Privacy Policy
Last updated:
Courtesy translation. In the event of any discrepancy, the Italian version of this document prevails: read the Italian version
This notice describes how Nexaura S.r.l. (the “Controller”) processes the personal data of those who visit the website www.nexaura.it (the “Site”) and of those who contact the Controller through the channels shown on the Site. It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “Regulation”) and to Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the Italian Privacy Code). Article 14 applies where the Controller receives data relating to persons other than the person who provides them (see section 3.2).
The notice covers the Site and any contact initiated through the details published on it. It does not apply to third-party sites or platforms reachable through links on the Site (for example social networks), which are governed by their own notices, nor to the processing carried out by the Controller in performing professional engagements, for which separate notices are provided.
In brief
- We collect only the data needed to run the Site securely and to reply to those who contact us.
- The Site uses no profiling cookies, no third-party analytics tools and no fonts loaded from external servers.
- The data entered in the contact form are used to handle your enquiry. No newsletter, no commercial communications unrelated to the enquiry, no transfer to third parties for marketing purposes.
- Data are kept only for as long as strictly necessary and are then deleted.
- You may exercise the rights granted by the Regulation at any time by writing to the contact details shown in the box above.
This summary is provided for clarity and does not replace the full notice set out below.
1. Data controller
The data controller is Nexaura S.r.l. The Controller’s identification and contact details (company name, registered office, VAT number, email address and certified email (PEC) address) are shown in the box at the top of this page. Any question concerning the processing of personal data may be sent to the email address or the PEC address indicated there.
2. Data Protection Officer (DPO)
[DA COMPLETARE: mantenere una sola delle due formulazioni, A oppure B, ed eliminare l’altra]
A. The Controller has appointed a Data Protection Officer (DPO) pursuant to Article 37 of the Regulation, who may be contacted at the email address [DA COMPLETARE: indirizzo dedicato] or by post at the Controller’s registered office. Data subjects may contact the DPO on any matter relating to the processing of their data and to the exercise of their rights (Article 38(4)).
B. The Controller has not appointed a Data Protection Officer, as the conditions set out in Article 37(1) of the Regulation do not apply. Any request concerning data protection may be addressed directly to the Controller using the contact details shown in the box.
3. Data processed, purposes and legal bases
3.1 Browsing data
The IT systems and software procedures that run the Site acquire, in the course of normal operation, certain data whose transmission is inherent in the use of internet communication protocols: the IP address of the device, the type and version of the browser and of the operating system (user agent), the date and time of the request, the page requested, the referring page, the outcome of the request and other technical parameters. These data are recorded in the server logs and are not collected in order to associate them with identified individuals; by their nature, however, they could make it possible to identify users through processing and matching with data held by third parties.
Purposes: to allow the Site to operate, to keep it secure and to prevent and detect abuse or cyber attacks. The data may also be used to derive, from the server logs alone and without third-party tools, aggregated and anonymous statistical information on the use of the Site, and to establish liability in the event of computer crimes committed against it.
Legal basis: the Controller’s legitimate interest in the security and continuity of the service (Article 6(1)(f) of the Regulation).
3.2 Data provided by the user
The contact form collects: first name and surname, email address and the content of the enquiry (mandatory fields); company, telephone number and area of interest (optional fields); confirmation of having read this notice and the request to be contacted, given by ticking the relevant box. That box does not constitute a request for consent: the processing needed to handle the enquiry rests on the legal bases set out in the table below. The form also contains a hidden anti-spam field, which users neither see nor complete: if it is found to have been completed, the enquiry is discarded as an automated submission. The field collects no user data.
Similar data are processed where the user contacts the Controller directly, by writing to the email addresses shown on the Site.
