Last updated: 27 August 2026

CAMELIA Technology S.r.l. respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect through this website, why we collect it, how we use it, and what rights you have over it.

This policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and applies to the website https://camelia-technology.com (the “Website”).

1. Data Controller

The data controller responsible for your personal data is:

CAMELIA Technology S.r.l. Via Giacomo Leopardi, 21 – 20123 Milano (MI), Italy VAT No. / Tax Code: 14307390964 Share capital: € 10,000.00 fully paid up

Email: info@camelia-technology.com Certified email (PEC): camelia-tech@pec.it

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. For any question concerning this policy or your personal data, please write to info@camelia-technology.com.

2. What personal data we collect and why

2.1 Contact form

When you use the contact form on our “Contact Us” page, we collect the following data:

  • First name
  • Last name
  • Email address
  • Telephone number
  • The subject and content of your message

We use this data solely to reply to your enquiry and, where relevant, to discuss a possible working relationship with you. Providing this data is voluntary, but without it we cannot respond to you.

Legal basis: performance of a contract or of pre-contractual measures taken at your request (Article 6(1)(b) GDPR), and our legitimate interest in responding to enquiries addressed to us (Article 6(1)(f) GDPR).

Messages submitted through the form are delivered to our company mailbox by email. They are not stored in a separate database on the Website.

2.2 Correspondence by email

If you contact us directly by email or by certified email (PEC), we process the data contained in your message and in its header for the same purposes and on the same legal bases described in section 2.1.

2.3 Navigation data and server logs

Like all websites, this Website relies on technical systems that record certain data transmitted automatically by your browser when you visit. This may include IP addresses, browser type and version, operating system, the pages requested, and the date and time of each request.

This data is used to allow the Website to function correctly, to ensure its security and stability, and to detect and prevent abuse or attempted attacks. It is not used to identify individual visitors, and it is not combined with other data to build user profiles.

Legal basis: our legitimate interest in operating and securing our Website (Article 6(1)(f) GDPR).

2.4 Cookies and analytics

The Website uses technical cookies necessary for its operation, and statistical cookies provided by Google Analytics, which help us understand how visitors use the Website in aggregate form.

Statistical and any non-essential cookies are only installed after you have given your consent through the cookie banner. You can withdraw or change your consent at any time using the consent management link available on the Website.

Legal basis: your consent (Article 6(1)(a) GDPR) for non-essential cookies; our legitimate interest (Article 6(1)(f) GDPR) for strictly technical cookies.

Full details of every cookie used, its purpose and its retention period are set out in our Cookie Policy.

2.5 Job applications

If you send us a spontaneous application or a curriculum vitae, we process the personal data contained in it in order to evaluate your profile for current or future openings.

Legal basis: pre-contractual measures taken at your request (Article 6(1)(b) GDPR). Please do not include special categories of data (such as health data, religious or political beliefs, or trade union membership) in your application, as they are not relevant to our assessment.

3. Who we share your data with

We do not sell your personal data, and we do not disclose it to third parties for their own marketing purposes.

Your data may be accessed by the following categories of recipients, each of which acts either as a processor appointed under Article 28 GDPR or as an independent controller:

  • Our web hosting and email provider, established in the European Union, which stores the Website and delivers our correspondence.
  • Google Ireland Limited, which provides the Google Analytics statistical service, where you have consented to statistical cookies.
  • Professional advisers (accountants, lawyers, IT consultants) bound by confidentiality obligations, where necessary.
  • Public authorities, where we are required to disclose data by law or by a binding order.

An up-to-date list of the processors we appoint is available on request by writing to info@camelia-technology.com.

4. Transfers outside the European Economic Area

Our hosting and email infrastructure is located within the European Union.

Where you consent to statistical cookies, data collected through Google Analytics may be transferred to the United States. Such transfers take place on the basis of the European Commission’s adequacy decision on the EU–U.S. Data Privacy Framework, and are additionally covered by the Standard Contractual Clauses adopted by the European Commission.

If we ever need to transfer your data to a country outside the European Economic Area that is not covered by an adequacy decision, we will do so only where appropriate safeguards under Chapter V GDPR are in place, and you may request a copy of those safeguards from us.

5. How long we keep your data

Data Retention period
Contact form messages and email correspondence 24 months from our last exchange, unless a contractual relationship begins
Data relating to a contractual relationship For the duration of the relationship and for 10 years thereafter, as required by Italian civil and tax law
Server logs Up to 12 months, save where a longer period is required to investigate a security incident
Analytics data As set out in the Cookie Policy (currently up to 14 months)
Curricula and applications 24 months from receipt, unless you ask us to delete them sooner

At the end of the applicable period, data is deleted or irreversibly anonymised.

6. Your rights

Under Articles 15 to 22 GDPR, you have the right to:

  • Access your personal data and obtain a copy of it;
  • Rectify data that is inaccurate or incomplete;
  • Erase your data (“right to be forgotten”), where one of the grounds in Article 17 GDPR applies;
  • Restrict our processing of your data in the cases set out in Article 18 GDPR;
  • Data portability, that is, receive the data you provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller;
  • Object at any time to processing based on our legitimate interest, on grounds relating to your particular situation;
  • Withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you.

To exercise any of these rights, write to info@camelia-technology.com. We will reply without undue delay and in any event within one month of receiving your request, as provided by Article 12 GDPR.

7. Right to lodge a complaint

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian supervisory authority:

Garante per la protezione dei dati personali Piazza Venezia 11 – 00187 Roma, Italy Email: garante@gpdp.it Website: https://www.garanteprivacy.it

You may also lodge a complaint with the supervisory authority of the EU Member State where you habitually reside or work.

8. Security

We apply technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), access controls, regular software updates and restricted access to mailboxes containing your correspondence. No transmission over the internet can be guaranteed to be entirely secure, but we work to protect your data against unauthorised access, loss, alteration and disclosure.

9. Minors

The Website and our services are addressed to businesses and professionals. We do not knowingly collect personal data from children under the age of 16. If you believe a minor has provided us with personal data, please contact us and we will delete it.

10. Links to other websites

The Website contains links to third-party websites and social networks, including LinkedIn. Once you follow such a link, this Privacy Policy no longer applies: we have no control over the content or the data practices of those websites, and we encourage you to read their own privacy policies.

11. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our activities or in applicable law. The current version is always published on this page, together with the date of the last update shown at the top. Where changes are substantial, we will make them clearly visible on the Website.