible for independently determining whether the organizational and technical measures of the Eclexia platform meet their own requirements, including their confidentiality obligations under the GDPR or other applicable data protection laws or regulations.

Communication of unpredictable events related to security

If Vetrya becomes aware of a security breach resulting in destruction, loss, accidental or illegal alteration, unauthorized disclosure of data processed on behalf of the Customer, promptly and without unjustified delay will communicate the unforeseen event related to the protection, will analyze the unexpected event and will provide the customer with detailed information about it, will take reasonable steps to mitigate the effects and reduce any related damages. Vetrya's notification of an unexpected event related to the protection or responding to it under this article does not constitute an admission of liability with respect to such event.

The Customer must promptly notify Vetrya of any improper use of the account or authentication credentials to access the Platform.

How to contact Vetrya

If the Customer considers that Vetrya does not fulfill its commitments regarding the protection of personal or security data, it may contact the dedicated support, as reported in the contract.

The mailing address of Vetrya is:

Vetrya S.p.A.

Via dell'Innovazione, 1 05018 - Orvieto (TR)