Last updated: 20 July 2026. This notice applies to www.calypso-bp.cloud and does not replace the specific notices for SaaS services, demos or secure areas.
1. Data controller
The data controller is Esabit - IT Solutions, with registered office at Via Nazionale, 135 Cedegolo BS, VAT number 02943760989. For privacy-related requests, please write to info@calypso-bp.cloud.
2. Data processed
Browsing data
The systems that make the website available may collect the IP address, request date and time, requested page, response outcome, browser type, operating system and similar technical information. This data is used for security, diagnostics and correct delivery of the website.
Data provided voluntarily
Contact and registration-request forms may collect full name, business email, company, telephone number, role, revenue range, plan or industry solution of interest and a description of the process. Sending an email entails processing the sender’s address and the information contained in the message.
Cookies and preferences
The website uses necessary technical tools and, only with consent, may use analytics or marketing tools. Details are available in the Cookie Policy.
3. Purposes and legal bases
| Purpose | Legal basis | Provision |
|---|---|---|
| Responding to contact or registration requests, arranging a demo, assessing a project and preparing an offer. | Taking pre-contractual steps requested by the data subject, Article 6(1)(b) GDPR. | Required to handle the request. |
| Ensuring security, preventing abuse and resolving technical issues. | The controller’s legitimate interest, Article 6(1)(f) GDPR. | Automatic when using the website. |
| Complying with tax, accounting or authority requirements. | Legal obligation, Article 6(1)(c) GDPR. | Mandatory where applicable. |
| Measuring website use or offering personalised content through non-essential tools. | Consent, Article 6(1)(a) GDPR. | Optional and revocable. |
4. Processing methods and security
Data is processed using IT tools and organisational measures proportionate to the risk, with access limited to those who need it. No measure can guarantee absolute security; procedures are nevertheless adopted to prevent unauthorised access, loss, alteration or improper disclosure.
5. Recipients and processors
Data may be processed by authorised personnel and suppliers required for hosting, email, maintenance, security, consultancy and sales management, appointed as processors where required. It may also be disclosed to professionals, authorities or other parties where provided by law. Form data is not sold.
6. Transfers outside the European Economic Area
Where a supplier involves a transfer to a country outside the EEA, the controller will adopt one of the safeguards provided by the GDPR, such as adequacy decisions, Standard Contractual Clauses and supplementary measures where necessary. Information about transfers may be requested using the contact details above.
7. Retention periods
- Sales and pre-contractual requests: for the time needed to handle the contact and, as a rule, no longer than 24 months from the last interaction unless a business relationship is established.
- Contractual and compliance data: for the periods required by applicable law.
- Technical and security logs: for a period proportionate to protection and diagnostic purposes.
- Data processed on the basis of consent: until consent is withdrawn or the purpose ceases to apply.
8. Automated decision-making
Data collected through the form is not used for solely automated decisions that produce legal or similarly significant effects on the data subject.
9. Data-subject rights
Where applicable, you may request access, rectification, erasure, restriction, portability and object to processing. You may withdraw consent at any time without affecting processing already carried out. To exercise your rights, write to info@calypso-bp.cloud; identity verification may be required.
You also have the right to lodge a complaint with the Italian Data Protection Authority.
10. Children
The website and services presented are intended for businesses and professionals and are not designed to knowingly collect children’s data.
11. Updates
This notice may be updated following legal, technical or organisational changes. The current version is published on this page with its update date.