Privacy Policy

Last updated 7 September 2026

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Privacy Code”). It describes how Mative S.r.l. processes the personal data of natural persons (the “Data Subject”) who visit or interact with the website www.mative.cloud (the “Application”).

This notice covers the website. The Mative Cloud services supplied to customers are governed by separate agreements and, where Mative acts as a processor, by a data processing agreement under Article 28 GDPR.

1. Data Controller

  • Company name: Mative S.r.l.
  • Registered and operating office: Via San Pio da Pietrelcina 81, 83100 Avellino (AV), Italy
  • Tax code / VAT number: 03190070643
  • E-mail: info@mative.ai
  • Certified e-mail (PEC): mative@pec.cloud
  • Telephone: +39 0825 1920080

Data Protection Officer (DPO). Mative has not appointed a DPO, as the conditions set out in Article 37 GDPR are not met: the Controller's core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. For any data protection matter, please use the contact form with “Privacy” as the subject, or the contact details in § 1.

2. Categories of personal data processed

The Application hosts no contact forms, no questionnaire, no newsletter sign-up, no conversational assistant and no private area: there is nothing for the Data Subject to submit. Commercial and support enquiries are collected on www.mative.ai, which is governed by its own privacy notice.

The only value the Data Subject types in is the account code on the access page. On submission, the code and the anti-bot verification token are sent to the Controller’s server for the sole purpose of establishing that the request does not come from a script and that the code has a valid format: neither is stored in any record, and the check ends with the request itself. Once it passes, the Data Subject is redirected to the console (my.mative.cloud), which handles authentication entirely under the relevant agreement.

Data collected automatically:

  • technical and connection data: IP address, browser and operating system type and version, date and time of the request, referring page. These are recorded in the hosting provider's logs and used for infrastructure security;
  • interaction data collected by the Google reCAPTCHA anti-fraud system, loaded on the access page only, which analyses how the page is interacted with and certain device characteristics in order to distinguish a human from a script, and may store information on the device (see § 6);
  • usage statistics collected through Google Analytics, only where consent has been given via the cookie banner (see § 5).

The Application does not require account creation, does not host any payment process, and does not collect payment card details, bank account details or authentication credentials. Special categories of data (Article 9 GDPR) are neither requested nor knowingly processed.

3. Cookies and storage technologies

The Application uses cookies and other technologies that store information on the Data Subject's device. No non-essential technology is activated before express consent is given. Full details, including the table of every individual cookie and instructions for withdrawing consent, are set out in the Cookie Policy.

4. Purposes, legal bases and retention

# Purpose Legal basis Retention
a Security of the Application: anti-bot verification (reCAPTCHA) of the access page, logging of security-relevant events and protection of the infrastructure from automated abuse Art. 6(1)(f) GDPR — the Controller's legitimate interest in protecting its infrastructure Technical logs: 12 months
b Establishing, exercising or defending legal claims Art. 6(1)(f) GDPR — legitimate interest Duration of the dispute and until the time limits for appeal have expired
c Statistical measurement of website usage Art. 6(1)(a) GDPR and Art. 122 Privacy Code — consent given via the cookie banner See Cookie Policy

At the end of the retention periods, data is deleted or irreversibly anonymised.

Processing related to commercial enquiries, supply contracts, the newsletter and job applications is not carried out through this Application, which collects none of that data: it is described in the privacy notice of www.mative.ai.

Legitimate interest balancing. For purposes a) and b) the Controller has carried out a balancing assessment between its own interest and the rights of the Data Subject, concluding that the processing is limited to what is necessary and does not cause disproportionate prejudice. A summary of that assessment may be requested through the contact form, and the Data Subject in any event has the right to object under Article 21 GDPR (see § 10).

5. Usage statistics

Subject to consent given via the cookie banner, the Application uses Google Analytics 4, provided by Google Ireland Limited (Dublin, Ireland). The service collects pseudonymised — not anonymous — data on pages visited, session duration and navigation paths, in order to measure website usage in aggregate form.

