A5 Tech

Legal

Privacy Policy

Last updated 27 July 2026 · A5 S.r.l., VAT IT02594460228

1. Purpose and scope of this notice

This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. It describes how A5 S.r.l. processes personal data in connection with the website a5revolve.co and with correspondence sent to the addresses published on it.

It does not cover processing carried out under a separate commercial, employment or research relationship, which is governed by the notice given at the time that relationship is established. It does not cover third-party websites reachable from links on this site; those operators publish their own notices and we exercise no control over them.

2. Data controller

The data controller is A5 S.r.l., registered office Via Brennero 1/D, 38068 Rovereto (TN), Italy, VAT and tax code IT02594460228, LEI 81560064766A3DA20904. The controller may be contacted at [email protected] or by post at the registered office.

3. Data Protection Officer

A5 S.r.l. does not carry out large-scale monitoring, nor large-scale processing of special categories of personal data, through this website. The appointment of a Data Protection Officer under Article 37 GDPR is therefore not mandatory in respect of the activities described in this notice. Responsibility for data protection rests with the legal representative of A5 S.r.l., who may be reached at [email protected].

4. Categories of personal data processed

This website has no user accounts, no contact forms, no newsletter and no e-commerce function. We do not ask visitors to provide personal data. Personal data nevertheless arises in three ways.

Connection and navigation data
The transmission protocols of the internet require that certain data be communicated for a page to be served. This includes the IP address of the device, the date and time of the request, the URL requested, the HTTP method and response status, the volume of bytes returned, and the user agent string identifying browser and operating system. These data are recorded in the web server and content delivery network logs.
Correspondence data
If you write to [email protected], [email protected] or [email protected], we process the email address you write from, the content of your message and any attachments, and the metadata your mail system transmits. Where you write to the hiring address, your message will ordinarily contain the personal data you have chosen to include in a curriculum vitae.
Data disclosed to third parties by technical necessity
Typefaces are currently requested at page load from the Google Fonts service. Fulfilling that request discloses your IP address and user agent to Google Ireland Limited. No cookie is set by this operation. Section 12 records our position on removing this dependency.

We do not process special categories of personal data under Article 9 GDPR, nor data relating to criminal convictions under Article 10, and we ask that you do not send such data to us unsolicited.

5. Purposes of processing and legal bases

Delivering the website
Connection data are processed to transmit the requested pages and assets and to allow the site to function. Legal basis: legitimate interest, Article 6(1)(f) GDPR, in operating a website we make available to the public.
Security, integrity and abuse prevention
Connection data are processed to detect and mitigate attacks, automated abuse, denial of service and attempts at unauthorised access, and to establish the facts of any incident. Legal basis: legitimate interest, Article 6(1)(f) GDPR, in the security of our network and information systems, an interest expressly recognised in Recital 49 GDPR.
Responding to correspondence
Correspondence data are processed to read, evaluate and answer your message. Legal basis: performance of a contract or of pre-contractual measures taken at your request, Article 6(1)(b) GDPR, where the exchange concerns a possible commercial or employment relationship; otherwise legitimate interest, Article 6(1)(f), in maintaining ordinary business communication.
Evaluating job applications
Data contained in an application are processed to assess your suitability for a role. Legal basis: pre-contractual measures at your request, Article 6(1)(b) GDPR. Retention of an unsuccessful application beyond the selection process is carried out only with your consent, Article 6(1)(a), which you may withdraw at any time without affecting the lawfulness of processing already performed.
Legal compliance and defence of rights
Personal data may be processed to comply with obligations imposed by Italian or European law and, where necessary, to establish, exercise or defend legal claims. Legal bases: Article 6(1)(c) and Article 6(1)(f) GDPR.

Providing data is not a statutory or contractual requirement. Connection data are technically unavoidable if you wish to view the site; correspondence data are voluntary, but without them we cannot reply to you.

6. Balancing of legitimate interests

Where we rely on Article 6(1)(f), we have assessed our interest against your rights and freedoms. The data concerned are limited to what the protocol requires, are not enriched with data from other sources, are not used to build a profile, are retained for a short period, and are accessible only to a restricted group of administrators. On that basis we consider that our interest is not overridden. You may object to this processing under Article 21 GDPR, and we will cease unless we demonstrate compelling legitimate grounds.

7. Absence of profiling and automated decision-making

We carry out no profiling and no automated decision-making producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 GDPR. We operate no analytics, no advertising technology and no behavioural tracking on this site.

8. Recipients and processors

Personal data are accessible to authorised personnel of A5 S.r.l. who have been instructed under Article 29 GDPR and are bound by confidentiality. Data are further disclosed to:

We do not sell personal data, do not share it for advertising purposes, and do not transfer it to third parties for their own independent marketing.

