PRIVACY POLICY

Hilo Impact Srl

Last updated: 09/07/2026

This Privacy Policy for Hilo Impact Srl (“we,” “us,” or “our”) describes how and why we process your personal information when you use our services (the “Services”), including when you:

  • visit our website at hiloimpact.com or any other website of ours that links to this Privacy Policy;
  • engage with us in other related ways, including business, marketing, or event activities.

Questions or concerns? Reading this Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services.

SUMMARY OF KEY POINTS

This summary sets out the key points of our Policy, but you can find more detail on each topic in the sections below.

Who is the Data Controller? Hilo Impact Srl, registered office at Viale Volga snc, Bari (70132), Italy – VAT No. 08639890725 – Legal representative Dr.-Eng. Caterina Picuno

What personal information do we process? Identification and contact data (name, surname, email, phone number, job title) that you provide to us directly when you visit, use, or interact with our Services.

Do we process sensitive personal information? No, we do not process special categories of data (e.g. racial or ethnic origin, sexual orientation, religious or trade-union beliefs, health data).

Do we collect information from third parties? No, we do not collect personal information from third parties.

How do we process your information? To provide and deliver the Services, manage our contractual or pre-contractual relationship with you, respond to your requests, for marketing purposes (only with your consent, where required), for security and fraud-prevention purposes, and to comply with legal obligations. We process your information only when we have a valid legal basis.

Who do we share information with? With suppliers and partners acting as data processors on our behalf (e.g. hosting, email, management software), with professional advisors and, where necessary, with public authorities or in connection with extraordinary corporate transactions.

Is data transferred outside the EU? Yes, in limited cases: as part of international research and cooperation projects (e.g. Erasmus+, Horizon Europe) we work with project partners, including universities and institutions located in Africa. See Section 6.

How long do we retain data? Only for as long as necessary for the purposes indicated, unless longer legal obligations (tax, accounting) apply, and in any case no longer than 5 years from the end of the relationship, unless otherwise stated.

What are your rights? Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, as well as the right to lodge a complaint with the data protection authority.

How can you exercise your rights? By contacting us using the details in Section 12. We will act on every request in accordance with applicable law.

1. DATA CONTROLLER

The Controller of your personal data is:

  • Company name: Hilo Impact Srl
  • Registered office: Viale Volga snc, Bari (BA), 70132, Italy
  • VAT number: 08639890725
  • Legal representative: Dr.-Eng. Caterina Picuno
  • Contact: caterina.picuno@hiloimpact.com

No Data Protection Officer (DPO) has been appointed, as the appointment is not mandatory under Art. 37 GDPR: Hilo Impact Srl’s activity does not involve the systematic, large-scale monitoring of data subjects, nor the large-scale processing of special categories of data. For any request concerning the processing of personal data, you can still contact us using the details in Section 14.

2. WHAT INFORMATION WE COLLECT

Personal information you provide directly. We collect personal information that you voluntarily provide when you express interest in obtaining information about our products and Services, when you take part in activities on the Services, or otherwise when you contact us. The data collected may include:

  • name and surname
  • phone number
  • email address
  • job title

Sensitive information. We do not process special categories of personal data under Art. 9 GDPR.

Information from third parties. We do not collect personal information from third-party sources.

All personal information you provide to us must be true, complete, and accurate; you must notify us of any changes to such information.

3. HOW AND WHY WE PROCESS YOUR INFORMATION

We process your personal information for the following purposes:

  • Providing and delivering the Services. To manage your account, respond to your requests, and deliver the Services you request.
  • Managing the contractual or pre-contractual relationship. To prepare offers, quotes, or proposals and to perform agreements with you or the company you represent.
  • Communications and support. To respond to questions, support requests, or reports.
  • Marketing purposes. To send you promotional communications about our products and Services, only with your prior consent, which can be withdrawn at any time.
  • Security and fraud prevention. To detect, prevent, and address fraudulent activity, abuse, or threats to the security of our systems.
  • Compliance with legal obligations. To comply with tax, accounting, or contractual obligations, or requests from competent authorities.
  • Protection of vital interests. When necessary to protect a person’s vital interest, for example to prevent harm.

4. LEGAL BASES FOR PROCESSING YOUR INFORMATION

The General Data Protection Regulation (GDPR) requires us to state the legal bases we rely on. Depending on the purpose, we rely on:

  • Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR). When processing is necessary to provide a Service you requested or to prepare an agreement at your request.
  • Consent (Art. 6(1)(a) GDPR). When you have given us permission to use your information for a specific purpose, e.g. marketing. You can withdraw your consent at any time by contacting us, without affecting the lawfulness of processing carried out before the withdrawal.
  • Legitimate interest (Art. 6(1)(f) GDPR). When we believe processing is necessary for our legitimate interests (e.g. managing B2B business contacts or system security), provided such interests do not override your fundamental rights and freedoms.
  • Legal obligations (Art. 6(1)(c) GDPR). When processing is necessary to comply with a legal obligation, cooperate with a law-enforcement body or regulatory authority, or to exercise or defend a legal right.
  • Vital interests (Art. 6(1)(d) GDPR). When processing is necessary to protect your vital interests or those of a third party.

