Privacy Policy
Last updated: 7 August 2026
This notice is provided under articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and describes how Puntanet S.r.l. processes the personal data of visitors to www.buildxguru.com. It covers this website only: the processing of data entered into the BuildXGuru platform by customers is governed by the service contract and its data processing agreement.
This English text is a courtesy translation. In the event of any discrepancy, the Italian version shall prevail.
1. Data Controller
The data controller is Puntanet S.r.l., registered office at Viale Odorico da Pordenone 33 — 95128 Catania (CT), Italy. Tax code and VAT no. IT05479560871 — REA no. CT-369530.
For any matter relating to personal data you may write to mail@puntanet.eu, to the certified address puntanet.srl@pec.it, or call +39 095 5187993.
2. Personal data processed
The website processes the following categories of data.
2.1 Browsing data
The IT systems and software procedures underlying this website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP address, browser and operating system type, date and time of the request, and the address of the requested resources. This data is used solely to deliver the website, to obtain anonymous statistics on its use and to verify its correct operation and security.
2.2 Data provided voluntarily
By completing the consultation request form, the user provides their name, company, email address, company size, the content of the message and, optionally, a telephone number. The optional, explicit and voluntary sending of messages to the published contact addresses entails the acquisition of the sender’s address and of the data contained in the communication.
2.3 Data collected through cookies and similar technologies
The website uses technical storage only and, subject to consent, measurement and marketing tools. Full details are set out in the Cookie Policy.
3. Purposes and legal bases
Data is processed for the following purposes and on the following legal bases:
| Purpose | Legal basis | Retention |
|---|---|---|
| Delivery and security of the website, abuse prevention | Legitimate interest of the controller (art. 6.1.f) | Up to 12 months for technical logs |
| Responding to consultation and contact requests | Pre-contractual measures at the data subject’s request (art. 6.1.b) | 24 months from the last contact |
| Statistical measurement of website usage | Consent (art. 6.1.a) | Until consent is withdrawn |
| Promotional communications and advertising campaigns | Consent (art. 6.1.a) | Until consent is withdrawn |
| Compliance with legal obligations, defence of legal claims | Legal obligation and legitimate interest (art. 6.1.c and f) | Applicable statutory periods |
4. Nature of the provision of data
The provision of browsing data is necessary in order to use the website. The provision of the data requested by the contact form is optional, but failure to provide the fields marked as mandatory prevents us from responding to the request. Consent to non-necessary cookies is always optional and may be withdrawn at any time, with no consequences for browsing.
5. Processing methods
Processing is carried out using automated and, where necessary, manual tools, for no longer than is necessary to achieve the stated purposes. Appropriate technical and organisational measures are in place to prevent data loss, unlawful or incorrect use and unauthorised access, including encryption of data in transit, access control and minimisation of the data collected.
6. Recipients of the data
Data may be processed by the controller’s authorised personnel and disclosed to the following categories of recipient, appointed as data processors under article 28 GDPR where they act on the controller’s behalf:
- hosting and cloud infrastructure providers;
- email and customer relationship management providers;
- providers of statistical measurement and marketing tools, limited to cases where the relevant consent has been given;
- professionals and advisers assisting the controller in legal, accounting and tax matters;
- public authorities, in the cases provided for by law.
Data is neither disseminated nor transferred to third parties for their own commercial purposes. An up-to-date list of data processors is available on request at the addresses given in article 1.
7. Transfers to third countries
Processing normally takes place within the European Economic Area. Should the use of certain services entail a transfer of data to third countries, the controller ensures that it takes place under an adequacy decision of the European Commission or on the basis of appropriate safeguards under articles 46 et seq. GDPR, such as Standard Contractual Clauses, accompanied where necessary by supplementary measures.
8. Retention period
Data is retained for the periods indicated in article 3. Once those periods expire, data is deleted or irreversibly anonymised, unless further retention is necessary to comply with legal obligations or to establish, exercise or defend legal claims.
9. Rights of the data subject
In relation to the data processed, the data subject may exercise at any time the rights provided for by articles 15-22 GDPR, and in particular:
- the right of access to their personal data;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure (“right to be forgotten”);
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on legitimate interest;
- the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Requests should be addressed to mail@puntanet.eu or to puntanet.srl@pec.it. The controller responds without undue delay and in any case within one month of receiving the request, extendable by two months where the request is particularly complex.
10. Complaint to the supervisory authority
A data subject who considers that the processing of their data infringes the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to bring proceedings before the competent courts.
11. Automated decision-making
The website does not carry out automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of article 22 GDPR.
12. Data relating to minors
The website is aimed at business customers and is not intended for minors. The controller does not knowingly collect personal data of minors. Should such data be detected, it will be deleted without undue delay.
13. Links to third-party sites
The website contains links to third-party sites and services, including the controller’s social profiles and the app stores. This notice does not apply to those sites: please consult their respective privacy notices.
14. Changes to this notice
The controller reserves the right to amend or update this notice, including as a result of changes in applicable law or in the services offered. Amendments take effect upon publication on this page; the date of last update is shown at the top of the document.