PLATFORM ERP Finance, CRM, HR, inventory, projects TALON Tickets, chat, knowledge base Webmail Email, calendar, contacts
SECURITY & IDENTITY VIGILANTE EDR for Windows endpoints Auris IAM-as-a-Service EU Auris Comply Compliance & audit trail NIS2/DORA
Featured Auris IAM Identity & Access Management One European control plane for adaptive MFA, federated SSO, and immutable audit trails. Explore →
COMPUTE Hosting Shared PHP/MySQL hosting on EU infrastructure VPS Virtual private servers
NETWORK & SECURITY Domains Domain registration & transfer Load Balancer Traffic balancing TLS Managed TLS certificates
STORAGE & DATABASE Object Storage S3-compatible EU storage Block Storage Block storage volumes Managed Databases Managed MySQL, PostgreSQL, MongoDB
MESSAGING & EMAIL Mailboxes Email hosting for business domains Go to console → cloud.altovar.net
DEVELOPMENT Web Development Web applications, SaaS & custom portals — from UI to production deploy. Software Development Custom software, API integrations, automations & scalable architectures for your business. IT & Systems On-site physical infrastructure, Dell PowerEdge servers, maintenance & systems support.
SECURITY & CONSULTING Cybersecurity Penetration testing, vulnerability assessment, incident response & NIS2/DORA/GDPR compliance. IT Consulting Technology roadmap, infrastructure audit & strategic advisory for CTOs and decision makers.
GROWTH & INNOVATION Marketing Digital strategy, SEO, campaigns, brand identity & EU-focused content marketing. Artificial Intelligence AI integration, autonomous agents & intelligent systems for enterprise processes. Machine Learning Custom models, data pipelines & bespoke ML solutions for your industry.
01 NIS2 & DORA

EU compliance for critical infrastructure — audit trail, encryption, incident reporting.

Explore →
02 MSP

Multi-tenant management, PULSE, Vigilante & Citadel in a single console.

Explore →
03 Enterprise

Operational security, IAM, office suite & EU infrastructure for large organisations.

Explore →
04 Research

Threat intelligence, R&D & advanced tools for European security teams.

Explore →
COMPANY CompanyCareersNewsContacts
TRUST Partner ProgramTrust & SecurityRoadmapPress / Media
Log in Request Demo
PLATFORM ERPFinance, CRM, HR, inventory, projectsTALONTickets, chat, knowledge baseWebmailEmail, calendar, contacts
SECURITY & IDENTITY VIGILANTEEDR for Windows endpointsAurisIAM-as-a-Service EUAuris ComplyCompliance & audit trail NIS2/DORA
COMPUTE HostingShared PHP/MySQL hosting on EU infrastructureVPSVirtual private servers
NETWORK & SECURITY DomainsDomain registration & transferLoad BalancerTraffic balancingTLSManaged TLS certificates
STORAGE & DATABASE Object StorageS3-compatible EU storageBlock StorageBlock storage volumesManaged DatabasesManaged MySQL, PostgreSQL, MongoDB
MESSAGING & EMAIL MailboxesEmail hosting for business domains
DEVELOPMENT Web DevelopmentWeb applications, SaaS & custom portals — from UI to production deploy.Software DevelopmentCustom software, API integrations, automations & scalable architectures for your business.IT & SystemsOn-site physical infrastructure, Dell PowerEdge servers, maintenance & systems support.
SECURITY & CONSULTING CybersecurityPenetration testing, vulnerability assessment, incident response & NIS2/DORA/GDPR compliance.IT ConsultingTechnology roadmap, infrastructure audit & strategic advisory for CTOs and decision makers.
GROWTH & INNOVATION MarketingDigital strategy, SEO, campaigns, brand identity & EU-focused content marketing.Artificial IntelligenceAI integration, autonomous agents & intelligent systems for enterprise processes.Machine LearningCustom models, data pipelines & bespoke ML solutions for your industry.
01NIS2 & DORAEU compliance for critical infrastructure — audit trail, encryption, incident reporting.02MSPMulti-tenant management, PULSE, Vigilante & Citadel in a single console.03EnterpriseOperational security, IAM, office suite & EU infrastructure for large organisations.04ResearchThreat intelligence, R&D & advanced tools for European security teams.
COMPANY CompanyCareersNewsContacts
TRUST Partner ProgramTrust & SecurityRoadmapPress / Media
Log in → Request Demo
CONTENTS 01 Data Controller 02 Data Protection Officer 03 Personal Data We Collect 04 Special Categories of Data 05 Legal Basis for Processing 06 Data Retention 07 Sub-processors & Third Parties 08 International Data Transfers 09 Your Rights Under GDPR 10 Exercising Your Rights 11 Cookies & Tracking Technologies 12 Security & Incident Response 13 Children's Privacy 14 Changes to This Policy
Cookie Policy → Terms of Service → Legal Notices → Data Processing & GDPR →
LEGAL · PRIVACY

