Skip to main content

Privacy Policy

Pursuant to Regulation (EU) 2016/679 (hereinafter “GDPR”), this notice provides information on the processing of users’ personal data when browsing the website of Soft Strategy S.p.A.

In this regard, the principles of fair and transparent processing require that the data subject be informed of the existence of data processing activities and their purposes, as set out in Article 13 of the GDPR.

  1. Data Controller and DPO 
    The Data Controller is Soft Strategy S.p.A. (VAT no. 08840121001), with registered office at Via Ombrone, 7, 00198 Rome, Italy (hereinafter also referred to as the “Controller”). The Controller has appointed a Data Protection Officer (DPO), who can be contacted at the following e-mail address: rpd@sgsolution.eu.

  2. Purpose of the Process 
    – personal, identifying, and contact data, as well as any other data voluntarily provided by the User (including but not limited to: first name, last name, e-mail address, telephone number, etc.);
    – browsing data acquired by IT systems and software procedures used to operate the website. This information is not collected to be associated with identified individuals; however, by its very nature, it may allow users to be identified through processing and association with data held by third parties. This category of data includes, for example, IP addresses or domain names of the computers used by users who connect to the website, as well as other parameters related to the user’s operating system.

  3. Purposes of Processing 
    Personal data will be processed lawfully and fairly for the following purposes:
    a) to respond to User inquiries submitted to the Controller (Art. 6, letter b), GDPR);
    b) to comply with legal and tax obligations to which the Controller is subject (Art. 6, letter c), GDPR);
    c) to pursue the legitimate interests of the Controller, based on a balancing of interests (Art. 6, letter f), GDPR);
    d) where necessary to establish, exercise, or defend legal claims.
  1. Mandatory Nature of Data Provision 
    The provision of personal data is necessary to access the requested services.

  2. Methods of Processing 
    The processing of personal data is carried out through the operations listed in Article 4(2) of the GDPR, including: collection, recording, organization, storage, consultation, processing, modification, selection, retrieval, comparison, use, interconnection, restriction, communication, erasure, and destruction of data.
    Personal data is processed both in paper form and by electronic and/or automated means.
    No automated decision-making processes are carried out.

  3. Data Retention 
    Personal data will be retained for the time strictly necessary to achieve the purposes for which it was collected, in compliance with applicable legal provisions.
    Once the retention period has expired, the data will be deleted or anonymized.

  4. Data Access and Disclosure
    Personal data may be accessed by: 
    i) employees and/or collaborators of the Controller, in their capacity as authorized persons and/or system administrators; 
    ii) service providers performing outsourced activities on behalf of the Controller, in their capacity as external data processors and/or sub-processors, carrying out activities related to, instrumental to, or in support of the Controller’s operations, such as: website content management and maintenance, customer support, customer care services, etc.; 
    iii) other companies within the Soft Strategy Group. 
    The full list of Data Processors is available upon request using the contact details provided in section 8. 
    The Controller may also disclose the User’s data to third parties (Public Authorities, Law Enforcement Agencies, or other public or private entities), solely for the purpose of fulfilling contractual obligations, legal requirements, and/or EU regulations. 


  5. Data Transfers
    There are no planned transfers of personal data to non-EU countries or to international organizations. 
    Should it become necessary, for technical and/or operational reasons, to engage entities located outside the European Union, or to transfer some of the collected data to technical systems and services managed in the cloud and located outside the EU, such processing will be carried out in accordance with Chapter V of the GDPR and authorized based on specific decisions issued by the European Union. 
    All necessary safeguards will be adopted to ensure the highest level of protection for personal data, and such transfers will be based on: 
    a) adequacy decisions regarding the destination third countries, issued by the European Commission; 
    b) appropriate safeguards provided by the third-party recipient, pursuant to Article 46 of the GDPR; 
    c) the adoption of binding corporate rules (BCRs). Corporate binding rules.

  6. Data Subject Rights 
    Soft Strategy S.p.A., as Data Controller, guarantees that data subjects may exercise their rights under the GDPR at any time, as listed below: 
    – Right of access, to obtain confirmation from the Controller as to whether or not personal data concerning the data subject is being processed and, where that is the case, to obtain information regarding the origin, purposes, categories of data processed, recipients of any communication and/or transfer of data, etc., and to know whether the Controller holds and/or processes personal data relating to the data subject and to access such data in full, including obtaining a copy (Art. 15);
    – Right to rectification, to obtain the correction of inaccurate personal data or the completion of incomplete data (Art. 16);
    – Right to erasure, to obtain from the Controller the erasure of personal data without undue delay, when requested by the data subject or in other cases provided for by the Regulation (Art. 17);
    – Right to restriction of processing, to request that the Controller restrict the processing to specific personal data, if one of the conditions provided for in the GDPR is met (Art. 18);
    – Right to data portability, to receive personal data from the Controller in a structured, commonly used and machine-readable format and to transmit such data to another data controller, applicable only when the processing is based on consent and carried out by automated means (Art. 20);
    – Right to object to processing, to object at any time to the processing of personal data, as provided for by Article 21 of the GDPR.

    These rights may be exercised by contacting the Data Controller or the Data Protection Officer (DPO)  at the following addresses: Controller: info@softstrategy.it / DPO: rpd@sgsolution.eu.  
    With regard to the processing activities described in this privacy notice, data subjects are always entitled to lodge a complaint with the Italian Data Protection Authority (http://www.gpdp.it).


    Updated on: February 7, 2025