Home

Privacy Policy

Privacy Policy

Last updated: July 29, 2026

  • Data controller
  • Categories of data collected
  • Purpose of processing
  • Legal basis
  • Retention period and minimisation
  • Data subject rights
  • Cookies and tracking technologies
  • Detailed cookie table
  • Third-party services and recipients
  • International data transfers
  • Technical and organisational security measures
  • Data breach notification
  • Privacy by design and privacy by default
  • AI assistant and chat
  • Children's data
  • Data protection in Switzerland (nFADP)
  • Right to opt out of data sale or sharing
  • Updates to this policy
  • Version history
  • Contact and exercising your rights

This privacy policy is provided pursuant to Art. 13 of the GDPR (Regulation EU 2016/679) and the Italian Code for the protection of personal data (D.lgs. 196/2003 as amended by D.lgs. 101/2018). It describes how Veridgex collects, processes, and protects the personal data of users of its website and services.

Data controller

The data controller is Massimo Rodi, based in Via dei Fiori 2, 86079 Sesto Campano (IS), Italia. Services are invoiced through Xolo Go (Estonian EU entity). For all data protection matters, write to info@veridgex.com. We respond within 30 days (Art. 12 GDPR).

Categories of data collected

We process the following categories of personal data:

  • Contact data: first name, last name, email, phone number — provided voluntarily via website forms or email.
  • Browsing data: IP address, browser type, operating system, pages visited, session duration — collected in aggregated and anonymized form for statistical purposes.
  • Consent data: cookie preferences, consent timestamp, version of the policy accepted.

Purpose of processing

Personal data is processed exclusively to: (a) provide requested services — digital audit, consulting, reports; (b) respond to inquiries; (c) improve the website and services; (d) comply with legal and tax obligations. No data is used for automated decision-making with legal or similarly significant effects (Art. 22 GDPR).

Legal basis

Processing is based on: (a) explicit consent of the data subject (Art. 6(1)(a) GDPR); (b) performance of pre-contractual measures or a contract (Art. 6(1)(b) GDPR); (c) compliance with legal obligations (Art. 6(1)(c) GDPR); (d) legitimate interests (Art. 6(1)(f) GDPR) limited to service improvement.

Retention period and minimisation

We follow the principles of data minimisation and storage limitation (Art. 5 GDPR). Contact data is retained for a maximum of 12 months from the last interaction, unless earlier deletion is requested. Anonymised browsing data is retained indefinitely. Consent data is retained until consent is withdrawn. Tax and accounting data is retained for 10 years as required by Italian law.

Data subject rights

As a data subject, you have the following rights (Art. 15-22 GDPR):

  • Right of access to your personal data and information about its processing.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure of data (right to be forgotten), subject to legal retention obligations.
  • Right to restriction of processing in certain circumstances.
  • Right to object to processing based on legitimate interests.
  • Right to data portability in a structured, machine-readable format.
  • Right to withdraw consent at any time, with immediate effect on future processing.

Cookies and tracking technologies

We use essential cookies for site functionality (session, language preferences) that do not require consent (Art. 122 Privacy Code). Analytics and marketing cookies are activated only with explicit, granular consent via the consent banner. You can manage your preferences at any time via the "Cookie preferences" link in the footer. We apply privacy by default: no non-essential cookies are set before consent.

Detailed cookie table

Below is the complete list of cookies used on the site:

NameTypePurposeDurationProvider
vx_langEssentialStores selected language1 yearVeridgex (first-party)
vx_consentEssentialStores cookie consent preferences6 monthsVeridgex (first-party)
__Secure-next-auth.session-tokenEssentialSession token for authenticationSessionVeridgex (first-party)
_gaAnalyticsDistinguishes unique users (Google Analytics)2 yearsGoogle LLC (USA)
_ga_*AnalyticsMaintains session state (Google Analytics 4)2 yearsGoogle LLC (USA)
_fbpMarketingMeta Pixel conversion tracking3 monthsMeta Platforms (USA)
li_sugrMarketingLinkedIn Insight Tag tracking90 daysLinkedIn (Ireland)

