This information governs the handling of personal data through the utilization of the website accessible at https://digitalecho.app (hereinafter referred to as the “Website”), managed by Digital Echo srl, in adherence to prevailing data protection regulations, notably the EU Regulation 2016/679, commonly known as the “GDPR”.
Data Controller
Digital Echo srl, registered with the Chamber of Commerce of Milan Monza Brianza Lodi (Italy) under number REA: MI-2734696, whose head office is located in Viale Premuda, 46 – 20129 Milan (MI) – Italy, e-mail: echo@digitalecho.app, registered e-mail (PEC): digital-echo@pec.it.
The Data Controller has not appointed a Data Protection Officer as the legal requirements are not met.
Purposes of the processing, Legal basis, Retention periods and Optional or mandatory nature of data provision
The personal data we collect through user registration on the Website, online purchases, or any service or information request, are used to effectively manage our business relationship with the user/customer and ensure optimal service management. The personal data we collect and process serves various purposes:
| Purposes of the processing | Legal Basis | Retention periods | Nature of data provision |
| A) Execution of the contract established with customers (e.g. provision of our services, establishment of a customer database, maintenance of customer relationships, handling of unpaid invoices and potential service-related disputes). | Article 6(1)(b) of the GDPR. | 10 years from the termination of the contractual relationship. | Mandatory in order to conclude the contract. Failure to comply will result in the inability to enter into the contract with Digital Echo Srl. |
| B) Sending newsletters and promotional messages to users, where they have given their consent. | Article 6(1)(a) of the GDPR. | 1 year from the withdrawal of consent by the user. | Optional. Without the user’s consent, no newsletter or promotional messages will be sent. |
| C) Legitimate interest of the Data Controller in advancing and promoting its business, (e.g. addressing information requests from prospective customers, sending newsletters and promotional messages to customers, compiling anonymous statistical data for internal use, excluding profiling, unless customers has given their consent, enhancing the quality of the services of Data Controller). | Article 6(1)(f) of the GDPR. | 3 years from the withdrawal of consent by the user. | Not applicable. |
| D) Adherence to any legal and regulatory obligations to which the Data Controller may be subject. | Article 6(1)(c) of the GDPR. | Throughout the legal limitation period. | Not applicable. |
We commit to refrain from selling or transferring your personal data to third parties for purposes other than those explicitly mentioned above, unless we inform you and/or seek your consent.
Types of Personal Data
Personal data pertains to information that can be utilized to identify an individual. We collect data falling into the following categories:
- Identification data, e.g. first name, last name, email address, phone number, ID card or passport number, when necessary;
- Technical data, e.g. IP address, logs;
- Data from recorded telephone calls, e.g., call dates and content.
Data Recipients
The recipients of the data include:
- Our company’s staff;
- Our Data Processors: Website hosting provider, CRM tool provider, secure payment service provider, newsletter/emailing service provider, telephony company and services provider;
- Organizations responsible for financial control (particularly external auditors), public service organizations (to fulfil legal obligations), court officials, ministerial officers, and entities involved in debt collection.
Principles of processing and Protection measures
The processing of personal data will take place in compliance with the GDPR, as well as the principles of lawfulness, fairness, and transparency, adequacy and relevance, using both paper-based and electronic methods, carried out by individuals authorized by the Data Controller and with the adoption of appropriate protective measures in order to ensure the security and confidentiality of the data.
No automated decision-making will be carried out.
Potential Transfer of Data Outside the EU
Your data is stored on servers operated by SiteGround Hosting Ltd, situated in Eemshaven (NL), and/or on servers owned by Google, located within the European Union.
In the course of our interactions with Data Processors and the utilization of tools, data may be transferred outside the European Union. These transfers are safeguarded due to the fact that the data is always transferred to a Country recognized by the European Commission as providing an adequate level of protection.
Alternatively, we enter into specific contracts with our Data Processors, addressing the transfer of your data outside the European Union. These contracts adhere to the standard contractual clauses approved by the European Commission, governing relationships between a Data Controller and a Data Processor.
Your Rights
You own the following rights concerning your personal data:
- Right to information: This document is designed to provide you with the necessary information;
- Right of access: You can access all your personal data at any time through your account;
- Right to rectification: Rectify any inaccurate, incomplete, or outdated personal data at your discretion, either through your account or, for specific information, by contacting our customer support at the provided address;
- Right to restrict processing: Exercise the right to restrict the processing of your personal data in cases defined by Article 18 of the GDPR;
- Right to erasure: Request the deletion of your personal data and prevent any future collection;
- Right to file a complaint with a relevant supervisory body, if you believe that the processing of your personal data violates applicable regulations;
- Right to define guidelines regarding the storage, deletion, and fate of your personal data after your death;
- Right to data portability: Receive your provided personal data in a standard machine-readable format and request its transfer to a chosen recipient;
- Right to object to processing: Object to the processing of your personal data, including the recording of telephone calls, as informed at the beginning of the call. Note that we may continue processing your data for legitimate reasons or to defend legal rights despite your objection.
Exercise of Rights
Requests to exercise the rights outlined in this information notice should be directed to the Data Controller at the email address data@digitalecho.app. Alternatively, you can assert your rights by sending a communication through a letter with a return receipt to Digital Echo srl – Privacy Office – Viale Premuda, 46 – 20129 Milan (MI) – Italy.
In some cases, we may request additional information or documents to verify your identity.
Modifications
We reserve the right to make changes to this policy at any time. The updated version will become effective on the date of implementation. It is advisable to regularly review the latest version of this page.
Last updated: 06.09.2024