Compliance document
Website and contact-form privacy notice
Processing of data on the commercial site and in contact forms.
Download PDFSHA-256 4734163aa1756db98e319aeea6e5455f6b8ef34d63ceda4565c700888a7f12bf
Preamble, nature and effect of this document
Nil Tech Europe S.r.l., with registered office at Via Calmaggiore 5, 31100 Treviso (TV), Italia, VAT No. IT 05614380268 (“Niltech”), adopts this document in order to provide individuals with complete information on website and form data, purposes, bases, recipients, retention and exercise of rights.
This document is a notice provided to data subjects. Consent is not required where processing relies on another lawful basis; where consent is necessary, it is requested separately in a freely given, specific, informed and withdrawable manner.
This notice is provided under Articles 12 and 13 of Regulation (EU) 2016/679 and the applicable Italian data-protection legislation. It must be read before personal data are submitted through forms, email or any other channel made available on the website.
Personal and material scope
The objective scope includes ClaimEvidence, its public interfaces and processing strictly connected with the described functions. The corporate website and document library are published on claimevidence.tech; the application service is available through the separate app.claimevidence.tech domain. Hostinger provides infrastructure and, according to the applicable configuration, mail transport. MySQL/MariaDB is software running in the controlled environment and not a separate subprocessor unless a distinct managed service is used. OpenAI provides API services only for enabled functions; any separate email provider must be identified and assessed before use.
The relevant operations concern guided photo and document collection, case organisation, completeness checks, configurable analytical support, human review and export. Potential information categories are: demo and security-pack requests on the site; in the application, case identifiers, authorised contacts, photographs, documents, notes, session metadata and assisted outputs. The actual privacy role, lawful basis and extent of processing depend on the contractual relationship and the lawful instructions of the party determining purposes and essential means.
Definitions and interpretation
- “Service” means the ClaimEvidence functions made available under the agreement.
- “Customer” means the legal person or professional entering into the agreement with Niltech.
- “Authorised User” means an individual enabled by the Customer to use the Service under its responsibility.
- “Customer Data” means data, documents, images, instructions and other content submitted or generated on the Customer’s behalf.
- “Assisted Output” means a result produced through automated rules or artificial-intelligence components and subject to the stated controls.
- “Further Supplier” means a third party providing Niltech with a technical service relevant to the documented scope.
- “Incident” means an event compromising or capable of compromising confidentiality, integrity, availability, authenticity or resilience.
- “Business Day” means a day other than Saturday, Sunday or an Italian national public holiday.
Specific duties and safeguards
1. Within its assigned role and without prejudice to the Customer’s responsibilities, Niltech shall inventory every field, technical metadata, log and form destination. The applicable file identifies the owner, scope, dependencies, acceptance criterion and evidence; absent those elements, the safeguard is not treated as demonstrated.
2. Within its assigned role and without prejudice to the Customer’s responsibilities, Niltech shall associate every purpose with a documented lawful basis and necessity. The applicable file identifies the owner, scope, dependencies, acceptance criterion and evidence; absent those elements, the safeguard is not treated as demonstrated.
3. Within its assigned role and without prejudice to the Customer’s responsibilities, Niltech shall limit free-text fields and warn against excessive or special-category data. The applicable file identifies the owner, scope, dependencies, acceptance criterion and evidence; absent those elements, the safeguard is not treated as demonstrated.
4. Within its assigned role and without prejudice to the Customer’s responsibilities, Niltech shall verify configured hosting, email transport, access and deletion. The applicable file identifies the owner, scope, dependencies, acceptance criterion and evidence; absent those elements, the safeguard is not treated as demonstrated.
5. Within its assigned role and without prejudice to the Customer’s responsibilities, Niltech shall provide notice before submission and record the document revision displayed. The applicable file identifies the owner, scope, dependencies, acceptance criterion and evidence; absent those elements, the safeguard is not treated as demonstrated.
6. Within its assigned role and without prejudice to the Customer’s responsibilities, Niltech shall route rights and complaints to authorised staff without improper disclosure. The applicable file identifies the owner, scope, dependencies, acceptance criterion and evidence; absent those elements, the safeguard is not treated as demonstrated.
Controller and scope
Nil Tech Europe S.r.l. is controller for the https://claimevidence.tech website.
The corporate website and document library are published on claimevidence.tech; the application service is available through the separate app.claimevidence.tech domain. Hostinger provides infrastructure and, according to the applicable configuration, mail transport. MySQL/MariaDB is software running in the controlled environment and not a separate subprocessor unless a distinct managed service is used. OpenAI provides API services only for enabled functions; any separate email provider must be identified and assessed before use.
Data and purposes
Contact data, organisation, request content, language and technical data strictly needed for security and delivery may be processed. Purposes are response, pre-contractual steps, security, abuse prevention and compliance.
Bases, recipients and transfers
Applicable bases are pre-contractual steps, legitimate interests in security and correspondence, legal obligations, and consent only where genuinely required. Hosting and email transport are technical recipients under contract.
Retention and rights
Website requests left unanswered or not converted into a contractual relationship, and related mailbox copies, are deleted within 90 days of receipt unless a documented negotiation or separate legal need applies. Data submitted to the service follow customer instructions, the agreement and the retention register. Deletion evidence is retained only as necessary for accountability and the establishment or defence of claims.
Individuals may request access, rectification, erasure, restriction, portability where applicable and objection, and may complain to the competent authority. Contact: info@nil-tech.net.