How the form is sent [DA COMPLETARE: prima della pubblicazione lasciare solo la modalità effettivamente attiva]:
- if the Controller has activated an external form-management service, the data are transmitted to that supplier, which delivers them to the Controller and acts as a processor (see section 6);
- otherwise, submitting the form opens the user’s email program with a pre-filled message, which the user sends from their own mailbox. In this case the Site stores no data: the information passes through the email provider chosen by the user and reaches the Controller’s mailbox.
| Purpose | Legal basis |
|---|---|
| Replying to the enquiry, contacting the data subject to explore the requirement described, providing the information requested and managing the pre-contractual relationship (meetings, proposals, quotations) | Performance of pre-contractual measures taken at the data subject’s request (Art. 6(1)(b)), where the data subject acts on their own behalf, as a professional or as a sole trader. Legitimate interest of the Controller and of the data subject’s own organisation in handling the enquiry (Art. 6(1)(f)), where the data subject acts on behalf of a company or other body and is not themselves a party to the future contract; in that case an objection may be raised at any time (section 9) |
| Complying with legal obligations, for example in accounting matters or at the request of the authorities | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising or defending the Controller’s rights in or out of court | Legitimate interest (Art. 6(1)(f)) |
The data provided are not used to send newsletters or commercial communications unrelated to the enquiry, nor are they disclosed to third parties for marketing purposes.
Users are asked not to include in their message data belonging to special categories (Article 9 of the Regulation: for example data concerning health, religious beliefs or trade union membership) or data relating to criminal convictions and offences (Article 10), unless strictly necessary. Where such data are nevertheless provided voluntarily, the Controller uses them only in so far as strictly necessary to handle the enquiry, does not record them in any further archive and deletes them as soon as possible. Where required, before any further use the Controller asks the data subject for explicit consent pursuant to Article 9(2)(a) of the Regulation.
Where a user provides third-party data (for example the contact details of a colleague or an associate), that user warrants that they are entitled to do so and undertakes to inform the individuals concerned. The Controller provides those individuals with the information required by Article 14 at the first appropriate opportunity, including by reference to this page.
3.3 Cookies and tracking tools
The Site uses no profiling cookies and no third-party analytics tools. Fonts are hosted on the Site’s own server: no connection is made to Google Fonts or to similar services, and no browsing data are therefore transferred to such parties by this route. There are no scripts, videos, maps or content embedded from external platforms. Detailed information on any strictly necessary technical cookies is set out in the Cookie Policy.
4. Provision of data and consequences of refusal
Browsing data are acquired automatically: providing them is necessary for the Site to function technically, and the only way to avoid it is not to visit the Site.
Providing the data requested by the contact form is optional. The fields marked with an asterisk are, however, essential in order to act on the enquiry: without them the form cannot be sent. The optional fields allow a more targeted reply. Ticking the box confirming that this notice has been read and requesting to be contacted is necessary in order to send the form: it serves to document that the information required by Article 13 has been provided, and does not constitute consent to the processing. Anyone who prefers not to use the form may contact the Controller using the details shown in the box.
5. How data are processed and security measures
Processing is carried out using IT tools and, in limited cases, paper records, by persons authorised and instructed pursuant to Article 29 of the Regulation and Article 2-quaterdecies of the Italian Privacy Code. The Controller adopts technical and organisational measures appropriate to the risk, in line with Article 32 of the Regulation, including:
- connections to the Site protected by encryption (HTTPS) [DA VERIFICARE: certificato e redirect HTTPS attivi in produzione];
- a Site built from static pages, with no restricted areas, no user databases and no authentication systems;
- access control over the mailboxes and the systems in which enquiries are held;
- backup copies;
- minimisation of the data collected;
- procedures for handling personal data breaches (Articles 33 and 34).
The data are not disseminated.
6. Data recipients
The data may be processed on the Controller’s behalf, under a contract compliant with Article 28 of the Regulation, by the following processors:
- the provider of the hosting services for the Site: [DA COMPLETARE: denominazione, sede e Paese del fornitore];
- the provider of the contact form management service, where activated: [DA COMPLETARE se attivato: denominazione, sede e Paese del fornitore];
- the providers of the email services and of the other IT tools used by the Controller to receive and handle enquiries: [DA COMPLETARE: denominazione, sede e Paese di ciascun fornitore].
