Privacy Policy
www.xseven.it
This Application collects some Personal Data from its Users.
Personal Data processed for the following purposes
Direct registration and data provided through this Application
Direct registration
Provider: XSEVEN S.R.L.S.
Personal Data: email address and, depending on the form used, first name, last name, phone number, company, role, LinkedIn profile, message content, CV, infrastructure information and any other data voluntarily entered by the User.
Purpose: collecting and recording information submitted directly by the User through website forms, handling contact requests, intake questionnaires, job applications and related communications.
This direct collection does not create a user account, a reserved area or an authentication service on the website.
Legal basis: pre-contractual steps requested by the User; consent where required for specific purposes, such as retaining a CV for future opportunities; legitimate interest in security and abuse prevention.
Contact form requests
Handling commercial and information requests
Personal Data: name, email address, phone number, message content, consent status and technical anti-abuse form data.
Purpose: responding to the User's request, arranging any follow-up contact and preventing automated or abusive submissions.
Legal basis: pre-contractual steps requested by the User and legitimate interest in website security.
Intake questionnaire and requirements collection
Preliminary project analysis
Personal Data: identification and contact details, company information, industry, organisation size, requested services, infrastructure details, priorities, timeline, communication preferences, operational challenges and free-text notes entered by the User.
Purpose: understanding the technical and organisational context of the request, preparing a first assessment and proposing suitable services.
Legal basis: pre-contractual steps requested by the User.
Job applications and recruitment
Managing spontaneous applications or applications for open roles
Personal Data: first name, last name, email address, phone number, LinkedIn profile, role of interest, cover message, CV and any further information included in the submitted documents.
Purpose: evaluating the application, contacting the candidate and, only when authorised, retaining the profile for compatible future openings.
Legal basis: pre-contractual steps for the current application; consent for optional retention for future recruitment.
Traffic optimization and distribution
Cloudflare
Provider: Cloudflare, Inc.
Personal Data: IP address, connection data, technical logs, browser and device information, security events and other information necessary to protect and distribute traffic.
Purpose: traffic optimization and distribution, security, mitigation of malicious traffic, website availability, caching and content delivery.
Service Privacy Policy: https://www.cloudflare.com/policies/privacy/.
Legal basis: the Controller's legitimate interest in keeping the website secure, available and reliable.
Technical logs and application security
Servers, reverse proxies and form/mail systems
Personal Data: IP address, request date and time, requested URL, user-agent, request result and the minimum data required to deliver requests submitted through forms.
Purpose: technical maintenance, abuse prevention, error diagnosis, operational continuity and protection of IT systems.
Legal basis: legitimate interest in infrastructure security and correct system operation.
Data retention
Data submitted through contact and intake forms is retained for the time necessary to handle the request and any resulting pre-contractual or contractual relationship. Recruitment data is retained for the time necessary to evaluate the position; if the candidate consents to retention for future opportunities, the data may be retained for up to 12 months from submission, unless consent is withdrawn earlier.
Technical and security logs are retained for periods proportionate to security, diagnostic and system protection purposes, unless further retention is required due to incidents, disputes or legal obligations.
Providers and Data Processors
The Controller may rely on technical providers for hosting, traffic delivery, security, email, form processing, backup and system maintenance. These providers process Personal Data according to the Controller's instructions and, where applicable, as data processors under Art. 28 GDPR.
Transfers outside the EU
Some technical providers, including traffic delivery and security services such as Cloudflare, may process data outside the European Economic Area. Where this happens, transfers are based on safeguards provided by the GDPR, such as adequacy decisions, standard contractual clauses or applicable supplementary measures.
Data Subject rights
The Data Subject may request access, rectification, erasure, restriction, objection to processing and data portability where provided by the GDPR. Where processing is based on consent, the Data Subject may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Requests can be sent to [email protected]. The Data Subject also has the right to lodge a complaint with the Italian Data Protection Authority.
Contact information
Owner and Data Controller
XSEVEN S.R.L.S.
Via Rita Levi Montalcini, 3, 90040 Capaci (PA) (IT)
Owner contact email: [email protected]
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User's browser.
Tracker
Tracker indicates any technology — e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting — that enables the tracking of Users, for example by accessing or storing information on the User's device.
Legal information
This policy relates solely to this Application, if not stated otherwise within this document.