Privacy Policy

PRIVACY POLICY

Last updated: June 2026

PIONIRS S.r.l. — https://www.pionirs.com
Pursuant to EU Regulation 2016/679 (GDPR) and D.Lgs. 196/2003 as amended by D.Lgs. 101/2018

================================================================================

1. DATA CONTROLLER

The Data Controller is PIONIRS S.r.l., with registered office at Via Timavo 24, Milano (Italy).

For any privacy-related matter, including the exercise of your rights under this Policy, you may contact us at:

Email: privacy@pionirs.com
Website: https://www.pionirs.com

No Data Protection Officer (DPO) has been appointed, as the processing activities carried out by PIONIRS S.r.l. do not fall within the cases where such appointment is mandatory under Art. 37 GDPR.

================================================================================

2. GENERAL PRINCIPLES

All personal data processing is carried out in full compliance with EU Regulation 2016/679 (GDPR) and applicable Italian legislation (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018), in accordance with the following principles:

– Lawfulness, fairness, and transparency
– Purpose limitation: data are collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes
– Data minimisation: only data that are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
– Accuracy and, where necessary, kept up to date
– Storage limitation: data are kept in a form that permits identification of data subjects for no longer than is necessary for the stated purposes
– Integrity and confidentiality: appropriate technical and organisational security measures are applied at all times
– Accountability: the Data Controller is responsible for, and able to demonstrate, compliance with all of the above

================================================================================

3. LEGAL BASES FOR PROCESSING

Depending on the specific processing activity, the applicable legal bases under Art. 6 GDPR are:

– Art. 6(1)(a) — Consent: for processing of contact form enquiry data (email address and optional name), and for voluntary newsletter subscriptions via the dedicated website form.
– Art. 6(1)(b) — Performance of a contract or pre-contractual measures: for managing authentication credentials and providing access to the reserved area.
– Art. 6(1)(c) — Legal obligation: where data retention is required by applicable law (e.g. for administrative, fiscal or security purposes).
– Art. 6(1)(f) — Legitimate interest: for bot and spam prevention via Cloudflare Turnstile (processing of IP address and browser user-agent), for access logging in the reserved area, for activity logging in the reserved area (recording of user actions such as file downloads, uploads, and feature usage for diagnostic and statistical purposes), for anonymous website analytics via WP Statistics, and for sending commercial newsletter communications to existing customers (soft opt-in), where such interests are not overridden by the data subjects’ fundamental rights and freedoms.

================================================================================

4. CATEGORIES OF PERSONAL DATA COLLECTED, PURPOSES AND LEGAL BASES

4.1 CONTACT FORM

When you use the contact form on this website, the following data are processed:

(i) Data provided by the user:
– Email address (mandatory)
– First name and last name (optional, provided voluntarily)
– Message content (the text of your enquiry)
Purpose: exclusively to process and respond to your enquiry. These data are not used for any other purpose, including marketing communications.
Legal basis: Art. 6(1)(a) GDPR — your explicit consent, given via the
mandatory checkbox prior to form submission.

(ii) Data automatically collected by the server:
– IP address and browser user-agent string
Purpose: bot and spam prevention, processed by Cloudflare Turnstile on behalf of PIONIRS S.r.l. (see Section 4.4(b) and Section 6).
Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the Data Controller in protecting the contact form from automated abuse.

Prior to submitting the form, you are required to confirm that you have read this Privacy Policy and consent to the processing of your personal data for the purpose of receiving a response (mandatory checkbox — the form cannot be submitted without this).

If you wish to subscribe to our newsletter, a separate and independent form is available on the website for that purpose (see Section 4.3(a)).

Provision of data — mandatory fields and consequences:
Providing your email address and the text of your message is necessary for us to process and respond to your enquiry. Failure to provide either will make it impossible for us to respond. Providing your first and last name is entirely optional and has no consequence on the processing of your request.

4.2 RESERVED AREA (AUTHENTICATED SECTION)

Access to the reserved area is granted exclusively through credentials (username and password) issued by PIONIRS S.r.l. and associated with the user’s name and email address.

(i) Authentication and account management

Data processed in this context:

  • Name and email address (associated with the user account)
  • Authentication credentials (username, hashed password)
  • Access log entries (timestamp, IP address, session identifier — strictly necessary for security purposes)

Processing purposes:

  • Authentication and session management
  • Security monitoring and access control

Access logs are retained for 360 days, after which they are permanently deleted.

