PRIVACY POLICY

1. INTRODUCTION

1.1 Purpose

COMO LIGHTING S.R.L. processes personal data for the design, planning, and production of lighting products dedicated to the fields of architecture, design, contract, public spaces, street lighting, and architectural lighting for large indoor and outdoor areas. COMO LIGHTING S.R.L., an established company in the sector, continuously invests in production to have technologically advanced equipment and develops ongoing staff training aimed at creating industrial safety protections for machinery and production lines. COMO LIGHTING S.R.L. develops a high level of specialization in safety and operates in constant synergy with other entities of the Pontiggia Group, allowing Metal-P to intervene at various scales. COMO LIGHTING S.R.L. respects the right to privacy of any individual who shares personal data, complying with the laws and regulations that protect personal data as decreed by the EU Regulation 2016/679. This Policy explains the most important principles of personal data protection and how these principles should be implemented.

1.2 Scope and Applicability

This Policy concerns all personal data collected, processed, shared, or used by COMO LIGHTING S.R.L. and applies to all employees, contractors, outsourcers, clients, and suppliers. This Corporate Personal Data Processing Policy is an integral part of the GENERAL OPERATING MANUAL FOR DATA PROCESSING AND PROTECTION that contains the methods of data processing, risk assessment for data processing, and the technical and organizational measures implemented by COMO LIGHTING S.R.L. under the EU GDPR 2016/679 Regulation. The General Operating Manual for Data Processing and Protection is updated and revised annually and/or reviewed and updated as necessary (e.g., changes in company structure, changes and/or additions in the purposes of processing, etc.) as required by Art. 24, Section 1 of the EU Regulation 2016/679.

1.3 Purpose of Processing

Data processing is intended for the following purposes: management of customer relationships (phone contacts, on-site visits, quotes, order management, invoice issuance, product technical documentation, certifications); contractual obligations, dispute management, compliance with legal obligations, particularly accounting, tax, and health and safety in the workplace.

2. PRINCIPLES AND RULES FOR EMPLOYEES AND OUTSOURCERS/CONTRACTORS OF COMO LIGHTING S.R.L.

2.1 Compliance with the Law

COMO LIGHTING S.R.L., a solid company of the Pontiggia Group Srl, with a rich professional history, is a reliable partner in the field of design, planning, and production of lighting products. The services offered by the company include: – Pre- and post-sales consulting starting from an accurate study of the space to be illuminated, offering the client a team of technicians who can recommend the most suitable type of product; once the product is chosen and developed, Como Lighting can provide ongoing technical support for implementation and maintenance; photometric calculations to thoroughly understand each requirement and determine the most effective type of light for a given environment. – Mechanical design of each individual component. – Heat management, ensuring high and constant lighting quality throughout the product’s lifespan. – Selection of the best LEDs available on the market, which guarantee high lighting values and lower consumption. All individuals and workers employed by COMO LIGHTING S.R.L. have the specific responsibility to comply with this commitment, as described in this Policy and as provided in applicable privacy laws. Employees are required to recognize if they are collecting, processing, sharing, or using personal data. They must be aware of general privacy requirements, the principles governing the management of personal data, and when to report issues to the Data Controller. The definition of personal data is any information concerning an identified or identifiable natural person (“data subject”); an identifiable person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.

