Privacy Policy
Your privacy is important to us. Discover how we protect and manage your personal data.
Introduction
NoRuleTech respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, and protect your personal information in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
Data We Collect
We collect different types of personal data when you interact with us: • Contact data: name, email, phone • Professional data: company, role • Technical data: IP address, browser, device • Usage data: pages visited, time spent • Marketing data: communication preferences Data is collected only when voluntarily provided or necessary to provide requested services.
Legal Basis for Processing
We process your personal data based on: • Consent: when you have given explicit consent • Contract: when necessary to perform a contract • Legitimate interest: to improve our services • Legal obligation: when required by law For marketing and analytics cookies, we always require your explicit consent.
Purpose of Processing
We use your data for: • Providing and improving our services • Communicating with you about projects and services • Sending updates and newsletters (only with consent) • Analyzing website usage to improve user experience • Complying with legal and regulatory obligations • Preventing fraud and abuse
Data Sharing
We share your data only with: • Service providers: who assist us in operations (hosting, email marketing, analytics) • Business partners: only when necessary to provide agreed services • Legal authorities: when required by law All providers are subject to strict data protection agreements and operate only on our instructions.
International Transfers
Your data may be transferred outside the EU/EEA only to countries that ensure an adequate level of protection or with appropriate safeguards such as the European Commission's Standard Contractual Clauses. We always provide transparent information about international transfers.
Data Retention
We retain your personal data only for the period necessary to achieve the purposes for which they were collected: • Contact data: 3 years from last interaction • Contract data: 10 years from contract end (legal requirement) • Marketing data: until consent withdrawal • Analytics data: 26 months We apply automatic deletion policies for data no longer needed.
Data Security
We implement advanced technical and organizational security measures: • End-to-end encryption for sensitive data • Data access based on least privilege principle • Continuous security monitoring • Regular backups and recovery testing • Periodic risk assessments • Staff training on data protection We report any data breaches to competent authorities within 72 hours.
Cookies and Similar Technologies
We use different types of cookies: • Necessary cookies: essential for website functionality • Analytics cookies: for usage analysis (only with consent) • Marketing cookies: for personalized advertising (only with consent) • Preference cookies: to save your choices You can manage your cookie preferences at any time through our banner or dedicated page.
Your GDPR Rights
You have the following rights: • Right of access: obtain copy of your data • Right to rectification: correct inaccurate data • Right to erasure: delete your data • Right to object: object to processing • Right to data portability: receive data in structured format • Right to restriction: restrict processing in certain circumstances • Right to withdraw consent: withdraw consent at any time
Exercising Your Rights
To exercise your rights: • Contact our DPO at: dpo@noruletech.com • Provide sufficient information to identify you • Specify which right you wish to exercise We will respond within 30 days of request. We provide data free of charge, except for manifestly unfounded or excessive requests.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee privacy compliance: • Email: dpo@noruletech.com • Phone: +39 02 82 86 01 03 • Address: Via della Privacy, 123 - Italy The DPO is your point of contact for any data protection matters.
Complaints to Authority
You have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your data violates the GDPR. In Italy, the competent authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).
Policy Changes
We periodically update this policy to reflect changes in our practices or legal obligations. Significant changes will be communicated via email or prominent website notices. The date of the last update is always indicated at the bottom of the page.
Contact
For any privacy questions or to exercise your rights: • Email: privacy@noruletech.com • DPO: dpo@noruletech.com • Phone: +39 02 82 86 01 03 • Address: Via della Privacy, 123 - 20100 Italy We respond to all legitimate requests within legal timeframes.
Last Updated
September 17, 2025