Legal Information
Privacy Policy
Effective Date: January 1, 2026
1. Data Controller
The data controller responsible for your personal data is datasafecore, located at Via Lucchesi Palli 22, 95121 Catania, Catania, Italy. You may contact us at [email protected] or by phone at +39 370 9182304.
2. Data We Collect
We collect and process the following categories of personal data:
- Contact Information: Name, email address, phone number, and postal address provided through contact forms or direct communications.
- Business Information: Company name, job title, industry, and project requirements submitted during service inquiries.
- Technical Data: IP address, browser type, operating system, referring URLs, and access timestamps collected automatically through standard web server logs.
- Service Data: Data processing records, audit findings, and compliance documentation created during the delivery of our data protection services.
3. Legal Basis for Processing
We process your personal data under the following legal bases as defined in Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): When you subscribe to communications or accept non-essential cookies.
- Contract Performance (Art. 6(1)(b)): When processing is necessary for the performance of a contract to which you are a party, or for pre-contractual measures taken at your request.
- Legitimate Interest (Art. 6(1)(f)): When processing is necessary for our legitimate interests, such as improving our services, ensuring network security, and preventing fraud — provided such interests are not overridden by your fundamental rights.
- Legal Obligation (Art. 6(1)(c)): When we are legally required to retain or disclose certain data.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Contact form submissions are retained for 24 months. Service engagement records are retained for the duration of the engagement plus 5 years in accordance with Italian commercial record-keeping obligations. Technical logs are retained for 12 months.
5. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Restriction (Art. 18): Request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
6. Data Security
datasafecore implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption at rest and in transit, role-based access controls, regular security assessments, and continuous monitoring of data processing systems.
7. International Transfers
If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions as applicable.
8. Supervisory Authority
You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) if you believe your data protection rights have been infringed. Visit garanteprivacy.it for more information.
Terms of Service
Effective Date: January 1, 2026
1. Acceptance of Terms
By accessing or using the services provided by datasafecore ("Company," "we," "us"), you agree to be bound by these Terms of Service. If you do not agree, do not use our services.
2. Services Description
datasafecore provides data protection and privacy consulting services including but not limited to: GDPR compliance audits, data pipeline security assessments, privacy impact assessments, breach response planning, consent management configuration, data retention policy design, vendor privacy reviews, and employee privacy training programs.
3. Service Engagement
All service engagements begin with a written proposal or statement of work (SOW) signed by both parties. The SOW defines the scope, deliverables, timeline, and fees. Any modifications to scope require a written change order agreed by both parties.
4. Fees and Payment
Fees are as specified in the applicable SOW. Invoices are due within 30 days of issuance. Late payments incur a monthly interest charge of 1.5% on the outstanding balance. All fees are exclusive of applicable taxes, which are the responsibility of the client.
5. Intellectual Property
Upon full payment, the client receives a perpetual, non-exclusive license to use all deliverables produced under the engagement. datasafecore retains ownership of pre-existing tools, methodologies, and frameworks used in service delivery.
6. Confidentiality
Both parties agree to maintain the confidentiality of all non-public information exchanged during the engagement. This obligation survives termination for a period of 3 years.
7. Limitation of Liability
datasafecore's total aggregate liability under any engagement shall not exceed the total fees paid by the client for the services giving rise to the claim. In no event shall datasafecore be liable for indirect, incidental, consequential, or punitive damages.
8. Termination
Either party may terminate an engagement with 30 days' written notice. In the event of termination, the client shall pay for all services rendered up to the termination date. Sections on confidentiality, intellectual property, and limitation of liability survive termination.
9. Governing Law
These terms are governed by the laws of the Republic of Italy. Any disputes shall be submitted to the exclusive jurisdiction of the courts of Catania, Italy.
Refund Policy
Effective Date: January 1, 2026
1. Service Deliverables
All services are provided as professional consulting and advisory engagements. Once a service has been initiated and work has commenced, fees are non-refundable for the portion of work completed.
2. Pre-Completion Cancellation
If you cancel a service engagement before work has commenced, you are entitled to a full refund of any advance payment. Cancellations received after work has commenced but before the midpoint of the agreed timeline are subject to a 50% refund of the total engagement fee.
3. Dissatisfaction with Results
If you are dissatisfied with the quality of deliverables, notify us in writing within 14 days of delivery. We will review the concern and, at our discretion, either remediate the deliverables at no additional charge or issue a partial refund proportional to the unresolved portion of the engagement.
4. Refund Process
Approved refunds are processed within 14 business days to the original payment method. You will receive written confirmation of the refund amount and expected processing date.
5. Exceptions
No refunds are provided for: (a) services fully delivered and accepted by the client; (b) third-party costs incurred on behalf of the client (e.g., regulatory filing fees, software licenses); (c) engagements terminated due to client breach of these Terms of Service.
6. Dispute Resolution
Refund disputes should be directed to [email protected]. We aim to resolve all disputes amicably within 30 days. Unresolved disputes are subject to the jurisdiction of the courts of Catania, Italy.