Compliance
Organizational Model 231 (Modello Organizzativo D. Lgs. 231/01)
The Legislative Decree 08.06.2001 n. 231 introduced, in the Italian legal system, an administrative liability in charge of the Companies for certain crimes committed in their interest or advantaging persons who are functionally linked to them.
In order to ensure in advance the commission of the offenses contemplated in the Decree, Dumarey Softronix S.r.l. Board of Directors adopted its own organization, management and control model («Model»).
The Model is divided into: General Part, Special Parts and Attachments which are binding for all parties who have professional relationships with the Company.
The so-called Surveillance Body has also been entrusted with the task of supervising the functioning and observance of the model, as well as ensuring its updating.
Code of Ethics
Dumarey Softronix S.r.l believes that acting in a sustainable, responsible, and ethical manner is the key for successful development and is fully committed to ensure a working environment based on mutual respect, trust, transparency and accountability in every-day actions.
Our Company attributes great importance to its employees, who represent an inestimable legacy of experience, passion and knowledge and guarantees the full respect of the principles of equal opportunity and equal treatment, regardless of skin colour, ethnic or social origin, age, disability, sexual identity, worldview, or gender.
Dumarey Softronix S.r.l protects health and safety in the workplace and guarantees the highest standards of quality and safety of its products and engineering solutions.
Environmental compliance is a priority for our Company, that operates in accordance with all applicable legislation and on-site procedures, actively involves employees in protecting the environment and commits to reduce waste and recycle materials through the production cycle.
Dumarey Softronix S.r.l. efforts are oriented towards the development of a more sustainable mobility and the transition to a zero-emission society, by producing technology and products that reduce negative environmental impact.
All these principles are defined and written in our Code of Ethics:
Whistleblowing
Dumarey Softronix S.r.l. rejects and does not tolerate any form of unethical or illegal behaviour. To protect itself and its employees from negative consequences and prosecution, Dumarey Softronix S.r.l. implemented and adopted a detailed procedure.
The early detection and reporting of a violation allow the Company to promptly react taking actions and preventing consequences to the company and the public.
Your support in identifying and resolving violations is highly important to Dumarey Softronix S.r.l. that instituted an internal reporting channel, which you may use to quickly and easily report any violation or misconduct that might affect you, the Company or the wellbeing of other people involved in working circumstances.
Which topics are covered by whistleblowing?
You can report any criminal or unethical activities, as per D. Lgs. 24/2023, e.g., about the following:
significant illegal conduct pursuant to Decree 231 and violations to 231 models.
violations to European legislation on transport safety, environmental protection, food safety, public health, consumer protection, privacy and personal data protection, network, and information system security.
violations to competition law and state aid.
violation to ethical standards (e.g., ISO standards, Code of Ethics) to which the Company has expressly declared that it adheres.
The following reports are excluded:
- related to a personal interest of the whistleblower, pertaining to individual employment relationships.
- in matters of defense and national security.
Reporting channel
Internal Reporting Channel
You can report violations using the electronic platform, where you can find the privacy notice:
https://dumarey.integrityline.com/
All reports will be promptly managed by Internal Auditor and Ethical Committee. All information will be taken seriously and treated confidentially.
Within 7 days from the reporting mail, you will receive confirmation of receipt.
Within 3 months from the confirmation of receipt, you will receive an update related to the reported violation. It could be either a partial or final update. In case of partial update, you will also be informed at closed investigation.
External Reporting Channel
There is also a public channel, managed by public body ANAC, https://www.anticorruzione.it/ that can be used only in the cases listed in art. 6 of D. Lgs. 24/2023.
Who can use these Channels
Compliance procedures
Privacy Notice
This privacy notice is aimed at describing the processing of personal data (“Data”) carried out by Dumarey Softronix S.r.l. (“Company”) through this website (“Website”).
WHICH PERSONAL DATA WE PROCESS AND FOR WHAT PURPOSE
The data collected through the Website and the related purpose of the processing are the following:
- Data provided by the user in the contact form (name, surname, phone number, e-mail address and organization), that will be processed by the Company in order to respond to requests of information related to its services, on the basis of article 6 (1) (b) of GDPR.