(ii) Activity logging (diagnostics and usage statistics)

In addition to authentication events, the reserved area records certain actions performed by authenticated users for technical diagnostic and statistical purposes. The following event types are logged:

  • Download of files made available by PIONIRS S.r.l. (e.g. manuals, software, updates): file name, username, IP address, timestamp
  • Upload of data files by the user: file extension only (not the file name), username, IP address, timestamp
  • Use of specific interface features: feature identifier, username, IP address, timestamp.

In all cases, the data recorded per event are: username, IP address, timestamp, event name, and event detail as described above. No file content is ever accessed or stored as part of this logging activity.

Processing purposes: technical diagnostics of the platform; anonymous statistical analysis of feature usage to support service improvement. These data are not used for profiling or for any purpose beyond the stated diagnostic and statistical scope.

Activity logs are retained for 360 days, after which they are permanently and automatically deleted.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the Data Controller in maintaining reliable operation of the platform, diagnosing technical issues, and understanding usage patterns, where such interests are not overridden by the data subjects’ fundamental rights and freedoms.

This Privacy Policy is delivered to the user via email together with their temporary credentials at the time of first access activation. By using the reserved area, the user acknowledges having received and read this Policy.

Provision of data: providing name, email address, and credentials is necessary to access and use the reserved area. Failure to provide these data makes it impossible to grant access to the service. Activity logging occurs automatically upon use of the reserved area and cannot be disabled without compromising the diagnostic and security functions of the platform.

4.3 NEWSLETTER

The newsletter service operates through two distinct channels, each with its own
legal basis:

(a) Voluntary subscription via website form
Data collected: email address (mandatory); first name (optional).
Users who wish to subscribe may do so via the dedicated newsletter form on the website. Subscription requires explicit, separate consent (checkbox independent from any other form on the site, and not pre-ticked). A double opt-in mechanism is in place: after submitting the form, the user receives a confirmation email and is only added to the mailing list upon clicking the confirmation link. The timestamp, IP address, and version of the policy accepted at the time of confirmation are logged as proof of consent.

Legal basis: Art. 6(1)(a) GDPR — your explicit consent.

You may withdraw your consent at any time by clicking the unsubscribe link present in every newsletter communication, or by contacting us at privacy@pionirs.com. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

(b) Existing commercial contacts (soft opt-in)
Data used: email address and name, collected in the context of an existing
commercial relationship and subject to the relevant contractual documentation.
Users with whom PIONIRS S.r.l. has an existing commercial relationship may
receive newsletter communications regarding products and services analogous
to those already provided, provided that:
– they were informed of this use at the time their data were collected
(via contractual documentation);
– the communications relate exclusively to PIONIRS S.r.l.’s own products
and services;
– every communication includes a clearly visible and immediately functional
unsubscribe option.
This channel applies to commercial relationships established from June 2026
onwards, following the update of contractual documentation to include the
relevant notice.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining
commercial relations with existing customers.

You may object to this processing at any time, without any formality, by clicking the unsubscribe link in any newsletter communication or by contacting us at privacy@pionirs.com. Upon receipt of your objection, processing for this purpose will cease immediately (Art. 21(3) GDPR).

Every newsletter communication sent by PIONIRS S.r.l. includes:
– Clear identification of the sender (PIONIRS S.r.l., Via Timavo 24, Milano)
– A functional unsubscribe link, effective immediately upon clicking, with no requirement to log in or provide additional data

4.4 COOKIES

This website uses the following categories of cookies:

(a) Strictly necessary cookies
Session cookies required for the technical functioning of the website and the reserved area (e.g. authentication session management). These cookies do not require consent and cannot be disabled without compromising the functionality of the service.

(b) Third-party technical cookies — Cloudflare Turnstile
This website uses Cloudflare Turnstile for bot and spam prevention on the contact form. Turnstile may set strictly necessary technical cookies for its functioning. Cloudflare, Inc. acts as a data processor on behalf of PIONIRS S.r.l. under a Data Processing Agreement. Data processed by Turnstile are not used by Cloudflare for its own commercial purposes. The data processed by Cloudflare as a processor are subject to the retention terms set out in the applicable DPA.
Privacy Policy: https://www.cloudflare.com/privacypolicy/
DPA: https://www.cloudflare.com/cloudflare-customer-dpa/

(c) Third-party technical cookies — CookieYes (Consent Management Platform)
This website uses CookieYes as a Consent Management Platform (CMP) to manage and record cookie consent. CookieYes sets strictly necessary cookies to store and manage your consent preferences. CookieYes / KeySoft Tech Ltd acts as a data processor on behalf of PIONIRS S.r.l. under a Data Processing Agreement. Data are stored on EU-based, GDPR-compliant servers and are subject to the retention terms set out in the applicable DPA.
Privacy Policy: https://www.cookieyes.com/privacy-policy/
DPA: https://www.cookieyes.com/dpa/

Cookie consent is managed via the banner displayed upon your first visit. You may review and change your cookie preferences at any time by accessing the cookie settings panel available on the website. Your consent preferences are valid for one year, after which you will be asked to confirm them again.

