Privacy notice on the processing of personal data
Provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) to the users of the portal cias-multisphera.com
Version of
Translation provided for convenience only: in case of discrepancy, the Italian text prevails.
1. Introduction and scope
This notice describes how the personal data of the people who use the portal cias-multisphera.com (the "Portal") are processed. The Portal is the tool with which CIAS Elettronica S.r.l. manages the licences of the MultiSphera software along its commercial chain: CIAS, branches, distributors, installers/integrators and end users.
Through the Portal you can: activate, renew and administer licences and subscriptions (including the CyberShield and Sphera+ add-ons); receive software updates and security advisories; open support requests, attaching — upon explicit authorisation — a pseudonymised diagnostic package of the installation.
The notice applies to every user of the Portal, whatever their role in the chain, and supplements any notice given in the supply contracts.
2. Data controller
The data controller is CIAS Elettronica S.r.l., registered office in Via Durando 38, 20158 Milan (Italy), VAT number 05050870154, REA MI-1096215.
- E-mail for privacy matters: info@cias.it
- Telephone: +39 02 3767161
3. Data processor and data protection officer
The development and technical operation of the Portal are entrusted to iDev S.r.l. (Via Alessandro Volta 22, 20094 Corsico MI, Italy; VAT number IT02656830185; contact: info@idev-srl.com), appointed data processor under Article 28 GDPR by a specific agreement setting out its obligations, security measures and the prohibition to use the data for its own purposes.
Data protection officer (DPO): the Controller has not appointed a data protection officer under Article 37 GDPR. For any matter concerning the processing of personal data and to exercise your rights, please contact the Controller directly at the contact details given in section 2.
4. Source of the data
Personal data may be collected:
- from another member of the chain (Article 14 GDPR): the Portal offers no self-registration, and your account is created by CIAS or by the higher-level member of the chain (branch, distributor or installer/integrator) who invites you to work on the Portal and provides your name, surname, company, e-mail, telephone and role;
- directly from you, when you complete the activation of your account by setting your password, update your profile, open a support request or use the Portal;
- from the MultiSphera software installed at the customer's premises, which sends the Portal the technical data needed to activate and verify licences (installation identifier, hash of the MAC addresses of the devices, installed version) and, only if authorised by the installation administrator, the diagnostic package;
- automatically, while browsing (access and security logs).
5. Categories of data processed
- Account data: name, surname, company, e-mail, telephone, role in the chain, language, authorisation level, user who created the account.
- Credentials and multi-factor authentication: password (stored exclusively as a bcrypt hash, never in clear text), multi-factor authentication secret, devices recognised as trusted.
- Access and security logs: IP address, date and time, browser user agent, outcome of login attempts, relevant operations on licences.
- Licence data: activation key, installation identifier, hash of the MAC addresses of the connected devices, active modules and add-ons, expiry dates, customer and commercial chain.
- Support requests: ticket content, attachments and diagnostic packages. Packages are pseudonymised by the software before sending (identifiers replaced by codes) and are transmitted only after the explicit authorisation of the installation administrator.
- Transactional communications: account activation invitation, password reset, OTP codes, expiry notices, updates and security advisories.
- Browsing data and cookies: described in the cookie policy.
The Portal does not request nor intentionally process special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). Please do not include them in support tickets.
6. Purposes and legal bases of the processing
| Purpose | Legal basis |
|---|---|
| Creation and management of the account; activation, renewal and administration of licences and subscriptions; handling of support requests; sending of transactional communications | Performance of a contract or of pre-contractual measures (Article 6(1)(b) GDPR) |
| Distribution of software updates and of vulnerability and incident advisories, in compliance with the manufacturer's obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act); other legal obligations and replies to authorities | Legal obligation (Article 6(1)(c) GDPR) |
| Security of the Portal and of the connected systems: access logs, multi-factor authentication, detection and prevention of abuse, fraud and unauthorised access; protection of the Controller's rights | Legitimate interest of the Controller and of the users in the security of the systems (Article 6(1)(f) GDPR; recital 49) |
The legitimate interest has been balanced against your rights: logs and security measures are limited to what is necessary, kept only for as long as necessary and never used to profile users. You may object to this processing as described in the Data subject rights page.
7. Nature of the provision of data
Providing account data, credentials and licence data is necessary to use the Portal: without them the account cannot be created and licences cannot be managed.
8. Processing methods and security measures
Data are processed by IT means, by authorised and trained staff, with technical and organisational measures appropriate to the risk (Article 32 GDPR), including: encryption of communications (HTTPS/TLS), storage of passwords exclusively as hashes, multi-factor authentication, role-based access control mirroring the chain, logging of security events, pseudonymisation of diagnostic packages, backups and separation of environments.
9. Retention period
| Category of data | Retention period |
|---|---|
| Account data and credentials | For the duration of the relationship; after the account is deactivated, only for as long as necessary to comply with legal obligations or to establish, exercise or defend legal claims |
| Access and security logs | For as long as necessary for the security of the Portal and to detect abuse or unauthorised access; beyond that, only where needed to establish, exercise or defend legal claims |
| Licence and activation data | For the duration of the licence and of the relationship; after they end, only for as long as necessary to establish, exercise or defend legal claims |
| Support tickets | For the duration of the relationship; after the ticket is closed, only for as long as necessary to establish, exercise or defend legal claims |
| Attachments and diagnostic packages | For as long as necessary to resolve the support request; after the ticket is closed, only for as long as necessary to establish, exercise or defend legal claims |
We do not keep data beyond the minimum required by law and by the purposes described: when they are no longer necessary they are deleted or anonymised. You can ask for their erasure at any time as described on the Data subject rights page.
10. Recipients of the data
Data may be accessed by:
- authorised staff of CIAS Elettronica S.r.l. and of iDev S.r.l. (data processor), within the limits of their duties;
- the other members of the commercial chain your account is linked to (for instance the distributor who serves the end user), limited to the data needed to manage the licences under their responsibility;
- hosting and e-mail service providers, appointed data processors: Aruba S.p.A. (registered office: Via San Clemente 53, 24036 Ponte San Pietro BG, Italy), for the dedicated server, in a data centre in Italy, and for e-mail;
- public and judicial authorities, when required by law.
Data are not disseminated nor transferred to third parties for marketing purposes.
11. Transfers to third countries
Data are stored in Italy, on a dedicated server of Aruba S.p.A. located in an Italian data centre; the Portal's e-mail is also handled by Aruba S.p.A. Data therefore remain within the European Union.
The Portal uses no third-party service that involves a transfer of personal data to third countries. Should a provider involve such a transfer in the future, this notice will be updated stating the safeguards adopted under Articles 44-49 GDPR.
12. Automated decision-making
The Portal takes no decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects the person (Article 22 GDPR). Automatic security checks (for instance the temporary lock-out after repeated failed logins) are technical protection measures and do not involve decisions about the person.
13. Data subject rights
You may at any time exercise the rights set out in Articles 15-22 GDPR: access, rectification, erasure, restriction, portability, objection, as well as withdraw consent without affecting the lawfulness of previous processing. Practical instructions are in the Data subject rights page.
You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or to seek a judicial remedy.
14. Minors
The Portal is intended for professional operators and is not addressed to persons under 18 years of age.
15. Changes to this notice
This notice may be updated to reflect changes in the service or in the law. The version date is shown at the top of the page; substantial changes are communicated to the users of the Portal and, when they introduce cookies requiring consent, entail asking for your prior consent.