Privacy Policy
Welcome to the SmartCAE S.r.l. Privacy Policy.
PRIVACY NOTICE PURSUANT TO ARTICLES 13 AND 14 OF REGULATION (EU) 2016/679
UPDATE DATE: 25/09/2026
1. Data Controller
The Data Controller is SmartCAE S.r.l., with registered office at Via Livorno 39, 50142 Florence (FI), Italy, VAT No. 01899650970, and can be contacted at [email protected].
Data Protection Officer: Alessio Signorini
2. Scope of this notice
This notice describes the processing of personal data carried out by SmartCAE through the website, related subdomains, contact forms, newsletter and webinar subscriptions, commercial and contractual relationships and other channels through which a data subject interacts with the company.
The notice applies to data collected directly from the data subject and, where relevant, to data obtained from companies, organizations, professional sources or lead identification and enrichment services.
3. Categories of personal data processed
SmartCAE may process the following categories of personal data:
- identification and contact data, such as first name, last name, company, role, email address and telephone number;
- information contained in requests sent through forms, email or other contact channels;
- data relating to quotations, projects, support, commercial, contractual and administrative relationships;
- data provided for newsletters, webinars, events, courses or content downloads;
- browsing and technical data, such as IP address, online identifiers, browser, device, visited URLs, traffic source and interactions with the website;
- data relating to the organization or company to which the user belongs, including data obtained through company identification services based on the IP address;
- data contained in CVs and job applications, where submitted through the website or other channels indicated by SmartCAE.
SmartCAE does not request the submission of special categories of personal data under Article 9 GDPR, except where strictly necessary and permitted by law. If such information is provided when it is not necessary, it will be processed only where an appropriate legal basis exists or, otherwise, deleted.
Anyone providing personal data relating to third parties must ensure that they are authorized to do so and must provide those data subjects with the information required by applicable law.
4. Sources of personal data
Personal data may be collected:
- directly from the data subject, through forms, email, telephone, event registrations or commercial relationships;
- automatically while browsing, through logs, cookies and similar technologies;
- from the employer, the organization to which the data subject belongs or other parties involved in a project or professional relationship;
- from lead intelligence and enrichment services, which may associate IP addresses and online interactions with companies or professional profiles;
- from publicly accessible sources, where their use is compatible with the original purpose and permitted by law.
5. Purposes, legal bases and provision of data
| Purpose | Legal basis | Provision and consequences |
|---|---|---|
| Operation, maintenance and security of the website; prevention of abuse; management of technical logs. | Legitimate interest of the Controller pursuant to Article 6(1)(f) GDPR and applicable regulatory obligations. | The necessary technical data are collected automatically. Without this processing, the website may not operate securely. |
| Responding to requests for information, contact, quotations or consultancy. | Pre-contractual measures requested by the data subject pursuant to Article 6(1)(b) GDPR. | Providing the necessary data is optional, but failure to provide them may prevent SmartCAE from responding to the request. |
| Performance of contracts, projects, support, training and commercial relationships. | Performance of a contract pursuant to Article 6(1)(b) GDPR. | Providing the necessary data is essential to establish and manage the relationship. |
| Administrative, accounting, tax, insurance and regulatory obligations; management of disputes. | Legal obligation pursuant to Article 6(1)(c) GDPR and, for the protection of rights, legitimate interest pursuant to Article 6(1)(f) GDPR. | Providing data required by law is mandatory. |
| Subscription to and sending of newsletters, promotional communications, invitations to webinars, courses and events. | Consent pursuant to Article 6(1)(a) GDPR. Only where permitted, soft spam pursuant to Article 130(4) of the Italian Privacy Code. | Providing the data is optional. Refusal does not limit other services. Consent may be withdrawn at any time. |
| Analysis of website usage through non-essential cookies or identifiers. | Consent pursuant to Article 6(1)(a) GDPR and the applicable rules on cookies. | Providing the data is optional. Refusal does not prevent use of essential functions. |
| Campaign measurement, visitor identification, attribution, profiling and commercial qualification of leads. | Consent pursuant to Article 6(1)(a) GDPR and the applicable rules on cookies. | Providing the data is optional. Without consent, the relevant non-essential tools are not activated. |
| Assessment of job applications and recruitment management, where applicable. | Pre-contractual measures pursuant to Article 6(1)(b) GDPR; for any special categories of data, Article 9(2)(b) GDPR and applicable law. | Providing the data is optional, but necessary to assess the application. |
Any consent to marketing or profiling is separate from the management of requests and the performance of contractual relationships. Consent may be withdrawn without affecting the lawfulness of processing carried out before withdrawal.
6. Cookies and similar technologies
Information on cookies, similar technologies, providers, categories and durations is provided in the Cookie Policy. Preferences can be managed or withdrawn at any time through the CookieYes panel available on the website.
7. Profiling and automated decisions
With prior consent, SmartCAE may use tools that link visits and interactions to online identifiers, analyze browsing behavior, identify the company to which a user belongs or assign a level of commercial interest. This information may be used to understand interest in products and services, qualify leads and organize subsequent commercial activities.
