Informativa sulla privacy
1. Titolare del trattamento
Quantirica S.r.l., Piazza Cacciaguida 8, 44121 Ferrara (FE), Italia, partita IVA IT01785370386, codice fiscale 01785370386. Per qualsiasi richiesta relativa ai dati personali: support@quantirica.com.
Questa informativa riguarda il portale https://portal.quantirica.com e il software TickerExplorer. Il sito istituzionale https://www.quantirica.it ha una propria informativa.
2. Quali dati trattiamo
| Categoria | Dati | Quando |
|---|---|---|
| Account | nome, cognome, email, telefono, password (conservata in forma cifrata), stato di attivazione | registrazione al Portale |
| Fatturazione | indirizzo, città, CAP, provincia, paese, codice fiscale, partita IVA, ragione sociale, codice destinatario SDI, PEC | compilazione dei dati di fatturazione, obbligatoria per acquistare |
| Pagamenti | identificativi Stripe del cliente e delle transazioni, importi, date, stato, esito di rimborsi e contestazioni. I dati completi della carta sono trattati solo da Stripe e non arrivano mai ai nostri sistemi | acquisti, rinnovi, verifica del metodo di pagamento |
| Licenze | credenziali di accesso al software, prodotto, scadenza, opzioni abilitate; indirizzo IP e data di attivazione della licenza nel software | attivazione e uso di TickerExplorer |
| Comunicazioni | email inviate e ricevute (attivazione, credenziali, avvisi di scadenza, conferme di pagamento, assistenza) | uso del servizio e richieste di assistenza |
| Dati tecnici | indirizzo IP, data e ora, pagina richiesta, browser (log del server); accettazione dei Termini con data, ora e IP | navigazione sul Portale, registrazione e acquisti |
Non trattiamo categorie particolari di dati (art. 9 GDPR) e non effettuiamo profilazione o decisioni automatizzate con effetti giuridici.
3. Perché li trattiamo e su quale base
| Finalità | Base giuridica |
|---|---|
| Creare e gestire l'account, fornire licenze e corsi, comunicare le credenziali, gestire rinnovi e disdette | esecuzione del contratto (art. 6.1.b) |
| Emettere fatture elettroniche e adempiere agli obblighi fiscali e contabili | obbligo legale (art. 6.1.c) |
| Inviare avvisi di scadenza, conferme di pagamento e comunicazioni di servizio | esecuzione del contratto (art. 6.1.b) |
| Prevenire frodi e abusi, controllare che una licenza sia usata da una sola sessione, gestire rimborsi e contestazioni, conservare la prova dell'accettazione dei Termini | legittimo interesse (art. 6.1.f) alla sicurezza del servizio e alla tutela dei nostri diritti |
| Sicurezza del Portale, log tecnici, protezione da attacchi e registrazioni automatiche | legittimo interesse (art. 6.1.f) |
| Rispondere alle richieste di assistenza | esecuzione del contratto e legittimo interesse |
| Inviare comunicazioni commerciali su nuovi prodotti o corsi | consenso (art. 6.1.a), revocabile in qualsiasi momento; oppure, per clienti esistenti e prodotti analoghi, legittimo interesse con possibilità di opposizione in ogni messaggio |
4. Chi vede i dati
I dati sono trattati dal personale di Quantirica autorizzato e da fornitori che agiscono come responsabili del trattamento (art. 28 GDPR) o titolari autonomi:
| Fornitore | Servizio | Dove |
|---|---|---|
| Stripe Payments Europe Ltd. (Irlanda) e Stripe Inc. (USA) | pagamenti, abbonamenti, fatture Stripe, portale clienti; titolare autonomo per i dati di pagamento | UE / USA |
| Fattura24 (Italia) | emissione e trasmissione delle fatture elettroniche al Sistema di Interscambio | Italia |
| Amazon Web Services EMEA SARL | server del Portale e database delle licenze | Regno Unito (regione Londra) |
| Google Ireland Ltd. (Google Workspace) | posta elettronica per l'invio delle comunicazioni | UE, con possibili trasferimenti secondo le condizioni Google |
| jsDelivr, Cloudflare (cdnjs) | distribuzione di librerie grafiche delle pagine; ricevono l'indirizzo IP del browser al caricamento | rete mondiale |
| Consulenti fiscali e legali, autorità | adempimenti di legge, difesa dei diritti | Italia |
Non vendiamo né cediamo i dati a terzi per finalità di marketing.
