Privacy notice

Privacy notice

Last updated:

1. Data controller

The controller of the personal data collected through this site is:

  • Company name: CYBERMAGISTER S.R.L.
  • Registered office: Via Salvador Allende Gossens 12, 80053 Castellammare di Stabia (NA), Italy
  • Tax code / VAT number: 10874081218
  • Company register (REA): NA-1138351
  • Certified email (PEC): [email protected]
  • Email: [email protected]
  • Legal representative: Giuseppe Longobardi

2. Data Protection Officer (DPO)

The designated Data Protection Officer is Giuseppe Longobardi, who can be reached at [email protected].

Data subjects may contact the DPO about anything concerning the processing of their personal data and the exercise of their rights under the GDPR.

3. Categories of personal data processed

3.1 Data provided through the site's forms

The contact, course information, session enrolment, custom training, demo and consulting request forms collect:

  • Identification and contact data: first name, last name, email address and, where given, phone, company and role.
  • Content of the request: the message written and the course, date or service it refers to.
  • Context data: the page the request started from and the browsing language.
  • Consents: date and time this notice was acknowledged and, where given, consent to commercial communications.

3.2 Data of the staff administering the site

Staff access the administration console with their CyberMagister account: the site processes name, email address, console role and the technical information needed to keep the session open.

3.3 Technical data collected automatically

  • The connection IP address, used to limit automated form submissions and not stored with the request.
  • Browser and page interaction information processed by Google reCAPTCHA (see section 6).
  • Technical cookies (see section 9).
  • Technical server logs, for security and operation.

4. Purposes and legal basis of processing

  • Replying to requests: answering requests sent through the forms and following up on the enrolment, offer or consulting requested. Legal basis: pre-contractual steps or performance of a contract (Art. 6(1)(b) GDPR).
  • Legal and tax obligations: keeping the documentation required by tax, accounting and regulatory obligations. Legal basis: legal obligation (Art. 6(1)(c)).
  • Site security: protecting the forms from automated submissions and abuse, preventing unauthorised access to the console, keeping security logs. Legal basis: the controller's legitimate interest (Art. 6(1)(f)).
  • Commercial communications: sending information about courses, services and initiatives, only to those who consented. Legal basis: consent (Art. 6(1)(a)), separate from the request, optional and revocable at any time without affecting what was requested.

5. How data is processed

Personal data is processed electronically, with the technical and organisational security measures required by Arts. 25 and 32 GDPR. The main measures in place:

  • encrypted HTTPS connection with a TLS certificate across the whole site;
  • access to the administration console only with a CyberMagister account, with distinct roles and least privilege;
  • console session cookies with the Secure, HttpOnly and SameSite attributes;
  • limits on submissions per IP address and protection of the forms from automated submissions;
  • server-side validation of all data received;
  • secure file uploads, checking the actual content and using random, unguessable names.

6. Recipients of the data

Personal data may be disclosed to the following categories of recipients:

  • Authorised staff of CYBERMAGISTER S.R.L., limited to the data their duties require.
  • Technical service providers hosting the site and handling email, appointed as processors under Art. 28 GDPR.
  • Google Ireland Limited, for the reCAPTCHA service protecting the forms from automated submissions. The service may involve a transfer of data to Google LLC in the United States, which participates in the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
  • Competent authorities — judicial, tax or administrative — where the law requires it.

Personal data is not published or passed to third parties for their own purposes. Where a provider operates outside the European Economic Area, the transfer relies on the safeguards set out in Chapter V of the GDPR.

7. Retention period

Data is kept only for as long as the purposes it was collected for require, in line with the storage limitation principle (Art. 5(1)(e) GDPR):

  • Requests not followed by a business relationship: 24 months from the last contact.
  • Data of a contractual relationship (enrolments, accepted offers): the length of the relationship plus 10 years, under the record-keeping obligations of Art. 2220 of the Italian Civil Code.
  • Consent to commercial communications: until withdrawn.
  • Technical and security logs: up to 12 months.

8. Rights of the data subject

Data subjects may exercise at any time the rights set out in Arts. 15-22 GDPR:

  • Access (Art. 15): to obtain confirmation as to whether their data is being processed and, if so, access to the data and to the information required.
  • Rectification (Art. 16): to have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17): to have their data erased where the conditions apply.
  • Restriction (Art. 18): to obtain restriction of processing where the conditions apply.
  • Portability (Art. 20): to receive the data they provided in a structured, commonly used and machine-readable format.
  • Objection (Art. 21): to object at any time to processing based on the controller's legitimate interest.
  • Withdrawal of consent (Art. 7): to withdraw at any time the consent given, without affecting the lawfulness of processing carried out before the withdrawal.
  • Complaint (Art. 77): to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

To exercise these rights, write to [email protected] or by certified email (PEC) to [email protected]. The controller replies within 30 days of receiving the request.

9. Cookies

The site uses only the technical cookies needed for it to work — the language preference and, for staff only, the console session — plus the cookies of the reCAPTCHA service protecting the forms. It uses no profiling cookies and no third-party analytics. Details are on the cookies page.

10. Providing the data

Providing the data marked as required in the forms is necessary to answer the request: without it, the request cannot be followed up. Providing other data and consenting to commercial communications are optional.

11. Changes to this notice

The controller may change or update this notice. Changes are published on this page, with the date of the latest revision, and communicated to data subjects where necessary.

12. Governing law and jurisdiction

This notice is governed by Italian law and by Regulation (EU) 2016/679 (GDPR). Any dispute concerning its interpretation or performance falls under the jurisdiction of the Court of Naples, save where the law sets a different court to protect the data subject.

The data controller — CYBERMAGISTER S.R.L., Sole Director Giuseppe Longobardi.