Privacy Policy

Last updated: 2026-04-04 · Version 2.0

Jurisdiction: European Union — GDPR Regulation (EU) 2016/679

TABLE OF CONTENTS
01 Data Controller 02 Data Protection Officer 03 Personal Data We Collect 04 Special Categories of Data 05 Legal Basis for Processing 06 Data Retention 07 Sub-processors & Third Parties 08 International Data Transfers 09 Your Rights Under GDPR 10 Exercising Your Rights 11 Cookies & Tracking Technologies 12 Security & Incident Response 13 Children's Privacy 14 Changes to This Policy
Cookie Policy → Terms of Service → Legal Notices → Data Processing & GDPR →
EU Data Residency & GDPR Commitment

As an EU-incorporated company, Altovar processes all personal data exclusively in accordance with GDPR. Your data is stored on EU infrastructure. Our Data Protection Officer is reachable at [email protected] and responds personally to every enquiry.

01 Art. 13 GDPR

Data Controller

Altovar S.r.l. (P.IVA IT03086750993) ("Altovar", "we", "us", or "our") is the data controller responsible for the processing of personal data collected through our websites, software products, APIs, and services (collectively, "Services").

Registered Office: Italy (European Union)
Privacy Enquiries: [email protected]
General Contact: [email protected]

As a company incorporated and operating within the EU, we are subject to Regulation (EU) 2016/679 (General Data Protection Regulation) in its entirety. Our supervisory authority is the Garante per la protezione dei dati personali (Italy).
02 Art. 37–39 GDPR

Data Protection Officer

Altovar has appointed a Data Protection Officer (DPO) as required under Article 37 of the GDPR, given the nature and scale of our data processing activities.

DPO Contact: [email protected]

The DPO operates independently and is responsible for:
— Monitoring compliance with the GDPR and applicable national data protection law
— Advising on Data Protection Impact Assessments (DPIAs) under Article 35
— Acting as the contact point for the supervisory authority
— Handling data subject enquiries and rights requests

You may contact the DPO directly for any matter relating to the processing of your personal data. All communications are treated confidentially and responded to within 30 calendar days.
03 Art. 13(1)(d) GDPR

Personal Data We Collect

We collect only the personal data that is necessary for the purposes described in this Policy (the principle of data minimisation, Art. 5(1)(c) GDPR).

Account and identity data: Name, email address, username, organisation name, job title, VAT/fiscal number for invoicing, and any information you voluntarily add to your profile.

Usage and interaction data: Features used, pages visited, clicks, session duration, search queries within the product, and error events. This data is collected in aggregate where possible and pseudonymised at ingestion.

Technical and device data: IP address (truncated to /24 prefix and anonymised within 24 hours), browser type and version, operating system, device type, screen resolution, referring URL, and session identifiers assigned by our infrastructure.

Communications data: Content of messages you send us via email, contact forms, or support tickets; metadata about those communications (timestamps, subject lines).

Payment and billing data: Billing name, address, and VAT/fiscal number. Card numbers and payment credentials are processed exclusively by our PCI-DSS Level 1 certified payment processor (Stripe, EU-hosted) and are never stored or processed by Altovar's systems.

Contractual and service data: Subscription tier, service configuration, usage quotas, API keys (hashed), and any data you upload or create while using the Services.

We do not collect data from third-party data brokers, social media platforms, or ad networks. We do not build advertising profiles.
04 Art. 9 GDPR

Special Categories of Data

Our Services are not designed to collect or process special categories of personal data as defined under Article 9(1) of the GDPR — including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, or data concerning a person's sex life or sexual orientation.

We strongly advise against uploading or processing special-category data using our Services unless you have implemented appropriate safeguards and have a valid legal basis under Article 9(2) GDPR.