Third-party services and recipients

We use the following third-party services, each with its own data processing agreement (Art. 28 GDPR):

  • Vercel Inc. (USA) — website hosting and CDN. Processing country: USA. Privacy policy: https://vercel.com/legal/privacy-policy
  • Google Analytics (Google LLC, USA) — web analytics, only with consent. Processing country: USA. Privacy policy: https://policies.google.com/privacy
  • Meta Pixel (Meta Platforms Inc., USA) — conversion tracking and retargeting on Facebook/Instagram, only with consent. Processing country: USA. Privacy policy: https://www.facebook.com/privacy/policy
  • LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Ireland) — B2B tracking and retargeting, only with consent. Processing country: EU. Privacy policy: https://www.linkedin.com/legal/privacy-policy

International data transfers

Personal data may be transferred to providers located outside the EU, particularly in the USA. Such transfers are based on: (a) European Commission Standard Contractual Clauses (SCC, decision 2021/914); (b) EU-US Data Privacy Framework (DPF), adopted by the European Commission on 10 July 2023. Destination countries: USA (Vercel, Google, Meta), Ireland (LinkedIn). No transfers to non-adequate countries without appropriate safeguards.

Technical and organisational security measures

We implement adequate technical and organisational measures (Art. 32 GDPR): TLS 1.3 encryption in transit, mandatory HTTPS with automatic redirect, security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, COOP, CORP), restricted data access to authorised personnel, data minimisation.

Data breach notification

In the event of a data security breach posing a risk to the rights and freedoms of natural persons, we notify the Italian Data Protection Authority (www.garanteprivacy.it) within 72 hours of discovery and, where necessary, inform the affected individuals (Art. 33-34 GDPR).

Privacy by design and privacy by default

We apply the principles of privacy by design and privacy by default (Art. 25 GDPR): data protection is integrated into the design of our services from the outset, and default settings are the most protective for the user. No non-essential tracking is active without explicit consent.

AI assistant and chat

The website uses an AI-based conversational assistant to answer user questions and qualify requests. Messages sent via chat are processed by an LLM provider (OpenAI) to generate responses. Conversation content is not used to train third-party models. Chat data is retained for 30 days for service quality purposes and then automatically deleted. No automated decision-making with legal effects is made by the AI assistant (Art. 22 GDPR).

Children's data

Our services are not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided data without parental consent, contact us at info@veridgex.com to request immediate deletion.

Data protection in Switzerland (nFADP)

For users residing in Switzerland, this policy is also compliant with the revised Federal Act on Data Protection (nFADP, in force since 1 September 2023). The data controller is responsible under the nFADP for data collected via this website. In case of violation, you may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). The legal bases under Art. 6 GDPR correspond to the principles of the nFADP (consent, contractual performance, legal obligations, prevailing interests).

Updates to this policy

This privacy policy may be updated periodically to reflect changes in services, legislation, or business practices. Material updates that change user rights or introduce new categories of processing will be notified via a visible notice on the home page and, where applicable, via email to registered users. The last updated date at the top of the page always indicates the current version. We encourage you to review this page regularly.

Right to opt out of data sale or sharing

Veridgex does not sell or share users' personal data with third parties for advertising purposes. Marketing cookies (Meta Pixel, LinkedIn Insight Tag) are used solely to measure the effectiveness of our campaigns and not for profiling or data sale. You can disable all non-essential cookies at any time via the cookie preferences in the footer. If you believe your data has been improperly shared, contact us at info@veridgex.com.

Version history

Below is the history of major policy versions:

  • July 29, 2026 — Added Swiss FADP section, detailed cookie table, AI assistant disclosure, children's section, data sale opt-out right, version history.
  • January 1, 2026 — Initial version. Basic GDPR and Italian Privacy Code compliant policy.

Contact and exercising your rights

To exercise your rights or for any data protection questions, write to info@veridgex.com. We respond within 30 days. If you believe our processing of your data is non-compliant, you have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

Legal pages

PrivacyTerms→Imprint→