Privacy Policy
Courtesy translation
This is an English translation provided for information only. The Italian version of this Privacy Policy, available at www.ipgsenergy.it/privacy-policy, is the authoritative text. In the event of any discrepancy, the Italian text prevails.
1. Introduction
This Privacy Policy describes how IPGS ENERGY S.r.l. collects, uses and protects users' personal data in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and Italian Legislative Decree 196/2003 (Privacy Code) as amended by Legislative Decree 101/2018.
It applies to the website www.ipgsenergy.it, to the client portal portale.ipgsenergy.it and to the email communications sent by IPGS ENERGY S.r.l.
2. Data Controller
The data controller is:
IPGS ENERGY S.r.l.
Registered office: Via Ugo Ojetti 7, 20151 Milan (MI), Italy
VAT and Tax Code: 07006920966
Milan Companies Register — REA MI-1928935
Share capital: EUR 10,000.00 fully paid up
Email: ipgsenergy@ipgsenergy.it
IPGS ENERGY S.r.l. has not appointed a Data Protection Officer, as the conditions of art. 37 of Regulation (EU) 2016/679 are not met: it does not carry out regular and systematic monitoring of data subjects on a large scale, nor does it process special categories of data on a large scale. For any data protection matter, please write to the address above.
Where IPGS ENERGY S.r.l. processes personal data on behalf of a business client — typically the data of contacts and employees contained in the supply documents uploaded to the portal — it acts as a processor under art. 28 GDPR, on the basis of a specific appointment.
3. Data Collected
We collect the following categories of data:
- Identification data: first name, last name, email, telephone number
- Company data: company name, VAT number, registered address
- Technical data: IP address, browser type, operating system
- Usage data: pages visited, time spent, actions performed
- Gas self-reading data: delivery point (PDR), meter serial numbers, readings
- Data contained in documents uploaded to the portal: supply contracts, invoices and bills, correspondence with suppliers, consumption data. These may include identification and contact data of company representatives.
- Support request data: ticket content, attachments, history of exchanges
- Authentication and security data: encrypted credentials, second authentication factor, recovery codes, access log and security event log
- Email interaction data: whether informational messages were opened, as described in section 9 below
- Application data: for those responding to an open position through the contact form, the identification data and professional information they voluntarily provide
- Consent data: date and time of acceptance of the legal documents, the version accepted and the cryptographic fingerprint of the text, IP address and browser identifier (user agent) at the time of acceptance. For cookie consent given on the public website, the IP address is stored only in irreversibly hashed form.
We do not intentionally process special categories of personal data (art. 9 GDPR). We ask users not to include such data in uploaded documents, support messages or contact requests.
4. Purposes of Processing
Data is processed for the following purposes:
- Providing the requested services and managing the contractual relationship
- Responding to contact and consultancy requests
- Analysing and optimising energy supplies, including the automated document processing described in section 11
- Handling support requests
- Complying with legal and tax obligations
- Sending service communications necessary to perform the relationship
- Sending informational communications about services and the energy market, with aggregate measurement of the interest they generate (section 9)
- Assessing applications for open positions
- Platform security, protection of public forms against automated submissions and fraud prevention
- Anonymous statistical analysis to improve the services offered
- Retaining evidence of the consents given, in compliance with the accountability obligation under art. 7(1) and art. 5(2) GDPR
5. Legal Basis
Processing is based on:
- Performance of a contract (art. 6(1)(b) GDPR) — for providing the services, managing accounts and support requests, and service communications
- Legal obligations (art. 6(1)(c) GDPR) — for tax and regulatory compliance
- Consent of the data subject (art. 6(1)(a) GDPR) — for analytics and marketing cookies and for sending informational communications to persons who are not already clients
- Legitimate interest (art. 6(1)(f) GDPR) — for platform security, bot protection, fraud prevention, documenting consents, and analysing and optimising energy supplies within the consultancy relationship
Informational communications sent to clients about services similar to those already provided rely on art. 130(4) of Italian Legislative Decree 196/2003: the data subject is informed at the time the address is collected and may object free of charge, at any time, both at collection and in every subsequent communication.
Providing the data necessary to perform the contract is required: without it the account cannot be activated and the service cannot be delivered. Providing data for informational purposes and non-essential cookies is optional and refusal does not affect access to the portal.
6. Processors and Recipients
Personal data may be disclosed to the following categories of recipients, appointed as processors under art. 28 GDPR:
- Supabase Inc. (USA, infrastructure in the European Union) — authentication, database and document storage services. Data is protected by the Standard Contractual Clauses (SCC) approved by the European Commission.
- Amazon Web Services, Inc. (USA) — sending transactional and informational email through AWS SES. Transfers governed by SCC and certification under the Data Privacy Framework.
- Vercel Inc. (USA) — hosting of the website and the portal. Transfers governed by SCC.
- Anthropic PBC (USA) — automated reading and structuring of the data contained in bills and supply documents uploaded to the portal. The content transmitted is not used to train the models and is retained by the provider only for as long as necessary to process it. Transfers governed by SCC.
- Cloudflare, Inc. (USA) — protection of public forms against automated submissions (Turnstile service), processing IP address and technical browser signals. Transfers governed by SCC and the Data Privacy Framework.
- Google LLC (USA) — Google Analytics for website traffic statistics (with consent only). Transfers governed by SCC and the Data Privacy Framework.
- Meta Platforms Ireland Ltd. (Ireland) — advertising campaign measurement tools on the public website, active only with consent to marketing cookies.
