Legal & Compliance

Privacy Policy

Last updated: September 2026 • Effective for DigitalWarden S.r.l. (Italy / EU)


At DigitalWarden, we prioritize transparency and the protection of your personal information. This Privacy Policy describes how DigitalWarden S.r.l. («DigitalWarden», «we», «us») collects, processes, and safeguards personal data when you visit our website (digitalwarden.xyz) or engage our digital engineering and cybersecurity services, in compliance with the General Data Protection Regulation (EU Regulation 2016/679 – «GDPR»).

1. Data Controller

The Data Controller responsible for processing your personal data is DigitalWarden S.r.l., registered in Italy.

For any questions, data subject requests, or regulatory inquiries, you can reach our team directly at privacy@digitalwarden.xyz.

2. Information We Collect

We only collect information necessary to provide our services and operate securely:

  • Contact & Identification Information: Name, business email address, company name, phone number, and project details provided when you submit a contact inquiry or request a proposal.
  • Technical & Connection Logs: Anonymized IP addresses, browser specifications, access timestamps, and HTTP request headers necessary for server security and network diagnostics.
  • Client Deliverable Data: Technical requirements and architecture notes shared strictly in the context of professional consulting engagements.

We do not collect sensitive data under Article 9 GDPR (such as health, biometric, or political data) or data relating to criminal convictions.

3. Legal Basis and Purposes of Processing

We process personal data only when an explicit legal basis under Article 6 GDPR applies:

  • Contract Execution (Art. 6.1.b): To formulate quotes, deliver web development and cybersecurity projects, and manage client communications.
  • Legitimate Interest (Art. 6.1.f): To maintain infrastructure resilience, prevent DDoS attacks, monitor system performance, and safeguard intellectual property.
  • Legal Obligation (Art. 6.1.c): To comply with applicable tax, accounting, corporate governance, and statutory disclosure requirements.
  • Consent (Art. 6.1.a): For optional telemetry or non-essential cookies, which may be withdrawn at any time.

4. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to satisfy statutory obligations:

Data CategoryRetention PeriodPrimary Purpose
Invoices & Commercial Contracts10 YearsTax & statutory compliance
Contact Requests & Proposals24 MonthsPre-contractual follow-up
Security Logs & Access Telemetry180 DaysNetwork defence & integrity
Cookie Preferences12 MonthsConsent storage

5. Security Measures

In accordance with Article 32 GDPR, we apply appropriate technical and organizational safeguards:

  • Strict transport layer security (TLS 1.3 encryption) for all data in transit.
  • Role-based access controls (RBAC) with multi-factor authentication for internal systems.
  • Encrypted database storage and regular automated snapshot backups located within EU regions.

6. Your Rights Under GDPR

Pursuant to Articles 15–22 of the GDPR, you have the right to:

  • Access: Request confirmation of whether your personal data is being processed and obtain a copy.
  • Rectification: Request correction of inaccurate or incomplete personal records.
  • Erasure: Request the deletion of your personal data («right to be forgotten»), subject to legal retention obligations.
  • Restriction & Objection: Limit or object to data processing carried out under legitimate interests.
  • Portability: Receive your data in a structured, commonly used, machine-readable format.

7. Contact & Inquiries

To exercise any of your statutory rights or if you have any questions regarding how your data is handled, please contact us at privacy@digitalwarden.xyz.

You also have the right to lodge a complaint with your local supervisory authority (in Italy, the Garante per la protezione dei dati personali).