Privacy Policy

Pursuant to Regulation (EU) 2016/679 (“GDPR”), this Privacy Policy describes the methods of processing personal data of users who browse the website www.beyond-aud.com (hereinafter, the “Website”).

1. Data Controller

The Data Controller is:

BEYOND AUD SRL
Registered office: Via Delle Palade 92/A, 39012 Merano (BZ), Italy
VAT number: 03317500217
Contact email: info@beyond-aud.com

2. Data Protection Officer (DPO)

The Data Controller has not appointed a Data Protection Officer (DPO), as this is not mandatory pursuant to Article 37 GDPR. For any request, users may contact the Data Controller using the contact details provided in section 1.

3. Categories of personal data processed

The Website processes the following categories of personal data:

  • Browsing data (e.g. IP address, technical logs, browser type, operating system, access times, pages visited), necessary for the operation and security of the Website.
  • Data voluntarily provided by the user through the contact form (e.g. name, email address, subject and content of the message).
  • Data collected via cookies (technical cookies only). For further information, please refer to the Cookie Policy.

4. Purposes of processing

Personal data are processed for the following purposes:

  • To ensure the proper technical functioning and security of the Website.
  • To manage and respond to requests submitted by users via the contact form or email.
  • To comply with legal obligations and/or requests from competent authorities.
  • To establish, exercise or defend a legal claim, where necessary.

The processing of personal data is based on the following legal grounds:

  • Performance of pre-contractual measures (Art. 6(1)(b) GDPR) to manage and respond to user requests.
  • Legitimate interest (Art. 6(1)(f) GDPR) of the Data Controller in ensuring Website security and preventing abuse or fraud.
  • Legal obligation (Art. 6(1)(c) GDPR) to comply with applicable laws.

6. Processing methods and security measures

Personal data are processed using electronic and telematic tools, in compliance with the principles of lawfulness, fairness, transparency, data minimisation and integrity. The Data Controller adopts appropriate technical and organisational security measures to prevent unauthorised access, disclosure, alteration or destruction of data.

7. Provision of data

The provision of data via the contact form is voluntary. However, failure to provide the data marked as necessary (such as the email address) will make it impossible to correctly submit the request and/or receive a response.

8. Data retention

Personal data are retained for the time strictly necessary to achieve the purposes indicated above and, in particular:

  • Contact form data (name, email address, message content): for the time necessary to manage the request and subsequently for a maximum period of 24 months, unless required by law or for the protection of legal rights.
  • Browsing and security log data: for the strictly necessary technical time, in accordance with system/hosting policies, unless required for the investigation of unlawful activities or requests by authorities.
  • Technical cookies: for the duration indicated in the Cookie Policy and/or until the end of the browsing session, depending on the cookie.

9. Cookies

The Website uses technical cookies necessary for its operation. No profiling or marketing cookies are used. For further information, please consult the Cookie Policy.

10. Data communication and recipients

Personal data are not disclosed. They may be communicated to third parties providing technical and organisational services, acting as data processors pursuant to Article 28 GDPR, such as:

  • hosting provider (with servers located within the European Union);
  • technical maintenance and Website management providers;
  • consultants (e.g. legal or tax advisors), where strictly necessary.

The updated list of data processors may be requested by contacting the Data Controller.

11. Data transfers outside the EU

The Data Controller does not transfer personal data outside the European Union/EEA in connection with the use of the Website. Should this become necessary in the future, such transfers will take place in compliance with the safeguards provided for by the GDPR.

12. Data subject rights

Users may exercise at any time the rights provided for in Articles 15–22 GDPR, including:

  • access to personal data;
  • rectification or erasure;
  • restriction of or objection to processing;
  • data portability (where applicable);
  • withdrawal of consent, where processing is based on consent (without affecting the lawfulness of processing carried out prior to withdrawal).

Requests may be sent to: info@beyond-aud.com

13. Automated decision-making and profiling

The Data Controller does not carry out automated decision-making processes or profiling activities pursuant to Article 22 GDPR.

14. Complaint to the supervisory authority

Data subjects have the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data violates the GDPR.

15. Changes to this Privacy Policy

The Data Controller reserves the right to amend this Privacy Policy at any time. Any changes will be published on this page.

Last updated: December 2025