Privacy Policy
This notice describes the processing of personal data of users (hereinafter “Data Subjects”) who visit the smooit.com website and its related pages and landing pages (hereinafter the “Application”), or contact Smooit through the channels made available on the website.
-
Data Controller and contact details
The Data Controller is Smooit S.r.l., with registered office at Via al Parco 15, 21010, tax code/VAT number 03985760127, e-mail [email protected], certified e-mail (PEC) [email protected] (hereinafter the “Controller”).
For requests concerning the protection of personal data and to exercise the rights described in this notice, the Data Subject may write to [email protected].
-
Categories of personal data processed
The Controller may process the following categories of data, depending on how the Application is used.
- Data provided through the contact form: first and last name, company, e-mail address, telephone number, selected area of interest and the content of the message or request sent.
- Data provided through direct contact: data voluntarily communicated by e-mail, telephone or WhatsApp, including, depending on the channel used, e-mail address, telephone number, name or profile identifier and the content of communications.
- Technical and security data: IP address, date and time of the request, device information, operating system, browser, connectivity provider, technical logs and information necessary for the security and proper operation of the website.
- Browsing and usage data: pages visited, source of the visit, clicks and interactions, duration and characteristics of the session, events generated on the website and online identifiers associated with cookies or similar technologies, within the limits permitted by the preferences expressed by the Data Subject.
The Application does not intentionally request special categories of personal data under Article 9 GDPR (for example, data concerning health, religious beliefs, political opinions or sexual orientation), or data relating to criminal convictions and offences. The Data Subject is invited not to include such information in free-text fields of the form or in contact communications unless strictly necessary.
If the Data Subject communicates personal data concerning third parties, they declare that they are entitled to do so and remain responsible for the lawfulness of that communication.
-
Methods of collection and contact channels
Data may be collected:
- directly from the Data Subject through the “Tell us what you need” form on the website;
- by e-mail at the addresses published on the website;
- by telephone contact;
- through the WhatsApp link made available on the website;
- automatically during browsing, through technical logs, cookies and similar technologies, in accordance with the preferences expressed by the Data Subject.
When the Data Subject chooses to contact Smooit through WhatsApp, they leave the Application and use a third-party service. For users in the European Economic Area, the WhatsApp service is provided by WhatsApp Ireland Limited in accordance with its own privacy notice. Smooit processes the data received through this channel solely to manage the conversation or the request for information, assistance or a quotation.
-
Purposes and legal bases of processing
The Controller processes personal data for the purposes and on the legal bases set out below.
- Handling requests, contact, assistance and pre-contractual or contractual activities: to respond to requests received, contact the Data Subject again, understand the needs indicated, prepare any proposals or quotations, provide support and take pre-contractual or contractual steps requested by the Data Subject. The legal basis is Article 6(1)(b) GDPR.
- Compliance with legal obligations: to comply with administrative, tax, accounting or other obligations laid down by applicable law. The legal basis is Article 6(1)(c) GDPR.
- Security, prevention of abuse and technical management: to protect the Application, infrastructure and networks, prevent fraudulent or malicious use, diagnose errors and ensure the availability, reliability and performance of systems. The legal basis is the Controller's legitimate interest under Article 6(1)(f) GDPR, with due regard for the rights and freedoms of Data Subjects.
- Non-essential analysis and statistics: to understand how the website is used, measure traffic and interactions and improve content and services through analytics tools. Where these activities require the use of non-essential cookies or technologies, processing is based on the Data Subject's consent under Article 6(1)(a) GDPR and applicable cookie legislation.
- Advertising measurement, remarketing and retargeting: to measure campaign effectiveness, attribute conversions and, with prior consent, create or use audiences to display relevant advertising. The legal basis is the Data Subject's consent under Article 6(1)(a) GDPR.
- Protection of the Controller's rights: where necessary, to establish, exercise or defend a right out of court or in court, on the basis of the Controller's legitimate interest and/or any other legal bases applicable to the specific case.
Any consent given for analytics or marketing purposes is optional and may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
-
Cookies, similar technologies and consent management
The Application uses cookies and similar technologies. Non-essential tools are activated according to the Data Subject's preferences through the consent management system adopted by the website.
Smooit uses Cloudflare Zaraz to manage measurement and marketing tools and to apply preferences expressed through the consent banner. For Google services, the Google Consent Mode mechanism is also used to communicate the status of consent preferences to Google services.
The Data Subject may accept, reject or change their preferences through the banner or the cookie preference management panel available on the Application. More detailed information about the technologies used, their providers and retention periods is available in the Cookie Policy.
