PRIVACY POLICY OF FLEXCON SRL
(v. 20260609)
Effective Date: June 9, 2026
Data Protection Notice & Privacy Policy
Pursuant to Articles 13 and 14 of the Regulation (EU) 2016/679 (“GDPR”)
Document Governance
a. Data Controller: Flexcon srl, with registered office in Turin, Italy, represented by its pro tempore Legal Representative (hereinafter, “Flexcon” or the “Company“).
b. Target Audience: Clients, prospective corporate clients, technical partners, software vendors, subcontractors, individual contact persons of corporate legal entities, and professional attendees of corporate training programs (collectively referred to as “Data Subjects“).
1. Scope and Nature of Processing
In accordance with standard industrial practices for highly technical engineering consultancy, software distribution, and corporate B2B services, this Policy governs the processing of ordinary personal data collected during commercial operations, software licensing, or the fulfillment of technical agreements.
Flexcon processes exclusively identification and corporate contact data (e.g., first name, last name, company email, direct business telephone lines, job title/corporate role, corporate tax identification numbers, and banking details required for transactional execution).
Important Regulatory Boundary: Flexcon does not collect, solicit, or process “special categories of personal data” under Article 9 of the GDPR (such as health, political, or religious data) or criminal data under Article 10 of the GDPR through its standard corporate channels.
2. Purposes of Processing and Legal Bases
Your personal data is handled by Flexcon only where an explicit, legally validated justification exists under Chapter II of the GDPR. Processing is structured across four primary pillars:
A. Execution of Technical Consultancy, Software Distribution & B2B Training
Purpose:
- To manage technical and commercial requests, issue professional project quotes, and execute technical simulation and consultancy contracts—specifically including Discrete Event Simulation (DES), robotics, and virtual commissioning projects.
- To manage deployment, licensing, and technical support for proprietary engineering modules, including Flexcon Emulation and Flexcon Helios.
- To administer and deliver dedicated corporate training classes and institutional technical certifications in our capacity as of major software platforms (such as Autodesk, Visual Components, and AnyLogic). Note: Flexcon does not offer public or open-enrollment consumer training; all training processing is strictly bounded by B2B corporate agreements.
Legal Basis: Processing is strictly necessary for the performance of a contract to which the Data Subject’s organization is a party, or to take steps at the request of the Data Subject prior to entering into a contract (Article 6(1)(b) of the GDPR).
B. Legal, Regulatory, Compliance, and Quality Standards
Purpose:To fulfill mandatory duties mandated by Italian and European Union legislation (corporate fiscal accounting, anti-money laundering controls, and labor safety laws), as well as to maintain the rigorous data traceability required under the Company’sISO 9001 Quality Management Certification.
Legal Basis: Processing is necessary for compliance with a legal obligation to which the Data Controller is subject (Article 6(1)(c) of the GDPR).
C. Maintenance of Professional B2B Relations and Industry Updates
Purpose: To invite established corporate clients, software users, and industrial partners to specialized technical seminars, webinars, or industry trade shows (such as SPS Italia) organized or attended by Flexcon, tracking solely to the Data Subject’s established technical or engineering scope.
Legal Basis: The legitimate interest of the Data Controller to foster, maintain, and develop its professional B2B
D. Digital Platform Security and Technical Operations
Purpose: To monitor the stability and security perimeter of Flexcon’s IT networks, website infrastructure, and to route spontaneous inbound contact form inquiries to the correct internal technical department.
Legal Basis: The legitimate interest of the Data Controller in securing its digital assets, protecting corporate intellectual property, and responding transparently to market requests (Article 6(1)(f) of the GDPR).
3. Data Retention and Minimization Matrix
Flexcon applies strict data minimization principles. Personal data is retained only for the exact duration necessary to satisfy the purposes for which it was gathered, unless an extended retention timeline is explicitly mandated by national law or quality audit standards.
| Data Category | Specific Processing Context | Maximum Retention Period | Primary Regulatory / Corporate Basis |
|---|---|---|---|
| Commercial & Contractual Records | Project files, simulation models, software licensing records (Autodesk, Visual Components, AnyLogic), billing details, signed NDAs. | 10 Years from the date of contract termination or completion. | Article 2220 of the Italian Civil Code (Statutory limitation for corporate accounting records) and ISO 9001 audit trail standards. |
| B2B Corporate Training Records | Attendance logs, Autodesk ATC certification pathways, corporate student lists. | 10 Years from the completion of the training module. | Compliance with software vendor certification criteria and contractual auditing obligations. |
| B2B Pre-Contractual & Technical Inquiries | Requests for proposals, unsolicited engineering inquiries, simulation software demo queries, pending corporate quotes. | 24 Months from the date of the last active, documented business interaction. | Internal data protection minimization policy. |
| B2B Contact Networks | Corporate stakeholder contact directories, partner business cards, trade show registry databases (e.g., SPS Italia). | Until the Data Subject explicitly objects or requests erasure. | Article 21 of the GDPR (Right to Object). |
| IT System Telemetry | IP addresses, website access logs, firewall connection stamps. | 30 Days from collection, unless flagged for security investigation. | IT Perimeter Security and Incident Response protocols. |
4. Processing Methods and Security Safeguards
Data processing is executed via highly secure protocols to minimize the risk of unauthorized access, disclosure, or destruction:
- Third-Party Transfer Restrictions: Flexcon does not sell, lease, or publicly disseminate personal data. Data is shared with external parties (such as legal advisors, accounting consultants, IT providers, or directly with partner software vendors like Autodesk for official ATC certification paths) only if they are formally bound by strict processing agreements or appointed as Data Processors under Article 28 of the GDPR. Transfers outside the EEA are strictly prohibited unless protected by Standard Contractual Clauses (SCCs).
- Operational Methods: Processing is performed via automated digital tools (hosted on enterprise-grade servers located exclusively within the European Economic Area) and restricted physical paper archives maintained within locked, monitored company facilities in Turin.
- Access Control: Access to personal data is restricted strictly to authorized internal personnel (such as designated project managers, simulation team managers, and administrative staff) who have been fully trained in data security and are bound by formal confidentiality agreements.
5. Rights of the Data Subject
Data Subjects may exercise their fundamental rights under Articles 15–22 of the GDPR at any point in time:
- Right of Access (Art. 15): The right to find out if Flexcon is processing your data and receive a clear copy of all records held.
- Right to Rectification (Art. 16): The right to have incomplete or inaccurate data corrected without undue delay.
- Right to Erasure / “Right to be Forgotten” (Art. 17): The right to request permanent deletion of your data when it is no longer legally or contractually required.
- Right to Restriction of Processing (Art. 18): The right to block active processing while a dispute over data accuracy or legality is evaluated.
- Right to Data Portability (Art. 20): The right to receive a digital, structured, machine-readable copy of your personal data to transfer to another provider.
- Right to Object (Art. 21): The absolute right to stop processing activities driven by legitimate interest, including any professional direct B2B communications or event invitations.
Contact Information for Rights Compliance
To submit a formal request regarding your data, or to appeal a data-handling practice, please contact Flexcon’s compliance function via email:
- Dedicated Email Address: privacy@flexcon.it
Should you remain unsatisfied with how Flexcon handles your request, you retain the right to lodge an official complaint with the competent national supervisory authority, which in Italy is the Garante per la protezione dei dati personali (Piazza Venezia n. 11, 00187 Roma; www.garanteprivacy.it).