LEGAL & TRUST
VISAC Privacy Policy &
Data Protection Framework™
Public Corporate Governance Document
Framework Version 1.1.1
Last Updated: 20 August 2026
Executive Overview
Privacy, security and responsible technology as governance principles.
VISAC Technologies develops AI-native intelligence, security and decision-support systems designed for organizations operating in complex and mission-critical environments.
We believe privacy, security, transparency and responsible innovation are foundational architectural principles rather than compliance obligations alone.
This Privacy Policy & Data Protection Framework explains how VISAC collects, uses, protects and governs personal data across its websites, digital platforms, business operations and technology services.
It reflects VISAC's commitment to responsible data governance, security-by-design practices and human-centered use of advanced technologies.
Trust & Governance Statement
Responsible data governance throughout the technology lifecycle.
At VISAC, privacy, security and responsible technology are treated as governance responsibilities embedded throughout the lifecycle of systems, services and business operations.
VISAC Trust & Governance Layer™
Three integrated governance layers.
Layer 1
Legal Compliance
GDPR compliance, lawful processing, data subject rights, retention governance and transfer safeguards.
Layer 2
Security Governance
Identity and access governance, infrastructure protection, secure communications, resilience and supplier governance.
Layer 3
Responsible Technology Governance
AI governance, human oversight, accountability, controlled processing and responsible innovation.
1. Scope and Applicability
This Privacy Policy applies to personal data processed through VISAC Technologies websites, digital channels, enterprise communications and business interactions.
It applies to individuals who:
- browse VISAC digital properties;
- request information about products and services;
- engage in commercial or professional discussions;
- interact with VISAC communication channels.
2. Regulatory Framework
This Framework is based on:
- Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR);
- applicable national data protection legislation;
- Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018;
- applicable regulatory requirements concerning digital governance, information security, responsible technology and artificial intelligence, where applicable.
VISAC applies data protection principles consistently with applicable legal, regulatory and governance requirements.
3. Data Controller
The Data Controller is:
VISAC Technologies Srl
Registered Office:
Via Montenapoleone, Milan, Italy
VAT / Tax Identification Number:
IT0012536208
Email:
info@visactechnologies.com
4. VISAC Data Governance Principles
VISAC considers data governance a fundamental component of trustworthy technology.
The company applies the following principles throughout its activities:
Privacy by Design
Privacy considerations are integrated into the design of processes, services and technology activities from the earliest stages.
Security by Design
Security principles are embedded throughout architecture, development and operational practices.
Data Minimization
VISAC processes only information that is necessary, relevant and proportionate to defined and legitimate purposes.
Purpose Limitation
Personal data is processed only for specified, explicit and legitimate purposes communicated to individuals.
Transparency
VISAC provides clear information regarding personal data processing activities and governance practices.
Responsible Technology
VISAC promotes accountable, human-centered and responsible approaches to advanced technologies, including artificial intelligence-enabled systems.
5. Categories of Personal Data
VISAC may process different categories of personal data depending on the nature of the interaction with users, business partners and website visitors.
5.1 Information Provided by Users
Users may voluntarily provide personal information through website forms, communication channels or business interactions.
This information may include:
- name and surname;
- professional contact details;
- company or organization;
- professional role;
- information included in requests, communications or inquiries.
5.2 Professional and Business Information
As a technology company operating primarily in a business-to-business environment, VISAC may process professional information related to enterprise interactions.
This may include:
- organization details;
- business context;
- professional interests;
- information required for demonstrations, discussions or enterprise engagement activities.
5.3 Technical and Navigation Data
During normal website operation, VISAC systems may automatically collect technical information necessary for security, functionality and service improvement.
Such information may include:
- IP address;
- browser information;
- operating system;
- device information;
- access logs;
- security-related technical information;
- navigation interactions.
These data are processed primarily for website operation, security protection, service reliability and technical analysis.
5.4 Cookies and Similar Technologies
VISAC may use cookies and similar technologies to support website functionality, improve user experience and analyse service performance.
Further information is available in the VISAC Cookie Policy™.
6. Processing Purposes
VISAC processes personal data exclusively for defined, legitimate and transparent purposes.
Information Requests and Enterprise Communications
To respond to requests for information, product inquiries, technology discussions, demonstrations or business communications.
Legal Basis: Pre-contractual measures and legitimate interest, where applicable.
Enterprise Engagement and Business Development
To manage professional relationships, evaluate potential collaborations and support enterprise interactions.
Legal Basis: Legitimate interest and pre-contractual measures.
Contractual Activities
To establish, manage and execute contractual relationships.
Legal Basis: Contractual obligations.
Security Protection
To protect VISAC digital services, prevent unauthorized access, detect misuse and maintain operational security.
Legal Basis: Legitimate interest.
Legal and Regulatory Compliance
To comply with applicable legal, regulatory or administrative obligations.
Legal Basis: Legal obligation.
Analytics and Service Improvement
To understand website performance, improve digital services and enhance user experience.
Legal Basis: Legitimate interest and/or consent where required.
Marketing Communications
To provide updates, information regarding products, services, events or corporate activities where permitted.