-
Services and providers used for the website and tracking
As at the date of this notice, the Application may use the following services:
- Cloudflare and Cloudflare Zaraz: delivery and protection of the website, traffic management, security, performance, management of tracking tools and consent preferences.
- Google Analytics 4: statistical measurement of website traffic and interactions, subject to applicable settings and consent.
- Google Ads: measurement of advertising campaigns, attribution of conversions and, if enabled and permitted, remarketing.
- Meta Pixel and Meta Conversions API: measurement of Meta campaigns, attribution of events and, if enabled and permitted, remarketing and audience creation.
- WhatsApp: an optional channel chosen by the Data Subject to contact Smooit directly.
Depending on the service and processing carried out, these providers may act as processors on behalf of Smooit or as independent controllers under their respective terms and notices. The list may be updated if the services used change.
Privacy notices of the main providers: Cloudflare, Google, Meta, WhatsApp.
-
Whether providing data is required
Providing the data requested in fields marked as mandatory in the contact form is necessary to allow Smooit to handle the request properly. Failure to provide it may make it impossible to respond or prepare what was requested.
Providing data for analytics, advertising measurement, remarketing and retargeting purposes is optional: refusing does not prevent normal browsing of the website or the submission of a contact request.
Any checkbox in the form through which the Data Subject declares that they have read the Privacy Policy serves to acknowledge receipt of the notice and does not, in itself, constitute consent to marketing or tracking purposes.
-
Recipients of personal data
Personal data may be processed by or disclosed, to the extent necessary for the purposes above, to:
- the Controller's staff, collaborators and authorised persons bound by confidentiality;
- providers of IT, hosting, cloud, security, communications, analytics and advertising services;
- consultants and professionals assisting the Controller in technical, administrative, tax or legal matters;
- persons or authorities to whom disclosure is required by legal obligations or lawful orders.
Personal data is not made available indiscriminately or transferred to third parties for their own independent marketing purposes, unless a specific notice is provided and an appropriate legal basis exists.
-
Transfers of data to countries outside the EEA
Some providers used by the Controller are part of international groups and may involve the transfer of, or access to, data from countries outside the European Economic Area. Where this occurs, the transfer is carried out in accordance with Articles 44 et seq. GDPR, using, as appropriate, adequacy decisions, the EU-US Data Privacy Framework for participating and certified recipients, standard contractual clauses approved by the European Commission and/or other safeguards provided for by applicable law.
Information about the safeguards applicable to individual services may be requested by writing to [email protected] or by consulting the providers' notices listed in this Privacy Policy.
-
Retention periods
Personal data is retained according to criteria consistent with the purposes for which it was collected and, in particular:
- contact and pre-contractual requests: for the time necessary to handle the request and, unless a contractual relationship is established or there are needs to protect legal rights, indicatively for up to 24 months from the last interaction;
- data relating to contractual, administrative and tax relationships: for the duration of the relationship and subsequently for the period required by law, normally up to 10 years for documents subject to civil-law and tax obligations, without prejudice to further needs to protect legal rights;
- technical and security logs: for the period strictly necessary for security, incident diagnosis and infrastructure protection, in accordance with the technical configurations adopted by the Controller and providers;
- analytics and marketing: according to the durations configured for each tool and indicated, where applicable, in the Cookie Policy, and in any event no longer than necessary for the purposes concerned or until consent is withdrawn, if that occurs earlier.
At the end of the applicable periods, data will be deleted, anonymised or made no longer identifiable, unless further retention is required by law or necessary to establish, exercise or defend a right.
-
Automated decision-making
The Controller does not use, within the Application, decision-making processes based solely on automated processing that produce legal effects concerning the Data Subject or similarly significantly affect them, within the meaning of Article 22 GDPR.
Advertising and analytics tools may use automated systems to measure, attribute and optimise campaigns or advertising content; Smooit does not use these activities to make individual decisions with legal or similarly significant effects concerning the Data Subject.
-
Data Subject rights
In the cases provided for by the GDPR, the Data Subject may exercise the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing and withdrawal of consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Requests may be sent to [email protected]. The Controller will respond without undue delay and, in any event, within one month of receiving the request, subject to the possibility of an extension in the cases and within the limits provided for by Article 12 GDPR, of which the Data Subject will be informed.
The Data Subject also has the right to lodge a complaint with the competent supervisory authority and, in Italy, with the Italian Data Protection Authority.
-
Changes to this Privacy Policy
The Controller may update this notice to reflect changes in law, technology or organisation, or changes to the services used. The updated version will be published on the Application with the date of the latest update.
Last updated: 23/09/2026