Website privacy and cookies

Last updated: 5 September 2026

This notice explains how Nuratronics Srl processes personal data when you visit this website, send a general enquiry, or report a potential security vulnerability. It does not cover personal data processed inside our published mobile applications, which have separate privacy policies.

1. Data controller

Nuratronics Srl
Via Suor Maria Pelletier 4
20900 Monza (MB), Italy
VAT and tax code: IT12606540966
Email: info@nuratronics.eu

Use the email address above for privacy questions and to exercise your data-protection rights.

2. Data processed when you visit

When your browser requests a page, the hosting and network systems may process technical information needed to deliver and protect the website, such as:

We process this information to deliver the website, maintain its availability and security, investigate faults and abuse, and establish or defend legal claims. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in operating a reliable and secure website.

3. General enquiries

When you use the contact form, we receive the subject, reply email address, message, and related delivery metadata. We use them to review and answer your request and to keep any necessary business correspondence.

When an individual contacts us about a contract to which that individual is, or may become, a party, the legal basis is Article 6(1)(b) GDPR, including steps taken at the individual's request before entering into a contract. For enquiries made on behalf of a company, and for other general communications, the basis is our legitimate interest under Article 6(1)(f) GDPR in communicating with people who contact us and managing our business relationships.

The subject, reply email address, and message are required to submit the form. Without them, we cannot receive or answer the request. Please do not include personal data that is not needed for your enquiry.

4. Security vulnerability reports

When you use our security-reporting form or report a potential security vulnerability to security@nuratronics.eu, we may process:

We use this information to receive and authenticate reports, investigate and reproduce issues, coordinate remediation and disclosure, protect users and systems, comply with applicable cybersecurity obligations, and establish or defend legal claims.

Our legal basis for receiving, investigating, and coordinating security reports is our legitimate interest under Article 6(1)(f) GDPR in maintaining product and user security. Article 6(1)(c) GDPR applies only to processing necessary for compliance with a legal obligation that directly binds Nuratronics Srl.

Where Stonex Srl or TopoGEOS is the relevant legal manufacturer, it may separately rely on Article 6(1)(c) GDPR for processing necessary to fulfil its own applicable vulnerability-handling and reporting duties, including duties under the EU Cyber Resilience Act when they apply.

Please do not send unnecessary personal data, credentials, customer records, or confidential information. If evidence must contain sensitive material, tell us first so that we can agree on a safer transfer method.

The reporting form uses a short-lived, locally generated submission pass to slow automated abuse. Your browser performs a small proof-of-work calculation and sends the result only to the Nuratronics server. The check uses no cookie or browser storage and contacts no outside verification provider.

5. Recipients

Access is limited to people who need the information for the purposes described above. Depending on the activity, recipients may include:

When Stonex Srl or TopoGEOS receives a report for its own product and decides how to fulfil its own legal responsibilities, it may act as a separate controller for that processing.

6. International transfers

Some technical or email service providers may process data outside the European Economic Area. Where this occurs, we use a transfer mechanism permitted by Chapter V GDPR, such as an adequacy decision or appropriate safeguards including the European Commission's standard contractual clauses, together with supplementary measures where required. Contact us for information about the safeguard applicable to a particular transfer.

7. Retention

We keep personal data only for as long as necessary for the relevant purpose:

Data is deleted or anonymised when it is no longer required, unless the law requires further retention.

8. Cookies and similar technologies

The public website and public security-reporting form do not intentionally use cookies, browser local storage, advertising pixels, analytics trackers, device fingerprinting, or other non-essential technology that stores information on or reads information from your device.

Technical request and security information processed by the web server, as described in section 2, is not used to profile visitors or deliver targeted advertising.

Under Article 122 of Legislative Decree 30 June 2003, No. 196 (the Italian Personal Data Protection Code), which implements the ePrivacy Directive's terminal-access rule in Italy, strictly necessary technical cookies and similar technologies may be used without consent but must be disclosed. Non-essential technologies will not be activated unless the visitor has provided valid consent in accordance with Articles 4(11) and 7 GDPR.

Because no non-essential technology is currently used, the website does not display a consent banner. If that changes, non-essential technology will remain disabled until you make a choice. The website will provide clear Accept all, Reject all, and granular settings, together with an accessible way to change or withdraw your choice later.

The optional read-aloud control prefers text-to-speech voices that your browser identifies as installed locally on your device. If no local English voice is available, it may offer voices provided by your browser or operating system that could use an online speech service; these are labelled may be online. Reading starts only when you select Read aloud. An online service may receive the public notice text and technical network information under its provider's terms. Nuratronics does not receive speech data or store your voice choice.

The security-reporting form's local submission-pass calculation uses no cookie or browser storage and sends its result only to the Nuratronics server.

We review cookies, browser storage, pixels, embedded third-party content, and similar technology before each website release and update this notice when their use changes.

9. Your rights

Subject to the conditions in applicable data-protection law, you may ask us to:

Where processing is based on consent, you may withdraw it at any time without affecting processing performed before withdrawal. We do not use solely automated decision-making that produces legal or similarly significant effects through this website.

To exercise a right, email info@nuratronics.eu. We may request information needed to verify your identity and locate the relevant data.

10. Complaints

You may lodge a complaint with the Garante per la protezione dei dati personali, the Italian data-protection authority, or another competent supervisory authority in the country where you live or work or where you believe an infringement occurred.

11. Changes to this notice

We will update this page when our processing, service providers, legal requirements, or use of cookies and similar technologies changes. The date at the top identifies the current version.

Back to home
Nuratronics