PRIVACY POLICY

Last updated: August 2, 2026

This Privacy Policy describes how the personal data of users who visit the Veltriany website and use its related services are processed, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable personal data protection laws.

  1. DATA CONTROLLER

The Data Controller responsible for the processing of personal data is:

Silvia Poggi
Veltriany

Email: info@veltriany.com

For any request concerning the processing of personal data or the exercise of your rights, you may contact us using the email address provided above.

  1. TYPES OF PERSONAL DATA PROCESSED

Through the website, personal data voluntarily provided by users may be processed, particularly through the “Contact” and “Get Started” forms, including:

  • first and last name;
  • email address;
  • telephone number;
  • company or business;
  • service of interest;
  • information included in the message or request;
  • any additional information voluntarily provided by the user.

During browsing, technical data necessary for the operation and security of the website may also be processed, including IP address, browser and device information, technical logs and other browsing data.

  1. PURPOSES AND LEGAL BASES FOR PROCESSING

Personal data may be processed for the following purposes:

A) Managing contact and information requests

Personal data is used to respond to requests voluntarily submitted by users through the website or by email.

Legal basis: taking steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.

B) Managing demo and consultation requests

Personal data may be used to analyse the needs indicated by the user, contact the user, arrange a demo or consultation, and prepare any requested commercial proposals.

Legal basis: taking steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.

C) Website operation and security

Technical data may be processed to ensure the proper functioning of systems, prevent abuse, protect the website and diagnose technical issues.

Legal basis: the legitimate interest of the Data Controller in ensuring the security and proper functioning of its systems, pursuant to Article 6(1)(f) of the GDPR.

D) Compliance with legal obligations

Personal data may be processed when necessary to comply with obligations imposed by applicable law.

Legal basis: Article 6(1)(c) of the GDPR.

Any use of personal data for marketing purposes not strictly connected with the user’s request will only take place where an appropriate legal basis exists and, where required, after obtaining the user’s specific consent.

  1. PROVISION OF PERSONAL DATA

Providing the personal data marked as mandatory in the forms is necessary to allow Veltriany to process the user’s request.

Failure to provide such data may make it impossible to respond to the request, arrange a demo or provide the requested information.

Any fields marked as optional may be left blank.

  1. PROCESSING METHODS AND SECURITY

Personal data is processed primarily using electronic and digital systems.

The Data Controller adopts appropriate technical and organisational measures, taking into account the nature of the processing, aimed at reducing the risks of unauthorised access, loss, alteration, disclosure or unlawful use of personal data.

  1. DATA RETENTION PERIOD

Personal data relating to contact, demo or consultation requests is retained for the period necessary to manage the request and any subsequent pre-contractual or contractual relationship.

Personal data may be retained for additional periods where necessary to comply with legal obligations, protect the rights of the Data Controller or manage potential disputes.

Where processing is based on consent, personal data will be processed until consent is withdrawn, unless other legal grounds exist that allow its continued retention.

  1. RECIPIENTS OF PERSONAL DATA

Personal data may be processed, to the extent necessary, by parties providing services required for the management of the website and business activities, including:

  • hosting and IT infrastructure providers;
  • email service providers;
  • providers of systems used for website forms;
  • CRM and automation service providers, where used;
  • consultants and professional advisers, where necessary;
  • public authorities or other parties where required by law.

Depending on the circumstances, these parties may act as data processors, independent data controllers or authorised persons.

Veltriany does not sell users’ personal data.

  1. TRANSFERS OF PERSONAL DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

Some technology providers that may be used could process personal data in countries located outside the European Economic Area.

Where applicable, such transfers will be carried out in accordance with the requirements of the GDPR and on the basis of safeguards provided for under applicable law, such as adequacy decisions or Standard Contractual Clauses approved by the European Commission.

Information concerning any international data transfers will be updated where necessary according to the providers actually used.

  1. COOKIES AND SIMILAR TECHNOLOGIES

The website may use technical cookies necessary for its operation and, where enabled, additional cookies or similar technologies.

Detailed information regarding the technologies actually used, their purposes and the methods available for managing consent can be found in the website’s Cookie Policy.

  1. AUTOMATED DECISION-MAKING

Personal data collected through the website forms is not used to make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject, unless otherwise indicated in the future to data subjects in accordance with applicable law.

  1. DATA SUBJECT RIGHTS

Where provided for under the GDPR, data subjects may exercise the rights recognised under Articles 15–22 of the Regulation, including the right to:

  • obtain confirmation as to whether or not personal data concerning them is being processed;
  • access their personal data;
  • request the rectification of inaccurate or incomplete personal data;
  • request the erasure of personal data where applicable;
  • request restriction of processing;
  • object to processing where applicable;
  • request data portability where applicable;
  • withdraw consent at any time where processing is based on consent.

The withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

To exercise these rights, you may contact the Data Controller at:

info@veltriany.com

  1. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY

Data subjects have the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data is carried out in violation of applicable data protection laws.

In Italy, the competent supervisory authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority).

  1. LINKS TO EXTERNAL WEBSITES AND SERVICES

The website may contain links to websites, social networks or services operated by third parties.

Veltriany does not control how such third parties independently process personal data. Users are therefore encouraged to review the respective privacy policies before using those services.

  1. CHANGES TO THIS PRIVACY POLICY

This Privacy Policy may be updated to reflect changes in applicable laws, organisational or technical developments, or changes to the services used by the website.

Any changes will be published on this page together with the date of the latest update.

For information or requests concerning the protection of personal data:

Veltriany
Data Controller: Silvia Poggi
Email: info@veltriany.com