5. Trasferimenti fuori dall'Unione Europea
Alcuni fornitori trattano dati fuori dallo Spazio Economico Europeo: Amazon Web Services nel Regno Unito, coperto da decisione di adeguatezza della Commissione Europea; Stripe e Google negli Stati Uniti, sulla base del Data Privacy Framework UE-USA e, in subordine, delle clausole contrattuali standard approvate dalla Commissione Europea. Puoi chiederci copia delle garanzie applicate.
6. Per quanto tempo
- Account e licenze: per tutta la durata del rapporto e per 24 mesi dopo la scadenza dell'ultima licenza, salvo richiesta di cancellazione anticipata.
- Fatture e dati di pagamento: 10 anni dall'emissione, per obbligo di legge.
- Prova dell'accettazione dei Termini: per la durata del rapporto e per i successivi 10 anni (termine di prescrizione ordinaria).
- Log tecnici: 12 mesi, salvo necessità di indagine su incidenti di sicurezza.
- Comunicazioni commerciali: fino alla revoca del consenso o all'opposizione.
7. I tuoi diritti
Puoi esercitare in qualsiasi momento i diritti previsti dagli artt. 15-22 GDPR: accesso ai dati, rettifica, cancellazione, limitazione, portabilità, opposizione al trattamento basato sul legittimo interesse, revoca del consenso. Scrivi a support@quantirica.com: rispondiamo entro 30 giorni. Hai inoltre diritto di proporre reclamo al Garante per la protezione dei dati personali (www.garanteprivacy.it) o all'autorità del tuo paese di residenza.
Il conferimento dei dati di account, fatturazione e pagamento è necessario per acquistare: senza, non possiamo fornire i Prodotti.
8. Cookie
Il Portale usa soltanto cookie tecnici, necessari al funzionamento: il cookie di sessione, che ti mantiene autenticato, e il cookie di protezione anti-CSRF dei moduli. Non usiamo cookie di profilazione, analitici o di terze parti, e per questo non è necessario un banner di consenso. Le pagine di pagamento caricano componenti di Stripe, che possono impostare cookie tecnici propri secondo la privacy policy di Stripe.
9. Sicurezza
Il Portale è raggiungibile solo tramite HTTPS. Le password sono conservate con algoritmi di hashing; i dati delle carte non transitano dai nostri sistemi; l'accesso ai server è limitato con chiavi crittografiche; i webhook di pagamento sono verificati tramite firma. In caso di violazione dei dati che comporti un rischio elevato per i tuoi diritti, ti informeremo come previsto dall'art. 34 GDPR.
10. Minori
Il Portale è riservato a persone maggiorenni. Non raccogliamo consapevolmente dati di minori di 18 anni; se ne venissimo a conoscenza, li cancelleremmo.
11. Modifiche
Questa informativa può essere aggiornata; la versione in vigore, con la data, è sempre pubblicata su questa pagina. In caso di modifiche rilevanti ne daremo avviso via email.
Privacy Policy
1. Data controller
Quantirica S.r.l., Piazza Cacciaguida 8, 44121 Ferrara (FE), Italia, VAT number IT01785370386, tax code 01785370386. For any request concerning personal data: support@quantirica.com.
This policy covers the portal https://portal.quantirica.com and the TickerExplorer software. The corporate website https://www.quantirica.it has its own policy.
2. What data we process
| Category | Data | When |
|---|---|---|
| Account | name, surname, email, phone number, password (stored hashed), activation status | registration on the Portal |
| Billing | address, city, postcode, province, country, tax code, VAT number, company name, SDI recipient code, certified email | filling in billing details, required to purchase |
| Payments | Stripe identifiers of the customer and of transactions, amounts, dates, status, outcome of refunds and disputes. Full card details are processed by Stripe only and never reach our systems | purchases, renewals, payment-method verification |
| Licences | software login credentials, product, expiry, enabled options; IP address and date of licence activation in the software | activation and use of TickerExplorer |
| Communications | emails sent and received (activation, credentials, expiry notices, payment confirmations, support) | use of the service and support requests |
| Technical data | IP address, date and time, requested page, browser (server logs); acceptance of the Terms with date, time and IP | browsing the Portal, registration and purchases |
We do not process special categories of data (Article 9 GDPR) and we do not carry out profiling or automated decisions with legal effects.
