Privacy Policy
Last updated May 2026
Legal documentsPrivacy Policy
This Data Protection and Privacy Policy ("Policy") describes how CommerceClarity ("CommerceClarity", "Company", "we", "our", or "us") collects, uses, stores, discloses, and protects personal data in connection with its website, software solutions, platforms, and related services (collectively, the "Services").
This Policy is intended to provide transparent information in accordance with Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
1. Introduction and Scope
CommerceClarity is committed to ensuring that personal data is processed lawfully, fairly, transparently, and securely.
This Policy applies to the processing of personal data relating to:
- website visitors;
- customers and prospective customers;
- users of the Services;
- suppliers and business partners;
- individuals interacting with CommerceClarity in a professional or commercial context.
The Policy applies to all personal data processed by CommerceClarity in connection with the provision, operation, support, improvement, and security of the Services.
2. Identity of the Data Controller
Data Controller: CommerceClarity S.r.l.
- Registered Office: Via di Affogalasino 34, 00148 Rome (RM), Italy
- VAT Number: IT15901031003
- Contact Email: privacy@commerceclarity.com
For the purposes of applicable data protection legislation, CommerceClarity acts either as:
- a Data Controller, where it determines the purposes and means of processing personal data; or
- a Data Processor, where it processes personal data on behalf of customers using the Services.
3. Categories of Personal Data Processed
Depending on the nature of the relationship and interaction with the Services, CommerceClarity may process the following categories of personal data.
Identification and Contact Data
- first name and surname;
- business email address;
- telephone number;
- company name;
- professional role or job title;
- billing and invoicing information.
Account and Authentication Data
- login credentials;
- user identifiers;
- authentication records;
- account settings and preferences.
Commercial and Transaction Data
- subscription information;
- payment-related data;
- contractual records;
- invoices and financial documentation.
Technical and Usage Data
- IP address;
- browser type and version;
- operating system;
- device identifiers;
- session logs;
- usage statistics;
- timestamps and access records;
- diagnostic and performance information.
Communication Data
- customer support requests;
- correspondence;
- survey responses;
- feedback and communications submitted through the Services.
Customer Content
Where customers upload or manage information through the Services, such content may include personal data controlled by the customer.
4. Sources of Personal Data
CommerceClarity may collect personal data:
- directly from users;
- through use of the Services;
- from business partners and service providers;
- from authentication providers;
- from publicly available sources;
- through cookies and similar technologies.
5. Purposes of Processing and Legal Bases
CommerceClarity processes personal data only where an appropriate legal basis exists under applicable law.
Service Provision and Account Management
Personal data may be processed to:
- provide access to the Services;
- manage accounts and subscriptions;
- process transactions;
- provide technical and customer support;
- administer contractual relationships.
Legal Basis: Performance of a contract.
Service Improvement and Operational Analytics
Personal data may be processed to:
- improve platform performance;
- develop new functionalities;
- analyze usage patterns;
- monitor reliability and operational efficiency.
Legal Basis: Legitimate interest.
Communications
Personal data may be processed to:
- send operational notices;
- provide security updates;
- respond to inquiries;
- deliver marketing communications where permitted.
Legal Basis: Performance of a contract, legitimate interest, or consent depending on the communication type.
Security and Fraud Prevention
Personal data may be processed to:
- maintain platform security;
- prevent unauthorized access;
- detect fraud, misuse, or malicious activity;
- enforce contractual terms.
Legal Basis: Legitimate interest and legal obligation.
Regulatory and Legal Compliance
Personal data may be processed to comply with:
- applicable laws;
- regulatory obligations;
- court orders;
- requests from competent authorities.
Legal Basis: Legal obligation.
Marketing Activities
Personal data may be processed to:
- send newsletters and promotional communications;
- provide information about products, services, events, and updates;
- invite users to webinars, demonstrations, and industry events;
- analyze the effectiveness of marketing campaigns and improve communication strategies.
Legal Basis: Consent, where required by applicable law, or legitimate interest for business-to-business communications where permitted.
Marketing activities are described in more detail in the Marketing Privacy Policy.
6. Automated Processing and AI-Assisted Functionalities
CommerceClarity may use artificial intelligence, machine learning, and automated processing technologies as part of its Services.
Such functionalities may support:
- content enhancement and optimization;
- classification and organization of information;
- workflow automation;
- analytics and reporting;
- operational insights;
- recommendation systems.
CommerceClarity implements safeguards designed to reduce risks associated with automated processing, including risks relating to:
- fairness;
- transparency;
- accuracy;
- security;
- unintended outcomes.
Where required by applicable law, meaningful human oversight is maintained over processing activities involving automated decision-making.
CommerceClarity does not intentionally conduct solely automated decision-making producing legal or similarly significant effects without appropriate safeguards.
7. Cookies and Similar Technologies
CommerceClarity uses cookies and similar technologies to:
- ensure proper operation of the website and Services;
- improve user experience;
- maintain security;
- analyze usage and performance;
- remember user preferences.
Categories of cookies may include:
- strictly necessary cookies;
- functional cookies;
- analytics cookies;
- performance cookies.
Users may manage cookie preferences through browser settings or through the cookie preference center made available on the website.
Further information regarding cookies and similar technologies is available in the dedicated Cookie Policy.
8. Recipients and Categories of Recipients
CommerceClarity may disclose personal data to authorized third parties where necessary for operational, contractual, legal, or security purposes.