If we inadvertently receive special-category data (for example, through a support ticket), we will delete it securely and notify the sender. If you need to process special-category data as part of a specific enterprise arrangement, please contact [email protected] to discuss appropriate contractual and technical safeguards.
05 Art. 6 GDPR

Legal Basis for Processing

We process personal data only when a valid legal basis exists under Article 6 of the GDPR. The applicable basis depends on the specific processing activity:

Performance of a contract (Art. 6(1)(b)): Provisioning the Services you have subscribed to, managing your account, processing payments, issuing invoices, and fulfilling all contractual obligations. This is the primary basis for most processing related to active accounts.

Legal obligation (Art. 6(1)(c)): Compliance with applicable law — including fiscal and accounting obligations under Italian law (D.P.R. 633/1972, D.P.R. 600/1973), anti-money-laundering requirements, and responses to lawful requests from competent public authorities (courts, regulators).

Legitimate interests (Art. 6(1)(f)): Security monitoring, abuse prevention, fraud detection, product improvement analytics, and direct marketing to existing customers for substantially similar services. We have carried out a legitimate interests assessment (LIA) for each such purpose and determined that our interests do not override your fundamental rights and freedoms.

Consent (Art. 6(1)(a)): Optional analytics and performance cookies, marketing communications to non-customers, and any processing activity for which we have expressly sought your prior consent. You may withdraw consent at any time — withdrawal does not affect the lawfulness of processing carried out before withdrawal. See Section 9 on how to withdraw consent.
06 Art. 5(1)(e) GDPR

Data Retention

We retain personal data only for as long as necessary for the stated purpose and in compliance with applicable legal obligations (storage limitation principle).

Data CategoryRetention PeriodLegal Basis
Account and profile dataDuration of contract + 5 years post-terminationContract / Legal obligation
Technical logs (identifiable)90 days, then anonymised or deletedLegitimate interests
Support communications3 years from last interaction (or longer if active dispute)Contract / Legitimate interests
Payment and invoicing records10 years (D.P.R. 633/1972, D.P.R. 600/1973)Legal obligation
Marketing consent recordsUntil withdrawal or 2 years from last interactionConsent
Security event logs12 months, then aggregatedLegitimate interests
Data subject rights request records3 years (compliance documentation)Legal obligation

Upon expiry of the applicable retention period, data is securely deleted or irreversibly anonymised using industry-standard methods so it can no longer be attributed to an identified or identifiable natural person.
07 Art. 28 GDPR

Sub-processors & Third Parties

We engage trusted third-party processors ("sub-processors") under binding data processing agreements that comply with Article 28 of the GDPR. We are responsible for the GDPR compliance of our sub-processors and carry out periodic due diligence.

Sub-processorPurposeLocationSafeguard
StripePayment processingEU (Dublin, Ireland)Article 28 DPA · PCI-DSS L1
GitHub / MicrosoftSource code hostingEU regionArticle 28 DPA · SCCs
Postmark / ActiveCampaignTransactional email deliveryEU regionArticle 28 DPA
Hetzner Online GmbHPrimary cloud infrastructureGermany / FinlandArticle 28 DPA · EU jurisdiction
CloudflareCDN · DDoS protectionEU network entryArticle 28 DPA · SCCs · EU DPA

We do not sell, rent, or trade your personal data to third parties. We do not share data with advertising networks or data brokers. We may share data with public authorities only when required by law or valid legal process, and we notify affected users where legally permissible.

An up-to-date sub-processor list is available on request at [email protected]. We provide 30 days' notice of new sub-processor additions.
08 Art. 44–49 GDPR

International Data Transfers

EU Data Residency Commitment: All primary data storage and processing takes place on infrastructure located within the European Economic Area (EEA). Altovar does not transfer personal data to third countries as a standard operational practice.

In the limited cases where a sub-processor operates infrastructure or support functions outside the EEA (for example, global CDN edge nodes or support personnel), we ensure that appropriate safeguards under Chapter V of the GDPR are in place before any transfer occurs:

— Adequacy decisions (Art. 45): Where the European Commission has recognised the destination country as providing adequate protection (e.g., UK IDTA, Swiss adequacy decision).
— Standard Contractual Clauses (Art. 46(2)(c)): The 2021 EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 are incorporated into all relevant sub-processor agreements.
— Technical safeguards: End-to-end encryption is applied to data in transit, ensuring no meaningful access to personal data by sub-processor infrastructure personnel.

