Compliance

Legal Information

Privacy Policy

Effective Date: January 1, 2026

1. Data Controller

The data controller responsible for your personal data is datasafecore, located at Via Lucchesi Palli 22, 95121 Catania, Catania, Italy. You may contact us at [email protected] or by phone at +39 370 9182304.

2. Data We Collect

We collect and process the following categories of personal data:

  • Contact Information: Name, email address, phone number, and postal address provided through contact forms or direct communications.
  • Business Information: Company name, job title, industry, and project requirements submitted during service inquiries.
  • Technical Data: IP address, browser type, operating system, referring URLs, and access timestamps collected automatically through standard web server logs.
  • Service Data: Data processing records, audit findings, and compliance documentation created during the delivery of our data protection services.

3. Legal Basis for Processing

We process your personal data under the following legal bases as defined in Article 6 of the GDPR:

  • Consent (Art. 6(1)(a)): When you subscribe to communications or accept non-essential cookies.
  • Contract Performance (Art. 6(1)(b)): When processing is necessary for the performance of a contract to which you are a party, or for pre-contractual measures taken at your request.
  • Legitimate Interest (Art. 6(1)(f)): When processing is necessary for our legitimate interests, such as improving our services, ensuring network security, and preventing fraud — provided such interests are not overridden by your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): When we are legally required to retain or disclose certain data.

4. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Contact form submissions are retained for 24 months. Service engagement records are retained for the duration of the engagement plus 5 years in accordance with Italian commercial record-keeping obligations. Technical logs are retained for 12 months.

5. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to Restriction (Art. 18): Request restriction of processing in certain circumstances.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

6. Data Security

datasafecore implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption at rest and in transit, role-based access controls, regular security assessments, and continuous monitoring of data processing systems.

7. International Transfers

If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions as applicable.

8. Supervisory Authority

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) if you believe your data protection rights have been infringed. Visit garanteprivacy.it for more information.

Terms of Service

Effective Date: January 1, 2026

1. Acceptance of Terms

By accessing or using the services provided by datasafecore ("Company," "we," "us"), you agree to be bound by these Terms of Service. If you do not agree, do not use our services.

2. Services Description

datasafecore provides data protection and privacy consulting services including but not limited to: GDPR compliance audits, data pipeline security assessments, privacy impact assessments, breach response planning, consent management configuration, data retention policy design, vendor privacy reviews, and employee privacy training programs.

3. Service Engagement

All service engagements begin with a written proposal or statement of work (SOW) signed by both parties. The SOW defines the scope, deliverables, timeline, and fees. Any modifications to scope require a written change order agreed by both parties.

4. Fees and Payment

Fees are as specified in the applicable SOW. Invoices are due within 30 days of issuance. Late payments incur a monthly interest charge of 1.5% on the outstanding balance. All fees are exclusive of applicable taxes, which are the responsibility of the client.

5. Intellectual Property

Upon full payment, the client receives a perpetual, non-exclusive license to use all deliverables produced under the engagement. datasafecore retains ownership of pre-existing tools, methodologies, and frameworks used in service delivery.

6. Confidentiality

Both parties agree to maintain the confidentiality of all non-public information exchanged during the engagement. This obligation survives termination for a period of 3 years.

7. Limitation of Liability

datasafecore's total aggregate liability under any engagement shall not exceed the total fees paid by the client for the services giving rise to the claim. In no event shall datasafecore be liable for indirect, incidental, consequential, or punitive damages.

8. Termination

Either party may terminate an engagement with 30 days' written notice. In the event of termination, the client shall pay for all services rendered up to the termination date. Sections on confidentiality, intellectual property, and limitation of liability survive termination.

9. Governing Law

These terms are governed by the laws of the Republic of Italy. Any disputes shall be submitted to the exclusive jurisdiction of the courts of Catania, Italy.

Cookies Policy

Effective Date: January 1, 2026

1. What Are Cookies

Cookies are small text files placed on your device by websites you visit. They help the site function correctly, remember your preferences, and provide analytics about site usage.

2. Cookies We Use

  • Strictly Necessary Cookies: Essential for the website to function. These cannot be disabled. Examples include session cookies, CSRF tokens, and cookie consent preferences stored in localStorage.
  • Functional Cookies: Remember your preferences and settings (e.g., language selection, form pre-fill data). These are optional.

3. Third-Party Cookies

datasafecore does not use third-party advertising or tracking cookies. We do not deploy Google Analytics, Facebook Pixel, or similar tracking technologies. The only external resource loaded is Google Fonts for typography, which may collect standard access data per Google's privacy policy.

4. Managing Cookies

You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies may impair site functionality. You can also clear cookies stored by this site through your browser's privacy settings.

5. localStorage

We use browser localStorage to persist your cookie consent preference. This data is stored locally on your device and is never transmitted to any server. It contains only a single key-value pair confirming your consent choice.

Refund Policy

Effective Date: January 1, 2026

1. Service Deliverables

All services are provided as professional consulting and advisory engagements. Once a service has been initiated and work has commenced, fees are non-refundable for the portion of work completed.

2. Pre-Completion Cancellation

If you cancel a service engagement before work has commenced, you are entitled to a full refund of any advance payment. Cancellations received after work has commenced but before the midpoint of the agreed timeline are subject to a 50% refund of the total engagement fee.

3. Dissatisfaction with Results

If you are dissatisfied with the quality of deliverables, notify us in writing within 14 days of delivery. We will review the concern and, at our discretion, either remediate the deliverables at no additional charge or issue a partial refund proportional to the unresolved portion of the engagement.

4. Refund Process

Approved refunds are processed within 14 business days to the original payment method. You will receive written confirmation of the refund amount and expected processing date.

5. Exceptions

No refunds are provided for: (a) services fully delivered and accepted by the client; (b) third-party costs incurred on behalf of the client (e.g., regulatory filing fees, software licenses); (c) engagements terminated due to client breach of these Terms of Service.

6. Dispute Resolution

Refund disputes should be directed to [email protected]. We aim to resolve all disputes amicably within 30 days. Unresolved disputes are subject to the jurisdiction of the courts of Catania, Italy.