aumatex.
Contact

Last update May 15, 2026

Privacy Policy

Notice provided pursuant to Articles 12, 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Article 122 of Legislative Decree 196/2003 (Italian Privacy Code) as amended by Legislative Decree 101/2018, to users browsing the website and using its contact channels. This notice is also provided in compliance with the Italian Data Protection Authority Cookie Guidelines of June 10, 2021 and subsequent clarifications (May 2025).

1. Data Controller

  • The Data Controller is Aumatex SRLS, Via Umberto Biancamano 25 - 00185 Rome (RM), VAT No. IT15617831001, PEC: aumatex@pec.it.
  • Privacy contacts: privacy@aumatex.it, info@aumatex.it.
  • The Controller determines the purposes and means of processing and remains responsible for GDPR, Italian Privacy Code and ePrivacy compliance.
  • No Data Protection Officer (DPO) has been appointed as the processing does not fall within the mandatory cases under Article 37 GDPR.

2. Categories of data processed and specific purposes

  • Browsing and system log data: IP address (also anonymized), request date/time, requested URL, user agent, browser, OS, language, referrer, session identifiers. Automatically collected by Cloudflare (proxy/DNS/security), Vercel (edge hosting) and application server for security, troubleshooting, rate limiting and site operation.
  • Data voluntarily provided via forms: name, email address, company/organisation, message content. Sent via email to the Controller; not stored in database.
  • Security data: source IP, timestamp, request fingerprint, temporary rate-limit counters in volatile memory (~10 minutes) for spam and abuse prevention.
  • Cookie consent data: choice made in banner (necessary/preferences/analytics), policy version, consent date/time, accepted categories. Stored in a first-party cookie (aumatex_cookie_consent) for 180 days.
  • Google Analytics 4 data: ONLY with specific consent - cookies _ga, _ga_<container-id>, browsing events, visited pages, interactions, aggregated geographic data. Configured with: (a) IP anonymization active, (b) Google Signals DISABLED, (c) ads personalization DISABLED, (d) max 14 months data retention.

3. Purposes and legal bases

  • The Controller processes personal data only for specific, explicit and legitimate purposes, applying minimisation, storage limitation, integrity, confidentiality and accountability principles.
PurposeDataLegal basis
Deliver the website, pages, cache, CDN, DNS and network security.Browsing data and technical logs.Legitimate interest in website security and operation, Art. 6(1)(f) GDPR; technical cookies exempt from consent under ePrivacy rules.
Reply to requests submitted through forms, email or contact links.Identification/contact data and message content.Pre-contractual or contractual measures requested by the user, Art. 6(1)(b) GDPR.
Prevent spam, abuse, bulk submissions and unauthorised access.IP, user agent, request metadata, temporary rate-limit counters.Legitimate interest in protecting the website and systems, Art. 6(1)(f) GDPR.
Comply with tax, accounting, administrative or authority requests.Data necessary for the request or relationship.Legal obligation, Art. 6(1)(c) GDPR.
Measure website usage with Google Analytics 4 and improve content/performance.Analytics cookies, events, pseudonymised technical and browsing data.Prior consent, Art. 6(1)(a) GDPR and Italian Privacy Code Art. 122.

4. Data provision

  • Technical browsing data is necessary to access the website.
  • Providing form data is optional, but name, email and message are required to send a request and receive a reply.
  • Consent to analytics, non-essential preference or marketing cookies is optional and may be refused or withdrawn without preventing website browsing.

5. Processing methods, security and preventive blocking

  • Data is processed through IT tools and organisational procedures consistent with the stated purposes, applying privacy by design and by default principles.
  • Technical measures adopted: HTTPS/TLS 1.3, security headers (CSP, HSTS, X-Frame-Options), MFA access controls, dev/staging/prod environment separation, advanced rate limiting, rigorous server-side validation, anti-spam honeypot, structured logging without message content.
  • PREVENTIVE COOKIE BLOCKING: Analytics scripts (GA4) and third-party widgets are blocked by default and loaded ONLY after explicit consent via banner. No non-technical cookies are installed before user choice.
  • Pseudonymization: Where possible, IPs are anonymized or masked before analytics processing.
  • System access is limited to authorised Controller personnel and technical providers qualified as Processors under Article 28 GDPR.

6. Retention periods and deletion criteria

  • Form/email messages to Controller: 12 months from last contact, unless contractual relationship established (then up to 10 years for tax/accounting obligations) or early deletion requested.
  • Data on Aumatex servers: NO retention - form data transits via API and email without database persistence or PII in application logs.
  • Cloudflare technical logs: 7-30 days (standard configuration), then aggregated/anonymized.
  • Vercel hosting logs: 1-7 days for runtime logs, then automatic deletion.
  • Rate-limit counters: max 10 minutes in volatile memory (Redis/memory), no persistence.
  • Consent preferences cookie (aumatex_cookie_consent): 6 months (180 days), renewable on each visit.
  • Google Analytics 4 data: max 14 months from collection (property setting), then automatic deletion by Google.
  • General criterion: Data is kept only as long as strictly necessary for stated purposes, with six-monthly retention reviews.