The data may also be disclosed to:
- consultants and professional advisers (legal, tax and IT) engaged by the Controller, bound by professional secrecy or by contractual confidentiality obligations, acting either as processors or as independent controllers;
- judicial, administrative and supervisory authorities, in the cases provided for by law or at their request.
Beyond these cases the data are not disclosed to third parties, nor transferred to other parties for purposes of their own. An up-to-date list of the processors may be requested from the Controller.
7. Transfers of data to third countries
The Controller does not transfer data outside the European Economic Area for its own purposes. Where the suppliers listed in section 6 use infrastructure or support services located in third countries, the transfer takes place in accordance with Chapter V of the Regulation: on the basis of an adequacy decision of the European Commission (Article 45) or of the standard contractual clauses approved by the Commission (Article 46(2)(c)), supplemented where necessary by additional measures. Information on the safeguards adopted, and copies of the relevant documents, may be requested from the Controller.
8. Retention period
| Data | Retention period |
|---|---|
| Technical server logs | For the period set out in the contractual documentation of the hosting provider, namely [DA CONFERMARE: N] months from the date of recording, unless a longer period is needed to investigate security incidents or unlawful acts, or to defend rights |
| Contact enquiries (form, email) and related correspondence | For as long as needed to handle the enquiry and in any event no longer than 24 months from the last substantive contact [DA CONFERMARE] |
| Data from enquiries that lead to a professional engagement | These become part of the contractual relationship and follow the periods set out in the notice provided in that context, including accounting record-keeping obligations (10 years, Article 2220 of the Italian Civil Code) |
| Evidence that the notice was read and that the enquiry was sent | Together with the enquiry to which it relates, for the same period and for such further time as is needed to demonstrate that the processing was lawful |
Once these periods expire, the data are deleted or anonymised. The periods may be suspended in the event of litigation or of a request from the authorities.
9. Rights of data subjects
Data subjects may exercise the following rights, within the limits and subject to the conditions set out in Articles 15 to 22 of the Regulation:
- access to their personal data and to information on the processing (Article 15);
- rectification of inaccurate data and completion of incomplete data (Article 16);
- erasure of the data, in the cases provided for (Article 17);
- restriction of processing (Article 18);
- portability of data processed by automated means on the basis of consent or of a contract (Article 20);
- objection to processing based on legitimate interest, on grounds relating to the data subject’s particular situation (Article 21);
- withdrawal of consent, where the processing rests on it, at any time and without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).
Requests may be sent to the Controller’s email address or PEC address shown in the box, or by post to the registered office. The Controller replies without undue delay and in any event within one month of receipt; that period may be extended by two months taking into account the complexity and number of requests, with reasons given to the data subject within the first month (Article 12(3)). Exercising these rights is free of charge, except in the case of manifestly unfounded or excessive requests. Where necessary, the Controller may ask for information in order to verify the identity of the person making the request.
Anyone who considers that the processing infringes the Regulation has the right to lodge a complaint with the Italian Data Protection Authority (Garante), in the manner set out at www.garanteprivacy.it (Article 77) or, alternatively, to bring proceedings before the courts (Article 79 of the Regulation and Article 140-bis of the Italian Privacy Code).
10. Minors
The Site and the Controller’s services are addressed to businesses, professionals and organisations. The Site is not intended for children under 14 and the Controller does not knowingly collect data relating to them (Article 8 of the Regulation and Article 2-quinquies of the Italian Privacy Code). Should the Controller become aware of having received a child’s data without the consent of the holder of parental responsibility, it will delete them. Holders of parental responsibility who believe that a child has provided data through the Site may contact the Controller using the details shown.
11. Automated decision-making
The Controller does not take decisions based solely on automated processing, including profiling, that produce legal effects concerning data subjects or similarly significantly affect them (Article 22 of the Regulation). The data collected through the Site are not used to build user profiles.
12. Changes to this notice
The Controller may update this notice to reflect legislative changes, new guidance from the Garante or changes in the processing carried out through the Site. The updated version is published on this page; the date of the last update is shown at the top. Readers are invited to consult it periodically. In the event of substantial changes affecting ongoing processing, the Controller will give notice, where possible, to the people with whom it is in contact.