We monitor decisions of the European Data Protection Board (EDPB) and the Italian Garante, and update our transfer mechanisms when required. A Transfer Impact Assessment (TIA) has been completed for each third-country transfer.
09 Art. 15–22 GDPR

Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR, exercisable free of charge and without undue restriction:

Right of access (Art. 15): Obtain confirmation of whether we process your personal data, and receive a copy of it together with supplementary information (purposes, categories, recipients, retention periods, safeguards for any third-country transfers).

Right to rectification (Art. 16): Request correction of inaccurate personal data and completion of incomplete data, without undue delay.

Right to erasure / "Right to be forgotten" (Art. 17): Request deletion of your personal data where it is no longer necessary for its original purpose, where consent is withdrawn, where you object to processing, where processing is unlawful, or where erasure is required by Union or Member State law — subject to legitimate overriding grounds (e.g., legal retention obligations).

Right to restriction of processing (Art. 18): Request that we limit processing to storage only while a dispute about accuracy, lawfulness, or a legitimate interests objection is resolved.

Right to data portability (Art. 20): Where processing is based on consent or contract and carried out by automated means, receive your data in a structured, commonly used, machine-readable format (JSON or CSV) and transmit it to another controller.

Right to object (Art. 21): Object at any time to processing based on legitimate interests (Art. 6(1)(f)), including profiling, on grounds relating to your particular situation. Object unconditionally to processing for direct marketing purposes — we will cease such processing immediately.

Rights related to automated decision-making (Art. 22): We do not make decisions based solely on automated processing that produce legal effects or similarly significant impacts on you. Any automated risk scoring or filtering used in our Services is reviewed by human operators before consequential decisions are made.

Right to withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time. See Section 10 for withdrawal methods.
10 Art. 12 GDPR

Exercising Your Rights

How to submit a request: Email [email protected] with the subject line "Data Subject Request — [Right Type]" (e.g., "Data Subject Request — Access"). You may also submit requests via our platform account settings where self-service options are available.

Identity verification: To protect your data, we will ask you to verify your identity before processing the request. Verification is carried out via your registered email address or, where necessary, via additional documentary evidence.

Response timelines: We respond to all requests within 30 calendar days of receipt. For complex or multiple requests, this period may be extended by a further 2 months — we will notify you within the initial 30 days if an extension is required, together with the reasons for the extension.

Withdrawing consent: To withdraw consent for analytics cookies, use the cookie preference manager accessible from the footer. To withdraw consent for marketing communications, click "Unsubscribe" in any marketing email or email [email protected].

No charge: All data subject requests are handled free of charge. If requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse to act — we will explain our reasoning.

Right to lodge a complaint: If you believe Altovar has violated your GDPR rights, you have the right to lodge a complaint with the competent supervisory authority:

— Garante per la protezione dei dati personali (Italy) — garanteprivacy.it
— The supervisory authority of your EU member state of habitual residence or place of work
— The supervisory authority of the member state where the alleged infringement occurred
11 ePrivacy Directive

Cookies & Tracking Technologies

We use cookies and similar technologies (web storage, pixel tags) to operate our websites and improve your experience. Our cookie usage is governed by the ePrivacy Directive (2002/58/EC, as amended) implemented in Italy by D.lgs. 69/2012 and the Garante's guidelines of July 2021.

Essential cookies are strictly necessary for security, authentication, and service operation. They are deployed without consent on the basis of Article 5(3) of the ePrivacy Directive as technically required for a service you have explicitly requested. You cannot opt out of these cookies without disrupting service functionality.

Analytics cookies are only set with your prior, freely given, specific, informed, and unambiguous consent. We use EU-hosted, privacy-preserving analytics tools. We do not use Google Analytics or any US-based analytics service without explicit consent covering international transfers.

Marketing cookies are not currently set on our marketing site. If this changes, we will request separate, granular consent.