4.5 WEBSITE ANALYTICS — WP STATISTICS

This website uses WP Statistics to collect anonymous statistical data about visits (e.g. number of visitors, pages viewed, traffic sources). WP Statistics operates without cookies and without storing any personally identifiable information (PII) in its default configuration:

– No cookies or persistent identifiers are used
– IP addresses are not stored in full (last segment masked)
– Visitor data is isolated to a single day, preventing cross-session tracking
– All analytics data is stored exclusively on PIONIRS S.r.l.’s own servers and is not transmitted to any third party

As no personal data or cookies are involved, this processing does not require user consent.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding website usage for service improvement purposes.

4.6 EMBEDDED CONTENT FROM THIRD PARTIES

Where pages on this site include embedded content from third-party websites (e.g. videos, images, or other media), such content behaves exactly as if you had visited those websites directly. Third-party providers may collect data about you, use cookies, and track your interactions, including if you have an account with them and are logged in. PIONIRS S.r.l. has no control over the data processing carried out by such third-party providers; users are advised to consult the privacy policies of the respective third parties before interacting with embedded content.

4.7 AUTOMATED DECISION-MAKING AND PROFILING

PIONIRS S.r.l. does not carry out any automated decision-making, including profiling, that produces legal effects or similarly significantly affects data subjects, as referred to in Art. 22 GDPR. No personal data collected through this website is used for profiling purposes.

================================================================================

5. DATA STORAGE AND RETENTION

All personal data are processed and stored exclusively on servers located within the European Economic Area (EEA). No transfers of personal data to third countries or international organisations take place.

Data controlled directly by PIONIRS S.r.l. are retained for the following periods:

– Contact form data (email, name, message, metadata): up to 2 years from collection, unless a longer retention period is required by applicable law for administrative, legal or security purposes.
– Access logs (reserved area): 360 days from the date of recording, after which they are permanently and securely deleted.
– Activity logs (reserved area — file downloads, uploads, feature usage): 360 days from the date of recording, after which they are permanently and automatically deleted.
– Authentication credentials: for the duration of the contractual relationship with the user. Upon termination, credentials are promptly deactivated and deleted.
– Newsletter subscriber data — consent-based (voluntary subscribers): until the user withdraws consent or unsubscribes, whichever occurs first. Data are deleted or anonymised without undue delay thereafter.
– Newsletter contact data — soft opt-in (existing commercial contacts): until the user objects to processing or unsubscribes, whichever occurs first. Data are removed from the mailing list without undue delay thereafter.
– Cookie consent records (CookieYes): retained for the period necessary to demonstrate proof of consent in accordance with applicable law.

Data processed by third-party processors (Cloudflare, Inc., CookieYes / KeySoft Tech Ltd, Aruba S.p.A.) are subject to the retention periods established in the respective Data Processing Agreements.

When the applicable retention period expires, data are securely and permanently deleted or irreversibly anonymised.

================================================================================

6. DATA DISCLOSURE AND SHARING

PIONIRS S.r.l. does not sell, rent, or otherwise transfer personal data to third parties. Data may be shared only in the following strictly limited circumstances, with entities acting as data processors under binding Data Processing Agreements:

– Cloudflare, Inc. (Turnstile — bot/spam prevention): processes IP address and browser user-agent data strictly for spam prevention on behalf of PIONIRS S.r.l., acting as data processor. Cloudflare does not use this data for its own commercial purposes.
Privacy Policy: https://www.cloudflare.com/privacypolicy/
DPA: https://www.cloudflare.com/cloudflare-customer-dpa/

– CookieYes / KeySoft Tech Ltd (Consent Management Platform): processes cookie consent records on behalf of PIONIRS S.r.l., acting as data processor. Data stored on EU-based, GDPR-compliant servers.
Privacy Policy: https://www.cookieyes.com/privacy-policy/
DPA: https://www.cookieyes.com/dpa/