9. Transfers outside the European Economic Area

Cloudflare is established in the United States and operates a globally distributed network, so connection data may be processed outside the European Economic Area. That transfer rests on two independent safeguards: Cloudflare's certification under the EU-U.S. Data Privacy Framework, an adequacy decision within the meaning of Article 45 GDPR, and the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated into Cloudflare's Data Processing Addendum under Article 46(2)(c). Cloudflare has undertaken to notify its customers if the Data Privacy Framework certification lapses, in which case the Clauses continue to govern the transfer.

Our email service is provided by Proton AG, established in Switzerland. Switzerland has been the subject of a European Commission adequacy decision since 26 July 2000, and on 15 January 2024 the Commission completed its first review of that decision and confirmed that Switzerland continues to afford an adequate level of protection under the GDPR. Correspondence data may therefore be transferred to Switzerland under Article 45 GDPR without further safeguards being required.

Any further transfer to a third country will be made only where an adequacy decision applies, or under Standard Contractual Clauses accompanied by whatever supplementary measures a transfer impact assessment requires. You may obtain a copy of the safeguards in place by writing to the address in section 2.

10. Retention periods

Connection and navigation logs
Retained for 30 days from collection, after which they are deleted or irreversibly anonymised. Where a specific log entry is relevant to an active security incident or to legal proceedings, that entry is retained for as long as the incident or proceedings require and is then deleted.
Correspondence
Retained for the duration of the exchange and thereafter for as long as necessary to document the relationship, subject to the limitation periods of Italian civil law and to the ten-year retention obligation for accounting records under Article 2220 of the Italian Civil Code where the correspondence forms part of them.
Job applications
Retained for the duration of the selection process. Applications not resulting in an appointment are deleted at the close of the process unless you have consented to retention for future opportunities, in which case they are kept for twelve months from the date of consent.

11. Security measures

We apply technical and organisational measures appropriate to the risk under Article 32 GDPR. These include encryption of traffic in transit by TLS, mailbox storage on an email service applying zero-access encryption at rest, restriction of administrative access on a need-to-know basis with individual credentials and multi-factor authentication, segregation of production infrastructure, logging of administrative operations, and periodic review of the measures in force. No measure eliminates risk entirely, and we make no representation that transmission over the internet is absolutely secure.

12. Third-party font delivery

We record here, in the interest of transparency, that requesting typefaces from Google Fonts discloses the visitor's IP address to a third party and that this disclosure is avoidable. Serving the same typefaces from our own infrastructure removes it entirely. We regard this as the correct configuration and intend to adopt it.

13. Your rights

Subject to the conditions and exceptions set out in the GDPR, you have the following rights.

Access, Article 15
To obtain confirmation of whether we process data concerning you, and if so a copy of it together with the information set out in this notice.
Rectification, Article 16
To have inaccurate data corrected and incomplete data completed.
Erasure, Article 17
To have data deleted where it is no longer necessary, where you withdraw the consent on which it rests, where you object successfully, or where it has been processed unlawfully.
Restriction, Article 18
To have processing limited to mere storage while accuracy is contested, while an objection is assessed, or where you require the data for a legal claim.
Portability, Article 20
To receive, in a structured, commonly used and machine-readable format, the data you provided to us where processing rests on consent or contract and is carried out by automated means.
Objection, Article 21
To object at any time, on grounds relating to your particular situation, to processing based on legitimate interest.
Withdrawal of consent, Article 7(3)
To withdraw consent at any time, where processing rests on it, without affecting the lawfulness of processing carried out before withdrawal.

14. Exercising your rights

Write to [email protected] or to the registered office. We will respond without undue delay and in any event within one month of receipt, extendable by two further months where the request is complex or numerous, in which case we will tell you within the first month and explain why. No fee is charged unless the request is manifestly unfounded or excessive. We may ask for information reasonably necessary to confirm your identity before acting.

15. Right to lodge a complaint

If you consider that processing of your data infringes the GDPR, you may lodge a complaint with the Garante per la protezione dei dati personali, the Italian supervisory authority, at garanteprivacy.it, or with the supervisory authority of the Member State of your habitual residence or place of work. You may also seek a judicial remedy.

16. Minors

This site is addressed to professional and institutional audiences and is not directed at children. We do not knowingly process the personal data of persons under sixteen. If you believe such data has reached us, write to us and we will delete it.

17. Changes to this notice

We may amend this notice to reflect changes in our processing, in our providers, or in the applicable law. The version in force is the one published on this page, and the date at the head of the page indicates when it was last revised. Substantive changes will be signalled on the page for a reasonable period.

← Back to site Privacy Policy Cookie Policy Terms of Use