Privacy Policy for Foreship Suppliers
Privacy Notice for the Processing of Personal Data
With this document, we inform you that your data will be processed in the manner and for the purposes outlined below:
JOINT CONTROLLERS AND DATA PROTECTION OFFICER
The companies of the RINA Group (hereinafter "Joint Controllers" or "RINA") are the Joint Controllers of data processing and can be contacted through the information available on the website www.rina.org. The Data Protection Officer can be contacted at the email address: rina.dpo@rina.org.
The Joint Controllers have established an agreement that defines their respective roles and relationships. In short, the Joint Controllers commit to performing all obligations under data protection regulations, fully respecting guidelines, the code of ethics, and Group procedures.
Personal data is processed following principles of legality, fairness, and data minimization, ensuring confidentiality and discretion. The agreement stipulates that the contact point for exercising data subjects' rights is the email address: rina.dpo@rina.org.
1. APPLICABILITY OF THE NOTICE AND TYPES OF PERSONAL DATA PROCESSED
RINA processes your personal data (hereinafter, "data") if you are part of an existing contractual relationship or are potentially interested in buying or supplying products/services and have provided your personal data for this purpose (e.g., at an event/meeting, while browsing our websites, or registering for applications and/or collaborative platforms, hereinafter referred to as Digital Services).
If you are required to provide third-party personal data in your relationship with RINA, please ensure you inform those individuals of the communication of their personal data and invite them to read this privacy notice. RINA will also inform them where possible.
The types of personal data processed for the purposes of this notice are:
- identification, personal, and contact data (e.g., name, surname, email address);
- economic, financial, and tax information (e.g., tax code, IBAN, and other data necessary for invoicing and credit recovery);
- photographic and audiovisual images, if the relationship between RINA and the supplier involves distance training sessions, including recorded sessions via electronic devices;
- data collected from our interactions with you, including the use of our products/services or the supply contract (e.g., communications exchanged, including online, audit evidence collection, even remotely, or other supporting documentation, including special categories of data such as health certificates, if required by law or reference standards for the service);
- data acquired by RINA through consultations of publicly available databases, internet sources, media news, and other company information databases;
- personal data contained in access logs, usage of Digital Services by registered users, related security functions, and data related to the devices you use (e.g., IP address and technical specifications of the device).
2. PURPOSES AND LEGAL BASES FOR PROCESSING
The data processing mentioned above will be carried out for the purposes described below:
- pre-contractual activities aimed at formulating offers and establishing a contractual relationship for the provision of services offered;
- qualifying the supplier according to RINA's internal procedures and establishing the contractual relationship for the supply of services and/or goods;
- identifying and preventing risks related to corporate liability, anti-corruption programs, and conducting ethical-reputational checks related to corporate social responsibility;
- fulfilling contractual, administrative, and tax obligations arising from ongoing relationships or required services and/or binding accreditation and/or certification requirements;
- ensuring access to RINA-provided applications in the reserved area for consulting information/documents related to services provided by the RINA Group or connected to activities and/or initiatives proposed by the Group;
- ensuring participation in online collaborative activities, diversified on the basis of the assignment to specific business sectors.
- processing distance training sessions, if the relationship with RINA includes this provision, including recorded sessions via electronic devices and their subsequent distribution to third parties within the scope of a contract executed with RINA.
Refusal to provide data will result in the inability to register your account or access certain applications, as well as the inability to benefit from the requested services or to complete the qualification and registration process of the supplier through the supply chain management platform.
The legal basis justifying this data processing lies in the execution of a contract you are a party to or pre-contractual measures taken at your request, as well as any applicable legal obligations.
- sending newsletters, promotional material for services, or engagement in initiatives similar to those related to the contract/service or measuring satisfaction with the quality of products/services through surveys or requests via email or phone;
- ensuring the possibility of securely accessing your reserved area and preventing unauthorized activities, such as potential access to protected areas of the portal by unauthorized persons (log files);
- guaranteeing the exercise of RINA's right to defense in legal proceedings.
