30 days of full access | No credit card required | No commitment
This document provides information regarding the protection of personal data processed in the context of the Easy CEMS service in compliance with the European General Data Protection Regulation (GDPR).
INFOITALIA SERVIZI SRL, with registered office in Reggio Calabria, Via Nazionale Pentimele, 167, Italy, VAT No. 02095920803 (hereinafter referred to as "Infoitalia") guarantees that the personal data provided by customers, as well as third-party data collected by customers and processed by Infoitalia (hereinafter collectively referred to as the "data subject") within the scope of the contract for the use of the service named Easy CEMS (hereinafter referred to as the "service"), are processed in compliance with the European General Data Protection Regulation No. 2016/679 (GDPR). As required by the aforementioned Regulation, the information requested by the legislation regarding the processing of personal data is provided to the Customer below.
Infoitalia, in its capacity as Data Controller, processes the following types of personal data: The data provided by the data subject for which Infoitalia acts as the Data Controller are: personal, tax, and commercial data of the customers. The provision of data is mandatory, and failure to provide such data prevents the execution of the service.
These are personal data of third parties, independently collected by the Customer and/or other parties authorized by them, and entered into the databases supporting the service in the context of its use; the Customer is the Data Controller of such data.
The appointment as Data Processor has a duration equal to that of the Customer's order to Infoitalia regarding the Service. The appointment will automatically cease to be effective in the event of termination, withdrawal, or loss of effectiveness of the Contract, except for the time necessary to allow the Data Controller to recover personal data, where contractually agreed between the parties. Similarly, in the event of subsequent purchases of the service by the Customer, the appointment as Data Processor will be considered automatically renewed for a duration equal to that contractually provided.
The customer authorizes Infoitalia to avail itself of its own sub-processors, including third-party suppliers for the provision of services connected to the contractually provided service, acknowledging and accepting that this may entail the processing of data by said parties to the extent necessary to fulfill the obligations delegated to them.
If appointed as External Data Processor, Infoitalia is responsible for:
Furthermore, Infoitalia will be available to provide assistance to the Customer within the limits of the nature of the processing and the information at its disposal.
The Data Controller (the Customer) has exclusive jurisdiction and responsibility for all types of data entered into the service's databases.
The data referred to in section 1.1 are collected and processed by Infoitalia for the execution of the contract, to fulfill tax and general legal obligations, and to provide assistance to the Customer, as well as for commercial activities.
Regarding the data referred to in section 1.2, the nature of said data is determined by the Customer, as is the lawfulness of collection and processing, which is the exclusive competence of the Customer; Infoitalia limits itself to the processing thereof for the provision of the services requested by the Customer, according to the specifications of the services themselves and in compliance with any further instructions provided by the Customer.
No data processed by Infoitalia shall be transferred to third parties.
All processed data is stored in electronic devices and archives, accessible telematically, located in data centers of countries belonging to the European Union and/or at Infoitalia's corporate headquarters. Infoitalia does not transfer personal data processed to countries where the GDPR is not applied (non-EU countries).
The personal data of the Data Subject, referred to in Section 1.1, are kept for as long as necessary with respect to the legitimate purposes for which they were collected and, in any case, kept for the fulfillment of certain obligations that remain even after the termination of the contract (art. 2220 of the Italian Civil Code), such as, for example, accounting and tax obligations. In the event that Infoitalia has acquired personal data not necessary for said purposes, it will proceed to delete them as soon as possible after the termination of the contract.
Personal data of third parties, independently collected by the Customer and other parties authorized by them — and therefore for which the Customer is the Data Controller — entered into the service databases and in use by the Customer, are processed by Infoitalia until one year after the last purchase made by them; after this term, the data is deleted.
Access to the personal data for which Infoitalia is the Data Controller may be granted to all employees of Infoitalia Servizi Srl and its affiliated companies (companies belonging to the same ownership group as Infoitalia and which have operational headquarters at the same location), with whom specific internal services — technical and administrative — are performed with common procedures and tools, as well as external tax consultants.
Access to the third-party data of the Customer for which Infoitalia acts as the Data Processor is restricted to specific individuals, employees of Infoitalia and affiliated companies, for purposes strictly related to the provision of the services themselves, such as, for example, updates, maintenance, or providing assistance to the Customer. These individuals have signed a confidentiality agreement with Infoitalia regarding the processing of third-party personal data and have been trained and instructed on the methods prescribed by the GDPR Regulation.
An updated document is kept at the Infoitalia headquarters with the following information:
The indicated document can be requested at the following e-mail address: infoitalia@infoit.it, referencing the "Easy CEMS" service.
This section reiterates the rights of the data subject, provided for by law, regarding the processing of data for which Infoitalia is the Data Controller.
In this regard, any request may be sent to the address infoitalia@infoit.it.
