Privacy Policy
Privacy Policy
Notice pursuant to Articles 13 and 14 of EU Regulation 2016/679 («GDPR») and Italian Legislative Decree 196/2003 (Privacy Code) as amended by Decree 101/2018. This policy covers processing carried out by Oncode S.r.l. as Controller for its own data (site visitors, sales leads, contracting customers). For data of customers' employees, see the App Privacy page.
- Version
- v1.0
- Effective
- 2026-04-25
Data Controller and DPO
Data Controller: Oncode S.r.l. (single-shareholder), Piazza Maestri del Lavoro 7, 20063 Cernusco sul Naviglio (MI), Italy, VAT IT09903240969.
Data Protection Officer (DPO): reachable at [email protected].
Categories of personal data collected
- Browsing data: IP addresses, access logs, user-agent, visited pages, technical cookies and — with consent — analytics.
- Data provided voluntarily: name, surname, business email, company name, role, phone, content of inquiries via contact forms.
- Contractual and billing data: company name, VAT, address, recipient code/PEC, banking details, contractual contacts.
- Marketing data (with consent or B2B soft opt-in): preferences, email and content engagement.
Purposes and legal bases
- Service delivery and contract management — basis: Art. 6(1)(b) GDPR (contract performance).
- Tax, accounting and administrative obligations — basis: Art. 6(1)(c) GDPR (legal obligation).
- Responding to contact and support requests — basis: Art. 6(1)(b) GDPR (pre-contractual measures) or 6(1)(f) (legitimate interest).
- Direct marketing on similar products to existing customers (B2B soft opt-in) — basis: Art. 130(4) Italian Privacy Code. Opt-out always available.
- Newsletter and promotional communications — basis: Art. 6(1)(a) GDPR (explicit consent).
- Security, fraud prevention, incident management — basis: Art. 6(1)(f) GDPR (legitimate interest in secure operations).
- Compliance with authorities' requests — basis: Art. 6(1)(c) GDPR.
Processing methods and location
Data are processed by electronic means, applying technical and organisational measures appropriate to GDPR Art. 32 and aligned with Oncode S.r.l.'s ISO/IEC 27001 certification.
Onwork and main sub-processors' servers are located in the European Union (Ireland — AWS eu-west-1). For details and extra-EU transfer mechanisms, see the next section.
Retention period
- Contractual and tax data: 10 years after contract termination (statutory obligation).
- Lead/sales contact data: up to 24 months from last interaction, unless marketing consent is granted.
- Newsletter: until consent is withdrawn or after 24 months of inactivity.
- Application logs: max 12 months, except for security or legal needs.
- Cookies: as indicated in the Cookie Policy.
Recipients and sub-processors
Data may be shared with qualified vendors appointed as Processors under GDPR Art. 28 (cloud, email marketing, observability, AI). The current list is at Sub-processors.
Transfers outside the EU
Where needed to deliver the Service, some data may be transferred to vendors located outside the European Economic Area. In such cases we adopt the safeguards of GDPR Chapter V: European Commission adequacy decisions, Standard Contractual Clauses (EU Decision 2021/914), Data Privacy Framework (USA) and — where needed — Transfer Impact Assessments.
Data subject rights
You may exercise the rights under GDPR Articles 15–22 at any time:
- Right of access and copy (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction (Art. 18)
- Right to data portability (Art. 20)
- Right to object, including direct marketing (Art. 21)
- Right not to be subject to automated decision-making (Art. 22)
Requests can be sent to [email protected]. We respond within 30 days (extendable in complex cases).
Complaint to the Authority
If you believe the processing of your data violates the GDPR or the Italian Privacy Code, you have the right to lodge a complaint with the Italian Data Protection Authority — Piazza Venezia 11, 00187 Rome.
Changes to this policy
This Privacy Policy is subject to update. Previous versions are retained for audit purposes. Substantive changes are communicated to data subjects via the most appropriate means.