Privacy & Data Governance Framework™
Security by Design · Data Ownership · Enterprise Intelligence Platform
1. Data Governance and Controller Responsibility
The SecurMatch platform is developed and operated by VISAC Technologies Srl, acting as the data controller for personal data collected in connection with access management, commercial requests and the delivery of related services.
For any request related to personal data processing:
info@securmatch.pro
2. Data Ownership Principle
Data belongs to its respective owners.
VISAC Technologies Srl does not monetize customer data, does not sell information collected through the platform and does not use customer-provided data for purposes other than those declared.
Fundamental principle:
The customer maintains control over its own data, configured assets, operational information and any datasets integrated into the platform.
3. Data Collected
SecurMatch collects only the information necessary to validate institutional access and manage the relationship with the customer organization.
- First and last name
- Professional corporate email address
- Organization affiliation
- Operational sector
- Professional role
4. Processing Purposes
Data is processed exclusively for:
- access request management;
- Pilot environment activation;
- SecurMatch service delivery;
- platform security;
- technical audit and service management.
5. GDPR Legal Basis
Processing is based on:
- pre-contractual measures taken at the request of the data subject or represented organization (Article 6.1.b GDPR);
- the legitimate interest of the controller in managing the service, protecting the platform and preventing unauthorized use (Article 6.1.f GDPR).
6. Security by Design
SecurMatch is designed according to Security by Design and Security by Default principles.
- multi-tenant architecture;
- logical data separation per customer;
- TLS-protected communications;
- access control mechanisms;
- operational session traceability.
7. Tenant Isolation
Each organization operates within a logically isolated environment.
Customer assets, configurations, events and operational information are not accessible by other platform tenants.
8. Enterprise Deployment
For organizations requiring advanced security configurations, dedicated deployments are available:
- On-Premise environments;
- Air-Gapped deployments;
- dedicated architectures according to organizational requirements.
9. Data Retention
Pilot requests not followed by a contractual relationship are retained for a maximum period of 24 months, unless different regulatory obligations apply.
Where a contractual relationship exists, retention follows the duration of the relationship and applicable legal requirements.
10. Data Subject Rights
Data subjects may exercise the rights provided under GDPR:
- access;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- objection.
Requests may be sent to: info@securmatch.pro
11. Complaints
The data subject retains the right to lodge a complaint with the competent Data Protection Authority.