Privacy Policy
Last updated: September 2026
Welcome to Reesly. Your privacy matters to us. This Privacy Policy explains how we collect, use, disclose and protect your information when you visit our website or use our SaaS software.
1. Data Controller
The data controller is GF Costruzioni e Manutenzioni S.r.l. (Reesly brand), with registered office at Via M. Monti 16/E, 48123 Ravenna (RA), Italy, VAT number 02672280399.
Contact email: [email protected]
2. Types of Data Collected
We may collect the following categories of data:
- Data you provide voluntarily: First and last name, work email address, phone number, job role, billing information.
- Technical and usage data: IP address, browser type, device information, pages visited and time spent on the site.
- Data uploaded into the software: Information about machinery, risks and technical documents entered by the user while using the SaaS.
- Cookie consent log: a pseudonymous identifier, date and time, the choices expressed on the cookie banner and the truncated IP address, kept to demonstrate consent under Article 7 of the GDPR. Details in the Cookie Policy.
3. Purposes of Processing
We process your data to:
- Provide and manage the SaaS service and access to the platform.
- Process payments and handle billing.
- Send service communications, technical updates and security notifications.
- Respond to support and assistance requests (e.g. demo requests).
- Improve the user experience and analyze use of the service.
4. Legal Basis
Processing is based on:
- Performance of a contract to which the user is a party.
- The user's consent (e.g. for marketing or newsletters).
- Compliance with legal obligations.
5. Data Sharing
We do not sell your data to third parties. We share data only with providers who process information on our behalf, including:
- Cloudflare, Inc. — content delivery network (CDN), security and protection against cyberattacks.
- Google LLC — Google Analytics 4, for aggregate statistics on site usage (active only with your consent).
- Meta Platforms Ireland Ltd. — Meta Pixel, for measuring advertising campaigns (active only with your consent).
- Hosting providers and payment services, solely for delivering the SaaS service.
For details on the individual cookies used by these providers, see the Cookie Policy.
6. Transfer of Data Outside the EU
Some of the providers listed above (Google, Meta, Cloudflare) are based in the United States. Data transferred to these countries is protected by appropriate safeguards under the GDPR, such as Standard Contractual Clauses (SCCs) and/or adherence to the EU-U.S. Data Privacy Framework.
7. Data Retention Period
We keep your data for as long as necessary to achieve the purposes for which it was collected:
- Contractual and billing data: for the duration of the relationship and, afterwards, for the period required by tax and civil law (up to 10 years).
- Browsing and cookie data: according to the durations set out in the Cookie Policy.
- Data collected on the basis of consent (e.g. marketing): until consent is withdrawn.
8. User Rights
Under the GDPR, you have the right to:
- Access your personal data.
- Request its rectification or erasure ("right to be forgotten").
- Restrict its processing or object to it.
- Request data portability.
- Lodge a complaint with the competent data protection authority (in Italy, the Garante per la Protezione dei Dati Personali, www.garanteprivacy.it, or the supervisory authority of your own EU member state), if you believe the processing of your data infringes applicable law.
9. Data Security
We adopt appropriate technical and organizational security measures to protect your data from unauthorized access, loss or destruction. We use SSL/TLS encryption for all communications.
10. Changes to This Policy
We may update this notice periodically. We will inform you of any material changes by publishing the new policy on this page.