Recipients may include:
- cloud and hosting providers;
- infrastructure providers;
- payment processors;
- analytics and monitoring providers;
- customer support platforms;
- cybersecurity providers;
- professional advisers;
- regulatory authorities where legally required.
All third-party service providers are subject to appropriate contractual and confidentiality obligations.
CommerceClarity does not sell personal data to third parties.
Key service providers currently engaged by CommerceClarity may include cloud hosting providers, payment service providers, customer relationship management (CRM) platforms, analytics providers, communication and collaboration tools, and artificial intelligence service providers. An updated list of relevant data processors and sub-processors may be made available upon request.
All processors and sub-processors are contractually bound to process personal data in accordance with applicable data protection laws and appropriate confidentiality and security obligations.
9. International Transfers of Personal Data
Personal data may be transferred to countries outside the European Economic Area ("EEA").
Where such transfers occur, CommerceClarity adopts appropriate safeguards in accordance with applicable law, including:
- adequacy decisions adopted by the European Commission;
- Standard Contractual Clauses ("SCCs");
- supplementary technical and organisational safeguards where necessary.
Additional information regarding transfer safeguards may be requested by contacting CommerceClarity.
Where personal data is transferred to organizations located in the United States, CommerceClarity may rely on the EU-U.S. Data Privacy Framework where applicable, in addition to Standard Contractual Clauses and supplementary safeguards where required.
10. Data Retention and Deletion
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, accounting, security, and contractual obligations.
Retention periods are determined considering:
- the nature and sensitivity of the data;
- legal and regulatory obligations;
- operational requirements;
- dispute management needs;
- security requirements.
Upon expiration of the applicable retention period, personal data is securely deleted, anonymized, or irreversibly de-identified.
Unless a longer retention period is required by law, CommerceClarity generally applies the following retention periods:
| Data Category | Retention Period |
|---|---|
| Contact and enquiry data | Up to 24 months from the last interaction |
| Customer account data | For the duration of the contractual relationship and up to 10 years thereafter where required by applicable accounting and tax laws |
| Technical logs and security records | Up to 12 months |
| Marketing communications data | Until consent is withdrawn or for a maximum of 24 months from the last interaction |
| Support requests and customer communications | Up to 36 months after resolution of the request |
Retention periods may be extended where necessary to establish, exercise, or defend legal claims, comply with legal obligations, or protect the security and integrity of the Services.
11. Technical and Organisational Security Measures
CommerceClarity implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Security measures may include:
- encryption;
- access controls;
- multi-factor authentication;
- security monitoring and logging;
- vulnerability management;
- incident response procedures;
- staff training and awareness measures.
CommerceClarity applies principles of privacy by design and privacy by default throughout the lifecycle of its Services and internal processes.
The management system behind these measures is described in the Management System Policy.
12. Data Subject Rights
Subject to applicable law, individuals may exercise the following rights regarding their personal data:
| Right | Description |
|---|---|
| Right of Access | Obtain confirmation and access to personal data |
| Right to Rectification | Correct inaccurate or incomplete data |
| Right to Erasure | Request deletion of personal data in certain circumstances |
| Right to Restriction | Restrict processing in specific cases |
| Right to Data Portability | Receive personal data in a portable format |
| Right to Object | Object to processing based on legitimate interests |
| Right to Withdraw Consent | Withdraw previously provided consent |
| Rights Related to Automated Processing | Request human intervention where applicable |
13. Exercise of Rights and Complaints
Requests relating to privacy rights may be submitted to: privacy@commerceclarity.com
CommerceClarity may request information necessary to verify the identity of the requester before processing the request.
Individuals also have the right to lodge a complaint with the competent supervisory authority. In Italy, the competent authority is the Garante per la Protezione dei Dati Personali (garanteprivacy.it).
14. Allocation of Controller and Processor Responsibilities
Where customers use the Services to process personal data relating to third parties, responsibilities may be allocated between CommerceClarity and the customer depending on the applicable processing activity.
Customers acting as Data Controllers are responsible for:
- ensuring a lawful basis for processing;
- providing required privacy notices;
- managing data subject requests;
- ensuring lawfulness of uploaded content.
Where acting as a Data Processor, CommerceClarity processes personal data only in accordance with documented instructions and applicable contractual obligations.
15. Compliance with Applicable Data Protection Laws
CommerceClarity seeks to maintain compliance with applicable privacy and data protection laws in jurisdictions where it operates, including:
- Regulation (EU) 2016/679 ("GDPR");
- applicable Italian data protection legislation;
- other applicable international privacy requirements where relevant.
Privacy and security practices are periodically reviewed and updated to reflect legal, operational, and technological developments.
16. Children’s Data
The Services are intended for professional and business use and are not directed to individuals under the age of 18.
CommerceClarity does not knowingly collect personal data relating to minors. Where such data is identified, appropriate measures will be taken to delete it without undue delay.
17. Changes to this Policy
CommerceClarity reserves the right to update or modify this Policy at any time to reflect:
- legal or regulatory developments;
- operational changes;
- technological updates;
- modifications to the Services.
The updated version will be published on the website together with the revised effective date.
Continued use of the Services following publication of changes constitutes acknowledgment of the updated Policy where permitted by law.
18. Contact Information
For questions, requests, or concerns regarding this Policy or the processing of personal data, please contact:
CommerceClarity S.r.l.
Via di Affogalasino 34, 00148 Rome (RM), Italy
Email: privacy@commerceclarity.com
This Policy may be made available in multiple languages. In the event of inconsistencies between versions, the English version shall prevail.