Regulation (EU) 2016/679 (GDPR)

Privacy & Data Protection

Transparency above all. How WARE SRL collects, safeguards, and utilizes personal data, including the responsible deployment of AI and automated security systems.

GDPR Compliance Policy — WARE SRL
Data Controller: WARE SRL privacy@ware.ly

The purpose of this privacy statement is to provide maximum transparency regarding personal information collected and the purposes and modalities of its processing. In strict compliance with the obligations arising from the General Data Protection Regulation (EU Regulation 2016/679 - GDPR) and applicable national privacy legislation, WARE SRL respects and protects the confidentiality of visitors, registered users, and enterprise clients (collectively, "Data Subjects").

1. Data Controller

Company Name: WARE SRL

Registered Office: Via Provinciale, 82 – 24021 Albino (BG), Italy

VAT ID & Tax Code: IT04876650161

Certified Email (PEC): wareint@pec.it

Dedicated Privacy Contact: privacy@ware.ly / privacy@dmware.com

2. Categories of Data Collected

A. Data Collected Automatically (System & Security Logs)

During user navigation, our web servers and edge infrastructure automatically log technical connection parameters:

  • Internet Protocol (IP) address and approximate geographical country origin;
  • Browser type, engine version, and operating system parameters;
  • Internet Service Provider (ISP) and referral URL / exit points;
  • Timestamp of requests and accessed endpoint resources.

This data is processed exclusively in aggregated, anonymized form for infrastructure telemetry, DDoS defense, bot protection, and network safety.

B. Data Provided Voluntarily by the User

When ordering services, creating a client account, or submitting support tickets:

  • Contact & Identity Details: First name, last name, email address, telephone number, billing address;
  • Corporate & Tax Information: Company name, VAT number, Tax/Fiscal Code, SDI Recipient Code;
  • Domain Registrant Data: Technical registrant attributes submitted to national/international Registries (e.g. NIC.it / ICANN);
  • Payment Identifiers: Transaction tokens, proforma IDs, and gateway settlement verification references (credit card data is handled directly by PCI-DSS compliant processors).

3. Processing Modalities & Datacenter Infrastructure

Personal data is processed electronically using strict encryption algorithms, in full accordance with principles of lawfulness, fairness, transparency, data minimization, and accuracy (Art. 5 GDPR).

All primary web hosting and cloud storage services are hosted within European Economic Area (EEA) Tier-IV datacenters operating under strict Data Processing Agreements (DPA) and ISO 27001 certifications. Data transfers outside the EEA only occur under standard contractual clauses (SCC) approved by the European Commission.

4. Purposes of Processing & Legal Bases

1. Contract Execution (Art. 6.1.b GDPR): Provisioning hosting plans, cloud servers, business email inboxes, certified PEC mailboxes, domain registration with competent Registries, and customer support.

2. Legal & Tax Obligations (Art. 6.1.c GDPR): Issuance of electronic invoices, tax auditing, compliance with Italian electronic invoicing (SDI), and anti-fraud regulations.

3. Legitimate Interest (Art. 6.1.f GDPR): Server infrastructure protection, firewall intrusion detection, malware prevention (CageFS / Imunify), and automated rate limiting.

5. Artificial Intelligence & Automated Systems

WARE SRL utilizes automated intelligence algorithms exclusively for operational telemetry, DDoS traffic mitigation, spam filtering, and internal ticket classification.

No External Model Training: Client personal data and hosted files are never utilized to train external public artificial intelligence models without explicit, unambiguous consent. No automated decision-making producing legal effects (Art. 22 GDPR) is conducted without human engineer oversight.

6. Your Rights under GDPR (Articles 15–22)

As a Data Subject, you hold enforceable statutory rights regarding your personal information:

Right of Access (Art. 15) Obtain confirmation whether your data is being processed and receive a full copy.
Right to Rectification (Art. 16) Request the immediate correction of inaccurate or incomplete information.
Right to Erasure / Forgotten (Art. 17) Request deletion of data when it is no longer required for legal or fiscal retention.
Right to Restriction (Art. 18) Request temporary restriction of processing in contested circumstances.
Right to Portability (Art. 20) Receive your data in a structured, commonly used machine-readable format.
Right to Object (Art. 21) Object at any time to processing based on legitimate interest or direct communications.

To exercise any of these rights, contact our Privacy Officer directly at privacy@ware.ly or privacy@dmware.com. You also hold the right to lodge a complaint with the competent supervisory authority (Garante per la Protezione dei Dati Personaliwww.garanteprivacy.it).

7. Cookie Policy & Data Retention

Our website utilizes technical cookies essential for session maintenance, security tokens, and customer cart processing. Analytical telemetry is collected in anonymized form without individual user profiling.

Personal data linked to billing and tax invoices is retained for 10 years in compliance with statutory Italian fiscal laws (Art. 2220 Italian Civil Code). Technical server access logs are purged on automated rolling 30-day cycles.

For any inquiries regarding data protection policies, contact: privacy@ware.ly.

WARE SRL — Via Provinciale, 82 – 24021 Albino (BG), Italy — VAT ID / Tax Code: IT04876650161 — PEC: wareint@pec.it

Italian customers: visit dmware.it/privacy for the Italian language privacy portal.