003

Privacy Policy

Information notice for the use of the website, contact requests, and the sending of newsletters and promotional communications
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 and Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018

CYBERSEL SRL, Tax Code No. 10617990014, with registered office in Turin (TO), Lungo Dora Colletta No. 81, represented by its legal representative pro tempore (hereinafter the “Controller” or “Cybersel”), provides this privacy notice to users of its website in accordance with the principles of transparency, fairness, and lawfulness set out in Regulation (EU) 2016/679 (hereinafter the “GDPR”).
This notice applies to the processing of personal data carried out through the Cybersel website and related contact channels, as well as the sending of newsletters and promotional communications by Cybersel. Any processing activities carried out through cookies and tracking technologies are governed by the separate Cookie Policy published on the website.
This notice concerns only the processing activities carried out within this website and does not apply to any other websites that users may access through links available on our site. Your personal data will be processed in accordance with the principles of lawfulness, fairness, transparency, data minimization, and security set forth in the GDPR.

1. Data Controller and Data Protection Officer

The Data Controller is CYBERSEL SRL, Tax Code No. 10617990014, with registered office in Turin (TO), Lungo Dora Colletta No. 81.
The Data Protection Officer (DPO) is Attorney Luca Francesco Montalbano, whose office is located in Turin (TO), Corso Bramante No. 91, and who may be contacted at: dpo@cybersel.eu.

2. Categories of Data Processed

Depending on the user's interaction with the website and the services offered, Cybersel may process the following categories of personal data

- identification and contact data, such as first name, last name, and email address;
- technical browsing data, such as IP address and other information related to the use of the website;
- data voluntarily provided by users through contact forms, information requests, or newsletter subscriptions;
- professional and business data, such as job title, company affiliation, and business contact details.

Data processing is carried out using manual, electronic, and telematic tools and methods designed to ensure the security and confidentiality of personal data.

3. Purposes of Processing and Legal Basis

Personal data are processed for the following purposes:

A) Compliance with Legal Obligations
Data may be processed to comply with obligations arising from laws, regulations, European Union legislation, or orders issued by competent authorities and supervisory bodies.
Legal basis: Article 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject).

B) Proper Operation, Management, and Security of the Website
Data may be processed to ensure the technical functioning of the website, including the management of technical cookies and functionalities strictly necessary for browsing.
Legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest in the proper operation, management, and security of the website).

C) Handling Requests Voluntarily Submitted by Users
Data voluntarily provided by users may be processed to respond to requests for information, contact requests, or other communications submitted through the website.
Legal basis: Article 6(1)(b) GDPR (performance of pre-contractual measures taken at the data subject’s request, or performance of a contract/existing relationship with the data subject).

D) Sending Newsletters and Informational/Promotional Communications Based on Consent
User data may be processed to send newsletters and informational or promotional communications concerning Cybersel’s activities, products, or services by email, subject to the user’s specific, freely given, informed, and separate consent.
Legal basis: Article 6(1)(a) GDPR (consent of the data subject).
Consent for this purpose is collected through a request that is clearly distinguishable from other purposes, uses simple and clear language, and is not inferred from pre-ticked boxes, silence, inactivity, or the general acceptance of the website’s terms and conditions.
Failure to provide consent does not affect website browsing or the ability to submit contact requests.

E) Sending Promotional Communications by Email to Existing Customers (“Soft Spam”)
Pursuant to Article 130(4) of Legislative Decree No. 196/2003, Cybersel may use the email address provided by a customer in the context of purchasing a product or service to send promotional communications relating to its own products or services similar to those already purchased, without requiring additional consent, provided that the customer was adequately informed of this possibility and did not object either initially or in subsequent communications.
Legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest), in compliance with the conditions set forth in Article 130(4) of Legislative Decree No. 196/2003.
This option applies exclusively to the email address and only to communications concerning Cybersel products or services that may reasonably be considered similar to those already purchased. Customers are informed, both when their email address is collected and in each subsequent communication, of their right to object to such processing at any time in an easy and free-of-charge manner.

4. Nature of Data Provision

Providing data for the purposes referred to in sections A), B), and C) is necessary, depending on the circumstances, to comply with legal obligations, enable website navigation, or respond to the user’s request. Failure to provide such data may make it impossible to provide the requested service or respond to the request.
Providing data for purpose D) is optional. Failure to provide data or consent will only result in the inability to receive newsletters or promotional communications based on consent.
For purpose E), the use of an email address without additional consent is permitted only within the limits established by Article 130(4) of Legislative Decree No. 196/2003, without prejudice to the customer’s right to object from the outset and at any time thereafter.

