CIAS Privacy and legal notices
EN
  • IT Italiano
  • EN English
  • FR Français
  • DE Deutsch
  • ES Español
  • PL Polski
  • RU Русский
  • PT Português (Brasil)
  • AR العربية
  • ZH 简体中文
Back to login
Index Privacy notice Cookie policy Terms of use Data subject rights

Contents

  1. 1. Introduction and scope
  2. 2. Data controller
  3. 3. Data processor and data protection officer
  4. 4. Source of the data
  5. 5. Categories of data processed
  6. 6. Purposes and legal bases of the processing
  7. 7. Nature of the provision of data
  8. 8. Processing methods and security measures
  9. 9. Retention period
  10. 10. Recipients of the data
  11. 11. Transfers to third countries
  12. 12. Automated decision-making
  13. 13. Data subject rights
  14. 14. Minors
  15. 15. Changes to this notice
← Index

Privacy notice on the processing of personal data

Provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) to the users of the portal cias-multisphera.com

Version of 2026-09-19

Translation provided for convenience only: in case of discrepancy, the Italian text prevails.

1. Introduction and scope

This notice describes how the personal data of the people who use the portal cias-multisphera.com (the "Portal") are processed. The Portal is the tool with which CIAS Elettronica S.r.l. manages the licences of the MultiSphera software along its commercial chain: CIAS, branches, distributors, installers/integrators and end users.

Through the Portal you can: activate, renew and administer licences and subscriptions (including the CyberShield and Sphera+ add-ons); receive software updates and security advisories; open support requests, attaching — upon explicit authorisation — a pseudonymised diagnostic package of the installation.

The notice applies to every user of the Portal, whatever their role in the chain, and supplements any notice given in the supply contracts.

2. Data controller

The data controller is CIAS Elettronica S.r.l., registered office in Via Durando 38, 20158 Milan (Italy), VAT number 05050870154, REA MI-1096215.

  • E-mail for privacy matters: info@cias.it
  • Telephone: +39 02 3767161

3. Data processor and data protection officer

The development and technical operation of the Portal are entrusted to iDev S.r.l. (Via Alessandro Volta 22, 20094 Corsico MI, Italy; VAT number IT02656830185; contact: info@idev-srl.com), appointed data processor under Article 28 GDPR by a specific agreement setting out its obligations, security measures and the prohibition to use the data for its own purposes.

Data protection officer (DPO): the Controller has not appointed a data protection officer under Article 37 GDPR. For any matter concerning the processing of personal data and to exercise your rights, please contact the Controller directly at the contact details given in section 2.

4. Source of the data

Personal data may be collected:

  • from another member of the chain (Article 14 GDPR): the Portal offers no self-registration, and your account is created by CIAS or by the higher-level member of the chain (branch, distributor or installer/integrator) who invites you to work on the Portal and provides your name, surname, company, e-mail, telephone and role;
  • directly from you, when you complete the activation of your account by setting your password, update your profile, open a support request or use the Portal;
  • from the MultiSphera software installed at the customer's premises, which sends the Portal the technical data needed to activate and verify licences (installation identifier, hash of the MAC addresses of the devices, installed version) and, only if authorised by the installation administrator, the diagnostic package;
  • automatically, while browsing (access and security logs).

5. Categories of data processed

  • Account data: name, surname, company, e-mail, telephone, role in the chain, language, authorisation level, user who created the account.
  • Credentials and multi-factor authentication: password (stored exclusively as a bcrypt hash, never in clear text), multi-factor authentication secret, devices recognised as trusted.
  • Access and security logs: IP address, date and time, browser user agent, outcome of login attempts, relevant operations on licences.
  • Licence data: activation key, installation identifier, hash of the MAC addresses of the connected devices, active modules and add-ons, expiry dates, customer and commercial chain.
  • Support requests: ticket content, attachments and diagnostic packages. Packages are pseudonymised by the software before sending (identifiers replaced by codes) and are transmitted only after the explicit authorisation of the installation administrator.
  • Transactional communications: account activation invitation, password reset, OTP codes, expiry notices, updates and security advisories.
  • Browsing data and cookies: described in the cookie policy.

The Portal does not request nor intentionally process special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). Please do not include them in support tickets.

6. Purposes and legal bases of the processing

PurposeLegal basis
Creation and management of the account; activation, renewal and administration of licences and subscriptions; handling of support requests; sending of transactional communicationsPerformance of a contract or of pre-contractual measures (Article 6(1)(b) GDPR)
Distribution of software updates and of vulnerability and incident advisories, in compliance with the manufacturer's obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act); other legal obligations and replies to authoritiesLegal obligation (Article 6(1)(c) GDPR)
Security of the Portal and of the connected systems: access logs, multi-factor authentication, detection and prevention of abuse, fraud and unauthorised access; protection of the Controller's rightsLegitimate interest of the Controller and of the users in the security of the systems (Article 6(1)(f) GDPR; recital 49)

The legitimate interest has been balanced against your rights: logs and security measures are limited to what is necessary, kept only for as long as necessary and never used to profile users. You may object to this processing as described in the Data subject rights page.

