1. Data Controller
Pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR), the Data Controller is:
Daniele Biancu
Via Torrita 43/B
00037 Segni (RM) – Italy
Phone: +39 328 9537839
Email: contact@arassystems.com
VAT No.: 17549031007
The Data Controller processes personal data in accordance with the principles of lawfulness, fairness, transparency, and confidentiality established by applicable data protection legislation.
2. Types of Data Collected
Through this website, the following categories of personal data may be collected:
- identification data (first name and last name);
- contact details (email address and telephone number);
- technical browsing data;
- IP addresses and security logs;
- any additional information voluntarily provided by users through the contact forms.
3. Purposes of Processing
Personal data are collected and processed for the following purposes:
a) Handling Contact Requests
Through the contact form available on the website, users may request information about the services offered.
The legal basis for this processing is the performance of pre-contractual measures requested by the data subject pursuant to Article 6(1)(b) of the GDPR.
b) Website Security
The website uses security tools to prevent unauthorised access, fraudulent activities, spam, and cyberattacks.
The legal basis for this processing is the legitimate interest of the Data Controller pursuant to Article 6(1)(f) of the GDPR.
c) Compliance with Legal Obligations
Personal data may also be processed to comply with legal obligations, regulations, or requests from competent public authorities.
4. Methods of Processing
Personal data are processed using electronic and IT-based systems in accordance with the security measures required by the GDPR and applicable national legislation.
Appropriate technical and organisational measures are implemented to prevent unauthorised access, disclosure, alteration, or destruction of personal data.
5. Data Retention
Personal data submitted through the contact form are retained for the time necessary to process the user’s request and, in any event, for no longer than 24 months from the last communication, unless a longer retention period is required by law.
Technical and security-related data may be retained for longer periods where necessary for legal protection or cybersecurity purposes.
6. Disclosure of Personal Data
Personal data are not disclosed to the public.
However, they may be shared with service providers whose activities are necessary for the operation of the website, including:
- hosting and web infrastructure providers;
- email service providers;
- cybersecurity service providers;
- technical consultants and professional advisers appointed by the Data Controller;
- public authorities, where required by law.
Where required, such parties act as Data Processors pursuant to Article 28 of the GDPR.
7. Services Used by the Website
WordPress
Content Management System (CMS) used for the management and publication of the website.
Contact Form 7
The contact form enables users to voluntarily submit their personal data in order to request information or receive communications.
Cloudflare Turnstile
To protect the website against automated messages and spam, this website uses Cloudflare Turnstile.
This service may collect technical information relating to the user’s device and connection in order to distinguish genuine users from automated systems.
WP Mail SMTP
Used exclusively to ensure the correct transmission and delivery of emails generated by the website.
Wordfence Security
Security service used to protect the website against unauthorised access, malware, suspicious activities, and cyberattacks.
Wordfence may process technical data such as IP addresses, user agents, requested URLs, and security logs.
Complianz
Tool used to manage cookie consent and automatically generate the Cookie Policy.
8. Cookies
This website uses technical cookies and, where required by law, additional categories of cookies subject to the user’s prior consent.
Detailed information regarding the cookies used is available in the dedicated Cookie Policy, accessible through the relevant link on this website.
9. Transfers of Personal Data Outside the European Union
Some technology providers used by the website may process personal data outside the European Economic Area (EEA).
In such cases, personal data are processed in accordance with Articles 44 et seq. of the GDPR and through the implementation of appropriate contractual safeguards.
10. Data Subject Rights
Data subjects may exercise the rights provided for under Articles 15–22 of the GDPR at any time, including the right to:
- access their personal data;
- request the rectification of inaccurate data;
- request the erasure of personal data;
- request the restriction of processing;
- object to the processing of personal data;
- receive their personal data in a portable format;
- withdraw consent previously given, where applicable.
Requests may be sent to:
11. Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with the competent Supervisory Authority if they believe that the processing of their personal data infringes applicable data protection legislation.
Further information is available on the website of the competent Data Protection Authority.
12. Changes to this Privacy Policy
The Data Controller reserves the right to update or amend this Privacy Policy at any time in order to reflect legal, technical, or organisational changes.
The most recent version will always be published on this page.
