Privacy Policy
Privacy Policy
This Privacy Policy describes how Nexim Global, acting as Data Controller, processes your personal data under Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, ePrivacy Directive 2002/58/EC, Brazilian LGPD (Law no. 13.709/2018), the California CCPA/CPRA, and every other regulation applicable to the jurisdictions in which we operate.
Data Controller
Nexim Italia S.r.l. (hereinafter "Nexim", "we") — operating under the Nexim Global brand.
Registered office: Via Caldera 21, 20153 Milan — Italy
VAT / Tax Code: IT02575760067 · REA: MI-2572189
Share capital: € 100,000.00 fully paid-up
Email: privacy@nexim.it · Tel: +39 02 8622 44
Data Protection Officer (DPO)
Data Protection Officer — Nexim Global — dpo@nexim.it
Postal address: Via Caldera 21, 20153 Milan — Italy. The DPO is the single point of contact for all matters relating to the processing of your personal data.
Types of data collected
We process the following categories of personal data:
- Contact data: name, surname, company name, job title, email, phone number, postal address.
- Navigation data: IP address (hashed), user agent, referrer URL, pages visited, timestamp, session identifiers and technical / profiling cookies (see Cookie Policy).
- Contractual data: orders, contracts, invoices, payment data (managed via PSD2-compliant providers; we do not store unencrypted card numbers).
- Technical service data: network logs, configurations, NOC events. Electronic traffic data is processed according to art. 132 of Legislative Decree 196/2003 and applicable AGCOM resolutions.
- Communications: email content, support chats, NOC call recordings (only with prior notice and for security and training purposes).
- Biometric / special data: we do not process special categories of data under art. 9 GDPR unless specific explicit documented consent is provided.
Purposes of processing
- Execution of connectivity, event, managed services, and NOC supply contracts.
- Fulfillment of legal obligations related to tax, accounting, anti-money laundering, cybersecurity (NIS2), and electronic traffic data retention.
- Infrastructure security: fraud prevention, abuse, DDoS, unauthorized access, incident investigations.
- Direct marketing on products and services similar to those already purchased (soft opt-in art. 130 c. 4 Privacy Code) and marketing on new products with prior explicit consent.
- Aggregated statistical analysis and profiling with prior consent.
- Defense of a right in court.
Legal bases
- Art. 6.1.b GDPR — performance of a contract to which you are a party.
- Art. 6.1.c GDPR — compliance with legal obligations.
- Art. 6.1.f GDPR — legitimate interest of Nexim in service security and legal defense.
- Art. 6.1.a GDPR — explicit consent for marketing and profiling, always revocable.
Retention period
| Category | Period | Basis |
|---|---|---|
| Contractual data | 10 years from termination | art. 2220 c.c. |
| Tax / invoicing data | 10 years | DPR 600/1973 |
| Electronic traffic data | 6 years | art. 132 Legislative Decree 196/2003, Law 167/2017 |
| Security logs | 12 months | legitimate interest |
| Commercial leads without contract | 24 months | legitimate interest / consent |
| Marketing data | until revoked + 12 months | consent |
| Cookie consent | 12 months | GDPR / Garante Guidelines 2021 |
| Whistleblowing reports | 5 years from closure | Legislative Decree 24/2023 |
Recipients of data
Your data may be shared with the following categories of recipients, appointed as Data Processors pursuant to art. 28 GDPR:
- Hosting and cloud providers (AWS Italy/Ireland, Cloudflare, Aruba S.p.A.)
- Email and transactional SMTP providers (Google Workspace, Postmark)
- CRM and marketing automation platforms (HubSpot, Mailchimp — only with prior consent)
- Payment providers (Stripe, corresponding banks)
- Legal and commercial firms, auditors
- Competent authorities upon legitimate request (Postal Police, AGCOM, Garante)
- Network partners and upstream providers solely for the technical provision of the service
Cross-border transfers
When we transfer data outside the European Economic Area (e.g., US cloud services or operations at our New York office), we ensure adequate safeguards pursuant to Chapter V of the GDPR:
- Adequacy decisions by the European Commission (e.g., EU-US Data Privacy Framework, where applicable).
- Standard Contractual Clauses (SCC) approved by the Commission (Decision 2021/914).
- Supplementary technical measures: at-rest and in-transit encryption, pseudonymization, access controls.
To obtain a copy of the applied safeguards, please write to the DPO.
Your rights
You have the right to exercise at any time the rights provided by arts. 15-22 GDPR (access, rectification, erasure, restriction, portability, objection, automated decisions) and to withdraw consent. See the dedicated page: Personal data protection.
Security measures
We adopt appropriate technical and organizational measures, aligned with ISO/IEC 27001, NIS2, ENISA, and CIS Controls v8 standards:
- At-rest encryption (AES-256) and in-transit encryption (TLS 1.2+ with perfect forward secrecy).
- Mandatory multi-factor authentication for privileged access.
- Segregation of duties, least privilege, immutable logs.
- Annual penetration tests and bug bounty program.
- Documented Incident Response and Data Breach Notification procedures (within 72 hours to the Garante and data subjects, where required, pursuant to arts. 33-34 GDPR).
- Mandatory staff training and NDA agreements with all collaborators and suppliers.
Minors
Our services are aimed at professional operators and are not intended for minors under 16 years of age. We do not intentionally collect personal data from minors. If you become aware that a minor has provided us with personal data without parental or guardian consent, please contact the DPO for deletion.
Cookies and similar technologies
The use of cookies and similar technologies is regulated in detail in our Cookie notice. You can manage your preferences at any time from the "Cookie preferences.
Changes to this notice
We reserve the right to modify this policy. The date of the last update is indicated at the top. Any substantial changes will be communicated via email or through a notice on our websites at least 30 days before they become effective.
Right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of the Member State where you habitually reside, work, or where the alleged infringement occurred.
© 2026 Nexim Global · Nexim Italia S.r.l. · Via Caldera 21, 20153 Milan — Italy