Privacy Policy
Last updated: 4 August 2026
Navis.net – GDPR compliance
Digibusiness Srl has its registered office in Collecchio (PR – Italy), Viale Libertà 10, REA no. PR-217228 and VAT no. IT02184210348, incorporated on 10 July 2001.
Corporate purpose: the design and development of IT systems and applications and the supply of the services deriving from them, in order to support customers in pursuing their business objectives.
Navis.net is a Management-CRM (Customer Relations Management) application supplied to marine businesses.
Summary
This document describes the processing of Personal Data carried out by Digibusiness, its GDPR compliance and obligations, as well as the organisational, physical and logical security measures that Digibusiness srl has decided to adopt in order to minimise the risks of destruction or loss, including accidental loss, of unauthorised access or of processing that is not permitted or not consistent with the purposes of the data, and to comply with the obligations laid down by the legislation in force on the protection of personal data (EU REGULATION 2016/679). A further level of detail on the subject is contained in the Digibusiness DPIA (Data Protection Impact Analysis), available on request.
With specific regard to the data processed by the Management-CRM application named Navis.net, the document describes:
- the type of personal data processed and the purposes of the processing
- the security and protection measures in place (organisational, physical, logical)
- the tools Navis.net provides to deliver the privacy notice and obtain consents
- the security protections for the other information owned by the Company which is not subject to the law, but which is critical to its business
- the risk assessment
The provisions of this document apply to all processing for which the Company is Controller and to processing for which the Company is appointed Processor by the businesses that use Navis.net for their commercial activities and, to that end, hold personal data of their own customers and prospective customers within this System.
Hereinafter the terms Controller, Processor, Authorised Person, Processing, Personal Data and Sensitive Data are used in accordance with the definitions of the Code. Periodic checks are carried out on the application of the provisions contained in or related to this document. The outcome of the checks is documented in a report whose details and any references to the documentation produced will be included in the revision of this document.
Preliminary considerations
Digibusiness srl is a company that provides consultancy services, Application Service (ASP) services and hosting services. In the exercise of its functions the Company is the Controller of the personal data relating to its own employees, customers and suppliers, while it is the Processor of the data that its customers (hereinafter also referred to as Users of the System) enter into the IT systems and/or environments that the Company manages.
Digibusiness SRL has its own equipment, located at its premises, for design and development activities, and IT resources supplied for use by third parties for the management of the Company and the provision of ASP and hosting services to its customers; in particular, with the exception of software design and development activities, the servers and storage systems are supplied by external providers: Microsoft AZURE and GOOGLE, companies with which Digibusiness has service agreements in place defining service parameters and data security and protection criteria.
The Company also uses third parties both for the management of administrative and accounting data and for the management of personnel data.
Processing carried out by Digibusiness Srl
This section identifies the processing carried out by the Controller on data managed directly (2), as well as the processing carried out by the Controller acting as a Processor appointed by third parties (3), indicating the nature of the data and the internal or external structure (site, function, etc.) operationally responsible for it, as well as the electronic tools used.
1. Organisation
As at the update date of this document, Digibusiness SRL has assigned to its Managing Director, Mr Gabriele Mendi, the role of Controller of the personal data processing for which the Company is responsible. The Controller takes the decisions on the purposes and methods of processing personal data and is also tasked with monitoring, including through periodic checks, the Processor's compliance with its instructions and with the applicable provisions on processing, including the security aspect.
The role of Processor for all Personal Data processing is likewise assigned to the active partner Mr Fausto Aimi, who at the same time also holds the role of System Administrator.
All employees and/or collaborators who, to varying extents and with specific authorisations, must be able to process — even occasionally — the personal data of Digibusiness and of Users, have been made accountable through a specific appointment that sets out their remit and limits their operational scope. The list of roles and the related duties to be performed are included in the Digibusiness DPIA, available on request.
2. Customer data for which Digibusiness is the Controller
The processing concerns contracts and invoicing and relates exclusively to ordinary data; no sensitive or judicial data is involved.
