Pursuant to Regulation (EU) 2016/679 (“GDPR”)
Website: www.skytool.it
1. Data Controller
The data controller for the personal data collected through this website is:
Infotech S.r.l.
28 Spagna Gallery
35127 Padua (PD) – Italy
VAT No. / Tax ID No. IT03262490281
Phone: +39 049 8703958
Email: info@infotechsrl.it
For any request regarding the processing of personal data or the exercise of rights under the GDPR, the data subject may contact the Data Controller at the contact information provided above, specifying “GDPR Request” in the subject line.
2. Scope of the Privacy Policy
This privacy policy applies exclusively to this website www.skytool.it and describes how the personal data of users who visit the site or interact with the services and forms on the site is processed.
This privacy policy does not apply to other websites that the user may visit via external links on this site.
3. Types of Data Processed
The Data Controller may process the following categories of personal data:
a) Browsing data
The computer systems and software procedures used to operate the website automatically collect certain data during their normal operation; the transmission of this data is implicit in the use of Internet protocols.
These may include, by way of example: IP addresses or domain names of the devices used, URI identifiers of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, a numeric code indicating the status of the server’s response, and other parameters related to the user’s operating system and computing environment.
b) Data voluntarily provided by the user
The optional, explicit, and voluntary submission of messages via the contact information published on the website or through the information request forms entails the processing of the data provided by the user, such as: name, email address, company, phone number, subject of the request, and content of the message.
c) Data collected through cookies and similar technologies
This website uses technical cookies and, subject to the user’s choice where required, may also use analytics cookies and/or other tracking tools, as described in more detail in the Cookie Policy section.
4. Purposes of Processing and Legal Bases
Personal data is processed for the following purposes:
a) To enable navigation and the proper technical functioning of the site
Legal basis: Article 6(1)(f) of the GDPR; the Data Controller’s legitimate interest in ensuring the functionality, security, and stability of the website.
b) Handle requests for information, business inquiries, demonstrations, or communications sent by the user
Legal basis: Article 6(1)(b) of the GDPR, the performance of pre-contractual measures taken at the request of the data subject.
c) Ensure the security of the site; prevent abuse, unauthorized access, fraudulent activity, or unlawful use
Legal basis: Article 6(1)(f) of the GDPR; the Data Controller’s legitimate interest in protecting its rights and systems.
d) Collect aggregate statistics on website usage and improve its content, performance, and usability
Legal basis:
-
Article 6, paragraph 1, subparagraph (f) of the GDPR, if the analytics tools are configured in such a way that they are comparable to technical cookies under applicable law;
or -
Article 6, paragraph 1, subparagraph (a) of the GDPR; user consent, where required.
The Data Controller does not carry out processing based solely on automated decision-making or automated profiling that has legal effects or similarly significant effects on the data subject.
5. Nature of the Data Provision
Providing the information requested in the contact forms is optional, but necessary in order to respond to the user’s requests.
Failure to provide this information may make it impossible to process the requests you have submitted.
6. Methods of Processing
Data processing is carried out using IT and telecommunications tools, as well as, where necessary, manually, in accordance with the principles of lawfulness, fairness, transparency, data minimization, and integrity set forth in the GDPR.
The Data Controller implements appropriate technical and organizational measures to protect personal data from destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
7. Recipients of the Data
Personal data may be processed, on behalf of the Data Controller, by parties that provide services necessary for the operation of the website and the delivery of related services, such as, for example:
-
hosting and IT infrastructure providers;
-
providers of technical maintenance and on-site support;
-
persons responsible for managing information technology systems and security;
-
any providers of the cookie consent management platform;
-
any analytics service providers, if they act as data processors.
These individuals act, when necessary, as Data Controllers pursuant to Article 28 of the GDPR or as independent data controllers, depending on their respective roles.
The data are not being disclosed.
8. Transfer of Data to Third Countries
Personal data is processed primarily within the European Economic Area.
If, for technical or organizational reasons, certain services involve the transfer of data to third countries, such transfer will be carried out in accordance with the conditions set forth in Articles 44 et seq. of the GDPR, with the appropriate safeguards in place.
9. Retention Period
Personal data is retained for no longer than is necessary to fulfill the purposes for which it was collected.
Specifically:
-
Data submitted via contact forms or email is retained for as long as necessary to process the request and, thereafter, for the period required to handle any related developments;
-
Technical data and system logs are retained for the time strictly necessary for security, monitoring, and maintenance purposes, within the limits permitted by applicable law;
-
The data collected through cookies is retained for the duration specified in the relevant section of this policy or in the consent management system.
10. Rights of the Data Subject
The data subject may exercise, in the cases provided for, the rights set forth in Articles 15–22 of the GDPR, including:
-
right of access to personal data;
-
right to correction;
-
right to erasure;
-
right to restrict processing;
-
right to object;
-
the right to data portability, where applicable;
-
the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.
To exercise their rights, data subjects may contact the Data Controller using the contact information provided in this privacy notice.
The data subject also has the right to file a complaint with the Data Protection Officer, in accordance with the procedures set forth in current legislation.