2.2 Collecting and Using Personal Data in a Proper and Lawful Manner

A fundamental principle of Privacy management requires that COMO LIGHTING S.R.L. processes personal data in a fair and lawful manner. When collecting and using personal data, consider how you would like to be treated by a company collecting your information, in line with the relevant laws, regulations, and this Policy. Employees must: – Collect and use personal data only for a justified reason that may include the legitimate business interests of COMO LIGHTING S.R.L. Before collecting information, inform individuals how their personal data will be used (through the data processing notice). – Collect only the personal data necessary for a specific business purpose. – Use personal data only for the specific purpose described in the privacy notice, consent form, or in a manner that a person would reasonably expect. – Use personal data in ways that do not have a negative impact on the data subject unless such use is justified by law. – Anonymize personal data or use pseudonyms where possible and appropriate. Definitions related to this Policy’s approach to the collection and use of personal data: – **”Anonymization”** refers to the process by which personal data is permanently stripped of all identifying elements and can no longer be linked to a person. Once this is done, they are no longer considered personal data. – **”Consent”** refers to any freely given, specific, informed, and unambiguous indication of the data subject’s wishes to have their data processed. – **”Explicit Consent”** means that the individual has been clearly given the option to accept or decline the collection, processing, or disclosure of personal data and can explicitly indicate their choice. – **”Privacy Notice”** is an oral or written statement provided to data subjects when their personal data is collected. The notice describes who is collecting the personal data, why the personal data is being collected, how it will be used, shared, and stored, and any other relevant information that the subject should be aware of. – **”Pseudonymization”** refers to replacing the data subject’s name and most other identifying features with a label, code, or other artificial identifier to prevent the identification of the subject. Pseudonymized data continues to be considered personal data.

2.3 Manage and Store Personal Data Responsibly

Responsible management of personal data is required to protect the right to privacy and comply with data privacy laws. Each employee is responsible for complying with data privacy obligations related to personal data. Employees who collect, use, and store personal data must: – Keep personal data accurate and up to date throughout their lifecycle (from collection to destruction). – Protect personal data so that it is not shared with others. – Comply with the policies and procedures in the COMO LIGHTING S.R.L. General Operating Manual for Data Processing and Protection regarding data security when handling personal data. – Prevent the misuse of personal data for purposes incompatible with the original purpose for which it was collected. – Ensure data traceability throughout their lifecycle. – Retain personal data only for as long as necessary for the indicated purpose or for the time required by law. Refer to record retention requirements for specific time periods for retaining personal data. – Report any data privacy violations to COMO LIGHTING S.R.L. by email at: como-lighting@legalmail.it. Definitions related to this Policy’s approach to the responsible management and storage of personal data: – **”Data Privacy Breach”** refers to any unauthorized disclosure, acquisition, access, destruction, or alteration, or any similar action involving personal data, or any incident in which the confidentiality of personal data may have been compromised. – **”Traceability”** tracks the lifecycle of data to monitor all access, modifications, and storage of personal data. Traceability helps COMO LIGHTING S.R.L. demonstrate transparency, compliance, and adherence to applicable laws and regulations.

3. IMPLEMENTATION FOR EMPLOYEES AND OUTSOURCERS/CONTRACTORS OF COMO LIGHTING S.R.L.

3.1 Training, Information, and Awareness for Employees

Employees must become familiar with this Policy and any other privacy-related document of COMO LIGHTING S.R.L. under the provisions of the EU Regulation 2016/679. To implement familiarity with the Corporate Privacy Policy, each employee must participate in training periodically provided by the Data Controller to maintain and enhance their skills in privacy-related matters. The Data Controller will implement training, information, and awareness for outsourcers and contractors of COMO LIGHTING S.R.L. through assignment and appointment procedures related to activities required for privacy purposes.

3.2 Training, Information, and Awareness for Outsourcers

The Data Controller will implement training, information, and awareness for outsourcers and external contractors of COMO LIGHTING S.R.L. through assignment and appointment procedures related to the activities they must perform for privacy purposes.

3.3 Reporting Potential Non-compliance/Non-Retaliation

Any employee who becomes aware of a potential violation of applicable privacy laws and/or a potential violation of this Policy is required to immediately report the suspicion to the Data Controller. Employees who report potential non-compliance, provide information, or participate in any investigation into possible non-compliance will be protected against retaliation.

3.4 Violation of this Policy

Violations of this Corporate Privacy Policy may lead to disciplinary or other actions, up to termination of employment or contract (for third-party contractors).

