1. Data Controller
The Controller of the processing of personal data pursuant to Art. 4(7) of Regulation (EU) 2016/679 (“GDPR”) is:
| Controller | Stefano Corazza |
| Registered/business address | [full address – to be added before public launch] |
| privacy@rfqsmart.com |
Corporate transition: In the event a company is established to take over the management of the platform, the controllership of the processing will be transferred to that entity, following notice to data subjects pursuant to Art. 13 GDPR. Notice will be given via the platform and by email with adequate advance notice before the transfer takes effect.
The transfer will take place in compliance with the principles of continuity of processing and the safeguards provided for by the GDPR. The new entity will fully assume the rights and obligations of the original controller, without prejudice to data subjects’ rights.
2. Purpose and Scope of this Notice
This notice describes how RFQ Smart collects, processes and stores the personal data of users who access the platform or use it in connection with the management of requests for quotation (RFQ) processes.
The platform is intended exclusively for business operators (B2B users). The data processed is therefore predominantly professional in nature.
The platform is not intended for consumer users (B2C). Any use not consistent with this purpose is the user’s responsibility.
3. Categories of Data Processed
3.1 Data provided directly by the user
- first and last name of the contact person
- professional email address
- company role or function
- name and details of the company the user belongs to
- data voluntarily entered in requests for quotation or communications
3.2 Data collected automatically
- device IP address
- platform access data (date, time, actions)
- system usage logs
- technical information about the browser and device
- browsing data (also collected via technical and analytics cookies – see Cookie Policy)
3.3 Data relating to uploaded documents
Users may upload technical documents, drawings, specifications and requirements. Such files may contain personal data of third parties (e.g. employee names, technical contacts). Users are responsible for such content and must not upload documents containing unnecessary personal data.
RFQ Smart does not carry out systematic checks or active analysis of the content of documents uploaded by users, except as necessary to ensure the technical security of the platform.
The platform does not process special categories of personal data pursuant to Art. 9 GDPR (health data, ethnic origin, political opinions, etc.). Users must not enter such categories of data.
4. Purposes and Legal Bases of Processing
| Purpose | Legal basis | GDPR reference |
| Creation and management of user accounts | Performance of the contract | Art. 6(1)(b) |
| Management of RFQs and supplier invitations | Performance of the contract | Art. 6(1)(b) |
| Security and prevention of unauthorized access | Legitimate interest of the controller | Art. 6(1)(f) |
| Improvement of platform functionality | Legitimate interest of the controller | Art. 6(1)(f) |
| Statistical analysis of visits (if enabled) | User consent | Art. 6(1)(a) |
| Handling assistance or support requests | Performance of the contract | Art. 6(1)(b) |
| Compliance with legal obligations | Legal obligation | Art. 6(1)(c) |
RFQ Smart acts as an independent controller for data relating to the technical management of the platform (e.g. accounts, security, analytics), and as a processor pursuant to Art. 28 GDPR for data processed on behalf of users in connection with RFQs.
5. Roles in the Processing of Personal Data
Depending on the context, RFQ Smart may act either as an independent controller or as a processor pursuant to Art. 28 of Regulation (EU) 2016/679 (“GDPR”).
In particular:
RFQ Smart acts as an independent controller for processing relating to the technical management of the platform, including the creation and management of accounts, system security, access management and statistical analysis of usage;
RFQ Smart acts as a processor for data processed on behalf of users in connection with requests for quotation (RFQs), including the management of supplier invitations and related contact data.
Where RFQ Smart acts as a processor, the platform’s standard Data Processing Agreement (DPA) applies, forming an integral part of the relationship between the parties.
6. Data of Invited Suppliers – Roles under Art. 28 GDPR
The RFQ Smart platform allows users (buyers) to invite suppliers to take part in a request for quotation (RFQ) by entering their contact details.
In this context:
- the user who invites the supplier acts as an independent controller for the data of its own suppliers;
- RFQ Smart acts as a processor pursuant to Art. 28 of Regulation (EU) 2016/679 (“GDPR”), limited to the technical management of the invitation and the related RFQ.
The user inviting suppliers warrants that it has a valid legal basis for processing and communicating the related personal data (for example, legitimate interest or a pre-existing business relationship).
The data of invited suppliers is used exclusively for:
- sending the invitation to take part in the RFQ;
- managing the request for quotation process;
- communications strictly related to the RFQ.
