Il Regolamento Generale sulla protezione dei dati (GDPR) definisce standard rigorosi per compliance, sicurezza e protezione dei dati in Europa. CoreTech supporta i clienti nella conformità con servizi, documentazione e responsabilità condivisa per ogni piattaforma.
The General Data Protection Regulation (GDPR) is the legal framework for the processing of personal data in Europe that introduces stringent requirements that set new standards in compliance, security and data protection.
In addition to ensuring its compliance, CoreTech is committed to offering services and resources that allow clients to comply with any GDPR requirements that they are required to comply with regarding their activities. In this regard, CoreTech has released new features and others will be.
CoreTech is a 100% Italian company and the data centers are located in Italy. For more information visit the Datacentre page
CoreTech recently announced its compliance with the CISPE Code.of Conduct of which Amazon AWS, Aruba, Register and OVH are also members.
The CISPE Code of Conduct enables cloud customers to assess their cloud infrastructure provider's compliance with data protection obligations under the GDPR.
This further reassures customers of their ability to control their data in a safe, secure and compliant environment.
To avoid misinterpretations of regulatory obligations, the essential expressions for understanding the GDPR are defined below:
CoreTech acts as the data processor for all processing activities and as the data controller only for client contact data.
This is certainly the case when your expectations of CoreTech are high. CoreTech acts as the "data processor" when processing personal data on behalf of a data controller or another processor.
This is the situation that occurs when using CoreTech services and storing personal data on a CoreTech infrastructure. Within the limits of its technical constraints, CoreTech will process hosted data solely as directed by you, and on your behalf.
In the role of data processor, CoreTech undertakes to carry out the following actions:
CoreTech acts as the "data controller" when it determines the means and purposes of processing its own personal data.
This is the case where CoreTech collects data for billing, service and performance improvement, sales operations, commercial management, etc ..., but also when CoreTech processes the personal data of its employees.
In this case, "your" data hosted on CoreTech services, are not affected, unlike some information concerning you or your employees (for example information relating to the identity and contact details of your contact in CoreTech as part of a request for Support ). This is why CoreTech is keen to explain the safeguards put in place to ensure the protection of this personal data:
It is essential to distinguish between the security of client hosted data and the security of the infrastructures hosting this data.
The client is solely responsible for the security of their resources and application systems implemented for the use of services. CoreTech provides tools to support clients in protecting their data. Each service has its own specific tools; some of them are listed below:
CoreTech is committed to guaranteeing the maximum security of its infrastructures, in particular by implementing an information systems security policy and responding to the needs of numerous laws and certifications. CoreTech takes the necessary measures to preserve the security and confidentiality of the personal data processed, in particular, to prevent them from being violated, damaged, or from unauthorized third parties accessing them.
In terms of compliance and data security, both CoreTech and the client are both responsible, albeit on different fronts.
CoreTech si occuperà quindi della manutenzione, dell'aggiornamento e della protezione dell'infrastruttura fisica su cui vengono eseguiti tutti i servizi cloud.
Only at the explicit request of the client or upon the release of access passwords, CoreTech will be able to intervene at a technical level on the service purchased.
Based on the CoreTech service used, the competencies of shared responsibility are detailed below. We invite all clients to read their responsibilities concerning the services used.
CoreTech is committed to applying all reference standards to ensure information security.
Documentazione ufficiale GDPR, contratti, DPA e riferimenti normativi.
Consulta il DPA, le certificazioni di sicurezza e l'informativa privacy per completare il quadro normativo dei servizi CoreTech.