Privacy notice for business contacts
This notice explains what happens to your data when we contact your company by email about our services. We provide it under Article 14 of the EU GDPR and of the UK GDPR, because we did not collect the data from you directly. If you write to us first, or visit this website, the same notice also gives you the information required by Article 13.
Who is responsible for your data
The controller is Modernize Studio (Riccardo), Italy — [email protected].
We have not appointed a Data Protection Officer, as the law does not require one for an activity of this size. For any question about this notice, write to the address above.
What data we use
We use only the following:
- the business email address your company publishes on its website, usually a general one such as info@ or sales@;
- your company name, website address and country;
- public information from your website that we used to write the message, for example the software you sell or a job advert that mentions Access or Excel;
- if you reply, our correspondence and the dates of each contact;
- if you ask us to stop, your email address, kept on a “do not contact” list.
We do not use special categories of data, and we do not buy contact lists.
Where the data comes from
From your company's own website, where the address is published for business enquiries.
Why we use it, and on what legal basis
We use the data to contact your company about modernising older desktop software, to send at most two short follow-ups, to deal with any reply, and to respect any request to stop.
The legal basis is our legitimate interest in offering our services to businesses that may need them (Article 6(1)(f) GDPR). We have weighed that interest against your rights in a written assessment, which we can send you on request.
We only send these emails where the law allows them without prior consent: in the UK, only to companies, not to sole traders or partnerships; in France, only when the subject relates to the recipient's line of work. We do not send this kind of email to recipients in Italy, Spain or Germany.
This website
This website uses no cookies, no analytics and no tracking scripts, and it loads nothing from other websites. Like any web host, Cloudflare processes technical data such as your IP address and browser type in order to deliver the pages and protect the site from attacks. The legal basis is our legitimate interest in running a secure website (Article 6(1)(f) GDPR).
If you write to us, for example through one of the email links on this website, we use your message and your address only to reply and to follow up on your request. The legal basis is the steps you ask for before a possible contract (Article 6(1)(b) GDPR) and our legitimate interest in answering (Article 6(1)(f) GDPR).
Who else sees the data
Nobody buys or receives your data from us. Some providers process it on our behalf, under a contract that binds them to the GDPR:
- email service: Zoho Corporation, with the mailbox hosted in its EU data centre;
- website hosting and DNS: Cloudflare.
Transfers outside Europe
The data is stored in the European Economic Area. We do not transfer it outside the EEA or the UK, except where one of the providers above does so: Cloudflare runs a global network, so the technical data of a visit to this website may be processed outside Europe. In that case the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses, and you can ask us for a copy of the relevant safeguards.
How long we keep it
We keep the data for 12 months after our last contact, then we delete it. If you object or ask us to stop earlier, we delete it straight away, except for your email address on the “do not contact” list, which we keep only to make sure we never write to you again.
Your right to object
You can object at any time, without giving a reason, to the use of your data for direct marketing (Article 21 GDPR). Simply reply STOP to any of our emails or write to [email protected]. We will stop immediately and will not contact you again.
Your other rights
You can ask us for access to your data, for its correction, for its deletion or for its use to be restricted (Articles 15 to 18 GDPR). The right to data portability does not apply, because the processing is based on legitimate interest and not on consent or a contract. Requests are free, and we reply within one month.
If you think we have handled your data wrongly, you can complain to a supervisory authority:
- Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it
- United Kingdom: Information Commissioner's Office (ICO), ico.org.uk
- France: Commission nationale de l'informatique et des libertés (CNIL), www.cnil.fr
- Spain: Agencia Española de Protección de Datos (AEPD), www.aepd.es
- Germany: the data protection authority of your federal state; the Federal Commissioner for Data Protection (BfDI) lists them all at www.bfdi.bund.de
You can also contact the authority of the EU country where you live or work.
Automated decisions
Every message is written by a person. No decision about you is made by automated means, and there is no profiling with legal or similar effects on you.
Changes
If we change this notice, we will update the date at the top.