Privacy Policy
Last updated: 7 September 2026
This Privacy Policy describes how personal data relating to users who visit www.xmetrix.it (the “Website”) are processed, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection legislation.
1. Data Controller
The Data Controller is:
XMETRIX s.r.l.
Via Ventiquattro Maggio 21
53100 Siena (SI), Italy
VAT No. and Tax Code: 01587980523
Email: info@xmetrix.it
Requests concerning the protection of personal data or the exercise of rights under the GDPR may be sent to the email address indicated above.
2. Categories of Personal Data Processed
The following categories of personal data may be processed through the Website.
Browsing Data
The IT systems and services used to operate the Website may automatically collect certain information relating to browsing activities, including, for example:
IP address;
browser and device type;
operating system;
date and time of access;
pages visited;
technical information required for the proper operation and security of the Website.
Such information is normally collected through Internet protocols, technical logs, cookies or similar technologies.
Data Voluntarily Provided by Users
When users voluntarily send communications to the email addresses indicated on the Website, XMETRIX may process the information provided by the user, including their email address, first and last name, organisation, and any additional information contained in the message or attachments.
The XMETRIX corporate Website does not require users to provide health-related information. Users are therefore requested not to send health data or other special categories of personal data through the general contact details available on the Website unless strictly necessary.
3. Purposes and Legal Bases for Processing
Personal data may be processed for the following purposes.
a) Operation and Security of the Website
Technical browsing data may be processed in order to:
ensure the proper display and operation of the Website;
protect the security of systems and services;
prevent abuse, anomalies or unauthorised access;
perform technical maintenance and diagnostic activities.
Legal basis: the legitimate interests of the Data Controller pursuant to Article 6(1)(f) GDPR.
b) Handling Contact Requests
Personal data voluntarily provided by users may be processed in order to respond to requests for information, cooperation proposals, business enquiries or other communications.
Legal basis: taking steps at the request of the data subject prior to entering into a contract pursuant to Article 6(1)(b) GDPR, where applicable, or the legitimate interest of the Data Controller in managing its correspondence and professional relationships pursuant to Article 6(1)(f) GDPR.
c) Compliance with Legal Obligations
Personal data may be processed where necessary to comply with legal obligations or requests from competent authorities.
Legal basis: Article 6(1)(c) GDPR.
d) Analytics, Marketing and Profiling
Should the Website in the future use cookies or other tracking technologies that are not strictly necessary, including for non-anonymised analytics, marketing or profiling purposes, such technologies will only be used in accordance with applicable legislation and, where required, after obtaining the user's consent.
Legal basis: the data subject's consent pursuant to Article 6(1)(a) GDPR and applicable legislation concerning cookies and other tracking technologies.
4. Provision of Personal Data
Providing personal data by contacting XMETRIX is voluntary.
However, failure to provide the information necessary to process a request may make it impossible for XMETRIX to provide an appropriate response.
Technical data strictly necessary for browsing are processed automatically as part of the normal operation of the IT systems used to provide the Website.
5. Processing Methods and Security
Personal data are processed using electronic and digital systems in accordance with the principles of lawfulness, fairness, transparency, data minimisation and storage limitation.
XMETRIX implements appropriate technical and organisational measures, taking into account the level of risk, in order to protect personal data against unauthorised access, loss, destruction, alteration or unlawful disclosure.
6. Recipients of Personal Data
Personal data may be processed, to the extent necessary for the purposes described above, by:
authorised XMETRIX personnel and collaborators;
IT, hosting, cloud and email service providers;
consultants and professional advisers assisting XMETRIX;
public authorities or other entities where disclosure is required by law.
The Website is currently built and hosted using Google Sites. As part of the provision of the platform and related technical services, Google may process technical information relating to the use of the Website in accordance with its applicable contractual terms and privacy policies.
Where required, third parties processing personal data on behalf of XMETRIX are appointed as Data Processors pursuant to Article 28 GDPR.
7. Transfers of Personal Data Outside the European Economic Area
The use of certain technology providers may involve the processing of, or access to, personal data from countries outside the European Economic Area (“EEA”).
Where applicable, such transfers are carried out in accordance with Articles 44 et seq. GDPR, on the basis of an adequacy decision adopted by the European Commission or through other appropriate safeguards provided for under applicable legislation, including Standard Contractual Clauses.
8. Data Retention
Personal data are retained only for as long as necessary to fulfil the purposes for which they were collected.
In particular:
personal data relating to contact requests that do not result in a contractual relationship are generally retained for no longer than 24 months from the last communication, unless a longer retention period is necessary;
where a request results in a contractual or professional relationship, personal data may be retained for the periods required under applicable administrative, tax and civil-law obligations;
technical and security-related data are retained for the period necessary to operate and protect the Website, also taking into account the retention periods applied by the relevant technology service providers.
Personal data may be retained for longer periods where necessary to establish, exercise or defend legal claims.
9. Cookies and Other Tracking Technologies
The Website may use technical cookies or other technologies that are strictly necessary for its operation.
Any use of non-essential cookies or tracking technologies, including analytics, profiling or third-party services involving tracking activities, will be carried out in accordance with applicable legislation and, where required, only after obtaining the user's consent.
Where such technologies are used, XMETRIX will make available a specific Cookie Policy containing information on their purposes, duration and the parties involved, as well as appropriate tools enabling users to manage or withdraw their preferences.
10. Links to Third-Party Websites and Services
The Website may contain links to third-party websites, applications or services, including websites relating to XMETRIX products and solutions.
The processing of personal data carried out through such third-party websites or services is governed by their respective privacy policies. XMETRIX therefore recommends that users review the relevant privacy policies before using such services.
11. Data Subject Rights
Under the conditions provided for by the GDPR, data subjects may exercise the rights set out in Articles 15 to 22 GDPR and, in particular, may request:
access to their personal data;
rectification of inaccurate personal data;
erasure of personal data;
restriction of processing;
data portability, where applicable;
objection to processing based on legitimate interests;
withdrawal of previously given consent, without affecting the lawfulness of processing carried out before such withdrawal.
Requests may be submitted to info@xmetrix.it.
Data subjects also have the right to lodge a complaint with the competent supervisory authority. In Italy, the competent authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority), if they believe that the processing of their personal data infringes applicable data protection legislation.
12. Changes to this Privacy Policy
XMETRIX may update this Privacy Policy from time to time, including as a result of changes in applicable legislation, organisational arrangements or technologies used.
The latest version will be published on the Website together with the date of the most recent update.