5. WHEN AND WITH WHOM WE SHARE YOUR PERSONAL INFORMATION

We may share your personal information in the following situations and with the following parties:

  • Suppliers and data processors. We share data with service providers who process information on our behalf under an agreement pursuant to Art. 28 GDPR, such as, by way of example, hosting providers, email providers, management software, or customer support tools.
  • Professional advisors. With legal, tax, or accounting advisors, to the extent necessary to provide their services.
  • Public authorities. When required by law or to respond to legitimate requests from public authorities, including for national security or law-enforcement purposes.
  • Business transfers. We may share or transfer your information in connection with, or during negotiations of, a merger, sale of company assets, financing, or the acquisition of all or part of our business by another company.

We do not sell your personal information to third parties.

6. DO WE TRANSFER YOUR DATA OUTSIDE THE EUROPEAN UNION?

As part of our consulting and research activities, we take part in internationally funded cooperation projects (e.g. Erasmus+, Horizon Europe) involving academic and institutional partners located outside the European Economic Area (EEA), including partners in Africa. In these cases, the contact details of project representatives (name, email, job title) may be shared with such partners to the extent necessary to manage and report on the project.

We ensure that such transfers comply with the GDPR through one of the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, included in the project partnership/consortium agreement;
  • an adequacy decision of the European Commission concerning the destination country, where applicable;
  • other appropriate safeguards provided for under the GDPR, including standard clauses required by EU funding programmes for non-EEA partners.

Outside of these research and international cooperation projects, we do not routinely transfer your data outside the EEA.

7. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

We may use cookies and similar tracking technologies to collect information when you interact with our Services. Some of these technologies are necessary for the proper functioning of the site (e.g. technical cookies), while others help us understand, in aggregate form, how the Services are used, for statistical analysis purposes.

Specific information on how we use these technologies and how you can manage your preferences is set out in our Cookie Policy.

8. HOW LONG DO WE RETAIN YOUR INFORMATION?

We will retain your personal information only for as long as necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by law (for example, for tax, accounting, or other legal obligations). No purpose set out in this Policy will require us to retain your data for more than 5 years from the end of the relationship, unless different statutory terms apply to specific categories of data (e.g. tax and accounting records).

When we no longer have a legitimate business need to process your personal information, we will delete or anonymize it, or, where this is not possible (for example, because it is stored in backups), we will securely store it and isolate it from any further processing until deletion becomes possible.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of the personal information we process. However, despite our safeguards, no transmission over the Internet or storage technology can be guaranteed to be 100% secure, so we cannot guarantee that unauthorized third parties will not be able to defeat our security measures. We recommend that you only access the Services in a secure environment.

10. WHAT ARE YOUR PRIVACY RIGHTS?

Under applicable data protection law, you have the following rights regarding your personal information:

  • request access to and obtain a copy of your personal information (right of access);
  • request rectification, if inaccurate or incomplete (right to rectification);
  • request erasure, in the cases provided for by law (right to erasure / “right to be forgotten”);
  • restrict the processing of your personal information (right to restriction);
  • receive your data in a structured, readable format, where applicable (right to data portability);
  • object to processing based on legitimate interest (right to object);
  • not be subject to automated decision-making that produces legal effects concerning you;
  • withdraw your consent at any time, where processing is based on it, without affecting the lawfulness of processing carried out before the withdrawal.

You can exercise these rights by contacting us using the details in Section 12. We will act on every request in accordance with applicable data protection law, generally within 30 days of receipt.

Right to complain. If you believe that the processing of your personal data infringes applicable law, you have the right to lodge a complaint with the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it), the Italian supervisory authority, or with the data protection authority of your Member State if you are located in another EEA country, or with the competent authority in the UK or Switzerland, where applicable.

Cookies and similar technologies. You can set your browser to remove or reject cookies. If you choose to remove or reject them, this may affect some features of the Services. For more information, see our Cookie Policy.

11. DO-NOT-TRACK CONTROLS

Most web browsers and some mobile operating systems and applications include a “Do-Not-Track” (“DNT”) feature that you can activate to signal your preference not to have your online browsing activity monitored. At this time, no uniform technology standard for recognizing DNT signals has been finalized; therefore, we do not currently respond to such signals. If a standard that we are required to follow is adopted in the future, we will inform you in an updated version of this Policy.

12. PROCESSING OF CHILDREN’S DATA

Our Services are not directed at individuals under the age of 16, and we do not knowingly collect personal data from minors. If we become aware that we have collected personal data from a minor without the consent of a person holding parental responsibility, we will promptly delete it.

13. DO WE MAKE UPDATES TO THIS POLICY?

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “last updated” date at the top of the document. In the event of material changes, we may notify you by posting a prominent notice or by sending you a direct notification. We encourage you to review this Policy frequently.

14. HOW CAN YOU CONTACT US ABOUT THIS POLICY

If you have questions or comments about this Policy, you can email us at caterina.picuno@hiloimpact.com or contact us by post at:

Hilo Impact Srl

Viale Volga snc

Bari, 70132

Italy

15. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT?

Depending on the law applicable in your country, you may have the right to request access to the personal information we collect, details on how we have processed it, correct any inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to processing. These rights may be subject to limitations in certain circumstances under applicable law. To request to review, update, or delete your personal information, please contact us using the details in Section 14.