Legal Basis: Consent.
| Processing Purpose | Legal Basis |
|---|---|
| Information Requests | Pre-contractual Measures |
| Enterprise Engagement | Legitimate Interest / Pre-contractual Measures |
| Contractual Activities | Contractual Obligations |
| Security Protection | Legitimate Interest |
| Legal Compliance | Legal Obligation |
| Analytics and Service Improvement | Legitimate Interest / Consent where required |
| Marketing Communications | Consent |
7. Processing of Data within Intelligence and Security Activities
VISAC Technologies develops intelligence-enablement technologies, AI-native systems, edge computing capabilities and decision-support solutions designed for organizations operating in complex environments.
The nature of VISAC technologies requires a clear distinction between:
- the development of intelligence-enabled capabilities and security technologies;
- the processing of personal data related to website visitors, business contacts and professional interactions.
Personal data collected through VISAC websites and digital channels is processed exclusively for legitimate business, operational, contractual, regulatory and communication purposes.
VISAC does not conduct intelligence activities, operational monitoring or investigative profiling of website visitors through ordinary website interactions.
Website visitors are not considered subjects of intelligence activities solely because they interact with VISAC digital properties.
Any intelligence, analytics or operational workflows performed through VISAC technologies are governed by:
- applicable laws and regulations;
- contractual arrangements;
- customer governance frameworks;
- appropriate accountability mechanisms.
8. Responsible AI and Intelligent Systems
VISAC recognizes that advanced technologies create both opportunities and responsibilities.
Accordingly, VISAC applies governance principles intended to promote:
- transparency;
- accountability;
- appropriate human oversight;
- responsible innovation;
- controlled processing.
These principles apply throughout the lifecycle of intelligent systems, from design and development to operational deployment and continuous improvement.
VISAC promotes responsible technology practices aimed at ensuring that intelligent systems are developed and used in a manner consistent with applicable legal, ethical and governance expectations.
8.1 Automated Decision-Making and Human Oversight
VISAC Technologies does not make decisions producing legal effects concerning individuals solely through automated processing unless expressly permitted by applicable law and supported by appropriate safeguards.
Where intelligent systems support analytical, security or operational workflows, meaningful human oversight remains an integral component of the decision process.
VISAC recognizes that technology-enabled analysis should support informed decision-making while maintaining appropriate accountability and human responsibility.
9. Legal Basis for Processing
VISAC processes personal data based on one or more of the following legal grounds:
- execution of pre-contractual measures requested by the individual;
- performance of contractual obligations;
- compliance with legal obligations;
- legitimate interests pursued by VISAC;
- consent provided by the individual where required by applicable law.
VISAC evaluates the appropriate legal basis according to the nature, purpose and context of each processing activity.
10. Technical and Organizational Security Measures
VISAC adopts appropriate technical and organizational measures designed to protect information throughout its lifecycle.
Security measures are intended to ensure:
- confidentiality;
- integrity;
- availability;
- resilience;
- protection against unauthorized access or misuse.
Identity and Access Management
Controls designed to ensure appropriate access authorization and protection of information resources.
Infrastructure Protection
Measures supporting the protection and reliability of digital infrastructure.
Secure Communications
Protection of communication channels through appropriate security practices.
Monitoring and Detection Capabilities
Capabilities supporting identification of security events and operational risks.
Business Continuity and Resilience Practices
Approaches designed to support service continuity and operational resilience.
Vendor Risk Management
Evaluation and governance of third-party providers involved in relevant processing activities.
Security measures are reviewed and updated periodically considering evolving operational, technological and regulatory requirements.
11. Data Recipients and Third-Party Governance
VISAC may share personal data with selected third parties where such communication is necessary for legitimate business, operational, contractual or legal purposes.
Potential recipients may include:
- hosting providers;
- cloud infrastructure providers;
- technology suppliers;
- IT service providers;
- professional advisors;
- legal, financial and administrative consultants;
- public authorities or regulatory bodies where required by applicable law.
VISAC evaluates third-party relationships according to appropriate governance principles, considering:
- confidentiality obligations;
- security requirements;
- data protection responsibilities;
- contractual safeguards;
- compliance with applicable regulations.
Third parties processing personal data on behalf of VISAC act as data processors where required or as independent controllers where applicable.
Personal data is not disclosed publicly or made available for unrelated purposes.
12. Supply Chain and Technology Provider Governance
VISAC recognizes that modern technology ecosystems rely on trusted suppliers, infrastructure providers and technology partners.
Accordingly, supply chain governance is considered an integral component of responsible data protection and security management.
Third parties involved in processing activities may include:
- cloud service providers;
- hosting providers;
- software and technology providers;
- infrastructure partners;
- specialized service providers.
VISAC expects relevant technology providers and suppliers to maintain appropriate standards regarding:
- confidentiality;
- information security;
- data protection;
- operational reliability;
- regulatory compliance.
Where applicable, VISAC establishes contractual arrangements and governance mechanisms designed to ensure appropriate protection of personal data throughout the technology ecosystem.
13. International Data Transfers
VISAC primarily operates within the framework of applicable European data protection requirements.
