Skip to content

1. Data controller

The data controller is Syncronika Srl, single shareholder company, with registered office at Bastioni di Porta Nuova 21, 20121 Milan (MI), Italy, VAT no. IT01802650380, REA MI-2098838.

For any request relating to the processing of your personal data you can contact us at: [email protected].

2. Categories of data we collect

We collect the following categories of personal data:

  • Data you provide voluntarily: name, surname, phone number, email address, message content and any other information you choose to share via the contact form on the website or via direct email.
  • Browsing data: IP address, browser type, operating system, pages visited, date and time of the visit, referring website, parameters concerning the user's operating system and IT environment. This data is collected by the systems and software procedures that operate the website.
  • Data collected via cookies and similar technologies: online identifiers, page-view events and, where consent is given, campaign measurement data (e.g. via Google Analytics 4 and Meta Pixel). For cookie details see our Cookie Policy.

3. Purposes and legal bases of processing

We process your personal data for the following purposes:

Purpose Legal basis
Reply to requests sent through the contact form Pre-contractual measures at your request (art. 6.1.b GDPR)
Comply with legal, accounting or tax obligations Legal obligation (art. 6.1.c GDPR)
Ensure website security and prevent fraud or abuse (including reCAPTCHA on the contact form) Legitimate interest of the controller (art. 6.1.f GDPR)
Statistics and visit analysis via Google Analytics 4 (aggregate form) Consent of the data subject (art. 6.1.a GDPR), given via the cookie banner (“Accept all”)
Measurement of advertising campaigns and remarketing via Meta Pixel (Facebook/Instagram) Consent of the data subject (art. 6.1.a GDPR), given via the same cookie banner (“Accept all”; one consent covers analytics and marketing)

Providing the data requested through the contact forms is optional. However, failure to provide data marked as mandatory makes it impossible for Syncronika to process the request.

4. How we process the data

Personal data is processed using both automated and manual tools, for the time strictly necessary to achieve the purposes for which it was collected. Specific technical and organisational security measures are adopted to prevent loss of data, unlawful or incorrect use and unauthorised access.

5. Retention period

Personal data is kept for the time required to pursue the purposes for which it was collected:

  • Contact request data: up to 24 months from the last interaction, unless the request results in a contractual relationship.
  • Contractual relationship data: for the duration of the contract and the 10 subsequent years, in compliance with legal obligations.
  • Browsing data: for the time strictly necessary to deliver the requested service and in any case no longer than 7 days (except for the purpose of investigating potential offences).
  • Data collected via analytics/marketing cookies (if you gave consent): according to the durations in the Cookie Policy (e.g. up to 2 years for GA4, up to 3 months for Meta _fbp / _fbc), or until you withdraw consent.

6. Recipients of the data

Your data may be communicated to:

  • Authorised Syncronika personnel, properly instructed.
  • Technology service providers acting as data processors (hosting, email, CRM, form management, anti-spam). The updated list is available on request at [email protected].
  • Google Ireland Limited / Google LLC (Google Analytics 4 and, on the contact form, reCAPTCHA), if you accepted analytics cookies via the banner or, for reCAPTCHA, when you submit the form.
  • Meta Platforms Ireland Limited (Meta Pixel), if you accepted marketing cookies via the banner; Meta may also act as an independent controller for some of its own purposes, under its own privacy notice.
  • Competent authorities, in compliance with legal obligations.

Your personal data will not be disclosed nor transferred to third parties for marketing purposes without your explicit consent (also expressed via the cookie banner, where applicable).

7. Transfers outside the EU

Some of our technology service providers may be located outside the European Union (for example Google and Meta / Meta Platforms, Inc. in the United States). In such cases we ensure that the transfer takes place in compliance with art. 46 GDPR, based on:

  • European Commission adequacy decisions (including, where applicable, the EU-US Data Privacy Framework), or
  • Standard contractual clauses approved by the European Commission, or
  • Other adequate safeguards provided for by the GDPR.

8. Your rights

As a data subject you can exercise the following rights at any time:

  • Right of access to your personal data (art. 15 GDPR).
  • Right to rectification (art. 16 GDPR).
  • Right to erasure, "right to be forgotten" (art. 17 GDPR).
  • Right to restriction of processing (art. 18 GDPR).
  • Right to data portability (art. 20 GDPR).
  • Right to object to the processing (art. 21 GDPR).
  • Right to withdraw the consent at any time, without affecting the lawfulness of the processing based on consent before its withdrawal.

To exercise these rights please write to [email protected]. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) if you believe that the processing of your personal data is in breach of the GDPR.

9. Changes to this policy

This policy may be updated over time. Updates will be published on this page, with the date of the last revision indicated.