For the complete list of cookies in use, their names, purposes, durations, and providers, and for managing your cookie preferences, please read our Cookie Policy →
12 Art. 32–34 GDPR

Security & Incident Response

We implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. Our security programme includes:

— Encryption: All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Database backups are encrypted end-to-end.
— Access controls: Role-based access control (RBAC), principle of least privilege, multi-factor authentication (MFA) for all internal systems, and privileged access management (PAM) for infrastructure access.
— Network security: Network segmentation, Web Application Firewall (WAF), DDoS mitigation, and intrusion detection/prevention systems (IDS/IPS).
— Vulnerability management: Regular penetration testing, automated SAST/DAST scanning, dependency vulnerability monitoring, and a responsible disclosure programme.
— Data Protection Impact Assessments (DPIAs): We conduct DPIAs for new processing activities that are likely to result in a high risk to individuals, as required under Article 35 GDPR.
— Staff training: All staff with access to personal data complete mandatory GDPR and information security training on onboarding and annually thereafter.

Personal data breaches: In the event of a breach likely to result in a risk to your rights and freedoms, we will notify the Garante within 72 hours of becoming aware (Art. 33). Where the breach is likely to result in a high risk, we will notify you directly without undue delay (Art. 34), including the nature of the breach, likely consequences, and measures taken or proposed.
13 Art. 8 GDPR

Children's Privacy

Our Services are professional and business-oriented and are not directed at, nor intended for use by, individuals under the age of 16 (or the higher digital age of consent applicable in certain EU member states, such as 13 in Finland, or 16 in the Netherlands and Ireland).

We do not knowingly collect personal data from minors. Account registration requires users to confirm they are of the requisite age. If we discover that we have inadvertently collected personal data from a minor, we will delete that data immediately and close the associated account.

If you believe a minor has created an account or provided us with personal data, please contact [email protected] with the details. We will investigate and take remedial action within 5 business days.
14 Art. 13(3) GDPR

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our data processing activities, changes in applicable law, or the introduction of new products and services. All updates are reviewed by our DPO before publication.

Material changes — those that meaningfully affect your rights or how we use your data — will be communicated to you by:
— Email notification to your registered address (for account holders), with at least 30 days' notice before the change takes effect
— A prominent notice on our website for the same 30-day period
— In-product notification for changes affecting the platform

Minor changes (corrections, formatting, clarifications that do not alter substance) may be made without notice. The "Last updated" date at the top of this Policy always reflects the date of the most recent revision.

Continued use of our Services after material changes take effect constitutes acceptance of the revised Policy. If you do not accept the revised Policy, you must discontinue use of the affected Services and may request deletion of your data under Section 09.
DATA PROTECTION

PRIVACY QUESTIONS?WE'RE TRANSPARENT.

Our DPO responds personally to every data protection enquiry — no automated replies, no outsourced legal team. Typically within one business day.

CONTACT OUR DPO →
DPO EMAIL [email protected]
SUPERVISORY AUTHORITY Garante · Italy
REGULATION GDPR 2016/679
RESPONSE SLA 30 calendar days

EU-sovereign stack for MSPs and enterprises. Security, cloud, productivity, and AI. A single European platform.

All products →
Cloud ↳VPS ↳Hosting ↳Object Storage ↳Managed Databases ↳Domains
Services ↳Cybersecurity ↳Web & Software Dev ↳IT & Systems ↳Marketing ↳AI & ML
Company ↳About Us ↳Careers ↳News ↳Contacts
Trust ↳Partner Program ↳Trust & Security ↳Roadmap ↳Press / Media
FORGED IN EUROPE. FOR EUROPE.
© 2026 Altovar · VAT IT03086750993 · ALL RIGHTS RESERVED
Privacy Policy · Cookie Policy · Terms of Service · Legal Notices · Data Processing & GDPR ·
TRUST & TRANSPARENCY
This website runs on green hosting - verified by thegreenwebfoundation.org GDPR COMPLIANT WCAG 2.2 AA — W3C Web Content Accessibility Guidelines, level AA
ALTOVAR
Cookies & tracking

We use technical cookies to keep the site running. With your consent we also use analytics and marketing cookies to improve the product. You can change your mind at any time.

Read the privacy policy →
Cookies & tracking

We use technical cookies to keep the site running. With your consent we also use analytics and marketing cookies to improve the product. You can change your mind at any time.

01
Necessary Always on

Required for the site to work (login, preferences, security). Always on.

02

Help us understand how the site is used, in aggregate and anonymous form.

03

Let us measure how well our campaigns perform. Off by default.

Read the privacy policy →