{ SDK }
services work approach company contact
IT / EN
start a project →
SDK / privacy

Privacy
policy.

// last updated22 April 2026
// version1.0
// referenceEU Reg. 2016/679 (GDPR)

This policy describes how Simply Develop Knowledge S.r.l. (hereinafter "SDK" or "the Controller") processes the personal data collected through the sdk.srl website and, in particular, through the contact form on the main page. Processing is carried out in compliance with EU Regulation 2016/679 (GDPR) and, where applicable, Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (Italian Privacy Code).

/ 01

Data Controller

The Data Controller of personal data is Simply Develop Knowledge S.r.l., an Italian-law company.

legal nameSimply Develop Knowledge S.r.l.
registered officeVia Melogrosso 94, 04018 Sezze (LT), Italy
VAT / Tax ID03370540597
privacy contactinfo@sdk.srl
/ 02

Personal data collected

The website collects personal data exclusively through the contact form on the main page. No other collection channels are present, and no profiling tools are used during navigation.

The form collects:

  • Data provided directly by the user: full name, email address, company or organization (optional field), project type, message text, confirmation of consent to processing.
  • Technical data collected automatically upon submission: IP address of the sender, browser user-agent string, date and time of submission. These data are included in the email body the Controller receives and are used for security purposes (anti-spam, rate-limiting).

No data is collected via cookies, tracking pixels, analytics tools or persistent identifiers. See the cookie policy for details.

/ 03

Purposes and legal basis

Personal data is processed for the following purposes:

  • Responding to the contact request and, where applicable, initiating a commercial or professional relationship. Legal basis: art. 6(1)(b) GDPR — performance of pre-contractual measures taken at the request of the data subject.
  • Ensuring the security of the contact system through rate-limiting and prevention of automated submissions (anti-spam). Legal basis: art. 6(1)(f) GDPR — legitimate interest of the Controller in protecting its infrastructure and preventing abusive communications.

Providing the data marked as required in the form is necessary to process the request. Failure to provide such data prevents a reply. The "company" field is optional.

/ 04

Retention period

Data is retained only for the time strictly necessary to achieve the purposes:

  • Emails received and form contents: retained for a maximum of 24 months from the date of the last interaction with the data subject, except where a different legal obligation applies (e.g. tax obligations or the management of contracts subsequently signed).
  • Hashed IP address used for rate-limiting: stored temporarily server-side (system file) for a maximum of 30 seconds after each submission; it is then overwritten or deleted.

At the end of these periods the data is deleted or anonymized, except for any retention required to comply with legal or regulatory obligations, or to protect rights in court proceedings.

/ 05

Recipients and external processors

Personal data is processed only by the Controller's authorized personnel and is not disclosed to third parties for their own purposes, nor is it disseminated.

For the sole technical delivery of the service, the Controller relies on the following provider, appointed as a Data Processor under art. 28 GDPR:

nameAruba S.p.A.
roleData Processor
servicesweb hosting, @sdk.srl email
addressVia San Clemente 53, 24036 Ponte San Pietro (BG), Italy

Data is stored on servers located within the European Economic Area. The Controller does not transfer personal data to third countries or to international organizations.

/ 06

Data subject rights

At any time, the data subject may exercise the rights provided by articles 15–22 of the GDPR:

  • Access (art. 15) — obtain confirmation of processing and a copy of the data
  • Rectification (art. 16) — correct inaccurate or incomplete data
  • Erasure (art. 17) — obtain deletion of the data ("right to be forgotten")
  • Restriction (art. 18) — temporarily suspend processing
  • Portability (art. 20) — receive the data in a structured, machine-readable format
  • Objection (art. 21) — object to processing based on legitimate interest

To exercise these rights, simply write to info@sdk.srl specifying in the subject line the right to be exercised. The Controller will respond within 30 days of receipt, under art. 12 GDPR. The exercise of rights is free of charge.

/ 07

Complaint to the supervisory authority

Where the data subject believes that the processing of their data breaches the GDPR, they have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, garanteprivacy.it) or with the competent supervisory authority of their Member State of habitual residence, place of work, or place of the alleged infringement.

/ 08

Amendments to this policy

This policy may be updated following regulatory changes, technical evolutions of the site, or changes in processing activities. The current version and the date of the latest update are always shown at the top of the page. In the event of substantial changes that materially affect the rights of data subjects, the Controller will take appropriate measures to inform users.

back to the site
{ SDK }
SIMPLY · DEVELOP · KNOWLEDGE

Simply Develop Knowledge S.r.l. is an Italian digital engineering firm based in Via Melogrosso 94, Sezze (LT).

Services
  • Software & Platforms
  • AI & Data Science
  • Cloud & API
  • IT Consulting
  • Training
  • R&D
Company
  • About us
  • Method
  • Contact
  • Careers
© 2026 Simply Develop Knowledge S.r.l.
VAT 03370540597 · Tax ID 03370540597 · Privacy Cookie