1. Controller and contact details
Controller: Netter srl, registered office at Via Indipendenza, 06081 Assisi (PG), Italy — VAT IT03569900545.
Privacy contact: email info@ventic.it (subject: “Privacy — Ventic”). We usually reply within 15 business days. For formal communications you can also write to the registered office, attn. “Privacy — Ventic”.
No Data Protection Officer (DPO) has been appointed under Art. 37 GDPR as the conditions are not met; this is reviewed periodically. If a DPO is appointed, contact details will be published here.
2. Scope
This notice applies to browsing ventic.it, to contact requests and to booking of technical calls via the site (Calendly/external links and email). It also applies to any forms or contact channels enabled on the ventic.it domain and functional sub-domains (e.g. docs, status). It does not apply to third-party sites reachable via links.
Language: if there is a conflict between the Italian version and the English translation, the Italian version prevails for users subject to Italian/EU law.
3. Categories of personal data
3.1 Browsing and technical logs
IT systems and software procedures used to operate the site acquire, in normal operation, some personal data whose transmission is implicit in Internet protocols. This includes: IP address, browser and device type, OS, pages visited, dwell time, referrer, any errors, date/time of the request and other device/environment parameters (e.g. HTTP headers).
This data is needed to make the site available, keep it secure and measure performance in aggregated form.
3.2 Data you provide voluntarily
- content of emails and messages sent to info@ventic.it or via “Book a call” / “Email us” buttons;
- name, surname, company, role, contact details and information you voluntarily share to request a demo, commercial information, support or to shortlist a configuration (BYOH / PaaS);
- when you book a call via an external provider (e.g. Calendly), data you enter in that provider’s form (name, email, messages, time preferences).
3.3 Anti-abuse / human verification
To protect the email address and forms from scraping and spam we use anti-bot solutions (Cloudflare Turnstile and/or TrustCaptcha). During verification technical identifiers such as IP, browser headers, interaction signals and the verification token may be processed; we do not use invasive fingerprinting or biometric data.
3.4 Cookies and similar technologies
See Section 4 “Cookies and similar technologies”.
We do not collect special categories of data (Art. 9 GDPR) or data on criminal convictions via the showcase site. Please do not send unnecessary data or third-party data without a lawful basis.
5. Purposes and legal bases
We process your data only when we have a lawful basis. Main purposes:
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Make the site available, keep it secure and prevent abuse (incl. anti-bot) | Browsing data, IP, anti-abuse tokens, logs | Legitimate interest (Art. 6(1)(f)) — protect and administer the site; legal security duty (Art. 32) |
| Reply to requests for information, demos, quotes and call bookings | Data you provide, message content | Pre-contractual steps at your request (Art. 6(1)(b)); legitimate interest in handling requests |
| Manage the pre-contractual / contractual relationship (BYOH, PaaS, server assessment, offers) | Business contact data, technical content shared | Contract / pre-contract (Art. 6(1)(b)); legal obligations (Art. 6(1)(c)) for invoicing |
| Administrative, accounting and tax compliance | Billing and contract data | Legal obligation (Art. 6(1)(c)) |
| Establish, exercise or defend legal claims | Logs, correspondence, contract data | Legitimate interest (Art. 6(1)(f)) and legal obligation |
| Service follow-ups you requested | Email and request content | Pre-contractual steps / consent where required |
We do not carry out automated decision-making producing legal effects nor profiling under Art. 22 GDPR via the showcase site.
6. How we process data and security
Processing is carried out by electronic means and, where needed, on paper, with logic strictly related to the purposes and with appropriate technical and organisational measures (Art. 32 GDPR): encryption in transit (TLS/HTTPS), minimisation, access controls, logging, backups, updates and role separation. Access is limited to authorised Netter srl personnel and to processors/suppliers bound by contract.
The encrypted mTLS overlay and GPUs described on the site concern the product Ventic delivered to the customer: those systems do not process visitor data of the showcase site except as needed to deliver the contracted service and as described in the relevant DPA.
7. Place of processing
Site data are processed at the controller’s premises and, for technical delivery, at hosting / CDN and email suppliers located mostly in the European Economic Area (EEA). Some technical services (e.g. Google Fonts, anti-bot Cloudflare/TrustCaptcha, call scheduling) may involve contact with servers outside the EEA as well: see §10.
