Contact DEC

Privacy policy

Processing of personal data collected through this website.

Last updated: 12 August 2026.

1. Data controller

The data controller is Digital Equipment Communication Srl, registered office at Via Giosuè Carducci 26, 20123 Milan, Italy, VAT number IT10027400968.

For anything relating to this policy or to your data, write to [email protected].

2. Data collected and purposes

Contact form

Data Purpose Legal basis Retention
Company, full name, email, phone (optional), service of interest, message Replying to your enquiry and, if you wish, starting a commercial evaluation Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract 24 months from the last contact, unless a contractual relationship begins

Fields marked with an asterisk are needed to handle your enquiry; without them we cannot reply. Please do not put special category data (Art. 9 GDPR) or confidential information in the message field — that is what SecureShare is for.

Server logs

Like any web server, ours records the IP address, date and time of the request, the page requested, the outcome and the browser type. We use these only to keep the infrastructure secure and to diagnose faults, on the basis of our legitimate interest in keeping the service available and protected (Art. 6(1)(f) GDPR). Logs are kept for up to 12 months.

Cookies and local storage

This website uses no profiling, advertising or analytics cookies and hosts no third-party tracking. The only thing stored on your device is a local-storage entry recording that you have already dismissed the cookie notice, so it is not shown again on every visit. It is technical, stays in your browser, is never transmitted to us, and requires no consent under Art. 122 of the Italian Privacy Code. You can remove it at any time by clearing the site data in your browser settings.

3. Data recipients

We do not sell, rent or trade your data. It is accessible only to authorised DEC staff and to the suppliers who process it on our behalf as processors under Art. 28 GDPR:

  • Basin (Ecomsend LLC, United States) — receives and forwards submissions from the contact form.
  • Our website hosting provider — serves the pages and keeps the server logs.
  • Our email provider — delivers and stores the correspondence that follows.

We may also disclose data to judicial or supervisory authorities where the law requires it.

4. Transfers outside the European Economic Area

Basin, which handles contact-form submissions, is provided by a company based in the United States. The transfer relies on the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR). You may request a copy at the address in section 1. If you would rather avoid this transfer altogether, contact us directly by email or phone instead of using the form.

5. Your rights

At any time you can ask us to:

  • give you access to your data and a copy of it (Arts. 15 and 20);
  • correct it if it is inaccurate or incomplete (Art. 16);
  • erase it or restrict how it is processed (Arts. 17 and 18);
  • object to processing based on legitimate interest (Art. 21).

Write to [email protected] and we will respond within 30 days. If you believe the processing breaches the law, you may lodge a complaint with the Italian Data Protection Authority or with the supervisory authority where you live.

6. Security

The site is served over HTTPS only and applies a restrictive Content Security Policy, HSTS and the other security headers that good practice calls for. Access to the data we collect is limited to the staff who need it for their work. No measure removes risk entirely, but these are the same controls we recommend to our own clients.

7. Automated decision-making

We carry out no profiling and no automated decision-making within the meaning of Art. 22 GDPR. Enquiries sent through the form are read by a person.

8. Reporting a vulnerability

If you have found a vulnerability in this website or in one of our services, write to us at [email protected]. We reply within three working days and keep you posted until the report is closed.

We ask that you do not disclose the vulnerability publicly before it has been fixed, do not access data that is not yours, and do not degrade our services while testing. We will take no legal action against anyone who follows these guidelines and, if they wish, we will publicly credit their contribution.

The machine-readable contacts, following the RFC 9116 standard, are published in security.txt (plain text file).

9. Changes to this policy

If we change how we handle data we will update this page and the date shown at the top. Substantial changes will be flagged prominently on the site.