Privacy notice

Privacy Policy
of goodea.

Notice pursuant to Articles 13 and 14 of EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as subsequently amended (Italian Privacy Code).

Last updated: 1 May 2026 · Version: 1.0

01 — Data Controller

Who processes
your data.

The Data Controller is Goodea S.r.l., with registered office at Via Toledo 156, 80134 Naples (NA), Italy, VAT and Tax Code 06876751212.

For any request relating to personal data, you may contact us at:

Goodea S.r.l. has not appointed a Data Protection Officer (DPO), as this is not required under Article 37 GDPR.

02 — Types of data collected

What data
we collect.

Depending on your interactions with the website www.goodea.it, we may collect the following categories of personal data:

BROWSING DATA

IP address (anonymised), browser type, operating system, pages visited, date and time of visit, referring website. Collected automatically by computer systems.

VOLUNTARILY PROVIDED DATA

Data you share by completing the contact form, writing to one of our email addresses or requesting a quote: first name, last name, email, phone (optional), company, role, message content.

COOKIES AND SIMILAR TECHNOLOGIES

Technical cookies and, subject to consent, analytical cookies (Google Analytics 4). The full list of cookies and how to manage them can be found in the Cookie Policy.

03 — Purposes and legal bases

Why we process
your data.

Your personal data is processed for the purposes listed below, each based on a specific legal ground pursuant to Article 6 GDPR.

A · RESPONDING TO REQUESTS

Contact and quote management

Legal basis: performance of pre-contractual measures at your request (Art. 6.1.b GDPR). Retention: for the time necessary to fulfil the request and thereafter for 24 months, unless a contractual relationship is subsequently established.

B · PERFORMING CONTRACTS

Service delivery

Legal basis: performance of a contract (Art. 6.1.b GDPR). Retention: for the duration of the contract and thereafter 10 years for civil and tax obligations (Arts. 2220 of the Civil Code and 22 of Presidential Decree 600/1973).

C · IMPROVING THE WEBSITE

Aggregate analytics

Legal basis: consent (Art. 6.1.a GDPR) via the cookie banner. Retention: 14 months (Google Analytics 4 default setting). Consent may be withdrawn at any time via the cookie banner.

D · LEGAL OBLIGATIONS

Regulatory compliance

Legal basis: legal obligation (Art. 6.1.c GDPR). Retention: for the periods prescribed by applicable regulations (e.g., invoicing 10 years, anti-money laundering 10 years).

04 — Processing methods

How we process
your data.

Data is processed using electronic and paper-based tools, in accordance with the adequate technical and organisational measures required by Article 32 GDPR. In particular:

  • — HTTPS connections with mandatory TLS 1.3
  • — access to systems restricted to authorised personnel appointed as Data Processors
  • — periodic encrypted backups
  • — firewall, intrusion monitoring and regular security updates
  • — strong password policies and two-factor authentication on critical systems

No automated processing with legal effects on data subjects or profiling activities within the meaning of Article 22 GDPR are carried out.

05 — Recipients and external processors

Who we share
data with.

Your data may be shared with the following recipients, all appointed as Data Processors pursuant to Article 28 GDPR and bound by specific contractual guarantees:

WEB HOSTING

Ergonet S.r.l.

Servers located in the European Union. Processing for the sole purpose of providing the hosting service.

EMAIL AND PEC

Email service providers

Providers with EU-based servers for managing institutional mailboxes (direzione@, commerciale@) and PEC (goodea.srl@pec.it).

ANALYTICS

Google Ireland Ltd. (Google Analytics 4)

Processing only with prior consent. Anonymised IP. Transfer outside the EU governed by Standard Contractual Clauses and the EU-US Data Privacy Framework (EU Adequacy Decision of 10 July 2023).

PROFESSIONALS

Accountant, employment consultant, legal advisors

For accounting, tax, contractual and rights-protection obligations. All bound by professional secrecy and appointed as Data Processors.

Your data is not disclosed to unspecified third parties and is not sold to third parties for marketing purposes other than those declared herein.

06 — Transfers outside the EU

Transfers
outside the EU.

The use of Google Analytics 4 may involve the transfer of personal data (anonymised IP and session identifiers) to Google LLC servers in the United States of America. Such transfer is governed by:

  • Adequacy Decision of the European Commission dated 10 July 2023 (EU-US Data Privacy Framework), certifying an adequate level of protection for participating US companies
  • Standard Contractual Clauses (SCC) approved by EU Decision 2021/914
  • Additional technical measures: IP anonymisation, disabling of Google Signals and ad personalisation
07 — Your rights

What you can
ask us.

As a data subject, you have the right to exercise at any time the following rights provided by Articles 15–22 GDPR:

  • Access (Art. 15) — find out whether we process your data and obtain a copy
  • Rectification (Art. 16) — correct inaccurate or incomplete data
  • Erasure (Art. 17) — request the removal of your data ("right to be forgotten")
  • Restriction (Art. 18) — limit processing in certain circumstances
  • Portability (Art. 20) — receive your data in a structured format and transmit it to another controller
  • Objection (Art. 21) — object to processing on legitimate grounds
  • Withdrawal of consent (Art. 7.3) — at any time, without prejudice to processing already carried out

To exercise your rights, write to direzione@goodea.it or send a PEC to goodea.srl@pec.it. We will respond within 30 days of receiving your request.

08 — Complaint to the Supervisory Authority

Right
to lodge a complaint.

If you believe that the processing of your personal data violates EU Regulation 2016/679, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante), pursuant to Article 77 GDPR and Article 141 of Legislative Decree 196/2003.

GARANTE PRIVACY

Piazza Venezia 11, 00187 Rome · Switchboard +39 06.69677.1 · www.garanteprivacy.it

09 — Changes

Updates
to this policy.

This Privacy Policy may be updated at any time to reflect regulatory, organisational or technical changes. The version in force is always the one published on this page. The date of the last update is indicated at the top. Any material changes will be notified via a notice on the website.

Any questions?

Write to us at
direzione@goodea.it.

Contact us →