Legal & Compliance
Privacy Policy
Last updated: September 2026 • Effective for DigitalWarden S.r.l. (Italy / EU)
At DigitalWarden, we prioritize transparency and the protection of your personal information. This Privacy Policy describes how DigitalWarden S.r.l. («DigitalWarden», «we», «us») collects, processes, and safeguards personal data when you visit our website (digitalwarden.xyz) or engage our digital engineering and cybersecurity services, in compliance with the General Data Protection Regulation (EU Regulation 2016/679 – «GDPR»).
1. Data Controller
The Data Controller responsible for processing your personal data is DigitalWarden S.r.l., registered in Italy.
For any questions, data subject requests, or regulatory inquiries, you can reach our team directly at privacy@digitalwarden.xyz.
2. Information We Collect
We only collect information necessary to provide our services and operate securely:
- Contact & Identification Information: Name, business email address, company name, phone number, and project details provided when you submit a contact inquiry or request a proposal.
- Technical & Connection Logs: Anonymized IP addresses, browser specifications, access timestamps, and HTTP request headers necessary for server security and network diagnostics.
- Client Deliverable Data: Technical requirements and architecture notes shared strictly in the context of professional consulting engagements.
We do not collect sensitive data under Article 9 GDPR (such as health, biometric, or political data) or data relating to criminal convictions.
3. Legal Basis and Purposes of Processing
We process personal data only when an explicit legal basis under Article 6 GDPR applies:
- Contract Execution (Art. 6.1.b): To formulate quotes, deliver web development and cybersecurity projects, and manage client communications.
- Legitimate Interest (Art. 6.1.f): To maintain infrastructure resilience, prevent DDoS attacks, monitor system performance, and safeguard intellectual property.
- Legal Obligation (Art. 6.1.c): To comply with applicable tax, accounting, corporate governance, and statutory disclosure requirements.
- Consent (Art. 6.1.a): For optional telemetry or non-essential cookies, which may be withdrawn at any time.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to satisfy statutory obligations:
| Data Category | Retention Period | Primary Purpose |
|---|---|---|
| Invoices & Commercial Contracts | 10 Years | Tax & statutory compliance |
| Contact Requests & Proposals | 24 Months | Pre-contractual follow-up |
| Security Logs & Access Telemetry | 180 Days | Network defence & integrity |
| Cookie Preferences | 12 Months | Consent storage |
5. Security Measures
In accordance with Article 32 GDPR, we apply appropriate technical and organizational safeguards:
- Strict transport layer security (TLS 1.3 encryption) for all data in transit.
- Role-based access controls (RBAC) with multi-factor authentication for internal systems.
- Encrypted database storage and regular automated snapshot backups located within EU regions.
6. Your Rights Under GDPR
Pursuant to Articles 15–22 of the GDPR, you have the right to:
- Access: Request confirmation of whether your personal data is being processed and obtain a copy.
- Rectification: Request correction of inaccurate or incomplete personal records.
- Erasure: Request the deletion of your personal data («right to be forgotten»), subject to legal retention obligations.
- Restriction & Objection: Limit or object to data processing carried out under legitimate interests.
- Portability: Receive your data in a structured, commonly used, machine-readable format.
7. Contact & Inquiries
To exercise any of your statutory rights or if you have any questions regarding how your data is handled, please contact us at privacy@digitalwarden.xyz.
You also have the right to lodge a complaint with your local supervisory authority (in Italy, the Garante per la protezione dei dati personali).