The identifying details of Users (customers of Digibusiness SRL) are held at the Company's premises, while administrative and accounting summaries are delegated to an external firm (Studio Vignetti, Vicolo Politi 7 – 43121 Parma, Italy), which handles them with its own resources. The purposes of the processing are to manage the supplier-customer relationship from a contractual and tax perspective and with regard to the services supplied and work developments. In some cases this data may also relate to employees and/or collaborators of these companies with whom a supply relationship is being developed, but it is in any case limited to telephone and/or postal contact details.
The privacy notice concerning the processing of User data is contained in the Service Charter, which forms an integral part of the contract signed by customers, who thereby give implicit consent to the processing of their data. Digibusiness does not carry out automated processing on the data of its customers and prospective customers and does not transfer such data to third parties, except as regards administrative and accounting matters.
Particular mention should be made of the data Digibusiness obtains from public sources in order to identify the companies to which it can offer its services (Prospective Users), with the aim of broadening its customer base. In this case, the privacy notice and the collection of consents to processing are handled at the time of first contact.
3. Data of Navis.net User businesses that have appointed Digibusiness as Processor
Navis.net is a management application owned by Digibusiness but it is also a services platform aimed at the businesses (Users) that sell recreational craft.
The services of the Navis.net platform comprise all the features that allow Users to manage their commercial activities optimally, and in particular: management of boats for sale, management of advertising, relations with customers and boaters, and relations with other businesses in the sector and with their own suppliers. Navis.net services are supplied to Users in ASP (Application Service Provider) mode.
3.1 Processing and purposes
User businesses (typically shipyards, dealers and brokers), as Controllers of the processing of their own customers' data, enter into the System information concerning natural or legal persons (companies) in order to maintain and develop commercial relationships. Digibusiness does not examine the merits of the data, but ensures the availability of the service and the protection of the data itself; service levels and the ability to provide a copy of the data are described in the Service Charter, which forms an integral part of every service contract. Through the Navis.net service contract, the Controller confers on Digibusiness the responsibility for data processing (external Data Processor).
The data is used to identify customers and define a profile of them in terms of nautical interests, so as to assist the seller (the Navis.net User) in promotional activities and to allow them to present proposals consistent with the profile drawn up. Navis.net allows profiling to be performed manually but also provides an automatic profiling feature (Brokerage Intelligence).
3.2 Protection and security measures
- The Controller has one or more sets of access credentials, made up of a UserID and Password, which it may make available to the persons it has authorised to process data. The access credentials restrict and confine processing solely to the data entered into the System by the Controller, or by automatic and/or bulk insertion operations authorised by it. The Password is structured so as to minimise the likelihood of it being guessed, and the system detects and blocks intrusion attempts.
- Management of access credentials is the responsibility of the Digibusiness System Administrator, while maintenance of the application and of the database is the responsibility of Digibusiness employees specifically authorised to process data and, as such, bound by confidentiality obligations.
- The servers and databases that power the Navis.net System are supplied by Microsoft AZURE and are held in data centres located in Europe with a high level of physical and logical protection. Data backup is performed daily. A detailed description of the protection and security measures can be provided on request.
3.3 GDPR compliance tools
Navis.net provides Users with what they need in order to:
- verify at any time whether all obligations have been fulfilled towards the people whose personal data is held;
- deliver or send the privacy notice to data subjects whenever the data of a new person is entered manually, and request the consent(s) to the processing of personal data, specifying the purposes;
- make the arrangements needed to fulfil the required obligations (privacy notice/consents) also for personal data acquired automatically following the processing of requests received by email, for which Navis.net can carry out an initial automatic profiling;
- automatically process and archive the delivery of privacy notices and the collection of consents;
- restrict bulk emailing solely to the people who have given their consent;
- classify people according to the consents they have given;
- respond to requests for documentation of the personal data held;
- erase personal data and/or amend consents at the request of the data subjects concerned.