3.5 Responsibilities and Implementation

Each department head appointed by COMO LIGHTING S.R.L. is responsible for compliance with this Policy within their area of functional responsibility, setting an example and providing guidelines to the employees reporting to them. All employees are responsible for complying with the principles and rules defined in this Corporate Privacy Policy.

4. DATA CONTROLLER IDENTITY

The Data Controller, identified as the owner and legal representative of COMO LIGHTING S.R.L., has the registered office at: COMO LIGHTING S.R.L., Via Sant’Ambrogio, 71 – 22040 ALZATE BRIANZA (COMO) – ITALY – Tel +39 031/5621594 – VAT and Fiscal Code: 03411080132 – Certified email: como-lighting@legalmail.it The Data Controller guarantees the security, confidentiality, and protection of the data in the possession of COMO LIGHTING S.R.L. at any stage of the processing. The data collected is used in compliance with current privacy laws, EU Regulation 2016/679 of the European Parliament and Council, dated April 27, 2016.

5. DATA PROCESSING LOCATION

Data will be processed by the Data Controller at the registered office and operational offices. Registered office: Via Sant’Ambrogio, 71 – 22040 ALZATE BRIANZA (COMO) – ITALY Operational office (administration): Via del Dosso, 105 – 22040 ALZATE BRIANZA (COMO) – ITALY

6. DATA RETENTION PERIOD

The Data Controller will process personal data for the time necessary to fulfill the purposes indicated above and, in any case, no longer than 10 years from the termination of the relationship for Service Purposes; some personal and particular data are retained for the period required by current regulations (e.g., documentation, analyses, and evaluations related to workplace health and safety, documentation related to legal actions, etc.). The User may always, at any time, request the cessation of Processing or the deletion and/or restriction of Data.

7. CONSENT REVOCATION

Pursuant to Article 6 of GDPR 679/16, the data subject may revoke consent at any time.

8. DATA SUBJECT RIGHTS

With reference to Articles 15 “Right of access by the data subject,” 16 “Right to rectification,” 17 “Right to erasure (Right to be forgotten),” 18 “Right to restriction of processing,” 20 “Right to data portability,” 21 “Right to object to automated decision-making” defined by GDPR 2016/679, the data subject exercises their rights by sending a registered letter with return receipt to the Data Controller at the following address: COMO LIGHTING S.R.L. Via Sant’Ambrogio, 71 – 22040 ALZATE BRIANZA (COMO) – ITALY – Tel +39 031/5621594 – VAT and Fiscal Code: 03411080132 – Certified email: como-lighting@legalmail.it – or sending an email to: info@como-lighting.it

9. MINORS

The Data Controller’s services are not intended for minors under 16 years of age (according to EU Regulation), and the Data Controller does not intentionally collect personal information from minors. If information about minors is unintentionally recorded, the Data Controller will promptly delete it at the user’s request. The only personal data collected about minors under 16 are related to internships, traineeships, and school-to-work programs (for health and safety at work purposes, consent to the processing of personal data for minors must be given by a guardian or by the holder of parental authority for work-related purposes, complying with the provisions of Legislative Decree No. 81 of April 9, 2008, as amended, Law 977 of October 17, 1967, as amended, MIUR Decree No. 195 of November 3, 2017, as amended – and for income tax declarations of persons dependent on the company’s employee).

10. LODGING A COMPLAINT

The data subject has the right to lodge a complaint with the supervisory authority of their country of residence.

11. INFORMATION NOT CONTAINED IN THIS POLICY

Further information regarding the processing of personal data can be requested at any time from the Data Controller using the contact information.

12. CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to make changes to this Privacy Policy at any time, providing notice to Users on the company website. Please consult the site www.gruppopontiggia.it (Como Lighting s.r.l. section) frequently, using the date of the last modification as a reference. In case of non-acceptance of the changes made to this privacy policy, the User can request the removal of their personal data, unless otherwise specified.

13. INFORMATION ABOUT THIS PRIVACY POLICY

The Data Controller is responsible for this privacy policy. Last updated: Alzate Brianza – September 15, 2022