We do not transfer personal data to third parties for commercial purposes.
Promotional communications require a separate and revocable choice.
Preferences, watchlists and subscriptions can be modified or deleted.
1. Data controller
The data controller is EudorIA, based in Italy, reachable at info@eudoria.it. For privacy questions or to exercise your rights you can write to the same address.
2. What data we process
- Contact requests: name, company, business email, optional phone number, area of interest and message.
- Account and security: email, name, company, protected credentials, MFA, sessions, access logs and relevant operations.
- Cyber Intelligence: newsletter preferences, watchlist, suppliers and domains entered, public DNS checks and support requests.
- Network Risk Assessment: analysis parameters and encrypted technical results. The original configuration file is not retained.
- Applications: personal and professional data, curriculum, contact details, professional profile and information provided voluntarily.
- Technical data: IP address, user agent, date and time, request identifiers and security events needed to protect the services.
We do not request special categories of personal data in the public forms. Please avoid entering them in the free-text fields, unless they are strictly necessary and requested by EudorIA.
3. Why we process it
We do not make decisions producing legal effects based solely on automated processing, and we do not sell personal data.
4. For how long
- commercial requests not turned into a relationship: up to 24 months from the last useful contact;
- contractual, administrative and tax data: for the period required by law, normally 10 years;
- accounts, preferences and data entered in the portal: for the duration of the service and up to 90 days from technical closure, save for obligations or disputes;
- application and security logs: normally 12 months, extendable if needed to investigate an incident;
- applications: up to 24 months, save for a deletion request or the start of a relationship;
- marketing: until revocation and in any case subject to periodic review.
5. Who may receive the data
The data is accessed only by authorised EudorIA personnel and by suppliers necessary for hosting, connectivity, mail, maintenance or support, appointed as processors where required. The data may be disclosed to authorities or advisers when required by law or necessary to protect a right.
We favour processing within the European Economic Area. Any transfers to third countries take place only where there is a legal basis and safeguards recognised by the GDPR.
6. Your choices and your rights
You may request access, rectification, erasure, restriction, portability and objection, or revoke a consent without affecting prior processing. Write to info@eudoria.it; we will respond within the timeframes set by the GDPR.
You may also lodge a complaint with the Italian Data Protection Authority.
7. Security and updates
We adopt service segregation, access control, MFA where provided, encryption, centralised logging, application protections and incident management procedures. The details that can be published are described on the Security and reliability page.
We will update this notice when services or processing change, indicating version and date.