Navis.net also facilitates:
- the management of privacy notice content, through customisable templates to be matched to each case;
- the presentation of GDPR compliance on the User's website.
3.4 Digibusiness guarantees
Digibusiness also implements organisational and technological measures, as well as protections to ensure the security and operational continuity of its own resources and information which are not subject to the regulations referred to as GDPR, but which are critical to the business of Digibusiness and consequently of the User businesses.
3.5 Risk assessment
Given the nature and specific characteristics of the data processed and the protection and security measures adopted, the processing of personal data with Navis.net presents a LOW level of risk. Nevertheless, Digibusiness implements monitoring measures to check that no gaps arise in the system and intends to adopt the technological measures that can further increase the level of protection.
1. Data Controller
The Controller of personal data processing is Digibusiness Srl, registered office at Viale Libertà 10, 43044 Collecchio (PR), Italy, VAT no. IT02184210348.
For any request regarding the processing of your personal data you can contact us at:
- Email: info@navisnet.it
- Phone: +39 0521 805714
2. Types of Data Collected
The Navisnet website and platform collect the following categories of personal data:
2.1 Data provided directly by the user
- First and last name
- Email address
- Phone number
- Company name and professional role
- Messages sent through the contact form
2.2 Data collected automatically
- IP address
- Browser type and operating system
- Pages visited and session duration
- Navigation data collected through cookies and analytics tools (see Cookie Policy)
3. Purposes and Legal Basis of Processing
Personal data is processed for the following purposes:
3.1 Service delivery and contract management
Legal basis: performance of a contract (art. 6.1.b GDPR). Data of user companies (shipyards, dealers, brokers) is processed to provide the Navisnet platform in ASP mode, manage billing and ensure service continuity.
3.2 Response to contact and demo requests
Legal basis: consent of the data subject (art. 6.1.a GDPR) or legitimate interest (art. 6.1.f GDPR). Data submitted through the contact form is used solely to respond to the request.
3.3 Statistical analysis and site improvement
Legal basis: legitimate interest (art. 6.1.f GDPR) and consent where required by law. The site uses web analytics tools to analyse user behaviour in aggregated and anonymous form.
3.4 Legal and tax compliance
Legal basis: legal obligation (art. 6.1.c GDPR).
4. Analytics Tools
The Navisnet website uses web analytics tools (such as Google Analytics or similar) that collect information about site usage in anonymous and aggregated form. These tools may set cookies on the user's device.
Data collected includes: pages visited, session duration, traffic source, device used. The data does not allow the user to be identified directly.
For more information about the use of cookies, please see our Cookie Policy.
5. Processing Methods and Retention
Data is processed using IT and telematic tools, with security measures suitable to prevent unauthorised access, loss or destruction.
Data is retained for the time strictly necessary for the purposes for which it was collected, and in any case within the periods required by applicable legal obligations.
6. Disclosure to Third Parties
Personal data is not sold or transferred to third parties for commercial purposes. It may be disclosed to:
- Technical and infrastructure service providers (e.g. Microsoft Azure, email providers)
- Analytics service providers (e.g. Google Analytics)
- External accounting firm for tax compliance (Studio Vignetti, Parma)
- Competent authorities, where required by law
All third parties processing data on our behalf are appointed as Data Processors under art. 28 GDPR.
7. Rights of the Data Subject
The user has the right to:
- Access their personal data (art. 15 GDPR)
- Obtain rectification of inaccurate data (art. 16 GDPR)
- Obtain erasure of data (art. 17 GDPR)
- Restrict processing (art. 18 GDPR)
- Object to processing (art. 21 GDPR)
- Receive data in a structured format – portability (art. 20 GDPR)
- Withdraw consent at any time, without prejudice to the lawfulness of previous processing
- Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)
To exercise your rights, you can contact us at: info@navisnet.it
8. Changes to the Privacy Policy
This notice may be updated periodically. The updated version will be published on this page with the date of the latest update.
For any request, contact us at: info@navisnet.it or by phone at +39 0521 805714.