pursuant to Article 13 of EU Regulation 2016/679 (GDPR) and Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018
This Privacy Policy describes how Veridatis srl (hereinafter also referred to as the “Data Controller”) processes the personal data of users who visit the website www.veridatis.ai (hereinafter the “Website”) and/or who fill in the contact form available therein. Please read this Privacy Policy carefully before providing any personal data.
1. Data Controller
Company name: Veridatis srl Registered office: Viale Milton 27, Florence VAT number: 01618160525 Email: info@veridatis.ai Privacy email: privacy@veridatis.ai Certified email (PEC): veridatis@legalmail.it
2. Data Protection Officer (DPO)
The Data Controller has not appointed a Data Protection Officer (DPO).
3. Categories of Personal Data Processed
3.1 Website Navigation Data
During the navigation of the Website, the computer systems and software procedures used for its operation automatically acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified data subjects, but by its very nature it could, through processing and association with data held by third parties, allow users to be identified. This category includes IP addresses or domain names of computers and terminals used by users, URI/URL addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numeric status code of the server’s response (success, error, etc.) and other parameters relating to the operating system and IT environment of the user.
3.2 Data Voluntarily Provided by the User – Contact Form
By filling in the contact form on the Website, users may voluntarily submit the following personal data:
- First and last name
- Email address
- Phone number (if requested)
- Company name (if requested)
- Any other information freely entered in the message field
3.3 Data Collected for Newsletter / Email Marketing Purposes
Should the user choose to subscribe to the newsletter or consent to the receipt of commercial communications, the following data are collected:
- Email address
- Name (optional)
4. Purposes of Processing and Legal Bases
4.1 Responding to Contact Requests
Purpose: managing and responding to requests for information, quotes or support submitted through the Website’s contact form. Legal basis: Art. 6(1)(b) GDPR – performance of pre-contractual measures taken at the request of the data subject; alternatively, Art. 6(1)(f) GDPR – legitimate interest of the Data Controller in responding to communications received.
4.2 Sending Newsletters and Commercial Communications
Purpose: sending promotional communications, newsletters, product/service updates and commercial offers. Legal basis: Art. 6(1)(a) GDPR – freely given, specific, informed and unambiguous consent of the data subject, provided in advance via a dedicated opt-in checkbox. Consent is free, specific, informed and revocable at any time without prejudice to the lawfulness of processing carried out prior to its withdrawal. Consent may be withdrawn via the unsubscribe link in any commercial email or by contacting the Data Controller at the details provided in Section 1.
4.3 Legal Obligations and Judicial Defence
Purpose: complying with legal, regulatory or contractual obligations and protecting the rights of the Data Controller in judicial or out-of-court proceedings. Legal basis: Art. 6(1)(c) and (f) GDPR.
5. Cookies and Tracking Technologies
The Website uses cookies and tracking technologies. For detailed information on the types of cookies used, their purposes and how to manage or withdraw consent, please refer to the Website’s Cookie Policy, available at [COOKIE POLICY URL].
6. Data Retention
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the principles of minimisation and storage limitation set out in Art. 5 GDPR:
- Contact form data: retained for the time necessary to handle the request and, thereafter, for a maximum period of [24/36] months to manage any commercial follow-up or legal obligations.
- Newsletter/email marketing data: retained until the data subject withdraws consent and, after withdrawal, for the time necessary to document the unsubscription (max. 12 months).
- Navigation logs: retained for no longer than [30 days], unless required for the investigation of criminal offences. Upon expiry of the retention period, data are deleted or irreversibly anonymised.
7. Recipients and Disclosure of Data
Personal data may be communicated or made accessible, to the extent strictly necessary to achieve the stated purposes, to the following categories of recipients:
- Employees and collaborators of the Data Controller authorised to process data, acting as authorised persons pursuant to Art. 29 GDPR.
- Providers of IT and technology services (e.g. hosting providers, email providers, CRM, email marketing platforms), appointed as Data Processors pursuant to Art. 28 GDPR.
- Competent authorities, where required by law or to protect the rights of the Data Controller. Data are not sold, transferred or disclosed to third parties for their own purposes.
8. Transfers of Data Outside the EU
Some service providers used by the Data Controller (e.g. email marketing platforms, analytics services, cloud hosting) may transfer personal data to countries outside the European Union or the European Economic Area (EEA). In such cases, the Data Controller ensures that the transfer takes place in compliance with the guarantees provided for in Arts. 44–49 GDPR, including:
- Adequacy decisions adopted by the European Commission (e.g. EU-US Data Privacy Framework for certified providers);
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Other appropriate safeguards pursuant to the GDPR. For detailed information on transfers outside the EU and the relevant safeguards, please contact the Data Controller at the details provided in Section 1.
9. Rights of Data Subjects
As a data subject, pursuant to Arts. 15–22 GDPR, you have the right to:
- Access (Art. 15): obtain confirmation as to whether personal data concerning you are being processed and, where applicable, obtain a copy of such data and related information.
- Rectification (Art. 16): obtain the correction of inaccurate personal data or the completion of incomplete data.
- Erasure / “Right to be Forgotten” (Art. 17): obtain the deletion of personal data, under certain conditions.
- Restriction of processing (Art. 18): obtain the restriction of processing in specific cases provided for by law.
- Data portability (Art. 20): receive personal data in a structured, commonly used and machine-readable format, where applicable.
- Right to object (Art. 21): object to the processing of personal data at any time, in particular for direct marketing purposes.
- Withdrawal of consent (Art. 7): withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to lodge a complaint (Art. 77): lodge a complaint with the competent supervisory authority (in Italy: Garante per la Protezione dei Dati Personali, www.garanteprivacy.it).
To exercise your rights, please contact the Data Controller by:
- Email: privacy@veridatis.ai
- Postal address: Viale Milton 27, Florence The Data Controller will respond within 30 days of receipt. This period may be extended by up to 90 days in cases of particular complexity or a high volume of requests, with prior notice to the data subject explaining the reasons for the extension.
10. Data Security
The Data Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. These include, by way of example:
- Data transmission via HTTPS protocol with SSL/TLS certificate;
- Access to data restricted to authorised personnel via individual credentials and authentication systems;
- Periodic data backup procedures;
- Regular assessment of risks associated with processing. Notwithstanding the measures adopted, the Data Controller notes that no data transmission or storage system over the Internet is completely secure.
11. Minors
The Website is not directed at persons under the age of 18 and the Data Controller does not knowingly collect personal data relating to minors. Should the Data Controller become aware of having inadvertently collected data relating to minors, it will proceed with their immediate deletion.
12. Changes to this Privacy Policy
The Data Controller reserves the right to amend or update this Privacy Policy at any time, in particular following regulatory, technological or organisational changes. The updated version will be published on the Website with the date of the latest update indicated. Users are encouraged to check this page periodically.
13. Applicable Law
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR);
- Legislative Decree No. 196 of 30 June 2003 (Personal Data Protection Code), as amended by Legislative Decree No. 101 of 10 August 2018;
- Provision of the Italian Data Protection Authority No. 231 of 9 June 2021 – Guidelines on cookies and other tracking tools;
- Applicable guidelines of the European Data Protection Board (EDPB).
Last updated: 01/01/2026
Veridatis srl