8. Retention periods
| Category | Retention |
|---|---|
| Security and anti-abuse technical logs | up to 12 months, unless extended for security, defence or authority requests |
| Contact requests / emails / messages | 24 months from last useful contact, unless it becomes a contractual relationship |
| Pre-contractual data and quotes | 24 months or until you withdraw interest |
| Contract data, invoices and tax records | 10 years under Art. 2220 Civil Code and tax law |
| Correspondence needed for litigation | until the dispute is settled and limitation periods expire |
After expiry data are deleted or anonymised. Periods may be extended only by law or order of an authority.
9. Recipients and processors
Data may be shared with:
- Processors under Art. 28 GDPR where they process data on our behalf: static-site hosting/CDN provider, email provider, anti-bot providers (Cloudflare — Turnstile; TrustCaptcha / TrustComponent), call-scheduling provider (e.g. Calendly) if you use the booking link, IT/legal consultants bound by confidentiality.
- Independent controllers: courts, administrative or supervisory authorities where required by law; Google LLC for font delivery as independent controller under its privacy policy.
- Authorised personnel of Netter srl (Art. 29 GDPR).
An up-to-date list of processors is available on request to the privacy contact. We do not disseminate data.
10. Transfers outside the EEA
Some suppliers may process data in countries outside the EEA (e.g. United States). Transfers then occur only to countries with an adequacy decision (Art. 45 GDPR — e.g. US under the Data Privacy Framework where applicable) or, failing that, on the basis of Standard Contractual Clauses (Art. 46) plus supplementary measures assessed case by case. A copy of safeguards can be requested from the privacy contact.
For Google Fonts we transmit only what is technically needed to deliver the font (HTTP request with IP and headers): we do not transmit profiling identifiers to the provider.
11. Nature of provision
Browsing data are necessary to use the site. Providing data for contact requests is optional: without the minimum data (at least a contact and the request content) we cannot reply. Consent, where required (e.g. future non-essential cookies), is always withdrawable without affecting prior lawful processing.
12. Your rights (Arts. 15–22 GDPR)
You have the right to obtain, where foreseen, access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and not to be subject to automated decisions.
- Access — know whether we process data about you and get a copy (Art. 15).
- Rectification — correct inaccurate data (Art. 16).
- Erasure (“right to be forgotten”) — Art. 17, where applicable (e.g. consent withdrawn, objection).
- Restriction — Art. 18.
- Portability — receive data you provided in a structured format when processing is based on consent or contract (Art. 20).
- Objection — Art. 21, in particular to processing for legitimate interest; for direct marketing you can object at any time.
- Withdraw consent — Art. 7(3), at any time without retroactive effect.
You may also lodge a complaint with the supervisory authority (see §13).
13. How to exercise rights and lodge a complaint
To exercise rights write to info@ventic.it subject “Exercise of privacy rights — Ventic” attaching a copy of an ID document minimised to what is needed. We reply without undue delay, at latest within one month (extendable by two months for complex cases, Art. 12(3)).
If you believe processing infringes the GDPR, you have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali — garanteprivacy.it (Art. 77 GDPR) — or to seek a judicial remedy (Art. 79). Information and forms are on the Garante’s site. For your local authority in other EEA states, see the EDPB list.
For consumer disputes, out-of-court settlement bodies may be available where applicable.
14. Children
The site is not directed at children under 14 (digital consent age in Italy, Art. 2-quinquies Privacy Code). We do not knowingly collect children’s data. If you believe a child has provided data, contact us for deletion.
15. Changes to this notice
We may update this notice to reflect regulatory, technical or service changes. The current version is the one published here with its “Last updated” date. Material changes will be highlighted with a notice on the site. Please review this page periodically.
For clarifications or copies of relevant contractual extracts (SCCs, DPA) for transfers, write to the privacy contact.
Legal note
This notice follows the Garante’s template and EDPB Guidelines, in plain language without loss of completeness. It is not individual legal advice; for specific cases consult your counsel. If you have specific contractual terms with Netter srl, the contract and its DPA prevail for processing as processor.
Questions about privacy?
Write to info@ventic.it — subject “Privacy — Ventic”. For commercial enquiries use the button below instead.