Privacy Policy

    How we collect, use, and protect your personal data

    Last updated: 30 Settembre 2025

    Who We Are and Why This Policy

    Neuratio S.r.l. (VAT: 04170290045), with registered office at Piazza Beppe Manfredi 9, 12045 Fossano (CN), Italy, is a company specialized in SaaS artificial intelligence solutions for after-sales support of industrial machinery manufacturers. This policy describes how we collect, use, and protect personal data when you visit our website, when you interact with us to request demos or information, when you use our services as a customer, and when you send email or WhatsApp messages that are managed by our customers through the Neuratio platform.

    Data Controller and Processor

    For data collected through the website and direct relationships with Neuratio, the Data Controller is Neuratio S.r.l. When our customers use the platform to manage communications and documentation with their users, they are Data Controllers. Neuratio acts as a Data Processor (art. 28 GDPR), processing data only on behalf of customers and according to their instructions.

    Types of Data Collected

    We collect different types of data depending on the type of interaction:

    Website visitors

    • Contact data entered in forms (first name, last name, business email, company)
    • Messages and communications sent (e.g., demo requests)
    • Technical and usage data (IP address, browser type, operating system, pages visited, cookies)

    Customers (companies using the platform)

    • Identification and contact data of company representatives
    • Contractual, administrative and billing data
    • Access and platform usage logs
    • Data, documents and content uploaded by customers to the platform

    Messages managed through the platform

    • Contents of emails and WhatsApp messages sent by end users to customers
    • Phone numbers and email addresses used in communications
    • Any technical attachments (manuals, images, documents)

    Neuratio does not establish direct relationships with the end customers of our Customers: message data is processed exclusively on behalf of the Customer Controller.

    Processing Purposes

    • Provide Neuratio platform services (ticket and message management)
    • Send and receive messages on behalf of customers via WhatsApp Business API (Meta Platforms)
    • Execute contractual obligations and legal compliance (e.g., administration and billing)
    • Respond to demo requests and provide information about our services
    • Statistical analysis and service improvement
    • IT security and abuse prevention
    • Technical and operational communications necessary for service delivery

    Legal Basis for Processing

    • Performance of a contract or pre-contractual measures (art. 6.1.b)
    • Compliance with legal obligations (art. 6.1.c)
    • Legitimate interest of the controller (art. 6.1.f) for security and service improvement
    • Explicit consent (art. 6.1.a), for example for sending marketing communications

    Methods and Location of Processing

    Processing takes place using IT/telematic tools, adopting adequate technical and organizational measures. Data may be accessed by: authorized internal personnel, external processors (e.g., cloud providers, legal consultants), and Meta Platforms for the use of WhatsApp Business API. Data is processed in the EU and, where necessary, transferred to non-EU countries in compliance with GDPR (e.g., Standard Contractual Clauses).

    Retention Period

    • Messaging and ticket data: retained for the entire duration of the contractual relationship with the Customer Controller and deleted within 60 days from contract termination, unless different legal obligations or specific Customer request
    • Contractual/billing data: retained for 10 years (tax obligations)
    • Marketing/contact data: retained until consent withdrawal

    At the end, data is deleted or anonymized.

    Data Sharing and Communication

    We do not sell or transfer data to third parties for commercial purposes. Data may be shared with trusted service providers necessary for service delivery, including: Meta Platforms (WhatsApp Business API), Google Cloud / Firebase (hosting and storage), and authorized IT providers and consultants. All operate as data processors or sub-processors.

    Data Security

    We adopt adequate technical and organizational measures to protect personal data, including access controls, backup systems and the use of secure channels provided by the providers used (e.g., Meta WhatsApp Business API, email and cloud services).

    Rights of Data Subjects

    Data subjects (visitors, customers, end users of customers) have the right to: access, rectification, erasure, restriction, objection, portability, withdrawal of consent. Requests should be sent to privacy@neuratio.ai and will be handled within 30 days. It is also possible to lodge a complaint with the Data Protection Authority.

    Legal Defense

    Data may be used to defend the Controller's rights in court or in pre-litigation phase.

    System Logs and Maintenance

    For operational and security reasons, system logs are collected (e.g., IP addresses, errors, operations performed).

    Changes to This Policy

    The Controller may modify this policy at any time. The updated version is always available on this page.

    Privacy Contacts

    For any questions or to exercise your data rights, contact us:

    Email: privacy@neuratio.ai

    Address: Piazza Beppe Manfredi 9, 12045 Fossano (CN), Italia

    VAT: 04170290045