Privacy Policy

Privacy Policy

This Privacy Policy describes how Nexim Global, acting as Data Controller, processes your personal data under Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, ePrivacy Directive 2002/58/EC, Brazilian LGPD (Law no. 13.709/2018), the California CCPA/CPRA, and every other regulation applicable to the jurisdictions in which we operate.

Last updated: ITENFRESPTAR

Data Controller

Nexim Italia S.r.l. (hereinafter "Nexim", "we") — operating under the Nexim Global brand.
Registered office: Via Caldera 21, 20153 Milan — Italy
VAT / Tax Code: IT02575760067 · REA: MI-2572189
Share capital: € 100,000.00 fully paid-up
Email: privacy@nexim.it · Tel: +39 02 8622 44

Data Protection Officer (DPO)

Data Protection Officer — Nexim Global — dpo@nexim.it
Postal address: Via Caldera 21, 20153 Milan — Italy. The DPO is the single point of contact for all matters relating to the processing of your personal data.

Types of data collected

We process the following categories of personal data:

  • Contact data: name, surname, company name, job title, email, phone number, postal address.
  • Navigation data: IP address (hashed), user agent, referrer URL, pages visited, timestamp, session identifiers and technical / profiling cookies (see Cookie Policy).
  • Contractual data: orders, contracts, invoices, payment data (managed via PSD2-compliant providers; we do not store unencrypted card numbers).
  • Technical service data: network logs, configurations, NOC events. Electronic traffic data is processed according to art. 132 of Legislative Decree 196/2003 and applicable AGCOM resolutions.
  • Communications: email content, support chats, NOC call recordings (only with prior notice and for security and training purposes).
  • Biometric / special data: we do not process special categories of data under art. 9 GDPR unless specific explicit documented consent is provided.

Purposes of processing

  1. Execution of connectivity, event, managed services, and NOC supply contracts.
  2. Fulfillment of legal obligations related to tax, accounting, anti-money laundering, cybersecurity (NIS2), and electronic traffic data retention.
  3. Infrastructure security: fraud prevention, abuse, DDoS, unauthorized access, incident investigations.
  4. Direct marketing on products and services similar to those already purchased (soft opt-in art. 130 c. 4 Privacy Code) and marketing on new products with prior explicit consent.
  5. Aggregated statistical analysis and profiling with prior consent.
  6. Defense of a right in court.

Retention period

CategoryPeriodBasis
Contractual data10 years from terminationart. 2220 c.c.
Tax / invoicing data10 yearsDPR 600/1973
Electronic traffic data6 yearsart. 132 Legislative Decree 196/2003, Law 167/2017
Security logs12 monthslegitimate interest
Commercial leads without contract24 monthslegitimate interest / consent
Marketing datauntil revoked + 12 monthsconsent
Cookie consent12 monthsGDPR / Garante Guidelines 2021
Whistleblowing reports5 years from closureLegislative Decree 24/2023

Recipients of data

Your data may be shared with the following categories of recipients, appointed as Data Processors pursuant to art. 28 GDPR:

  • Hosting and cloud providers (AWS Italy/Ireland, Cloudflare, Aruba S.p.A.)
  • Email and transactional SMTP providers (Google Workspace, Postmark)
  • CRM and marketing automation platforms (HubSpot, Mailchimp — only with prior consent)
  • Payment providers (Stripe, corresponding banks)
  • Legal and commercial firms, auditors
  • Competent authorities upon legitimate request (Postal Police, AGCOM, Garante)
  • Network partners and upstream providers solely for the technical provision of the service

Cross-border transfers

When we transfer data outside the European Economic Area (e.g., US cloud services or operations at our New York office), we ensure adequate safeguards pursuant to Chapter V of the GDPR:

  • Adequacy decisions by the European Commission (e.g., EU-US Data Privacy Framework, where applicable).
  • Standard Contractual Clauses (SCC) approved by the Commission (Decision 2021/914).
  • Supplementary technical measures: at-rest and in-transit encryption, pseudonymization, access controls.

To obtain a copy of the applied safeguards, please write to the DPO.

Your rights

You have the right to exercise at any time the rights provided by arts. 15-22 GDPR (access, rectification, erasure, restriction, portability, objection, automated decisions) and to withdraw consent. See the dedicated page: Personal data protection.

Security measures

We adopt appropriate technical and organizational measures, aligned with ISO/IEC 27001, NIS2, ENISA, and CIS Controls v8 standards:

  • At-rest encryption (AES-256) and in-transit encryption (TLS 1.2+ with perfect forward secrecy).
  • Mandatory multi-factor authentication for privileged access.
  • Segregation of duties, least privilege, immutable logs.
  • Annual penetration tests and bug bounty program.
  • Documented Incident Response and Data Breach Notification procedures (within 72 hours to the Garante and data subjects, where required, pursuant to arts. 33-34 GDPR).
  • Mandatory staff training and NDA agreements with all collaborators and suppliers.

Minors

Our services are aimed at professional operators and are not intended for minors under 16 years of age. We do not intentionally collect personal data from minors. If you become aware that a minor has provided us with personal data without parental or guardian consent, please contact the DPO for deletion.

Cookies and similar technologies

The use of cookies and similar technologies is regulated in detail in our Cookie notice. You can manage your preferences at any time from the "Cookie preferences.

Changes to this notice

We reserve the right to modify this policy. The date of the last update is indicated at the top. Any substantial changes will be communicated via email or through a notice on our websites at least 30 days before they become effective.

Right to lodge a complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of the Member State where you habitually reside, work, or where the alleged infringement occurred.

© 2026 Nexim Global · Nexim Italia S.r.l. · Via Caldera 21, 20153 Milan — Italy