This privacy notice describes how www.kalinode.it ("Website") processes the personal data of its users. This notice is provided pursuant to Articles 12 and 13 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 ("Privacy Code").
1. Data Controller
The Data Controller for the processing of personal data is:
Kalinode S.r.l.
Registered office: Via Leone Pancaldo n. 6, 37138 Verona (VR), Italy
Tax Code / VAT: 05187990238
Email for exercising privacy rights: privacy@kalinode.it
The Controller is not required to appoint a Data Protection Officer (DPO) pursuant to Article 37 GDPR, as it does not fall within the categories specified therein. For any request regarding the processing of personal data, please contact the Controller at privacy@kalinode.it.
2. Categories of Personal Data Collected
The Website collects the following categories of personal data:
a) Data voluntarily provided by the user
Through the contact form for requesting quotes, the user provides: name, surname, email address, and phone number. Providing this data is necessary to process the request; failure to provide it will make it impossible to process the requested quote.
b) Automatically collected data
During browsing, the Website automatically collects usage data such as: IP address (truncated/anonymized where possible), browser type and operating system, pages visited, date and time of access. Such data is collected through server system logs and, where active, through cookies and similar tools (see Section 8 - Cookie Policy).
3. Purposes and Legal Bases for Processing
Each processing activity is based on a specific legal basis, as required by Article 6 GDPR. The following table illustrates the connection between each purpose, its legal basis, and the data processed.
| Purpose of processing | Legal basis (Art. 6 GDPR) | Data processed |
|---|---|---|
| Managing quote requests via contact form | Art. 6(1)(b): performance of pre-contractual measures at the request of the data subject | Name, surname, email, phone |
| Responding to general information requests | Art. 6(1)(b): pre-contractual measures | Data provided in the message |
| Aggregate and anonymous web traffic statistics | Art. 6(1)(f): legitimate interest of the Controller in optimizing the Website | Anonymized browsing data |
| B2B contact management | Art. 6(1)(f): legitimate interest (relevant communications between professionals) | Business contact data |
| IT security and abuse prevention | Art. 6(1)(f): legitimate interest in system security | System logs, IP addresses |
| Legal defense | Art. 6(1)(f): legitimate interest in protecting its rights | All relevant data |
| Compliance with legal obligations (e.g., tax, accounting) | Art. 6(1)(c): legal obligation | Contractual and tax data |
Note on legitimate interest: where processing is based on the legitimate interest of the Controller (Art. 6(1)(f) GDPR), the Controller has carried out a balancing test between its own interests and the rights and freedoms of data subjects, concluding that the processing does not disproportionately prejudice such rights. The Legitimate Interest Assessment is available upon request by writing to privacy@kalinode.it.
4. Processing Methods
Personal data is processed using IT and electronic tools, with logic strictly related to the stated purposes and, in any case, in a manner that ensures the security and confidentiality of the data, in accordance with Article 32 GDPR.
The Controller adopts appropriate technical and organizational measures to protect data from unauthorized access, loss, destruction, or unlawful disclosure.
5. Recipients and Data Processors
Personal data may be disclosed to the following categories of recipients:
- Authorized internal staff: employees and collaborators of Kalinode S.r.l. assigned to administrative and commercial functions, duly instructed pursuant to Article 29 GDPR.
-
External data processors (Art. 28 GDPR), appointed with a specific agreement (DPA):
- Aruba S.p.A. - hosting and server management services, based in Italy. DPA available at aruba.it/gdpr.
- Odoo S.A. - CRM platform for lead management, quotes, and invoicing, with servers in the European Union. GDPR-compliant DPA.
The updated list of data processors is available upon request by writing to privacy@kalinode.it.
Personal data is not subject to dissemination.
6. Data Transfers
Personal data is processed and stored on servers located within the European Union. The Controller does not transfer personal data to third countries or international organizations outside the European Economic Area (EEA). Should such transfers become necessary in the future, the Controller will adopt the safeguards provided for in Articles 44-49 GDPR (e.g., standard contractual clauses, adequacy decisions).
7. Data Retention Period
Personal data is retained for the time strictly necessary to fulfill the purposes for which it was collected, according to the following criteria:
- Data collected via contact form (quotes): maximum 12 months from collection, or until the conclusion of negotiations. If the quote does not result in a contract, the data is deleted after 12 months.
- Contractual and tax data: retained for 10 years from the end of the contractual relationship, in compliance with civil and tax obligations (Articles 2220 Italian Civil Code, D.P.R. 600/1973).
- System logs (IP addresses): retained for a maximum of 6 months for IT security and maintenance purposes.
- Analytics cookies: according to the durations indicated in the Cookie Policy (Section 8).
Upon expiration of the retention periods, data is deleted or irreversibly anonymized.
9. Data Subject Rights (Articles 15-22 GDPR)
As a data subject, the user has the following rights:
Access Art. 15
Obtain confirmation of whether personal data is being processed and access such data.
Rectification Art. 16
Obtain the correction of inaccurate data or the completion of incomplete data.
Erasure Art. 17
Obtain the deletion of personal data in the cases provided by law.
Restriction Art. 18
Obtain the restriction of processing in the cases provided by law.
Portability Art. 20
Receive personal data in a structured, commonly used, and machine-readable format.
Objection Art. 21
Object to processing based on legitimate interest, on grounds relating to one's particular situation.
Withdrawal of consent Art. 7
Withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
No automated decisions Art. 22
Not be subject to decisions based solely on automated processing with significant legal effects.
How to exercise your rights: you may exercise your rights by sending a request to privacy@kalinode.it. The Controller will respond within 30 days of receiving the request, a period that may be extended by an additional 60 days in case of particular complexity or high number of requests, subject to notification to the data subject (Art. 12(3) GDPR). The exercise of rights is free of charge, except for manifestly unfounded or excessive requests (Art. 12(5) GDPR).
10. Right to Lodge a Complaint
Without prejudice to any other administrative or judicial remedy, a data subject who believes that the processing of their personal data violates the GDPR has the right to lodge a complaint with the Italian Data Protection Authority:
Garante per la protezione dei dati personali
Piazza Venezia n. 11, 00187 Rome, Italy
Website: www.garanteprivacy.it
Email: garante@gpdp.it
PEC: protocollo@pec.gpdp.it
Phone: (+39) 06.696771
11. Changes to This Policy
The Controller reserves the right to amend this privacy notice at any time, notifying users by publishing the updated version on the Website. Users are encouraged to periodically review this page. In case of material changes, the Controller will provide notice through additional channels (e.g., email, banner on the Website).
12. Legal References
- Regulation (EU) 2016/679 of 27 April 2016 (GDPR).
- Italian Legislative Decree 30 June 2003, no. 196, as amended by Legislative Decree 10 August 2018, no. 101 (Privacy Code).
- Directive 2002/58/EC (ePrivacy Directive), as transposed by Article 122 of the Privacy Code.
- Guidelines of the Italian Data Protection Authority of 10 June 2021 on cookies and other tracking tools (provision no. 231).
- EDPB Guidelines 5/2020 on consent under Regulation (EU) 2016/679.