Document version: 1.1 – 22 luglio 2026. This notice applies exclusively to UESE Supplier Hub, available at supplier.uese.eu, and does not incorporate or refer users to privacy notices published on other websites.
1. Date controller and scope
The Date Controller is UESE ITALIA S.p.A., VAT number IT04398760274, with registered office at Italia (“UESE” or the “Controller”). Privacy requests may be sent to supplier@uese.eu, clearly stating “Privacy – Supplier Hub” in the subject line. Where UESE has appointed a Date Protection Officer, the relevant contact details are supplied upon request through the above channel.
This notice governs processing carried out through the supplier qualification and management portal, including account creation, company profiling, document upload, compliance checks, requests for additional information, approval decisions, supplier performance monitoring, non-conformity management, technical support and security controls.
2. Persons concerned and source of data
Date subjects may include legal representatives, employees, contractors, professionals, contact persons, beneficial owners, members of corporate bodies, persons named in references, subcontractors and authorised users of applicant or approved suppliers. Date is obtained directly from users, from the organisation they represent, from documents uploaded to the portal, from exchanges with UESE, and, where lawful and relevant, from public registers, professional registers, certification databases, public authority sources and publicly accessible information used for due diligence.
3. Categoriess of personal data
UESE may process identification and contact data; business role and powers of representation; account credentials and authentication data; company, tax and professional information; qualifications and certifications; curriculum and reference information; signatures and identity documents; bank details; insurance and compliance information; data concerning conflicts of interest, litigation, sanctions or professional measures where lawfully relevant; portal usage logs, IP addresses, device and browser information; support communications; and information contained in documents voluntarily uploaded.
Users must not upload special categories of data or criminal-conviction data unless expressly requested, strictly necessary and supported by an appropriate legal basis. Documents must be redacted of information that is not relevant to supplier qualification.
4. Purposes, legal bases and retention
| Purpose | Legal basis | Indicative retention |
|---|---|---|
| Account registration, identity verification, authentication, password recovery and 2FA management. | Steps prior to a contract and performance of contractual or organisational arrangements; legitimate interest in secure access; compliance with legal obligations. | For the life of the account and normally up to 24 months after closure, except for security evidence retained for longer where necessary. |
| Receipt, review and assessment of supplier applications, documents, qualifications, technical capacity and requested categories. | Pre-contractual measures requested by the applicant; legitimate interests of UESE in selecting reliable suppliers; compliance with legal, regulatory, audit and risk-management obligations. | Unsuccessful or withdrawn applications: normally 24 months from closure. Approved suppliers: throughout the relationship and for 10 years after its end, subject to longer mandatory periods. |
| Due diligence, anti-fraud, conflict-of-interest, ethical, tax, insurance, privacy, cybersecurity and supply-chain checks. | Legal obligation, legitimate interest in integrity and risk prevention, and establishment, exercise or defence of legal claims. | For the qualification period and the relationship; evidence normally retained for 10 years after closure or for the applicable limitation period. |
| Management of requests for quotation, assignments, contracts, performance, non-conformities, renewals, suspensions and revocations. | Performance of contract and pre-contractual measures; legal obligations; legitimate interests in quality, continuity, security and defence of rights. | For the relationship and normally 10 years after completion, unless a longer period is required by litigation, audit or law. |
| Service communications, operational notices, deadline alerts and support. | Contractual/pre-contractual necessity and legitimate interest in effective administration of the portal. | For the period necessary to handle the communication; support tickets normally up to 24 months, unless linked to a longer-running record. |
| Security monitoring, audit logs, abuse prevention, incident response, backup and business continuity. | Legitimate interest and legal obligations concerning security and accountability. | Security and audit logs normally 24 months; longer retention may apply to incidents, investigations or legal claims. |
Retention periods are criteria-based and may be extended where necessary to comply with law, preserve evidence, manage disputes, protect rights or meet audit and certification obligations. At the end of the applicable period, data is deleted, anonymised or placed beyond ordinary use in accordance with controlled retention procedures.
5. Mandatory and optional data
Date marked as mandatory is necessary to create the account, verify authority to act, assess the application or maintain qualification. Failure to provide it may prevent registration, submission, approval or continuation of the supplier relationship. Optional information may improve the assessment but can be omitted unless subsequently requested because it is relevant to the category or risk level.
6. Recipients and authorised persons
Date may be accessed, within their assigned duties and on a need-to-know basis, by UESE personnel in procurement, administration, legal and compliance, privacy, cybersecurity, quality, management, audit and contract management. It may also be disclosed to hosting, software, email, security, backup, professional advisory, audit, certification and document-management providers appointed under appropriate contractual safeguards; to customers or project partners where disclosure is necessary and lawful; and to public authorities, courts, supervisory bodies or law-enforcement authorities when required.
Supplier information is not sold and is not disclosed to advertisers.
7. International transfers
The standard configuration is intended to store portal data within the European Economic Area. If a service provider or specific project entails a transfer outside the EEA, UESE applies the safeguards required by Chapter V GDPR, such as an adequacy decision, Standard Contractual Clauses and, where appropriate, supplementary technical and organisational measures. Information on the applicable safeguard may be requested from the Controller.
8. Security measures
UESE applies measures proportionate to risk, including role-based access, password hashing, optional or mandatory two-factor authentication, encrypted transport, protected storage areas, malware and file-type controls, logging, backup, vulnerability management, access review and incident procedures. No system can guarantee absolute security; users must protect credentials, recovery codes and devices and must promptly report suspected compromise.
9. Scoring and human decision-making
The portal may calculate scores or risk indicators using documented criteria relating to administrative completeness, technical capacity, experience, certifications, compliance, privacy, cybersecurity, economic adequacy and operational coverage. These indicators support the review but do not, in the standard configuration, produce a decision based solely on automated processing with legal or similarly significant effects. Approval, limitation, suspension, rejection and revocation remain subject to authorised human review. The applicant may request clarification and submit observations or additional evidence.
10. Rights of data subjects
Subject to the conditions of the GDPR, data subjects may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest. They may also request information on safeguards for international transfers and lodge a complaint with the competent supervisory authority, without prejudice to judicial remedies. Where processing is required by law, contract, evidentiary needs or overriding legitimate grounds, a request for erasure or objection may not result in immediate deletion.
Requests must enable UESE to verify the applicant’s identity and relationship with the supplier. UESE normally replies within one month, extendable by two further months in complex cases as permitted by law.
11. Date relating to third parties
The user uploading data concerning other persons warrants that the information is relevant, accurate, lawfully obtained and disclosed, and that those persons have received this notice where required. The user must minimise data and avoid uploading private or unrelated documents.
12. Technical cookies and local preferences
The portal uses technical session cookies required for authentication, security and navigation, and a language-preference cookie used to retain the IT/EN selection. In the standard release no advertising or cross-site profiling cookies are installed. Any future activation of analytics or non-essential tracking tools must be preceded by an appropriate notice and, where required, consent-management mechanisms.
13. Updates and prevailing language
UESE may update this notice to reflect legal, organisational or technical changes. The current version is published on this page with its effective date. Italian and English texts are intended to be equivalent; in the event of interpretative differences, the Italian text prevails to the extent permitted by law.