The legal basis for these processes lies in RINA's legitimate interest in improving the quality of services, maintaining the established contractual relationship, keeping you updated, providing support, and ensuring a secure service. You can object to this purpose at any time by requesting the deactivation of your account as outlined in point 6 of this notice.
- sending newsletters, promotional materials, or engagement in initiatives for individuals without an established contractual relationship or communications about services not similar to those already purchased.
The legal basis for these processes is your consent, which you are free to withdraw as outlined in paragraph 6 of this notice. Refusal to consent will only result in the inability to receive newsletters, promotional material, or engagement in collaborative initiatives.
3. DATA PROCESSING METHODS AND RETENTION
Processing can be carried out in paper or electronic format.
The data processed in the execution of the contract/service will be retained for the time strictly necessary to achieve the purposes indicated in this notice and, in any case, no later than 10 years after the termination of the contractual relationship or 2 years from collection for marketing or engagement purposes, unless consent is renewed.
Navigation/log data will be deleted within six months of the event that generated them.
In exceptional and properly documented cases, data may be retained for longer periods to protect your or RINA's rights, limiting access to the legal office only.
4. DATA RECIPIENTS
Your data may be made accessible, for the purposes of paragraph 2, to the following recipients in addition to RINA's authorized data processors:
- companies or other third parties (suppliers, other customers, professional firms, consultants, partners, financial institutions, e-payment service providers, insurance companies for providing insurance services, etc.) that RINA relies on, bound by specific legal agreements, including data processors;
- public bodies, supervisory authorities, judicial and regulatory authorities, accreditation or notification bodies, auditing firms, etc., for fulfilling legal or regulatory obligations.
5. DATA TRANSFER
Personal data are stored on servers located within the European Union. However, should it become necessary, RINA may transfer personal data to non-EU countries. In such cases, the transfer of data outside the EU will be in accordance with applicable legal provisions, including standard contractual clauses established by the European Commission and the adoption of binding corporate rules for intra-group transfers.
6. DATA SUBJECT RIGHTS
As a data subject, you have the right to:
i. obtain confirmation of the existence or otherwise of processing of your personal data, as well as a copy of such data;
ii. obtain details of: a) the origin of personal data; b) the purposes and methods of processing; c) the logic applied in cases of electronic processing; d) RINA's identification details, the data processors, and the data protection officer; e) the entities or categories of entities to whom personal data may be communicated or who may become aware of it as designated representatives within the state, data processors, or individuals in charge;
iii. obtain: a) the updating, correction, or integration of data; b) the deletion, anonymization, or blocking of data processed unlawfully; c) certification that the operations referred to in a) and b) have been notified, including as regards their content, to those to whom the data has been communicated or disseminated, unless this proves impossible or involves a disproportionate effort; d) obtain from RINA, in a structured, commonly used, and intelligible format, the personal data concerning you and, where technically feasible, obtain the direct transmission of such data from one controller to another;
iv. object: a) to the processing of your personal data, even if relevant to the purpose of collection; b) to the processing of your personal data for sending advertising material or commercial communications via e-mail;
v. withdraw consent previously given.
As a data subject, you also have the right to file a complaint with the competent supervisory authority.
7. EXERCISING RIGHTS AND COMMUNICATIONS
RINA Group has appointed a Data Protection Officer who can be contacted at any time for all matters relating to the processing of personal data and the exercise of related rights by sending an email to rina.dpo@rina.org.
Please note that you have the right to withdraw consent at any time by writing to rina.dpo@rina.org.
PRIVACY NOTICE UPDATE
This notice was updated in April 2025.
RINA reserves the right to further update this notice to reflect changes in applicable privacy regulations and internal data protection procedures. RINA encourages to periodically consult the website www.rina.org and your Preference Center for information on any changes.