Privacy policy
The short version. We collect what you type into the Alpha application form, so that we can reply to you. We measure site traffic, and — only if you consent — which advertising campaigns bring in applications. We do not sell your data, we do no profiling beyond campaign measurement, and we make no automated decisions about you.
1.Who processes your data
The data controller is:
- Simplethicam SRLS
- Via Leonardo Da Vinci 21, 10126 Turin (TO), Italy
- Italian VAT and tax code 13158840010
- Turin Companies Register (REA) no. TO-1343693
- Email: hello@nexusplm.com
NexusPLM is a product of Simplethicam SRLS. We have not appointed a Data Protection Officer: the conditions under Article 37 GDPR do not apply. For anything concerning personal data, write to the address above.
2.What we collect and why
2.1 Alpha programme application (site form)
Data collected: name, work email, brand/company, level of interest (Starter/Pro/Enterprise, optional) and whatever you write in the message field. If you arrive from an advertisement, the form also carries the technical parameters of that origin (the click identifier gclid and utm_* parameters, landing page, referring site).
Purpose: to get back to you, assess whether the Alpha programme fits your company, arrange the introductory call and — if you go ahead — manage your access to the Alpha environment.
Legal basis: Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract. For the origin parameters alone the basis is Article 6(1)(f), the controller's legitimate interest in knowing which channels generate contacts and in not wasting advertising budget; it is a narrow interest that does not override your rights, and you may object to it at any time (§8).
Provision of data: name and email are required in order to reply — without them we cannot follow up. All other fields are optional.
2.2 Email correspondence
If you write to hello@nexusplm.com we process the content of your message and your contact details in order to answer. Legal basis: Article 6(1)(b) or 6(1)(f), depending on whether the enquiry is pre-contractual.
2.3 Technical browsing data
The site is hosted on Cloudflare Pages. Like any web server, the infrastructure records technical data (IP address, browser and operating system, date and time of the request, page requested) needed to deliver pages, keep the service secure and prevent abuse.
Legal basis: Article 6(1)(f) — legitimate interest in the security and correct operation of the site.
2.4 Aggregate traffic statistics
We use Cloudflare Web Analytics, which sets no cookies, performs no fingerprinting and does not track users across sites: it produces aggregate counts of page views and referrers only. For that reason it does not require your consent.
Legal basis: Article 6(1)(f) — legitimate interest in understanding how the site is used.
2.5 Advertising campaign measurement (only with your consent)
If you consent through the banner, we activate Google Analytics 4 and the Google Ads tag. Their purpose is to tell us how many applications come from each campaign and keyword. We process pseudonymous identifiers assigned by cookies, your IP address (anonymised for Google Analytics), the pages you visit and whether you submit the form.
Legal basis: Article 6(1)(a) GDPR — your consent, freely given and withdrawable at any time (§4). Until you give it, these tools run in consent mode with storage denied: they write no cookies and send Google only anonymous, aggregate signals.
What we do not do. We do not sell or otherwise transfer your data to third parties for their own marketing. We do no advertising profiling beyond the campaign measurement described here. We use no automated decision-making producing legal effects concerning you (Article 22 GDPR). We do not process special categories of data (Article 9) and we do not ask you to provide any.
3.Cookies and similar technologies
This site sets no profiling cookies without your consent. What may be stored on your device:
| Name | Type | Purpose | Duration | Consent |
|---|---|---|---|---|
nexus_consent | localStorage — technical | Remembers the choice you made on the banner so we do not ask again | Until you clear it | Not required |
nexus_attr | sessionStorage — technical | Holds the advertisement origin parameters so they can be attached to the form if you choose to submit it | End of browser session | Not required |
_ga, _ga_* | Third-party cookie — Google Analytics 4 | Distinguishes sessions and returning users for statistics | Up to 24 months | Required |
_gcl_au | Third-party cookie — Google Ads | Links the visit to the ad click in order to attribute the conversion | 90 days | Required |
nexus_consent and nexus_attr are not cookies in the strict technical sense but browser local storage; we list them anyway because in substance they are the same thing. They are strictly necessary to the function you asked for and cannot identify you.
You can block or delete cookies from your browser settings at any time. Blocking the technical ones may make parts of the site behave unexpectedly; blocking the measurement ones leaves the site working normally.
4.Managing or withdrawing consent
Withdrawing consent is as easy as giving it, and withdrawal does not affect the lawfulness of processing carried out beforehand (Article 7(3) GDPR). Use the button below: it reopens the banner so you can change your choice.
5.Who we share data with
Your data is accessible to authorised personnel of Simplethicam SRLS and to the suppliers that process data on our behalf, appointed as processors under Article 28 GDPR:
| Supplier | Service | Data processed |
|---|---|---|
| Formspree, Inc. | Form receipt and forwarding | Contents of the application form |
| Cloudflare, Inc. | Hosting, CDN, security, aggregate statistics | Technical browsing data |
| Google Ireland Ltd. | Google Analytics 4, Google Ads | Measurement data, subject to consent only |
We may also disclose data to public authorities where required by law, or to establish, exercise or defend a legal claim.
6.Transfers outside the European Union
Some of the suppliers listed above are established in the United States or may process data on non-EU infrastructure. Where that happens, the transfer relies on the safeguards set out in Chapter V of the GDPR: Standard Contractual Clauses approved by the European Commission (Article 46(2)(c)) and, where the supplier participates in it, the adequacy decision covering the EU-U.S. Data Privacy Framework (Article 45).
You can ask us for a copy of the safeguards in place by writing to hello@nexusplm.com.
7.How long we keep it
| Data | Retention |
|---|---|
| Alpha applications and correspondence | 24 months from the last meaningful contact, or until you ask us to delete it |
| Applications that become a contractual relationship | For the duration of the relationship and the statutory periods that follow (tax and civil law, normally 10 years) |
| Server technical logs | According to the hosting provider's standard periods, normally no more than 30 days |
| Measurement data (Google) | According to the property configuration, in any case no more than 14 months |
Once those periods elapse, data is deleted or irreversibly anonymised.
8.Your rights
At any time you may exercise the rights granted by Articles 15-22 GDPR:
- Access — find out whether we process data about you and obtain a copy.
- Rectification — correct inaccurate data or complete incomplete data.
- Erasure — ask for data to be removed, in the cases set out in Article 17.
- Restriction — ask for processing to be suspended, in the cases set out in Article 18.
- Portability — receive your data in a structured, commonly used format, or have it transmitted to another controller.
- Objection — object at any time to processing based on legitimate interest, including the origin measurement described in §2.1.
- Withdrawal of consent — withdraw consent to campaign measurement, without prejudice to processing already carried out (§4).
To exercise them, write to hello@nexusplm.com. We reply within one month of the request, extendable by two further months in complex cases, of which we will inform you.
If you believe the processing infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of the EU state where you reside, as well as to seek a judicial remedy.
9.Security
We apply technical and organisational measures appropriate to the risk: encrypted HTTPS transmission across the whole site, data access limited to authorised personnel, and selection of suppliers offering adequate guarantees under Article 28 GDPR. No system is absolutely secure: in the event of a personal data breach likely to result in a high risk to your rights, we will inform you as required by Article 34 GDPR.
10.Changes to this policy
We may update this policy when our services, suppliers or the applicable law change. The version in force is always the one published on this page, with the last-updated date at the top. Where changes are substantial we will give notice through a prominent notice on the site or by email, where we hold your address.