Where personal data is transferred outside the European Economic Area (EEA), VISAC applies appropriate safeguards according to applicable data protection laws.
Such safeguards may include:
- adequacy decisions adopted by the European Commission;
- Standard Contractual Clauses (SCCs);
- other transfer mechanisms recognized under applicable data protection legislation.
VISAC evaluates international transfers considering the destination country, applicable legal framework and required protection measures.
14. Data Lifecycle Management
VISAC considers data protection as a lifecycle responsibility rather than a single processing activity.
Collection
↓
Processing
↓
Protection
↓
Retention
↓
Deletion / Anonymization
Collection
Personal data is collected only through transparent and defined channels.
Processing
Data is processed only for legitimate purposes communicated to individuals.
Protection
Information is protected through appropriate technical and organizational measures.
Retention
Data is maintained only for the period necessary to achieve defined purposes or satisfy applicable requirements.
Deletion / Anonymization
When retention periods expire, data is securely deleted or anonymized according to applicable procedures.
15. Data Retention
VISAC retains personal data only for the period necessary to achieve the purposes for which it was collected.
Retention periods depend on factors including:
- nature of the data;
- purpose of processing;
- legal obligations;
- contractual requirements;
- security considerations;
- dispute resolution requirements.
The retention periods described below are indicative and may vary where longer retention is required by law, contractual obligations, dispute resolution or security requirements.
Contact Requests
Personal data related to information requests and business inquiries may be retained for up to 24 months, unless a longer period is required or justified.
Marketing Communications
Data used for marketing communications is retained until consent is withdrawn or according to applicable legal requirements.
Legal and Regulatory Obligations
Data required for compliance purposes is retained for the period established by applicable legislation.
Security Information
Technical and security-related information may be retained for the period necessary to protect systems, investigate events and maintain operational security.
At the end of applicable retention periods, personal data is deleted or anonymized.
16. Data Subject Rights
Individuals may exercise the rights recognized under applicable data protection legislation, including Articles 15–22 of the GDPR.
These rights include:
- the right to obtain access to personal data;
- the right to request rectification of inaccurate information;
- the right to request erasure where applicable;
- the right to request restriction of processing;
- the right to object to certain processing activities;
- the right to data portability where applicable;
- the right to withdraw consent;
- the right not to be subject, where applicable, to decisions based solely on automated processing.
To exercise these rights, individuals may contact VISAC using the information provided in this Framework.
17. Accountability and Governance Responsibility
VISAC considers accountability a fundamental principle of responsible data governance.
The company maintains appropriate processes designed to ensure that personal data processing activities are conducted transparently, lawfully and consistently with applicable regulatory requirements.
Accountability principles are embedded within VISAC governance practices, security measures, operational controls and oversight mechanisms.
VISAC considers governance responsibility an essential component of trustworthy technology development and responsible innovation.
18. Supervisory Authority Complaints
VISAC is committed to handling personal data in accordance with applicable data protection laws and recognized privacy principles.
If an individual believes that the processing of personal data carried out by VISAC violates applicable regulations, the individual has the right to lodge a complaint with the competent supervisory authority.
For individuals located in Italy, complaints may be submitted to:
Garante per la Protezione dei Dati Personali
or to the competent supervisory authority of the country where the individual resides, works or where the alleged violation occurred, where applicable.
The right to lodge a complaint does not affect any other administrative or judicial remedies available under applicable law.
19. Cookies and Tracking Technologies
VISAC may use cookies and similar technologies to support the operation, security and performance of its digital services.
Cookies may be used for purposes including:
- ensuring website functionality;
- maintaining security;
- improving user experience;
- analysing website performance;
- supporting digital service optimization.
The use of cookies and similar technologies is governed by the principles of:
- transparency;
- user choice;
- consent management;
- responsible data use.
Where required by applicable law, non-essential cookies are activated only following valid user consent.
Users may manage cookie preferences through available consent management tools or browser settings.
Further information regarding cookie categories, technologies and preference management is available in:
20. Updates to this Framework
VISAC may update this Privacy Policy & Data Protection Framework™ to reflect:
- changes in applicable laws or regulatory requirements;
- developments in technology;
- changes to VISAC services or operational practices;
- improvements to governance processes.
Material changes may be highlighted through appropriate notices where required by applicable law.
The updated version will be published on this page together with the corresponding revision date.
VISAC encourages users to periodically review this Framework to remain informed about how personal data is governed and protected.
21. Contact Information
VISAC welcomes privacy-related inquiries, requests and concerns.
Individuals may contact the Data Controller using the following information:
VISAC Technologies Srl
Registered Office:
Via Montenapoleone, Milan, Italy
VAT / Tax Identification Number:
IT0012536208
Email:
info@visactechnologies.com
Italian Translation
An Italian translation of this Framework may be provided for convenience purposes.
In the event of any inconsistency or conflict between the English version and any translated version, the English version shall prevail to the extent permitted by applicable law.
Document Status
VISAC Privacy Policy & Data Protection Framework™
Framework Version:
1.1.1
Document Classification:
Public Corporate Governance Document
Status:
Approved for publication