
Privacy Policy
Notice on the processing of personal data pursuant to art. 13 of EU Regulation 2016/679 (GDPR).
Last updated: 26 August 2026
In short
- We collect only the data strictly necessary to provide you with our services
- We do not sell your data to third parties — the servers are in Europe
- You can access, modify or delete your data at any time
- Analytics and marketing cookies are installed only with your consent
Contents
1. Data Controller
The Controller of the processing of personal data is:
G Tech Group S.R.L.S.
Via di Gagia, 22, 38086 Giustino (TN) — Italia
VAT ID: 02743570224
REA: TN – 246638
Email: info@gtechgroup.it
PEC: gtechgroup@pec.it
Phone: +39 0465 846 245
2. Types of data collected
The Controller collects, directly or through third parties, the following categories of personal data:
Data provided voluntarily by the user
- Identification data: first name, surname, company name
- Contact data: email address, phone number, postal address
- Tax data: VAT number, tax code, SDI code (for invoicing)
- Content of communications: messages sent via contact forms, email, WhatsApp or phone
Data collected automatically
- Browsing data: IP address, browser type, operating system, pages visited, date and time of access, referring site
- Cookies and tracking technologies: technical, analytics and profiling cookies (see Cookie Policy)
3. Purposes and legal basis of the processing
Personal data is processed for the following purposes:
Performance of the contract (art. 6.1.b GDPR)
- Provision of the requested services (hosting, web development, marketing, software)
- Management of the customer account and the contractual relationship
- Technical assistance and customer support
- Invoicing and accounting obligations
Consent of the data subject (art. 6.1.a GDPR)
- Sending commercial and promotional communications
- Profiling for personalised offers
- Installation of analytics and profiling cookies
Legitimate interest of the Controller (art. 6.1.f GDPR)
- Responding to information requests sent via contact forms
- Fraud prevention and IT security protection
- Aggregated and anonymised web traffic analysis to improve services
Legal obligation (art. 6.1.c GDPR)
- Tax, accounting and fiscal obligations
- Obligations under current legislation
4. Processing methods
Personal data is processed with IT and/or electronic tools, with organisational and logical methods strictly related to the purposes indicated. Processing takes place through technical and organisational security measures adequate to ensure the confidentiality, integrity and availability of the data.
In addition to the Controller, in some cases the data may be accessed by parties involved in the company organisation (administrative, technical, commercial staff) or external parties (third-party technical service providers, postal couriers, hosting providers, IT companies) appointed, where necessary, as Data Processors pursuant to art. 28 of the GDPR.
5. Data retention
Personal data is kept for the time strictly necessary to achieve the purposes for which it was collected:
- Contractual data: for the entire duration of the contractual relationship and for the following 10 years (tax and accounting obligations under art. 2220 of the Italian Civil Code)
- Data from contact forms: for the time needed to handle the request and in any case no longer than 24 months from the last interaction
- Browsing data and cookies: according to the timeframes indicated in the Cookie Policy
- Data for direct marketing: until consent is withdrawn, and in any case no longer than 24 months from the last interaction
At the end of the retention period, the data is irreversibly deleted or made anonymous.
6. Disclosure and transfer of data
Personal data may be disclosed to:
- Hosting and infrastructure service providers (OVHcloud, Hetzner, Nehos) with servers located in the European Union
- Email and communication service providers
- Consultants and professionals for tax and legal obligations
- Technology service providers for the mobile application (voice processing, virtual assistant, push notifications, payment collection), listed in § 8.2, some of which located outside the European Union
- Competent authorities, in the cases provided by law
Data is not sold to third parties. Any transfers to non-EU countries take place exclusively on the basis of adequate safeguards (European Commission adequacy decisions, Standard Contractual Clauses).
7. Third-party services
The site uses the following third-party services that may collect personal data:
Google Tag Manager (GTM-NSFGQ8V) / Google tag (GT-M3K6ZQ7L)
Tag management and tracking services provided by Google LLC. Google Tag Manager coordinates the loading of analytics and marketing scripts; the Google tag collects browsing and conversion data. Google Privacy Policy.
Formspree
Contact form management service. The data sent via the forms is processed by the servers of Formspree Inc. Formspree Privacy Policy.
WhatsApp Business
Messaging service provided by Meta Platforms Inc. Conversations started via the WhatsApp button are managed according to the WhatsApp Privacy Policy.
G Tech Group Chat
Live chat service for real-time customer support, provided by G Tech Group via the chat.gtechgroup.it platform. It collects session data and the content of conversations for support purposes. The data is processed on European servers.
Google Fonts
The fonts used on the site are served locally (self-hosted) and do not make calls to Google servers during browsing.