– Aruba S.p.A. (newsletter delivery service): manages and delivers newsletter communications on behalf of PIONIRS S.r.l., acting as data processor under a Data Processing Agreement. Servers located within the EEA.
Registered office: Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy.
Privacy Policy: https://www.aruba.it/informativa_sulla_privacy.aspx

– Aruba S.p.A. (web hosting and infrastructure): manages the servers on which this website and its data are hosted, acting as data processor under a Data Processing Agreement. All servers are located within the EEA.
Registered office: Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy.
Privacy Policy: https://www.aruba.it/informativa_sulla_privacy.aspx

– Competent public authorities: data may be disclosed to public authorities or law enforcement where required by applicable law or by a binding legal order.

In no case are personal data used beyond the minimum purpose necessary to provide the requested services.

================================================================================

7. YOUR RIGHTS UNDER GDPR (ARTS. 15-22)

As a data subject under EU Regulation 2016/679, you have the following rights:

– Right of access (Art. 15): obtain confirmation of whether your personal data are being processed and, if so, access a copy of the data together with information on the purposes, categories of data, recipients, retention periods, and other relevant processing information.
– Right to rectification (Art. 16): have inaccurate personal data corrected or incomplete data completed without undue delay.
– Right to erasure (Art. 17): request deletion of your personal data where no legitimate ground for continued processing remains. Note: this right may be limited where processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
– Right to restriction of processing (Art. 18): request that processing be restricted in specific circumstances (e.g. while accuracy is contested or while an objection under Art. 21 is pending).
– Right to data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format and transmit them to another controller. This right applies only to data processed on the basis of consent (Art. 6(1)(a)) or contract (Art. 6(1)(b)), and only where processing is carried out by automated means. It does not apply to data processed on the basis of legitimate interest (Art. 6(1)(f)).
– Right to object (Art. 21): object at any time to processing based on legitimate interest (Art. 6(1)(f)). Where you object to processing for direct marketing purposes (including newsletter soft opt-in), processing for that purpose shall cease immediately upon receipt of your objection, without any need for justification on your part.
– Right to withdraw consent (Art. 7(3)): where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal shall be as easy as giving consent.

To exercise any of the above rights, please contact us at: privacy@pionirs.com

We will respond within 30 days of receipt of your request. Where necessary due to the complexity or number of requests, this period may be extended by a further two months, in which case we will notify you of the extension within the initial 30-day period, stating the reasons for the delay (Art. 12 GDPR).

You may also request an export of the personal data we hold about you, including data you have voluntarily provided. This may not include data we are legally required to retain for administrative, legal or security purposes.

================================================================================

8. RIGHT TO LODGE A COMPLAINT

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent data protection supervisory authority. In Italy, the competent authority is:

Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma (Italy)
https://www.garanteprivacy.it

You also have the right to an effective judicial remedy against a legally binding decision of a supervisory authority or against a controller or processor (Arts. 78-79 GDPR).

================================================================================

9. SECURITY MEASURES

PIONIRS S.r.l. adopts appropriate technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration or destruction, in accordance with Art. 32 GDPR.

Measures in place include, among others:
– Encrypted data transmission (HTTPS/TLS) for all communications
– Access controls limited to authorised personnel on a need-to-know basis
– Secure credential management and temporary credentials at first access
– Access logging for the reserved area with defined retention periods
– Regular review of processing activities and security configurations

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, PIONIRS S.r.l. will notify the Garante per la protezione dei dati personali within 72 hours of becoming aware of the breach (Art. 33 GDPR). Where the breach is likely to result in a high risk, affected data subjects will also be informed without undue delay (Art. 34 GDPR).

================================================================================

10. UPDATES TO THIS PRIVACY POLICY

This Privacy Policy may be updated periodically to reflect changes in applicable law, our services, or our data processing activities. The date of the latest revision is indicated at the top of this document.

Where changes are material, PIONIRS S.r.l. will take appropriate steps to inform users — including, where applicable, via email notification to registered users of the reserved area.

The current version of this Policy is always available at:
https://www.pionirs.com/wp/privacy/

================================================================================

PIONIRS S.r.l. — Via Timavo 24, Milano (Italy)
privacy@pionirs.com — https://www.pionirs.com
Pursuant to EU Regulation 2016/679 (GDPR) and D.Lgs. 196/2003 as amended by D.Lgs. 101/2018