Skip to main content
Decorative background privacy notice
Privacy Notice

Privacy Policy

Notice on the processing of personal data pursuant to art. 13 of EU Regulation 2016/679 (GDPR).

Last updated: 26 August 2026

This is a courtesy English translation. The Italian version of this Privacy Policy is the legally binding one and prevails in case of any discrepancy.

In short

  • We collect only the data strictly necessary to provide you with our services
  • We do not sell your data to third parties — the servers are in Europe
  • You can access, modify or delete your data at any time
  • Analytics and marketing cookies are installed only with your consent

1. Data Controller

The Controller of the processing of personal data is:

G Tech Group S.R.L.S.

Via di Gagia, 22, 38086 Giustino (TN) — Italia

VAT ID: 02743570224

REA: TN – 246638

Email: info@gtechgroup.it

PEC: gtechgroup@pec.it

Phone: +39 0465 846 245

2. Types of data collected

The Controller collects, directly or through third parties, the following categories of personal data:

Data provided voluntarily by the user

  • Identification data: first name, surname, company name
  • Contact data: email address, phone number, postal address
  • Tax data: VAT number, tax code, SDI code (for invoicing)
  • Content of communications: messages sent via contact forms, email, WhatsApp or phone

Data collected automatically

  • Browsing data: IP address, browser type, operating system, pages visited, date and time of access, referring site
  • Cookies and tracking technologies: technical, analytics and profiling cookies (see Cookie Policy)

3. Purposes and legal basis of the processing

Personal data is processed for the following purposes:

Performance of the contract (art. 6.1.b GDPR)

  • Provision of the requested services (hosting, web development, marketing, software)
  • Management of the customer account and the contractual relationship
  • Technical assistance and customer support
  • Invoicing and accounting obligations

Consent of the data subject (art. 6.1.a GDPR)

  • Sending commercial and promotional communications
  • Profiling for personalised offers
  • Installation of analytics and profiling cookies

Legitimate interest of the Controller (art. 6.1.f GDPR)

  • Responding to information requests sent via contact forms
  • Fraud prevention and IT security protection
  • Aggregated and anonymised web traffic analysis to improve services

Legal obligation (art. 6.1.c GDPR)

  • Tax, accounting and fiscal obligations
  • Obligations under current legislation

4. Processing methods

Personal data is processed with IT and/or electronic tools, with organisational and logical methods strictly related to the purposes indicated. Processing takes place through technical and organisational security measures adequate to ensure the confidentiality, integrity and availability of the data.

In addition to the Controller, in some cases the data may be accessed by parties involved in the company organisation (administrative, technical, commercial staff) or external parties (third-party technical service providers, postal couriers, hosting providers, IT companies) appointed, where necessary, as Data Processors pursuant to art. 28 of the GDPR.

5. Data retention

Personal data is kept for the time strictly necessary to achieve the purposes for which it was collected:

  • Contractual data: for the entire duration of the contractual relationship and for the following 10 years (tax and accounting obligations under art. 2220 of the Italian Civil Code)
  • Data from contact forms: for the time needed to handle the request and in any case no longer than 24 months from the last interaction
  • Browsing data and cookies: according to the timeframes indicated in the Cookie Policy
  • Data for direct marketing: until consent is withdrawn, and in any case no longer than 24 months from the last interaction

At the end of the retention period, the data is irreversibly deleted or made anonymous.

6. Disclosure and transfer of data

Personal data may be disclosed to:

  • Hosting and infrastructure service providers (OVHcloud, Hetzner, Nehos) with servers located in the European Union
  • Email and communication service providers
  • Consultants and professionals for tax and legal obligations
  • Technology service providers for the mobile application (voice processing, virtual assistant, push notifications, payment collection), listed in § 8.2, some of which located outside the European Union
  • Competent authorities, in the cases provided by law

Data is not sold to third parties. Any transfers to non-EU countries take place exclusively on the basis of adequate safeguards (European Commission adequacy decisions, Standard Contractual Clauses).

7. Third-party services

The site uses the following third-party services that may collect personal data:

Google Tag Manager (GTM-NSFGQ8V) / Google tag (GT-M3K6ZQ7L)

Tag management and tracking services provided by Google LLC. Google Tag Manager coordinates the loading of analytics and marketing scripts; the Google tag collects browsing and conversion data. Google Privacy Policy.

Formspree

Contact form management service. The data sent via the forms is processed by the servers of Formspree Inc. Formspree Privacy Policy.

WhatsApp Business

Messaging service provided by Meta Platforms Inc. Conversations started via the WhatsApp button are managed according to the WhatsApp Privacy Policy.

G Tech Group Chat

Live chat service for real-time customer support, provided by G Tech Group via the chat.gtechgroup.it platform. It collects session data and the content of conversations for support purposes. The data is processed on European servers.

