Skip to content

Privacy Policy

Last updated: 7 August 2026

This notice is provided under articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and describes how Puntanet S.r.l. processes the personal data of visitors to www.buildxguru.com. It covers this website only: the processing of data entered into the BuildXGuru platform by customers is governed by the service contract and its data processing agreement.

This English text is a courtesy translation. In the event of any discrepancy, the Italian version shall prevail.

1. Data Controller

The data controller is Puntanet S.r.l., registered office at Viale Odorico da Pordenone 33 — 95128 Catania (CT), Italy. Tax code and VAT no. IT05479560871 — REA no. CT-369530.

For any matter relating to personal data you may write to mail@puntanet.eu, to the certified address puntanet.srl@pec.it, or call +39 095 5187993.

2. Personal data processed

The website processes the following categories of data.

2.1 Browsing data

The IT systems and software procedures underlying this website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP address, browser and operating system type, date and time of the request, and the address of the requested resources. This data is used solely to deliver the website, to obtain anonymous statistics on its use and to verify its correct operation and security.

2.2 Data provided voluntarily

By completing the consultation request form, the user provides their name, company, email address, company size, the content of the message and, optionally, a telephone number. The optional, explicit and voluntary sending of messages to the published contact addresses entails the acquisition of the sender’s address and of the data contained in the communication.

2.3 Data collected through cookies and similar technologies

The website uses technical storage only and, subject to consent, measurement and marketing tools. Full details are set out in the Cookie Policy.

3. Purposes and legal bases

Data is processed for the following purposes and on the following legal bases:

PurposeLegal basisRetention
Delivery and security of the website, abuse preventionLegitimate interest of the controller (art. 6.1.f)Up to 12 months for technical logs
Responding to consultation and contact requestsPre-contractual measures at the data subject’s request (art. 6.1.b)24 months from the last contact
Statistical measurement of website usageConsent (art. 6.1.a)Until consent is withdrawn
Promotional communications and advertising campaignsConsent (art. 6.1.a)Until consent is withdrawn
Compliance with legal obligations, defence of legal claimsLegal obligation and legitimate interest (art. 6.1.c and f)Applicable statutory periods

4. Nature of the provision of data

The provision of browsing data is necessary in order to use the website. The provision of the data requested by the contact form is optional, but failure to provide the fields marked as mandatory prevents us from responding to the request. Consent to non-necessary cookies is always optional and may be withdrawn at any time, with no consequences for browsing.

5. Processing methods

Processing is carried out using automated and, where necessary, manual tools, for no longer than is necessary to achieve the stated purposes. Appropriate technical and organisational measures are in place to prevent data loss, unlawful or incorrect use and unauthorised access, including encryption of data in transit, access control and minimisation of the data collected.

6. Recipients of the data

Data may be processed by the controller’s authorised personnel and disclosed to the following categories of recipient, appointed as data processors under article 28 GDPR where they act on the controller’s behalf:

  • hosting and cloud infrastructure providers;
  • email and customer relationship management providers;
  • providers of statistical measurement and marketing tools, limited to cases where the relevant consent has been given;
  • professionals and advisers assisting the controller in legal, accounting and tax matters;
  • public authorities, in the cases provided for by law.

Data is neither disseminated nor transferred to third parties for their own commercial purposes. An up-to-date list of data processors is available on request at the addresses given in article 1.

7. Transfers to third countries

Processing normally takes place within the European Economic Area. Should the use of certain services entail a transfer of data to third countries, the controller ensures that it takes place under an adequacy decision of the European Commission or on the basis of appropriate safeguards under articles 46 et seq. GDPR, such as Standard Contractual Clauses, accompanied where necessary by supplementary measures.

8. Retention period

Data is retained for the periods indicated in article 3. Once those periods expire, data is deleted or irreversibly anonymised, unless further retention is necessary to comply with legal obligations or to establish, exercise or defend legal claims.

9. Rights of the data subject

In relation to the data processed, the data subject may exercise at any time the rights provided for by articles 15-22 GDPR, and in particular:

  • the right of access to their personal data;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure (“right to be forgotten”);
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object to processing based on legitimate interest;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Requests should be addressed to mail@puntanet.eu or to puntanet.srl@pec.it. The controller responds without undue delay and in any case within one month of receiving the request, extendable by two months where the request is particularly complex.

10. Complaint to the supervisory authority

A data subject who considers that the processing of their data infringes the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to bring proceedings before the competent courts.

11. Automated decision-making

The website does not carry out automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of article 22 GDPR.

12. Data relating to minors

The website is aimed at business customers and is not intended for minors. The controller does not knowingly collect personal data of minors. Should such data be detected, it will be deleted without undue delay.

13. Links to third-party sites

The website contains links to third-party sites and services, including the controller’s social profiles and the app stores. This notice does not apply to those sites: please consult their respective privacy notices.

14. Changes to this notice

The controller reserves the right to amend or update this notice, including as a result of changes in applicable law or in the services offered. Amendments take effect upon publication on this page; the date of last update is shown at the top of the document.