SmartCAE does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject.
8. Processing methods and security
Processing is carried out using electronic tools and, where necessary, paper-based tools. SmartCAE adopts technical and organizational measures appropriate to the risk in order to protect data against unauthorized access, loss, destruction, alteration or improper disclosure.
Data are accessible only to authorized personnel and providers who need access for the purposes described.
9. Recipients and providers
Personal data may be disclosed or made accessible, within the limits of their respective functions, to:
- SmartCAE personnel and authorized collaborators;
- hosting, maintenance, security, email and IT infrastructure providers;
- newsletter, webinar, form, CRM and marketing automation providers;
- analytics, consent management, lead intelligence, advertising and campaign measurement providers;
- video, maps, embedded content and download providers;
- administrative, tax, legal, insurance and professional advisers;
- public authorities and other entities where disclosure is required by law or ordered by a competent authority.
In relation to the website, these entities may include CookieYes, Cloudflare, Google, YouTube, Vimeo, Intuit Mailchimp, Leadpages, Opentracker, Meta, LinkedIn, Zift Solutions, Snazzy Maps and their related infrastructure providers, depending on the services actually enabled and the user's preferences.
Providers that process data on behalf of SmartCAE are appointed as processors pursuant to Article 28 GDPR where the relevant requirements are met. An up-to-date list may be requested from the Controller.
10. Transfers outside the European Economic Area
Some providers may process data in countries outside the European Economic Area. In such cases SmartCAE uses, depending on the applicable circumstances, an adequacy decision of the European Commission, the EU-US Data Privacy Framework, standard contractual clauses approved by the European Commission or another safeguard provided for by Articles 44 and following of the GDPR. Data subjects may request information on the safeguards applied and how to obtain a copy.
List of servers and services hosting the data:
- Server hosting the websites: Serverplan (Italy)
- Services hosted in EU data centers: Zoho CRM, Salesforce
- Services compliant with the EU-US DPF: Google/Analytics, Google Ads, Google Maps, Meta, LinkedIn, Cloudflare, YouTube/Google, Vimeo, Intuit Mailchimp, Zift Solutions
- European Commission adequacy decision for commercial organizations subject to PIPEDA (Canada): Snazzy Maps
- Services compliant with EU SCCs 2021/914: Leadpages, Leadboxes, Center.io
11. Retention periods
SmartCAE retains personal data for the time necessary for the purpose for which they were collected and for any additional periods required by law or necessary to protect its rights. The retention periods are set out below.
| Processing | Retention period |
|---|---|
| Contact, information and quotation requests | Up to 24 months from the closure of the request, unless a contractual relationship is established. |
| Contractual relationships, projects and support | For the duration of the relationship and up to 10 years after its conclusion, except in the event of disputes or additional periods required by law. |
| Administrative, accounting and tax documentation | 10 years or any different period required by applicable law. |
| Newsletters and promotional communications based on consent | Until consent is withdrawn and, in any event, no longer than 24 months from the last significant interaction, unless renewed or subject to a different documented assessment. |
| Webinars, events, courses and downloads | Up to 24 months from the event or the last interaction, unless followed by a contractual relationship or separate marketing consent. |
| Lead identification and commercial profiling | Until consent is withdrawn or 24 months from the last significant interaction. |
| Job applications | Up to 24 months from receipt, unless an employment relationship is established or earlier deletion is requested. |
| Technical and security logs | Up to 6 months, unless necessary to investigate incidents or abuse or to protect rights. |
| Records of preferences and proof of consent | For 5 years, to demonstrate compliance with legal obligations. |
| Cookies and online identifiers | For the durations indicated in the Cookie Policy and in the CookieYes table. |
At the end of the applicable period, data are deleted or anonymized, unless further retention is necessary to comply with a legal obligation, manage proceedings or protect a right.
12. Data subject rights
In the cases provided for by the GDPR, the data subject may ask SmartCAE for:
- confirmation as to whether personal data are being processed and access to those data;
- rectification of inaccurate data and completion of incomplete data;
- erasure of data;
- restriction of processing;
- portability of the data provided, where processing is based on consent or contract and is carried out by automated means;
- objection to processing based on legitimate interest;
- withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- information on the possible existence of automated decisions and, where provided for, human intervention and the possibility to contest the decision.
The data subject may object at any time to direct marketing, including profiling related to such marketing, without having to provide any reason.
Requests may be sent to [email protected]. SmartCAE may request the information necessary to verify the identity of the requester and responds within the time limits provided for by Article 12 GDPR.
13. Complaint to the supervisory authority
The data subject may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) by consulting www.garanteprivacy.it, or with the competent supervisory authority in the Member State where the data subject resides, works or believes that the infringement occurred.
14. Changes to the Privacy Policy
SmartCAE may update this Privacy Policy following regulatory or organizational changes or changes to the processing activities carried out. The date shown at the beginning of the document identifies the latest published version.