7. Nature of the provision of data

Providing account data, credentials and licence data is necessary to use the Portal: without them the account cannot be created and licences cannot be managed.

8. Processing methods and security measures

Data are processed by IT means, by authorised and trained staff, with technical and organisational measures appropriate to the risk (Article 32 GDPR), including: encryption of communications (HTTPS/TLS), storage of passwords exclusively as hashes, multi-factor authentication, role-based access control mirroring the chain, logging of security events, pseudonymisation of diagnostic packages, backups and separation of environments.

9. Retention period

Category of dataRetention period
Account data and credentialsFor the duration of the relationship; after the account is deactivated, only for as long as necessary to comply with legal obligations or to establish, exercise or defend legal claims
Access and security logsFor as long as necessary for the security of the Portal and to detect abuse or unauthorised access; beyond that, only where needed to establish, exercise or defend legal claims
Licence and activation dataFor the duration of the licence and of the relationship; after they end, only for as long as necessary to establish, exercise or defend legal claims
Support ticketsFor the duration of the relationship; after the ticket is closed, only for as long as necessary to establish, exercise or defend legal claims
Attachments and diagnostic packagesFor as long as necessary to resolve the support request; after the ticket is closed, only for as long as necessary to establish, exercise or defend legal claims

We do not keep data beyond the minimum required by law and by the purposes described: when they are no longer necessary they are deleted or anonymised. You can ask for their erasure at any time as described on the Data subject rights page.

10. Recipients of the data

Data may be accessed by:

  • authorised staff of CIAS Elettronica S.r.l. and of iDev S.r.l. (data processor), within the limits of their duties;
  • the other members of the commercial chain your account is linked to (for instance the distributor who serves the end user), limited to the data needed to manage the licences under their responsibility;
  • hosting and e-mail service providers, appointed data processors: Aruba S.p.A. (registered office: Via San Clemente 53, 24036 Ponte San Pietro BG, Italy), for the dedicated server, in a data centre in Italy, and for e-mail;
  • public and judicial authorities, when required by law.

Data are not disseminated nor transferred to third parties for marketing purposes.

11. Transfers to third countries

Data are stored in Italy, on a dedicated server of Aruba S.p.A. located in an Italian data centre; the Portal's e-mail is also handled by Aruba S.p.A. Data therefore remain within the European Union.

The Portal uses no third-party service that involves a transfer of personal data to third countries. Should a provider involve such a transfer in the future, this notice will be updated stating the safeguards adopted under Articles 44-49 GDPR.

12. Automated decision-making

The Portal takes no decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects the person (Article 22 GDPR). Automatic security checks (for instance the temporary lock-out after repeated failed logins) are technical protection measures and do not involve decisions about the person.

13. Data subject rights

You may at any time exercise the rights set out in Articles 15-22 GDPR: access, rectification, erasure, restriction, portability, objection, as well as withdraw consent without affecting the lawfulness of previous processing. Practical instructions are in the Data subject rights page.

You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or to seek a judicial remedy.

14. Minors

The Portal is intended for professional operators and is not addressed to persons under 18 years of age.

15. Changes to this notice

This notice may be updated to reflect changes in the service or in the law. The version date is shown at the top of the page; substantial changes are communicated to the users of the Portal and, when they introduce cookies requiring consent, entail asking for your prior consent.

© 2026 CIAS Elettronica S.r.l. · All rights reserved · Powered by iDev
Privacy notice Cookie policy Terms of use Data subject rights Report a vulnerability Cookie settings

This portal uses cookies

We use technical cookies that are necessary for the portal to work and for authentication. Only with your consent may the non-necessary cookies described in the cookie policy be enabled. No non-necessary cookie is set before you choose. Closing this notice with the X continues without non-necessary cookies. You can change your mind at any time from "Cookie settings" in the footer. Read the cookie policy

Cookie preferences

Choose which categories of cookies to allow. Necessary cookies cannot be disabled because the portal does not work without them. Your choice is stored for 6 months in the technical cookie ms_cookie_consent and will be asked again when it expires or when the notice changes.

  • Always active

    Essential for the portal to work: working session, authentication, chosen language and storage of this very cookie choice. They do not require consent.

  • Remember non-essential preferences to improve the user experience. The portal currently uses none: the category is reserved for future uses, which will be described in the cookie policy.

    Category not currently in use: the portal sets no cookie of this kind.

  • Collect aggregated information on how the portal is used. The portal currently uses no statistics cookies and no traffic analysis tools.

    Category not currently in use: the portal sets no cookie of this kind.

  • Set by services external to the portal. The portal currently uses no third-party service that sets cookies.

    Category not currently in use: the portal sets no cookie of this kind.

Withdrawing disables every non-necessary category and deletes the stored choice. Read the cookie policy