Orangedev and the GDPR

Orangedev guarantees its customers the correct application of the GDPR provisions for the services provided.
Data processing performed through our software occurs separately for each Service through the ” Special Conditions for the Processing of Personal Data” (DPA), customized for the specific Service, generally provided as a separate document.

The data controller is Orangedev Srl, with registered office at Via Giovanni Pian dei Carpini 01 (Edificio B12) – 50127, 50127 Florence. Interested parties may contact us by sending their requests to privacy@orangedev.it.

Processing of Customer Personal Data

Our customers’ data is handled with the utmost care, in compliance with the GDPR regulations.

Privacy by default and by design

Our software has always been designed and built following the concept of “Data protection by default and by design”.

Data Integrity and Security

We use encryption for data for which we believe we need to ensure a level of security appropriate to the risk of their loss or theft.

Legally Required Log Retention

We are responsible for legally retaining logs for the period required by Italian law.

Data Export

Access logs and audit logs can be exported by service administrators using dedicated tools made available at any time during the contract term.

Data Deletion

Users may delete their data at any time. When a permanent deletion request is submitted (such as deleting an account used to provide our Services), the data will be removed from any system within a maximum of 90 days, unless otherwise required by law.

Data Privacy

In order to maintain security and prevent data processing in violation of the regulation, we undertake to assess the risks inherent in processing and implement measures to mitigate those risks, such as encryption to protect data in transit.

Vulnerability Management

We use internally developed tools to detect software vulnerabilities and conduct periodic testing to identify potential breaches.

Processing Register

We have prepared a “Processing Register”, a register of the processing activities carried out, available to the supervisory authority.

Staff Training

All Orangedev employees have completed internal training courses on GDPR requirements and are constantly updated and educated on the security and confidentiality of the data we process.

Orangedev as Data Controller

Orangedev srl acts as “Data Controller” when it determines the purposes and means of processing personal data. This is the case when Orangedev collects data for billing, service improvement, sales initiatives, requests for technical support, sales management, or even when Orangedev processes the personal data of its employees.

In this case, “your” data hosted on Orangedev services are not affected by the processing, unlike some information concerning you or your employees (for example, information relating to the identity and contact details of your Orangedev contact in the context of a Support request).

More generally, Orangedev guarantees:

limit data collection to what is strictly necessary;
not use personal data for purposes other than those for which they were originally collected;
retain personal data for a limited period, i.e. for the entire duration of the contract and the subsequent 12 months;
not to transfer this data to third parties who are not part of the Group companies or who are not involved in the execution of the contract.

Orangedev as Data Processor

Orangedev srl acts as a “Data Processor” when it processes personal data on behalf of a Data Controller, for example, when using Orangedev services and storing users’ personal data on Orangedev’s infrastructure. Within the limits of its technical constraints, Orangedev will process the hosted data exclusively as directed, and on behalf of, Customers who are Data Controllers or have received instructions from other Data Controllers to authorize Orangedev to process the data.

In these cases Orangedev undertakes to:

process personal data exclusively for the correct performance of the services;
do not transfer your data outside the EU;
implement high security standards in order to ensure a high level of security for our services;
notify you as soon as possible in the event of a data breach;
assist you in fulfilling your regulatory obligations by providing you with adequate documentation of our services.

What Orangedev customers must do

The new regulation requires you to adopt a series of measures to adequately protect the data of the people with whom your company or firm works, such as the data of your employees and customers.

The first thing to do, therefore, is to become aware :

Get informed (for example here www.garanteprivacy.it/guida-all-applicazione-del-regolamento-europeo-in-materia-di-protezione-dei-dati-personali , http://ec.europa.eu/justice/smedataprotect/index_it.htm and here https://ec.europa.eu/commission/priorities/justice-and-fundamental-rights/data-protection/2018-reform-eu-data-protection-rules_it ) and evaluate which of the innovations introduced by the new Regulation are applicable to your business.
Consult an expert for legal advice regarding your business;
Inform your customers/employees, for services active with us, that the Data Controller is Orangedev;
Update your privacy policy to reflect Orangedev’s.

Contact details of the DPO (Data Controller)

Article 37, paragraph 7 of the European Privacy Regulation EU/2016/679 (GDPR) requires every data controller or data processor to make public the contact details of their DPO (Data Protection Officer) and to communicate them to the Italian Data Protection Authority.

In compliance with this regulation, Orangedev srl publishes the contact details of its DPO, as communicated to the Privacy Guarantor on 17/07/2020:

dpo@orangedev.it
PROTOCOL N. 20200005508 of 17/7/2020

FAQ ( Frequently Asked Questions)

Who is the Data Controller:

The Data Controller is the person who determines the purposes and means of the processing of personal data.

Who is the Data Controller:

A Data Controller is someone who processes personal data on behalf of a Data Controller.

What is personal data?

Personal data is any information relating to an identified or identifiable living individual.

What is sensitive data?

Sensitive data is data that may reveal racial or ethnic origin, religious, philosophical, or other beliefs, political opinions, membership in political parties, trade unions, associations, or organizations of a religious, philosophical, political, or trade union nature, health, or sex life.

Example of personal data:

name and surname;
home address;
email address, such as firstname.lastname@company.com;
identity card number;
location data (e.g. the positioning function on a mobile phone);
an Internet Protocol (IP) address;
a cookie ID;

Examples of data not considered personal:

company registration number of a company;
email address not attributable to a specific person, for example “info@azienda.com”;
anonymized data.

What constitutes data processing?

Processing includes a wide range of operations performed on personal data, including those performed manually or by automated means. It includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data.

Who owns the data hosted and stored on Orangedev services?

Data stored by customers using Orangedev services remains the property of the customer. Orangedev does not access or use this data except when strictly necessary and within the limits of its technical constraints.

In what circumstances can Orangedev access Customer data hosted and stored on our services?

Orangedev accesses data only in the following situations:

For the purposes of providing services, and in particular to optimize customer support when contacting Orangedev’s technical support. In this case, access to user data remains controlled thanks to specific authorizations and activity logs;
to fulfill legal obligations in the context of strictly controlled judicial and/or administrative requests.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.