3. Why we process it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing the account, supplying licences and courses, sending credentials, managing renewals and cancellations | performance of the contract (Art. 6(1)(b)) |
| Issuing electronic invoices and complying with tax and accounting obligations | legal obligation (Art. 6(1)(c)) |
| Sending expiry notices, payment confirmations and service communications | performance of the contract (Art. 6(1)(b)) |
| Preventing fraud and abuse, ensuring a licence is used by one session at a time, handling refunds and disputes, keeping proof of acceptance of the Terms | legitimate interest (Art. 6(1)(f)) in the security of the service and the protection of our rights |
| Portal security, technical logs, protection against attacks and automated sign-ups | legitimate interest (Art. 6(1)(f)) |
| Answering support requests | performance of the contract and legitimate interest |
| Sending commercial communications about new products or courses | consent (Art. 6(1)(a)), which can be withdrawn at any time; or, for existing customers and similar products, legitimate interest with the option to object in every message |
4. Who sees the data
Data are processed by authorised Quantirica staff and by providers acting as processors (Article 28 GDPR) or as independent controllers:
| Provider | Service | Where |
|---|---|---|
| Stripe Payments Europe Ltd. (Ireland) and Stripe Inc. (USA) | payments, subscriptions, Stripe invoices, customer portal; independent controller for payment data | EU / USA |
| Fattura24 (Italy) | issuing and transmitting electronic invoices to the Italian exchange system | Italy |
| Amazon Web Services EMEA SARL | Portal servers and licence database | United Kingdom (London region) |
| Google Ireland Ltd. (Google Workspace) | email for sending communications | EU, with possible transfers under Google's terms |
| jsDelivr, Cloudflare (cdnjs) | delivery of the pages' front-end libraries; they receive the browser's IP address on page load | global network |
| Tax and legal advisers, authorities | legal compliance, defence of rights | Italy |
We do not sell or pass on data to third parties for marketing purposes.
5. Transfers outside the European Union
Some providers process data outside the European Economic Area: Amazon Web Services in the United Kingdom, covered by a European Commission adequacy decision; Stripe and Google in the United States, on the basis of the EU-US Data Privacy Framework and, alternatively, the standard contractual clauses approved by the European Commission. You may ask us for a copy of the safeguards applied.
6. How long we keep it
- Account and licences: for the duration of the relationship and 24 months after the expiry of the last licence, unless you ask for earlier deletion.
- Invoices and payment data: 10 years from issue, as required by law.
- Proof of acceptance of the Terms: for the duration of the relationship and the following 10 years (ordinary limitation period).
- Technical logs: 12 months, unless needed to investigate security incidents.
- Commercial communications: until consent is withdrawn or you object.
7. Your rights
You may at any time exercise the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, withdrawal of consent. Write to support@quantirica.com: we reply within 30 days. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of your country of residence.
Providing account, billing and payment data is necessary to purchase: without it we cannot supply the Products.
8. Cookies
The Portal uses technical cookies only, necessary for it to work: the session cookie, which keeps you logged in, and the anti-CSRF protection cookie for forms. We do not use profiling, analytics or third-party cookies, so no consent banner is required. Payment pages load Stripe components, which may set their own technical cookies according to Stripe's privacy policy.
9. Security
The Portal is served over HTTPS only. Passwords are stored using hashing algorithms; card data never pass through our systems; server access is restricted by cryptographic keys; payment webhooks are signature-verified. In the event of a data breach likely to result in a high risk to your rights, we will inform you as required by Article 34 GDPR.
10. Minors
The Portal is reserved for adults. We do not knowingly collect data of persons under 18; should we become aware of it, we would delete them.
11. Changes
This policy may be updated; the version in force, with its date, is always published on this page. We will notify material changes by email.