Data controller
- Company name: SETEC Informatica Srls
- VAT number: 04535350401
- Registered office: Via Niccolò Copernico, 101 - 47122 Forlì (FC)
- Phone: 0543 796146
- Email: setec.informatica@setecom.it
- Certified email: setec.informatica@pec.it
Categories of personal data
- Account and profile data: name, title, company, username, email, phone number and address
- Contact and trial request data, including request type, product of interest and message
- Order and billing data: products, quantities, term, prices, discounts, country, tax code or VAT number and taxes
- License and subscription data: serial code, seats, expiration, status and linked Stripe identifiers
- Reserved download data: account, downloaded software, file, date and technical security information
- Technical and security data, such as IP address, browser, session and fraud or abuse-prevention information
Main purposes
- Management of contact, demo, support and quote requests
- Registration, email verification, authentication and customer-area management
- Management of restricted software downloads and download logging
- Management of cart, payments, taxes, invoicing, automatic renewals and subscription portal
- Generation, delivery, renewal and updating of purchased licenses
- Prevention of fraud, free-trial abuse and unauthorized access
- Commercial communications only when the user has given specific consent
Legal basis
- Taking pre-contractual steps at the user’s request
- Performance of the contract for purchasing, renewing and managing software subscriptions
- Compliance with applicable civil, tax, accounting and administrative obligations
- Legitimate interests in security, fraud prevention, support and protection of legal rights
- Consent, which can be withdrawn at any time, for newsletters and promotional communications
Source, provision and consequences
- Profile, request, order and licence data are provided directly by the user; technical and security data are collected automatically while using the website and Customer Area.
- Fields marked as required are necessary for registration, authentication, trials, handling a request or, when available, completing a purchase. Without this data, the relevant operation cannot be completed.
- Optional fields and newsletter consent may be omitted without preventing registration, access, trials or support.
Registration and promotional choice
- The declaration that the Privacy Policy has been read is an acknowledgement separate from consent to promotional communications.
- Promotional consent is optional, separate, withdrawable and not preselected. Refusal does not prevent registration, access, trials, licences, downloads or support.
- Essential service communications may be sent without promotional consent, solely for accounts, security, trials, licences, requested support or necessary technical notices.
- Service communications are not used for offers, discounts, advertising or other promotional content.
- Newsletters, news and commercial offers are sent only when promotional consent is active.
- The preference can be changed in the Customer Area or withdrawn using the unsubscribe link in newsletters.
- The backend separately records the acknowledgement, promotional choice, date and time, user, email, language, source and any subsequent withdrawal.
Account, purchases and licenses
- E-commerce is currently suspended: the price list remains visible, but the site does not allow checkout, renewals or paid changes to be started.
- The password is stored in a non-readable hashed form; profile data can be updated from the customer area.
- Restricted downloads may be logged for security, support and account-related commercial management.
- Once e-commerce is activated, the order, cart contents, amounts, status, renewal and technical transaction references will be recorded before and after payment.
- Once e-commerce is activated, after payment confirmation the backend will generate or update the serial, seat count and expiration, then send summary emails to the customer and caDDrag staff.
Payments and Stripe
- Once e-commerce is activated, checkout and the subscription portal will be hosted by Stripe; profile, cart, billing, tax and transaction data required for the service may be transmitted.
- caDDrag receives amounts, payment outcome, subscription status and technical identifiers, but does not store the full card number or CVC.
- caDDrag Checkout accepts supported cards, excluding American Express, as well as PayPal and SEPA Direct Debit; Apple Pay and Google Pay are shown on compatible devices. Link and Klarna are not enabled.
- Depending on the activity, Stripe may act as a processor or independent controller and applies its own Privacy Policy.
Recipients and transfers
- Once e-commerce is activated, the data required to manage purchases and invoicing will be disclosed to SOLUSOFT Srls, the seller of e-commerce licences and subscriptions, which will separately issue official tax invoices through its own accounting system.
- Data may be processed by authorized staff, hosting and email providers, Stripe and the selected payment-method providers, accounting or legal advisers and competent authorities.
- Some providers may process data outside the European Economic Area; in such cases, applicable legal safeguards and the measures declared by the provider apply.
Retention period
- Contact and trial requests: for the time needed to handle them and any follow-up.
- Account: for the duration of the relationship and afterwards when required by law or to protect legal rights.
- Orders, invoices, payments and contracts: for the periods required by applicable civil, tax and accounting law.
- Logs and security data: for a period proportionate to preventing abuse, incidents and disputes; Stripe applies its own retention periods.
- Technical trial anti-abuse identifier: up to 5 years; related technical fingerprints are retained according to criteria proportionate to preventing repeated requests.
- Newsletter preference: until consent is withdrawn or the account is deleted, except for the minimum data required to document withdrawal and prevent further messages.
Contacts, trials and communications
- The contact form sends the entered information to staff; special-category or unnecessary data must not be submitted.
- A technical device identifier and cryptographic fingerprints of the IP address and browser are used to prevent repeated trial requests.
- Marketing consent is optional, does not affect purchases or support and can be withdrawn in account settings or by contacting the controller.
Security and fraud checks
- Protected sessions, access controls, security tokens, a local CAPTCHA and technical logs are used; however, no system can guarantee absolute security.
- Anti-abuse checks may automatically prevent a new trial when an account, email, licence or browser identifier has already been used, or when the network exceeds the applicable limit. If blocked, a manual review can be requested through support.
- SETEC does not make decisions based solely on automated processing that produce legal or similarly significant effects on the user within the meaning of Article 22 GDPR.
- Stripe may perform automated fraud checks and require additional verification or decline a transaction. The user may contact SETEC for assistance or a review.
Rights and contacts
- The data subject may request access, rectification, erasure, restriction and portability, object where applicable and withdraw consent without affecting prior processing.
- Requests relating to privacy or data protection can be sent to setec.informatica@setecom.it.
- Certified communications can be sent to setec.informatica@pec.it.
- A complaint may be lodged with the Italian Data Protection Authority.
- Last updated: 29 September 2026. Transparency on restricted downloads, data provision, recipients, retention and anti-abuse controls has been updated.