- Browsing Data or data arising from the interaction of the users with the Website; these Data are necessary to ensure the functioning of the Website and are not collected to be associated with specific users, but through them or through other information collected, user identification is still possible.
- Cookies, which are small text strings that can be sent and recorded on the user’s computer by the websites visited, to then be retransmitted to the same websites when the user visits them again; for more information please to refer to our Cookie Notice.
PROCEDURES OF THE PROCESSING
The data will be processed by automated or electronic means, in compliance with current regulations regarding the processing of personal data.
COMMUNICATION OF DATA TO THIRD PARTIES
The Data may be communicated to third parties operating on behalf of the Company by virtue of a contractual relationship, appointed as data processors where applicable.
The Data may also be sent to third parties, if necessary, to comply with legal obligations, orders from public authorities or to allow the Company to exercise its rights before judicial authorities.
DATA RETENTION
The Data provided by the user in the contact form will be kept for three years, unless will be further processed to execute a contract, in which case they will be kept according to the applicable legal requirements.
The browsing Data used by the Website will be kept for one year.
The cookies will be kept according to the retention periods indicated in the Cookie Notice.
DATA CONTROLLER AND DATA PROTECTION OFFICER
The data controller is Dumarey Softronix S.r.l. with its registered office in Corso Castelfidardo 36, Torino. You can contact our DPO at the following email address: DPOTorino@dumarey.com
DATA SUBJECTS’ RIGHTS
Data subjects can exercise the following rights:
- right to access means the right to obtain from the Company whether your Data are being processed and, where applicable, have access to them;
- right to rectification and right to erasure means the right to obtain the rectification of inaccurate and/or incomplete Data, as well as the erasure of Data when the request is legitimate;
- right to restriction of processing means the right to request suspension of the processing when the request is legitimate;
- right to data portability means the right to obtain Data in a structured format, ordinary used and readable, as well as the right to transfer Data to other controllers;
- right to object means the right to object to the processing of Data when the request is legitimate, including when the Data are processed for marketing or profiling, if applicable;
- right to lodge a complaint with a supervisory authority in case of unlawful processing of Data.
Data subjects can exercise the abovementioned rights by writing to the e-mail address privacytorino@dumarey.com.
SOCIAL MEDIA
The Company has created a page on Linkedin and may create pages on other social media.
When visiting these pages, Social Media collect user Data as data controllers. Further information on the processing of Data by the various Social Media are available on their respective privacy policies.
The Company only has access to information shared by the user as “public” through the interaction with Social Media pages. The Company can also view the Data that users of Social Media pages provide by sending public or private messages; such Data may be used by the Company to provide the information requested by the user.
Social Media will send anonymous statistics to the Company on the use of the pages, containing information such as the number of followers, the number of interactions on a post or advertisement or the demographics of users, which will be used to improve the online content of the Company and to better respond to users’ interests.
AMENDMENTS AND UPDATES
This Privacy Notice was updated in October 2024.
The Company reserves the right to amend or updates the Privacy Notice. Any update will be published on the Website and it will be effective upon posting.
Corporate Social Responsibility
Certifications
TISAX
The Dumarey Group applies TISAX
For the Dumarey Group, confidentiality, availability and integrity of information have great value, therefore we have taken extensive measures to protect sensitive information by following the catalogue of information security questions of the German Automotive Industry Association (VDA ISA).
The assessment was successfully conducted for all companies of the Dumarey Group by a certified audit provider TISAX (Trusted Information Security Assessment Exchange).
Through this assessment, all the Dumarey Group’s companies have demonstrated their commitment to the stringent TISAX VDA ISA security standards.
The group has always prioritised product quality and customer satisfaction. With this TISAX assessment, Dumarey further strengthens its leadership in ensuring data protection and information security.
Paolo Carlo Pomi, CISO of the Dumarey Group, said: ‘We will continue to invest in best practices and technologies to ensure the ongoing security of our customers’ data’.
The result is available exclusively on the ENX portal: https://portal.enx.com/en-US/TISAX/tisaxassessmentresults/.