7. Data processors and authorised providers (Art. 28 GDPR)

  • Data is processed exclusively by subjects qualified as Processors under Article 28 GDPR, with formal appointment and security checks. No transfer to third parties for their own purposes.
Subject / serviceGDPR roleCountryTransfer safeguardsSpecific processing
Cloudflare Inc.Processor (DNS, proxy, CDN, security)USAData Privacy Framework + SCC 2021/914 + supplementary measuresDNS/proxy management, DDoS protection, edge cache, anonymized technical logs. Edge servers also in EU.
Vercel Inc.Processor (edge hosting)USAData Privacy Framework + SCC 2021/914Static site delivery, API runtime, technical logs. Edge network with data replication also in EU.
Aruba S.p.A.Processor (domain registrar)ItalyN/A - EUAdministrative domain management for aumatex.it only.
Resend (Resend Inc.)Processor (transactional email)USAData Privacy Framework + SCC 2021/914Form email sending from server to Controller. Metadata access only, no content access.
Google Ireland Ltd. / Google LLCProcessor ONLY if analytics consentIreland/USAData Privacy Framework (Google LLC certified) + SCCGA4: statistical measurement ONLY with prior consent. Configured: IP anonymized, no Signals, no ads.
Aumatex email providerProcessor (recipient mailbox)EU (typically)N/A - EUReceipt and storage of Aumatex SRLS emails.

8. International data transfers

  • Transfers to third countries (outside EU/EEA) occur exclusively to certified providers or with adequate safeguards under Articles 44-50 GDPR.
  • Cloudflare Inc. (USA): EU Commission adequacy decision 2023/1795 (Data Privacy Framework) + EU Commission Standard Contractual Clauses 2021/914. Supplementary measures: log pseudonymization, limited access, EU edge servers preferred.
  • Vercel Inc. (USA): Data Privacy Framework + SCC 2021/914. Distributed edge network; log data may temporarily reside also in USA.
  • Google Ireland / Google LLC (USA): Google LLC is Data Privacy Framework certified. For GA4: transfer only with consent, with IP anonymization and privacy-safe configuration.
  • Resend Inc. (USA): Data Privacy Framework + SCC 2021/914. Processing limited to transactional email metadata.
  • Complete SCC documentation and Transfer Impact Assessments (TIA) available from Aumatex SRLS upon request.

9. Cookies and tracking technologies

  • The website uses technical cookies necessary for operation and, only with consent, non-essential analytics or functional tools.
  • Full details are available in the Cookie Policy and cookie preference banner.

10. Data subject rights and exercise methods

  • Rights under Articles 15-22 GDPR: access (Art. 15), rectification (Art. 16), erasure/right to be forgotten (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), consent withdrawal (Art. 7.3).
  • Methods: Written request to privacy@aumatex.it with subject "GDPR Request - [your name/surname]". Attach ID document for verification.
  • Response time: Within 1 month of receipt (extendable to 3 months for complexity, with motivated communication within 1 month).
  • Consent withdrawal: Possible at any time via (a) "Cookie preferences" link in footer, (b) reopenable cookie banner, (c) email to privacy@aumatex.it. Withdrawal does not affect lawfulness of prior processing.
  • Complaint: Right to lodge complaint with Italian Data Protection Authority (www.garanteprivacy.it) or supervisory authority of residence/workplace Member State.
  • Marketing objection: Any promotional communications require specific prior consent (double opt-in). Every email includes immediate unsubscribe link.

11. Complaint

  • A complaint may be lodged with the Italian Data Protection Authority, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or another competent supervisory authority.

12. Protection of minors

  • The website is not intended for children under 14 and does not knowingly request data from minors.
  • Forms do not include age verification but are not designed to attract underage users.
  • Persons with parental responsibility who believe a minor has provided personal data may contact privacy@aumatex.it to request verification, rectification or immediate deletion.

13. Updates

  • Aumatex SRLS may update this notice due to legal, technical or organisational changes. The applicable version is the one published on the website with its last update date.

We build digital systems together.

Websites, software, infrastructure and automation for companies that want to operate better.

Contact

Aumatex

  • Home
  • About us
  • Case studies
  • Blog
  • Tech stack
  • Careers
  • Contact

Services

  • Custom software
  • iOS apps
  • Web Apps & PWA
  • Business platforms
  • Websites
  • E-commerce
  • UX/UI Design
  • AI, chatbots & automation
  • Cloud & infrastructure
  • Public tenders & MEPA

Products

  • View all products
  • Native Apps
  • Web App & PWA
  • Business Platforms
  • Websites
  • E-commerce

Legal

  • Privacy policy
  • Cookie policy
Aumatex
aumatex.
Aumatex SRLS · Via Umberto Biancamano 25, 00185 Roma (RM), Italy© 2026 Aumatex SRLS · VAT IT15617831001•Privacy policy•Cookie policy•