top of page

PRIVACY POLICY
(Pursuant to Article 13 of Regulation (EU) 2016/679 – GDPR)

1. Data Controller
The Data Controller is:
SPAI S.r.l.
Registered Office: VIA SANSOVINO 53 - 31029 - VITTORIO VENETO (TV), ITALY
VAT Number: 00898190269
Email: info@spaisoft.com
Dedicated Privacy Email: support@spaisoft.com

(hereinafter referred to as "SPAI" or the "Data Controller").

2. Scope of Application
This Privacy Policy applies to personal data collected through:

  • Company website

  • Social media pages

  • Information and quotation request forms

  • Contact collection during trade fairs and events

  • Company CRM and technical support ticket management

  • Proprietary software provided to customers

  • Commercial and technical email communications


3. Categories of Personal Data Processed
SPAI processes exclusively professional and business-related data, including:

  • First and last name

  • Job title or company role

  • Company name

  • VAT number

  • Business address

  • Business email address

  • Business telephone number

  • Data relating to commercial or technical support requests

  • Technical access logs from portals or software

  • IP addresses and browsing data

SPAI does not process special categories of personal data as defined under Article 9 of the GDPR.

4. Purposes of Data Processing
Personal data is processed for the following purposes:
A) Management of Commercial Inquiries

  • Responding to information requests

  • Preparing quotations

  • Pre-contractual communications

B) Contract Performance

  • Provision and management of software licenses

  • Activation and management of technical services

  • After-sales support

  • Ticket management and remote technical assistance

C) Technical Management and Security

  • Monitoring software performance and operation

  • Access logging and IT security

  • Data backup and protection

D) Administrative and Tax Compliance

  • Invoicing

  • Accounting management

  • Compliance with legal and regulatory obligations

E) Direct B2B Marketing

  • Sending technical newsletters

  • Communications regarding new products

  • Invitations to trade fairs and events


Marketing communications are sent exclusively with prior consent or on the basis of legitimate interest in a B2B context.

5. Legal Basis for Processing
The processing of personal data is based on:

  • Article 6(1)(b) GDPR – Performance of a contract or implementation of pre-contractual measures

  • Article 6(1)(c) GDPR – Compliance with legal obligations

  • Article 6(1)(f) GDPR – Legitimate interests of the Data Controller (security and technical management)

  • Article 6(1)(a) GDPR – Consent (for marketing purposes, where required)


6. Methods of Data Processing
Personal data is processed using electronic and digital systems, including:

  • Company CRM systems

  • Cloud servers with access protection

  • Backup systems

  • Appropriate technical, organizational and physical security measures

Access to personal data is restricted to authorized personnel only.

7. Data Retention
Personal data is retained for the following periods:

  • Contractual data: 10 years (tax obligations)

  • Pre-contractual data: Maximum 24 months

  • Marketing data: Until consent is withdrawn

  • Technical logs: Maximum 12 months, unless longer retention is required for security purposes


8. Recipients of Personal Data
Personal data may be disclosed to:

  • Tax and legal advisors

  • Cloud service and hosting providers

  • IT service providers responsible for software maintenance

  • Cybersecurity companies

  • Competent authorities, where required by law


These parties act either as Data Processors pursuant to Article 28 of the GDPR or as independent Data Controllers.

9. Transfers Outside the European Union
Personal data is primarily processed within the European Union.
Where service providers established outside the European Union are used (e.g., Microsoft, Google, AWS), data transfers are carried out in compliance with the Standard Contractual Clauses approved by the European Commission.

10. Data Subject Rights
Data subjects may exercise the following rights at any time:

  • Right of access to personal data

  • Right to rectification

  • Right to erasure

  • Right to restriction of processing

  • Right to object to processing

  • Right to data portability


Requests may be sent to: support@spaisoft.com.
Alternatively, data subjects may complete the form available at the bottom of this page.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).

11. Nature of Data Provision
Providing personal data for contractual purposes is necessary.
Failure to provide such data will prevent SPAI from delivering the requested services.
Providing personal data for marketing purposes is optional.

12. Automated Decision-Making
SPAI does not carry out automated profiling or make decisions based solely on automated processing of personal data.

13. Updates
Last updated: October 3, 2026

bottom of page