Scope, audience and status of this document
This document is intended for customers, prospects, authorised users, advisers and control functions needing to understand the ClaimEvidence scope. Its specific objective is to provide individuals with complete information on website and form data, purposes, bases, recipients, retention and exercise of rights. It applies to the stated document revision and date and must be read with the applicable agreement, order, DPA, technical specifications and controlled procedures.
The corporate website and document library are published on claimevidence.tech; the application service is available through the separate app.claimevidence.tech domain. Hostinger provides infrastructure and, according to the applicable configuration, mail transport. MySQL/MariaDB is software running in the controlled environment and not a separate subprocessor unless a distinct managed service is used. OpenAI provides API services only for enabled functions; any separate email provider must be identified and assessed before use.
Executed agreements and actually approved configurations prevail in case of inconsistency. Public information describes the control programme; it does not turn optional provider capabilities into Niltech controls or automatically attest legal applicability or satisfaction.
Exceptions, non-conformity and escalation
A deviation is not accepted by custom. The owner records the affected requirement, cause, impact, exposed data and persons, compensating measures, approver, expiry and closure criterion. The exception is reviewed if risk changes or a measure does not work as expected.
Incidents, possible unlawful processing, loss of data control, outputs with severe impact, contractual breaches, unapproved suppliers or unreliable evidence must be escalated without delay. Current Legal and functional scope: Payment services are outside the scope described by this documentation.
- contain risk and suspend the affected phase where needed
- preserve evidence, timing, decisions and communications
- involve privacy, security, product, legal or management owners as appropriate
- resume only after measure verification and documented authorisation
Review, change and improvement
The document is reviewed at least every six months and earlier when purpose, audience, data, GDPR or AI Act role, supplier, model, architecture, location, contractual terms or legal requirements change. Incidents, complaints, failed tests and new vulnerabilities trigger an extraordinary review.
Each review records inputs, participants, decision, changes, superseded evidence, remaining gaps and next date. Material corrections are published without retroactively altering the prior document revision. Contact and requests: info@nil-tech.net.
- check change register and related documents
- retest affected controls
- update manifest, PDF, HTML and hashes
- notify recipients where the change affects their rights or duties
Information under Articles 13 and 14 GDPR
The controller is Nil Tech Europe S.r.l. The site collects data supplied by the individual through forms or correspondence and technical data generated by the HTTP request. Where an organisation supplies a representative’s data, that organisation is the source and the categories remain limited to professional identity, contact details, role and request content.
Responding to a request and taking pre-contractual steps rely on Article 6(1)(b) GDPR; security, abuse prevention, establishment or defence of claims and orderly correspondence management rely on the legitimate interests in point (f), balanced against the individual’s impact; mandatory compliance relies on point (c). Electronic marketing, if introduced, requires a separate basis and notice and is not inferred from a mere information request.
Data may be accessed by authorised personnel and strictly necessary suppliers, including the Hostinger hosting provider and the actually configured mail-transport service. Data are not published. Any third-country transfer must rely on an adequacy decision or safeguards under Articles 46 et seq. GDPR, documented in the supplier register.
Providing fields marked as required is necessary to process the request; failure to provide them prevents a response. Free-text fields must not contain health or criminal-offence data or case documents. The commercial website does not make any decision based solely on automated processing within Article 22 GDPR.
Retention, rights and complaint
Requests left unanswered or not converted into a contractual relationship, and the related mailbox copies, are deleted within 90 days of receipt unless a documented negotiation begins in the meantime or a separate legal need applies. Contractual, pre-litigation or legally required correspondence follows the applicable periods. Security logs follow a separate period proportionate to purpose and documented in the retention register. A reasoned legal hold suspends deletion only for relevant material.
Within their applicable scope, individuals may exercise access, rectification, erasure, restriction, portability, objection and withdrawal of consent without affecting prior lawfulness. They may also complain to the Italian Data Protection Authority. Requests should be sent to info@nil-tech.net; Niltech may verify identity and authority proportionately.
Allocation of responsibility and reliance limitations
Within its sphere of responsibility, the Customer warrants the lawfulness of submitted data and instructions, user authorisation, suitable lawful bases and notices, and professional verification of outputs. Niltech remains responsible for activities directly under its control and does not assume the Customer’s regulatory, professional or decision-making functions.
Outputs from ClaimEvidence are auxiliary. Unless expressly agreed and subject to mandatory law, they are not legal advice, an expert determination, insurance decision, liability finding, credit assessment or other reserved professional act. The recipient must examine sources, completeness, consistency and consequences before use.
Nothing excludes liability that cannot lawfully be excluded. Outside those cases, attribution, remedies, limitations and quantification principles follow the applicable agreement, taking account of contributory conduct, mitigation duties and foreseeability under the governing law.
Evidence, review, requests and governing law
Every material assertion must be traceable to a contract, approved configuration, register, minutes, test, log or other reliable evidence. Supplier statements and Niltech controls are kept distinct. Absence of incidents is not, by itself, proof that a measure is effective.
Revisions are dated, reasoned and approved. A later revision does not retroactively alter facts or commitments applicable to earlier periods. Published copies are identified by code, date and cryptographic digest; those elements evidence copy integrity, not the substantive effectiveness of described controls.
Reports, clarification requests, rights requests and complaints may be sent to info@nil-tech.net. Niltech verifies identity and authority where necessary, records the request, responds within applicable periods and communicates any reasoned extension or refusal.
Unless mandatory law or a written agreement provides otherwise, Italian law governs interpretation. The Italian text is controlling; the English translation is provided for convenience.