Such data must not be used for further purposes incompatible with those indicated above, such as unauthorized marketing activities or unsolicited communications.
7. Processing Methods and Security
The processing of personal data is carried out using IT and telematic tools, in compliance with the principles of lawfulness, fairness and transparency, and with the adoption of technical and organizational measures appropriate to the risk pursuant to Art. 32 of Regulation (EU) 2016/679 (“GDPR”).
Such measures include, without limitation:
- encrypted HTTPS/TLS connections
- user authentication and secure credential management
- access control based on authorization profiles
- logging of system access
- periodic data backup systems
RFQ Smart adopts measures proportionate to the nature of the service and the current state of the art, but cannot guarantee the absolute inviolability of its systems or the total absence of risks connected with the transmission or storage of data in a digital environment.
The user is responsible for its use of the platform and the management of its own data, including the adoption of any additional security and backup measures for data considered critical.
In the event of a personal data breach that may pose a risk to the rights and freedoms of data subjects, the controller will notify the competent supervisory authority pursuant to Art. 33 GDPR and, where necessary, data subjects pursuant to Art. 34 GDPR.
Where RFQ Smart acts as a processor, it will cooperate with the controller in managing the breach and in fulfilling the obligations required by applicable law.
RFQ Smart does not guarantee the absolute inviolability of the system. In the event of a personal data breach that may pose a risk to the rights and freedoms of data subjects, the controller will notify the Garante pursuant to Art. 33 GDPR and, where necessary, data subjects pursuant to Art. 34 GDPR.
8. Data Retention
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, in accordance with the principles of storage limitation and data minimization set out in Regulation (EU) 2016/679 (“GDPR”).
In particular:
- user account data: for the entire duration of the account and up to 12 months from its closure;
- RFQ data: for the duration of the contractual relationship and according to the retention settings configured by the user, and in any event for a period not exceeding 5 years from the closure of the RFQ, unless otherwise requested by the user or required by law;
- access and security logs: for a limited period, generally between 6 and 12 months, unless required for security purposes or by regulatory obligations;
- data of invited suppliers: for the duration of the RFQ and any associated archiving period;
- backups: for the period strictly necessary to restore the service, in protected environments with limited access.
Once the above periods have elapsed, personal data is deleted or irreversibly anonymized, except where retention is necessary to comply with legal obligations or to protect the controller’s rights.
The user may request the deletion of their data at any time, within the limits provided for by applicable law.
9. Recipients of the Data
Personal data may be disclosed to third parties that provide technical services necessary for the operation of the platform, including:
- hosting and cloud infrastructure service providers (acting as processors under Art. 28 GDPR)
- transactional email service providers
- access analytics service providers (e.g. Google Analytics – see Cookie Policy)
- technical service providers for the management and maintenance of the platform
Such parties act as processors pursuant to Art. 28 GDPR and are bound by specific contractual agreements that ensure the protection of personal data.
10. Transfer of Data to Third Countries
Personal data is processed primarily within the European Economic Area (EEA). Should it be necessary to transfer data to third countries (e.g. for the use of tools such as Google Analytics), this will take place in compliance with GDPR provisions, adopting appropriate safeguards such as:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- other appropriate safeguards pursuant to Art. 46 GDPR
11. Rights of Data Subjects
Data subjects may exercise the rights set out in Articles 15-22 GDPR, including:
- the right of access to their personal data (Art. 15)
- the right to rectification of inaccurate or incomplete data (Art. 16)
- the right to erasure (“right to be forgotten”) (Art. 17)
- the right to restriction of processing (Art. 18)
- the right to data portability (Art. 20)
- the right to object to processing (Art. 21)
- the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal
Requests may be sent by email to: privacy@rfqsmart.com. The controller will respond within 30 days of receipt.
12. Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with the competent supervisory authority pursuant to Art. 77 GDPR. For processing carried out by the RFQ Smart platform, the competent authority is:
| Authority | Garante per la protezione dei dati personali (Italian Data Protection Authority) |
| Website | www.garanteprivacy.it |
| garante@gpdp.it |
13. Changes to the Privacy Policy
This notice may be updated over time to reflect regulatory changes or the evolution of the platform. In the event of material changes, users will be informed via the platform or by email with adequate advance notice.