Regarding the type of data referred to in point 1.2, for which Infoitalia acts as Data Processor, the data subject must contact the Data Controller.
The data subject has the right to obtain from the data controller the following:
Personal data are processed by Infoitalia through an IT infrastructure consisting of its own devices and cloud platforms provided by leading companies in the sector. For its part, Infoitalia adopts every measure aimed at ensuring the security of the processed data.
Infoitalia's suppliers ensure the use of IT platforms compliant with the requirements of the ISO/IEC 27001:2005 standard. In the facilities used for the provision of services, great importance is given to the security of the environments and the data contained therein. For this reason, a whole series of systems are in place to ensure the integrity of environments and services. Data centres are continuously monitored and equipped with the most advanced security solutions.
For its part, Infoitalia, in the creation and management of its management software/applications, uses tools aimed at ensuring the confidentiality, integrity, and immediate availability of the processed data. With the capability to promptly restore the availability of and access to personal data in the event of an incident.
Listed below are some of the security features related to the EASY CEMS service:
For the management of its service, Infoitalia provides the Customer with an administration panel, through which the Customer may, in complete autonomy, create access credentials for their users and limit access based on different authorization profiles, including action and viewing permissions for different modules, as well as consult access logs.
The service provides for management through an area accessible with access credentials assigned to the Customer, where it is possible to perform all administration and customization operations of the service itself, perform backups, and add and delete data.
The Customer is the sole and exclusive administrator of the service's Administration Panel and as such declares to be solely responsible at their own risk for the management of data and/or information and/or content processed, their security, and their backup, and for the performance of every other activity deemed useful or necessary to guarantee their integrity, undertaking, as a result, to apply, at their own care and expense, appropriate and adequate security measures.
The Customer assumes full responsibility for the actions of internal processors regarding their operations as if said operations had been performed by the Customer themselves.
The Customer also acknowledges and accepts that Infoitalia does not control or monitor how the Customer uses the service; in any case, Infoitalia is and remains extraneous to the activities that the Customer carries out in full autonomy.
Regarding the service, Infoitalia performs a full database backup, relative to the previous 15 days of use; furthermore, it performs daily backups of database data (excluding files), also stored in locations different from those where the data centers are based. Despite this, Infoitalia cannot provide absolute guarantees against data loss due to force majeure or circumstances not dependent on the control it can exercise, just as it, in turn, does not receive guarantees in this regard from its data center service providers. To this end, Infoitalia provides its customers with suitable tools to independently perform backups of their data.
In order to ensure an adequate level of security against unwanted access, Infoitalia requires that passwords for the use of its management software must have minimum requirements, represented by the following format: minimum 8 characters, at least one uppercase letter, at least one lowercase letter, at least one number, and at least one special character. The password must be renewed after a period of time not exceeding 6 months.
The authentication system also provides for a limited number of access attempts, in order to prevent so-called brute force attacks (i.e., using software that tries all possible combinations of characters and numbers until it identifies the exact one).
The Customer, for their part, is obliged to take all necessary security measures to safeguard their data from unwanted access in the management software/applications used and assumes full responsibility for any improper use by users authorized by the Customer. The Customer is obliged to perform, at their own care and with the periodicity they deem most appropriate, a complete backup of the data and/or information and/or content present in the management software/applications in use.
Infoitalia guarantees the Customer the provision and use of the service 24/7, 365 days a year, barring unforeseen circumstances. The obligations and responsibilities of Infoitalia toward the Customer are those defined by the Contract or in the order. The Customer acknowledges that the internet network cannot be controlled by Infoitalia and that, due to the peculiar structure of the network itself, its performance and functionality cannot be guaranteed, nor can the content of information transmitted via said network be controlled. For this reason, no liability may be attributed to Infoitalia for any illicit acts committed by third parties to the detriment of the Customer during the use of the Service via the internet connection.
Without prejudice to the mandatory cases provided for by law, in no other case, for any reason and/or cause, shall Infoitalia be held liable toward the Customer, or toward other parties directly or indirectly connected or linked to the Customer, for damages, direct or indirect, loss of data, violation of third-party rights, delays, malfunctions, or interruptions, total or partial, of the Services resulting from facts or acts not attributable to Infoitalia, such as, by way of example:
Without prejudice to the above, the Customer undertakes, now for then, to indemnify and/or hold harmless Infoitalia from any and all liability and/or compensation for damages caused by the aforementioned acts and/or behaviors. In any case, and for any potential case of violation or breach attributable to Infoitalia, it shall respond, as a maximum amount, exclusively within the limits of the sum spent by the Customer in the last 12 months. Infoitalia reserves the right to interrupt the provision of the Service to perform technical interventions aimed at improving its functionality. In such a case, notice will be given to the Customer via e-mail with advance warning; said notice will also indicate the restoration timeline.
Your 30-day free trial has been activated. Check your email for login credentials and next steps.
Back to Home