8. «Customer Area» mobile app
This section describes the processing carried out via the G Tech Group — Customer Area application, available for Android devices. The app is reserved for customers and requires login with credentials.
8.1 Data collected via the app
Registration and login data
Company name, first name, surname, email address and password. Optional: VAT number and phone number. The device platform (Android or iOS) is also recorded.
Content the user chooses to send
- Text of support tickets and their replies
- Photographs attached to tickets, taken with the camera or chosen from the gallery. Access to the camera and gallery is requested only at the time of use and can be denied without preventing use of the app
- Voice notes recorded via the microphone, used to open a ticket by dictating its content
- Messages exchanged with the «Peter AI» virtual assistant
Technical data
- Device identifier for notifications (Firebase Cloud Messaging token), necessary to deliver push notifications
- IP address, device type and application used, recorded for each operation for security purposes and to reconstruct any disputes
Payment data
Card details do not pass through or get stored on our systems: they are entered directly in the secure interface provided by Stripe. We keep only the payment outcome and the invoice reference.
Biometric data
If the user enables fingerprint or face-recognition unlock, verification takes place entirely on the device via the operating system's functions. No biometric data is transmitted or stored by us: we receive only the outcome (successful or unsuccessful).
8.2 Processing involving external providers
| Purpose | Provider | Where | What it receives |
|---|---|---|---|
| Transcription of voice notes | OpenAI Ireland Ltd / OpenAI OpCo, LLC | United States | The audio file recorded by the user |
| «Peter AI» virtual assistant | OVHcloud (AI Endpoints) | European Union | The text of the messages exchanged with the assistant |
| Delivery of push notifications | Google Ireland Ltd (Firebase) | European Union / United States | The device identifier and notification text |
| Payment collection | Stripe Payments Europe Ltd | European Union | Card details, amount, invoice reference |
The transfer to the United States for the transcription of voice notes takes place on the basis of the Standard Contractual Clauses (SCC) adopted by the European Commission (decision of 4 June 2021) and incorporated into OpenAI's Data Processing Addendum (contracting entity for the European Economic Area: OpenAI Ireland Ltd), which ensure adequate safeguards pursuant to Chapter V of the GDPR. The user can at any time avoid this processing by not using the voice-note function and writing the ticket in text form.
8.3 Retention
- Tickets, attachments and voice notes: kept together with the support history, for the duration of the contractual relationship and subsequently for the time needed for legal defence
- Conversations with the virtual assistant: automatically deleted after 24 months
- Access log (IP, device): automatically deleted after 12 months
- Login sessions: session credentials automatically expire after 90 days of inactivity
- Invoices and accounting documents: 10 years, by legal obligation
8.4 Account deletion
The user can delete their account:
- from the app, in Settings → Delete account: deletion is immediate
- from the web, without installing the app, at crm.gtechgroup.it/elimina-account: the request is handled within 30 days
The following are deleted: contact registry data, sessions, devices registered for notifications, notifications and conversations with the virtual assistant.
The following are retained, by legal obligation or for legal defence: invoices and accounting documents, and support tickets with their attachments.
8.5 No advertising tracking
The app does not contain statistical analysis, profiling, advertising or attribution tools. The device's advertising identifier is not collected and no cookies are used.
9. Rights of the data subject
Pursuant to arts. 15-22 of the GDPR, the data subject has the right to:
Access
Obtain confirmation of processing and a copy of the personal data
Rectification
Request the correction of inaccurate data or the completion of incomplete data
Erasure
Request the deletion of data (right to be forgotten)
Restriction
Request the restriction of processing in certain cases
Portability
Receive the data in a structured format and transmit it to another controller
Objection
Object to processing for legitimate reasons, including direct marketing
Withdrawal of consent
Withdraw consent at any time without affecting the lawfulness of prior processing
Complaint
Lodge a complaint with the Data Protection Authority (www.garanteprivacy.it)
To exercise their rights, contact the Controller at the email address info@gtechgroup.it or at the certified email (PEC) gtechgroup@pec.it.
11. Changes to this notice
The Controller reserves the right to make changes to this notice at any time, giving notice to users on this page and, where possible, through the Controller's contact channels. Please consult this page regularly to check for any updates.
Should the changes concern processing whose legal basis is consent, the Controller will collect the data subject's consent again, where necessary.
12. Contacts
For any questions regarding this notice or the processing of personal data, you can contact the Controller:
Email: info@gtechgroup.it
PEC: gtechgroup@pec.it
Phone: +39 0465 846 245
Address: Via di Gagia, 22, 38086 Giustino (TN)