Google Fonts

The fonts used on the site are served locally (self-hosted) and do not make calls to Google servers during browsing.

8. «Customer Area» mobile app

This section describes the processing carried out via the G Tech Group — Customer Area application, available for Android devices. The app is reserved for customers and requires login with credentials.

8.1 Data collected via the app

Registration and login data

Company name, first name, surname, email address and password. Optional: VAT number and phone number. The device platform (Android or iOS) is also recorded.

Content the user chooses to send

  • Text of support tickets and their replies
  • Photographs attached to tickets, taken with the camera or chosen from the gallery. Access to the camera and gallery is requested only at the time of use and can be denied without preventing use of the app
  • Voice notes recorded via the microphone, used to open a ticket by dictating its content
  • Messages exchanged with the «Peter AI» virtual assistant

Technical data

  • Device identifier for notifications (Firebase Cloud Messaging token), necessary to deliver push notifications
  • IP address, device type and application used, recorded for each operation for security purposes and to reconstruct any disputes

Payment data

Card details do not pass through or get stored on our systems: they are entered directly in the secure interface provided by Stripe. We keep only the payment outcome and the invoice reference.

Biometric data

If the user enables fingerprint or face-recognition unlock, verification takes place entirely on the device via the operating system's functions. No biometric data is transmitted or stored by us: we receive only the outcome (successful or unsuccessful).

8.2 Processing involving external providers

PurposeProviderWhereWhat it receives
Transcription of voice notesOpenAI Ireland Ltd / OpenAI OpCo, LLCUnited StatesThe audio file recorded by the user
«Peter AI» virtual assistantOVHcloud (AI Endpoints)European UnionThe text of the messages exchanged with the assistant
Delivery of push notificationsGoogle Ireland Ltd (Firebase)European Union / United StatesThe device identifier and notification text
Payment collectionStripe Payments Europe LtdEuropean UnionCard details, amount, invoice reference

The transfer to the United States for the transcription of voice notes takes place on the basis of the Standard Contractual Clauses (SCC) adopted by the European Commission (decision of 4 June 2021) and incorporated into OpenAI's Data Processing Addendum (contracting entity for the European Economic Area: OpenAI Ireland Ltd), which ensure adequate safeguards pursuant to Chapter V of the GDPR. The user can at any time avoid this processing by not using the voice-note function and writing the ticket in text form.

8.3 Retention

  • Tickets, attachments and voice notes: kept together with the support history, for the duration of the contractual relationship and subsequently for the time needed for legal defence
  • Conversations with the virtual assistant: automatically deleted after 24 months
  • Access log (IP, device): automatically deleted after 12 months
  • Login sessions: session credentials automatically expire after 90 days of inactivity
  • Invoices and accounting documents: 10 years, by legal obligation

8.4 Account deletion

The user can delete their account:

  • from the app, in Settings → Delete account: deletion is immediate
  • from the web, without installing the app, at crm.gtechgroup.it/elimina-account: the request is handled within 30 days

The following are deleted: contact registry data, sessions, devices registered for notifications, notifications and conversations with the virtual assistant.

The following are retained, by legal obligation or for legal defence: invoices and accounting documents, and support tickets with their attachments.

8.5 No advertising tracking

The app does not contain statistical analysis, profiling, advertising or attribution tools. The device's advertising identifier is not collected and no cookies are used.

9. Rights of the data subject

Pursuant to arts. 15-22 of the GDPR, the data subject has the right to:

Access

Obtain confirmation of processing and a copy of the personal data

Rectification

Request the correction of inaccurate data or the completion of incomplete data

Erasure

Request the deletion of data (right to be forgotten)

Restriction

Request the restriction of processing in certain cases

Portability

Receive the data in a structured format and transmit it to another controller

Objection

Object to processing for legitimate reasons, including direct marketing

Withdrawal of consent

Withdraw consent at any time without affecting the lawfulness of prior processing

Complaint

Lodge a complaint with the Data Protection Authority (www.garanteprivacy.it)

To exercise their rights, contact the Controller at the email address info@gtechgroup.it or at the certified email (PEC) gtechgroup@pec.it.

11. Changes to this notice

The Controller reserves the right to make changes to this notice at any time, giving notice to users on this page and, where possible, through the Controller's contact channels. Please consult this page regularly to check for any updates.

Should the changes concern processing whose legal basis is consent, the Controller will collect the data subject's consent again, where necessary.

12. Contacts

For any questions regarding this notice or the processing of personal data, you can contact the Controller:

Email: info@gtechgroup.it

PEC: gtechgroup@pec.it

Phone: +39 0465 846 245

Address: Via di Gagia, 22, 38086 Giustino (TN)