If consent is not given, or is withdrawn, the Google Analytics script is not loaded and no analytics cookie is set. Mative has not enabled Google Signals or interest-based advertising features. Further information is available in the Google privacy policy.

The Google Maps map in the footer is not loaded automatically: it appears only after an express click on the relevant button, from which point Google's terms and privacy notice apply.

6. Recipients of personal data and transfers outside the European Economic Area

Personal data is processed by the Controller's authorised personnel, appropriately instructed and bound by confidentiality, and may be disclosed to the following recipients:

Recipient Role and activity Location Transfer safeguards
Amazon Web Services EMEA SARL Processor — hosting of the Application, CDN, perimeter protection European Union (Luxembourg) Processing within the EEA; Standard Contractual Clauses for any third-country access
Google Ireland Limited Processor — usage statistics (subject to consent); reCAPTCHA anti-bot verification on the access page; map service on user activation Ireland, with possible transfers to Google LLC (USA) EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses
E-mail and IT service providers, accounting, tax and legal advisers Processors or independent controllers, according to their role European Union
Judicial and administrative authorities Independent controllers, in the cases provided for by law Italy / EU

All processors are appointed under Article 28 GDPR and are contractually bound to process the data solely on the Controller's instructions, applying appropriate technical and organisational measures.

Where data is transferred outside the EEA, the Controller applies the safeguards provided for in Chapter V GDPR, as set out in the table above. A copy of the safeguards adopted may be requested through the contact form.

Personal data is never disseminated, sold or transferred to third parties for their own marketing purposes.

7. Automated decision-making and profiling

Pursuant to Article 13(2)(f) GDPR, the Controller does not carry out solely automated decision-making producing legal effects concerning the Data Subject or similarly significantly affecting them.

The Controller does not carry out profiling: the Application hosts no advertising technology, builds no individual profiles and sends no promotional communications.

8. Processing methods and security measures

Processing is carried out using electronic and, residually, paper-based tools, with logic strictly related to the stated purposes. The Controller applies technical and organisational measures appropriate under Article 32 GDPR, including: encryption of communications in transit (HTTPS), role-based access control, rate limiting on public forms, server-side input validation, segregation of application credentials, and logging of security-relevant events.

9. Minors

The Application is addressed to professionals, businesses and public bodies and is not intended for persons under sixteen years of age. The Controller does not knowingly collect personal data from minors. A holder of parental responsibility who believes a minor has provided their data may report this through the contact form and the data will be deleted without delay.

10. Rights of the Data Subject

The Data Subject has the right to:

  • access their personal data and obtain a copy of it (Art. 15);
  • obtain rectification of inaccurate data or completion of incomplete data (Art. 16);
  • obtain erasure of the data, in the cases provided for (Art. 17);
  • obtain restriction of processing (Art. 18);
  • receive their data in a structured format and obtain its portability to another controller (Art. 20);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
  • object to processing based on legitimate interest, on grounds relating to their particular situation (Art. 21(1)).

Withdrawing cookie consent. Consent given through the banner can be changed or withdrawn at any time via the “Cookies settings” link in the footer of every page of the website.

Requests may be submitted through the contact form, to the contact details in § 1, or to the certified e-mail address given there. The Controller responds within one month of receipt; that period may be extended by two further months where necessary, taking into account the complexity and number of requests, with reasoned notice given to the Data Subject within the first month (Article 12(3) GDPR). Exercising these rights is free of charge, save in the case of manifestly unfounded or excessive requests.

11. Complaint to the supervisory authority

A Data Subject who considers that the processing of their personal data infringes applicable law has the right to lodge a complaint with the Italian supervisory authority:

Garante per la protezione dei dati personali Piazza Venezia 11 — 00187 Rome, Italy www.garanteprivacy.itprotocollo@pec.gpdp.it

without prejudice to the right to an effective judicial remedy (Articles 77 and 79 GDPR).

12. Changes to this notice

The Controller may update this notice to reflect legislative changes or the evolution of the services offered. The version in force is always published on this page, with the date of the last update. Where changes materially affect processing based on consent, the Controller will highlight them and, where necessary, obtain consent again.

Top ^