Data may also be disclosed to professionals and advisers (accountants, lawyers, auditors) and to the competent authorities where required by law. It is not disseminated or sold to third parties.
Backup copies of company documents may be stored on dedicated storage infrastructure managed directly by IPGS ENERGY S.r.l. and located within the European Union.
The up-to-date list of processors is available at www.ipgsenergy.it/legal.
Transfers of data to the United States take place in accordance with Chapter V of the GDPR, through Standard Contractual Clauses (SCC) and, where applicable, on the basis of adequacy recognised under the EU-US Data Privacy Framework.
7. Data Retention
Personal data is retained for as long as necessary for the purposes for which it was collected:
- Consultancy relationship data: for the duration of the relationship + 10 years (tax obligations, art. 2220 Italian Civil Code)
- Tax documents: 10 years (Italian tax law)
- Supply documents uploaded to the portal: for the duration of the relationship and thereafter within the limits of legal obligations
- Energy consumption data: 5 years from the end of the relationship
- Support tickets: 2 years from closure
- Access logs and security events: 12 months (security measures), save for longer retention in the event of a dispute or incident
- Contact data (information requests): 24 months from the request
- Job applications: 12 months from receipt, unless the data subject consents otherwise
- Open data for informational communications: 24 months
- Analytics data: 26 months (Google Analytics)
- Register of consents to the legal documents: 10 years from acceptance, as evidence of contractual compliance and of the accountability obligation
- Register of cookie consents: 24 months from collection
8. Data Subject Rights
Under arts. 15-22 GDPR, data subjects have the right to:
- Access their personal data (art. 15 GDPR)
- Obtain rectification of inaccurate data (art. 16 GDPR)
- Obtain erasure of their data (art. 17 GDPR)
- Obtain restriction of processing (art. 18 GDPR)
- Request data portability (art. 20 GDPR)
- Object to processing, including the sending of informational communications (art. 21 GDPR)
- Withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal
- Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)
Requests are handled without undue delay and in any case within 30 days of receipt, extendable by a further 60 days in the cases provided for by art. 12(3) GDPR, with notice to the data subject.
Client portal users may also exercise the rights of access and portability themselves by downloading their data from Settings › Privacy in the portal, where the history of consents given is also available, and change their communication preferences under Settings › Notifications.
To exercise your rights, write to: ipgsenergy@ipgsenergy.it
9. Email communications and open statistics
The informational communications sent by IPGS ENERGY S.r.l. contain a minimal transparent image (commonly known as a tracking pixel) which, when the mail client downloads images, tells us that the message has been opened. This data is used to measure the interest generated by our content and to improve it; it does not feed individual profiling or decisions about any individual recipient.
The processing relies on the Controller's legitimate interest in assessing the effectiveness of its communications (art. 6(1)(f) GDPR). You may object at any time by writing to the addresses in section 8, by switching off informational communications under Settings › Notifications in the portal, or by preventing images from loading automatically in your mail client. Service communications necessary to perform the relationship contain no measurement tools.
10. Job applications and recruitment
Those responding to an open position published at www.ipgsenergy.it/lavora-con-noi send their data through the contact form. That data is processed solely to assess the application, on the basis of pre-contractual measures taken at the data subject's request (art. 6(1)(b) GDPR), and is accessible only to staff involved in recruitment.
Applications are retained for 12 months from receipt and then deleted, unless the data subject consents to longer retention for future opportunities. We ask applicants not to include data that is not relevant to the professional assessment, in particular special categories of data under art. 9 GDPR.
11. Automated processing and decision-making
To speed up the handling of bills and supply documents, IPGS ENERGY S.r.l. uses automated tools to read and structure data, including tools based on artificial intelligence models provided by Anthropic PBC. The documents transmitted are not used to train the models.
The output of automated processing is preliminary and is always reviewed by a member of staff. IPGS ENERGY S.r.l. does not carry out automated decision-making, including profiling, producing legal effects or similarly significantly affecting the data subject (art. 22 GDPR).
12. Cookies
The website uses technical cookies and, with consent, analytics and marketing cookies. For more information on cookie management, see our Cookie Policy.
13. Minors
The services of IPGS ENERGY S.r.l. are intended exclusively for individuals of legal age (minimum 18 years) acting as representatives or delegates of client companies. We do not knowingly collect personal data of persons under 18. Should we become aware of having collected a minor's data, we will delete it promptly.
14. Security
IPGS ENERGY S.r.l. adopts appropriate technical and organisational measures to ensure the security of personal data and prevent unauthorised access, loss or disclosure, including: encryption of data in transit (TLS/SSL), storage of credentials in encrypted form, multi-factor authentication for administrative and operational accounts, role-based access control (RBAC) with data isolation at database level, security event logging and periodic backups.
In the event of a personal data breach involving a high risk to the rights and freedoms of data subjects, IPGS ENERGY S.r.l. will notify the Italian Data Protection Authority and communicate with the data subjects within the time limits set by arts. 33 and 34 GDPR.
15. Changes
This Privacy Policy may be amended. Changes will be published on this page with the date of the latest update and, if material, notified by email to registered users at least 30 days in advance. Every previous version remains available in the archive published at www.ipgsenergy.it/legal.
SHA-256 fingerprint of this version: fddfb94140898688bd25f4100ab7219afefc89ae33ff6f28a6ee8ab51f49d8eb
It is the reference recorded alongside portal users' acceptances: it allows anyone to verify that the accepted text is exactly this one.