This notice is provided under Articles 12 and 13 of Regulation (EU) 2016/679 (“GDPR”) and describes processing carried out through this website.
1. Data controller
The data controller is KAYRO DIGITAL STUDIO SOCIETA' A RESPONSABILITA' LIMITATA SEMPLIFICATA (“Kayro”, “we”, “us”), whose registered office is listed in the Legal notice.
For questions about personal-data processing or to exercise your rights, use the privacy contact below or our Contact page.
- Legal name
- KAYRO DIGITAL STUDIO SOCIETA' A RESPONSABILITA' LIMITATA SEMPLIFICATA
- Registered office
- Piazzale dello Sport 8, 56122 Pisa (PI), Italia
- VAT number
- 02587120508
2. Data we process
We process only data that is adequate and relevant to the stated purposes.
Name, email, telephone, company, language and the message submitted through our contact form.
Protected credentials, customer references, orders, project status, documents and communications when you use the client area.
Amount, currency, status and transaction identifiers. Full card details are handled by the payment provider and are not stored by Kayro.
IP address, date and time, requested URL, browser, device, security logs and technical cookies required for operation.
3. Purposes, legal bases and retention
Actual retention may be extended where necessary to comply with law, handle disputes or establish, exercise or defend legal claims. At the end of the applicable period, data is deleted or anonymised.
| Purpose | Legal basis | Retention |
|---|---|---|
| Respond to enquiries and prepare quotations | Pre-contractual steps and legitimate interest in managing communications | Up to 24 months after the last contact unless the relationship develops |
| Deliver projects, orders and support | Performance of a contract | For the relationship and then for applicable limitation periods |
| Invoicing, accounting and compliance | Legal obligation | Normally 10 years or another period required by law |
| Accounts, authentication and security | Contract and legitimate security interests | For the account lifetime; technical logs normally up to 90 days unless an incident occurs |
| Manage and verify payments | Contract and legal obligations | Metadata for applicable contractual, accounting and dispute periods |
| Defend rights and prevent misuse | Legitimate interests and legal claims | For as long as needed for the review or dispute |
4. Whether data is required
Fields marked as required are necessary to answer your request or provide the service. Without them, we may be unable to handle your enquiry, create an account or perform the agreement. Any optional purpose will be presented separately.
5. Recipients and processors
Data may be handled by authorised staff and providers supporting hosting, infrastructure, email, support, security, accounting and payments. Where they act for us, providers are appointed as processors under Article 28 GDPR.
We use Mollie for online payments. Mollie also processes some data under its own roles and privacy terms. Data may also be disclosed to authorities or professional advisers where required by law or necessary to protect a right.
6. Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. We then rely on an adequacy decision or safeguards under Articles 44–49 GDPR, such as Standard Contractual Clauses, together with supplementary measures where needed. You may ask us about the applicable safeguards.
7. Your rights
Where applicable, you may request access, correction, deletion, restriction, portability and object to processing. You may withdraw consent at any time without affecting processing carried out lawfully before withdrawal.
We normally respond within one month, subject to a reasoned extension for complex requests. We may first ask for information needed to verify your identity.
8. Complaints to a supervisory authority
If you believe processing infringes data-protection law, you may complain to the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, or to the supervisory authority where you live or work in the EU. We nevertheless invite you to contact us first so we can review your concern.
9. Security, children and automated decisions
We apply technical and organisational safeguards proportionate to risk, including access protection, role separation, backups, updates and monitoring. No system can, however, be entirely risk-free.
The website and our B2B services are not aimed at children. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for website users.
10. Changes to this notice
We may update this notice to reflect legal, organisational or technical changes. The current version and update date will remain available here; where appropriate, we will provide an additional notice for material changes.
This text is structured around the GDPR, the Italian Privacy Code and guidance from the Italian Data Protection Authority. It is not a substitute for legal advice.
Use our contact form. For data-protection requests, write “Privacy” in the subject of your message.