Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Last updated: 26 September 2026
1. Data controller
The Data Controller is K4 Solutions S.r.l., registered office at Via Enrico Stevenson 24, 00162 Rome, Italy, VAT number 15211071004.
For privacy enquiries and to exercise your rights, use the secure contact form or write to info@k4solutions.it.
2. Scope and principles
This notice concerns the K4 Solutions corporate website and does not cover third-party websites reached through external links. Personal data is processed lawfully, fairly and transparently, for specified purposes and in accordance with the principles of data minimisation, accuracy, storage limitation, integrity and confidentiality.
3. Data processed and source
Browsing and security data
The systems and software procedures used to operate the website may acquire technical data transmitted as part of Internet protocols, such as IP address, requested resource, request time, response status, browser and device information. This data is used to deliver the website, diagnose faults, prevent abuse and protect systems.
Data submitted through the contact form
The form collects name and surname, email address, area of interest and message. Organisation and telephone number are optional. The email address is verified through a six-digit one-time code (OTP) before the request is delivered to K4 Solutions.
While verification is pending, the form data is stored in encrypted form in a temporary WordPress record for up to ten minutes. The OTP is stored only as a non-reversible hash. After successful delivery, the temporary record is deleted. Pseudonymised technical identifiers derived from the email address and IP address are retained for thirty minutes to limit automated or repeated requests.
Cookies and analytics
The website uses essential cookies and, only when configured and after the user has provided consent, Google Analytics 4 for aggregate visit statistics. Analytics is disabled by default. Details, retention periods and preference controls are available in the Cookie Policy.
Restricted WordPress administration area
Authorised website administrators may have WordPress accounts. The platform processes account details, authentication and security logs and technical preferences required to manage the website. The public website does not provide visitor registration or public comments.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Deliver the website and ensure its technical operation. | Legitimate interest in operating and protecting the service (Article 6(1)(f) GDPR). |
| Reply to enquiries, assess projects and take steps at the user’s request before entering into a contract. | Steps prior to entering into a contract or performance of a contract (Article 6(1)(b) GDPR). |
| Prevent spam, automated submissions and security incidents. | Legitimate interest in service and information security (Article 6(1)(f) GDPR). |
| Produce aggregate visit statistics through optional analytics. | Consent (Article 6(1)(a) GDPR and applicable ePrivacy rules). |
| Comply with legal obligations and establish, exercise or defend legal claims. | Legal obligation and legitimate interest (Articles 6(1)(c) and 6(1)(f) GDPR). |
5. Is providing data mandatory?
Browsing data is required for the technical delivery of the website. Fields marked as required in the contact form are necessary to verify the sender and reply to the request; failure to provide them prevents submission. Optional fields may be left blank. Consent to analytics is always optional and refusal does not affect access to the website.
6. Processing methods and security
Processing is carried out with electronic tools and organisational measures appropriate to the risk. The contact workflow applies input validation, anti-CSRF controls, a honeypot, time limits, rate limiting, email verification, encryption of temporary form data and restricted administrative access. No Internet transmission or storage system can, however, provide an absolute guarantee of security.
7. Recipients and processors
Data may be processed by authorised K4 Solutions personnel and by suppliers that provide hosting, infrastructure, maintenance, security, email and SMTP delivery services, acting as processors where required. Data may also be disclosed to professional advisers or public authorities when required by law or necessary to establish, exercise or defend legal claims. Data is not sold.
An up-to-date list of processors may be requested from the Data Controller.
8. International transfers
K4 Solutions selects service providers and configurations designed to keep data within the European Economic Area where reasonably possible. If a provider processes data in a third country, the transfer will be based on an adequacy decision, Standard Contractual Clauses or another safeguard permitted by Chapter V of the GDPR. If Google Analytics is enabled, additional information on Google’s role and transfers is provided in the Cookie Policy.
9. Retention periods
- Unverified contact form payload: up to 10 minutes; pseudonymised anti-abuse counters: 30 minutes.
- Verified enquiries and related correspondence: for the time needed to reply and manage any subsequent pre-contractual or contractual relationship, and thereafter for legal, accounting or defence requirements.
- Security and server logs: for the period established by the infrastructure provider and no longer than necessary for security, diagnostics and legal requirements.
- Cookie preferences and optional analytics: for the periods listed in the Cookie Policy.
- Authorised WordPress accounts: for the duration of the authorisation and for any further period required for security and accountability.
10. Rights of data subjects
Under Articles 15–22 GDPR, where applicable, the data subject may request access to personal data, rectification, erasure, restriction of processing, data portability, and may object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Requests may be submitted through the secure contact form or to info@k4solutions.it. The Controller may request information necessary to verify the identity of the requester.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority, without prejudice to any other administrative or judicial remedy. Information from the Italian Data Protection Authority.
11. Automated decisions and minors
The website does not make decisions producing legal or similarly significant effects based solely on automated processing, nor does it perform profiling for advertising purposes. The corporate website is not specifically directed at children; minors should not submit requests without the assistance of a parent or guardian.
12. Changes to this notice
This notice may be updated following changes to the website, providers, processing operations or applicable law. The current version and its update date are always published on this page.