5. Data Retention Period

Personal data are retained for no longer than necessary to achieve the purposes for which they were collected, in accordance with the storage limitation principle. In particular:

• data processed for purpose A) are retained for the period required by applicable law and, in any event, no longer than necessary for that purpose;
• data processed for purpose B) are retained for no longer than 12 months from collection, unless further technical or security requirements justify a longer period as permitted by law;
• data processed for purpose C) are retained for the time necessary to manage the request and related obligations and, in any event, for no longer than 10 years after the termination of the relationship for the purposes of legal protection;
• data processed for purpose D) are retained until consent is withdrawn;
• data processed for purpose E) are retained until the data subject objects to such use.

Following withdrawal of consent or the exercise of the right to object, the data subject’s email address may be retained in a dedicated suppression list solely for the purpose of ensuring that the individual is not contacted again and to demonstrate compliance in the event of disputes. Once the applicable retention periods have expired, data will be permanently deleted or anonymized.

6. Recipients of Personal Data

Personal data may be disclosed, within the limits of the purposes indicated above, to:

1. parties acting as data processors and/or sub-processors, including providers of platforms used for sending newsletters and promotional communications;
2. persons authorized by Cybersel to process personal data and bound by confidentiality obligations;
3. IT service providers, internet service providers, consultants, and other entities supporting the Controller in managing the website and related activities;
4. parties entitled to receive the data pursuant to laws, regulations, or orders issued by competent authorities;
5. parties involved in extraordinary corporate transactions, such as mergers, acquisitions, transfers of businesses, or transfers of business units.

An updated list of categories of recipients or specific recipients may be requested from the Controller using the contact details provided in this privacy notice. Personal data are not subject to public disclosure.

7. Transfer of Data to Third Countries

Personal data are generally stored and processed within the European Economic Area (EEA). Should it become necessary to transfer personal data to third countries or international organizations, for example in connection with newsletter delivery service providers, Cybersel shall ensure that such transfers take place on the basis of an adequacy decision adopted by the European Commission or through the implementation of appropriate safeguards pursuant to Article 46 GDPR (such as Standard Contractual Clauses). A copy of these safeguards may be requested from the Controller using the contact details provided in this notice.

8. Communications under the Soft Spam Regime

Where Cybersel sends communications pursuant to Article 130(4) of Legislative Decree No. 196/2003, such communications concern exclusively its own products or services similar to those already purchased by the customer and are sent to the email address collected in the context of the sale.
At the time the email address is collected and in each subsequent communication, customers may exercise their right to object in a clear, simple, and free-of-charge manner. The soft spam exemption does not allow promotional communications regarding third-party products or services, nor products or services that are not similar to those already purchased.

9. Absence of Automated Decision-Making

Cybersel does not carry out processing based solely on automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them, pursuant to Article 22 GDPR.

10. Data Subject Rights

Within the cases and limits provided for under Articles 15–22 GDPR, data subjects may exercise the following rights:

• right of access to personal data;
• right to rectification of inaccurate data;
• right to erasure of personal data;
• right to restriction of processing;
• right to object to processing;
• right to data portability, where applicable.

Where processing is based on consent, the data subject has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Where data are processed for direct marketing purposes (including purposes D and E), the data subject has the right to object at any time to such processing. Upon objection, personal data will no longer be processed for those purposes. This right is explicitly brought to the data subject’s attention and presented clearly and separately from any other information, at the latest when the first communication is sent.
Requests relating to the exercise of rights may be sent to: cybersel@pec.it.
Data subjects also have the right to lodge a complaint with the competent supervisory authority (the Italian Data Protection Authority – Garante per la Protezione dei Dati Personali) pursuant to Article 77 GDPR if they believe that the processing of their personal data infringes applicable data protection laws.

11. Unsubscribe and Objection Procedures

In every newsletter or direct marketing communication, Cybersel informs recipients of their right to object or unsubscribe easily and free of charge through a dedicated link included in the communication or by contacting Cybersel using the contact details provided in this privacy notice.

12. Security Measures

Cybersel adopts appropriate technical, organizational, and logistical measures to protect the confidentiality, integrity, availability, and security of personal data, reducing the risk of loss, alteration, misuse, unauthorized access, or unlawful disclosure. The Controller periodically reviews and evaluates the effectiveness of the security measures adopted in order to ensure the continuous improvement of data protection.

13. Changes to This Privacy Notice

The Controller reserves the right to update this privacy notice at any time and will communicate such updates through the channels it deems most appropriate. For further information, please contact the Controller at cybersel@pec.it.

Last updated: 14/07/2026