Privacy policy
Information on the processing of personal data through the nexusdynamics.it website and its contact channels.
1. Introduction
This notice describes the processing of personal data carried out through the website nexusdynamics.it and its contact channels, pursuant to Regulation (EU) 2016/679 (the “GDPR”).
2. Data controller and contact details
The processing of data connected with the website refers to Nexus Dynamics Service — a business project currently undergoing company incorporation.
For any request concerning the protection of personal data, the following address is available: privacy@nexusdynamics.it
3. Data provided voluntarily
When a user submits a request through the forms on the Contact or Service pages, the data entered are transmitted to the server solely to validate the request and forward it, through the email service, to the Nexus Dynamics Service mailbox matching the type of contact selected. An acknowledgement of receipt is sent automatically to the email address provided.
The content of the forms is not stored in the website's application database. Once sending is complete, the request is handled through the email systems used by Nexus Dynamics Service. The website keeps only technical metadata about the submission (request identifier, form type, outcome and date), without content or identifying data; to prevent abuse, submissions are subject to rate limits calculated on a pseudonymised identifier, without storing the IP address.
Depending on the form, the data may include: name, company, email address, telephone number, information about the equipment, type of request, error codes and message content. They are processed in order to handle and manage the request received; the same applies to messages sent directly to the email addresses published on the website.
If a user chooses to attach photos or short videos to the Service form, those files are processed solely to forward and handle the technical request. Attachments are not stored in the website's application database: they are transferred to the recipient mailbox together with the request, and the web server does not keep a permanent copy. The website records only the number and total size of the attached files, without names, types or content.
Providing data is optional; without the necessary information it is not possible to follow up the request.
The forms must not be used to transmit diagnostic images, patient-identifiable data or health information.
4. Technical browsing data
During normal use of the website, technical data necessary for the operation, security and correct delivery of the web service may be processed.
This information may include data relating to the HTTP request, the device and browser used, the pages requested and the technical events generated while browsing. It is recorded in the web server's technical logs for a limited period (see the section “Data retention”) and is not used to identify users or for marketing purposes.
5. Usage statistics
The website uses a first-party statistics system hosted on the infrastructure used for Nexus Dynamics Service. The system does not use profiling cookies, advertising platforms or third-party analytics tools.
The information used for statistics is minimised and may include, for example:
- pages visited;
- source of the visit;
- device type and browser;
- browsing events and interactions with website features, without the content entered;
- approximate geographic area, where technically available.
The full IP address is not stored in the analytics database. It may be used temporarily while the request is being processed to generate a technical session identifier that is not directly attributable to the user's identity; this identifier changes every day and does not allow the user to be followed over time.
The analytics system does not receive names, email addresses, telephone numbers or the content of service requests.
Detailed data are kept for 90 days. Aggregated statistical data may be kept for up to 13 months.
6. Website security
To protect the website and infrastructure from unauthorised access, automated scanning, abuse attempts and other potentially harmful events, certain technical information relating to security events is recorded.
This information may include:
- source IP address;
- user agent;
- date and time;
- resource or path requested;
- type of event detected.
These data are used exclusively for security purposes, abuse prevention, analysis of technical events and protection of the infrastructure. They are not used for advertising or commercial profiling. In the event of anomalous activity, access from an IP address may be temporarily restricted. Login attempts to the website's private area are recorded in pseudonymised form, without storing the IP address in clear text.
Detailed security records are normally kept for a maximum of 90 days from the last event; information relating to blocked addresses may be kept for the duration of the block. Aggregated information may be kept for up to 13 months.
7. Purposes and legal bases
A. Handling technical, commercial or information requests. Data provided voluntarily are processed to respond to requests for service, information, demos or contact and for the activities arising from them. Legal basis: steps taken at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR), where applicable; for information requests not linked to a pre-contractual stage, the legitimate interest in following up the communications received (Article 6(1)(f) GDPR); for requests concerning the exercise of data subject rights, compliance with legal obligations (Article 6(1)(c) GDPR).
B. Website operation and analysis. Technical browsing data are processed to deliver the web service correctly; usage statistics are processed to understand how the website is used and to improve its content and operation. Legal basis: legitimate interest (Article 6(1)(f) GDPR) in ensuring the operation of the website and measuring its use with minimised data, without cookies and without directly identifying users.
C. IT security. Information on security events is processed to protect the website, the infrastructure and the data from unauthorised access and abuse. Legal basis: legitimate interest (Article 6(1)(f) GDPR) in the security of the website and infrastructure.
8. Data retention
Data are kept for as long as necessary for the purposes indicated:
- data contained in request emails: for the time needed to handle the request and, thereafter, for any applicable administrative, contractual or legal-defence obligations;
- technical metadata of form submissions (identifier, form type, outcome, date): 90 days;
- web server technical logs: up to 30 days;
- usage statistics: detailed data 90 days, aggregated data up to 13 months;
- security events: detailed records normally 90 days from the last event (for the duration of the block in the case of blocked addresses), aggregated information up to 13 months;
- login attempts to the private area: 30 days, in pseudonymised form.
9. Recipients of the data
Data may be processed by authorised persons and, where necessary, by technical suppliers used to deliver the services, such as hosting infrastructure, email services, maintenance and security.
Where required by law, these parties operate on the basis of specific agreements and instructions on data processing.
Data are not sold and are not disclosed to third parties for their own advertising purposes.
10. Data transfers
The main systems used directly by the website to deliver the service, the statistics and the security functions are hosted on infrastructure located in the European Union.
Some technical suppliers may rely on additional parties or infrastructure; where this involves transfers of data outside the European Economic Area, such transfers are carried out in compliance with Chapter V of the GDPR and the safeguards provided for by the applicable legislation, such as European Commission adequacy decisions, standard contractual clauses or other appropriate safeguards.
11. Rights of the data subject
Where provided for by law, the data subject may exercise the rights set out in Articles 15 et seq. of the GDPR, including:
- access to their personal data;
- rectification of inaccurate data;
- erasure;
- restriction of processing;
- objection to processing;
- data portability, where applicable.
Requests may be sent to: privacy@nexusdynamics.it
Requests are handled within the time limits set by the applicable legislation.
12. Complaint to the supervisory authority
Data subjects who believe that the processing of their personal data infringes the applicable legislation may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with Article 77 of the GDPR.
13. Updates to this notice
This notice may be updated in the event of changes to the services, to the processing carried out or to the applicable legislation. The version published on this page is the one currently in force.