Last updated: 20/08/2026
This notice describes how personal data is processed in GRADO Reflow, the software through which the customer organisation connects to the national RENTRI system (Registro Elettronico Nazionale per la Tracciabilità dei Rifiuti) to consult and manage forms and registers. It is provided pursuant to Arts. 13 and 14 of EU Regulation 2016/679 (GDPR) and supplements the general notice published on the GRADO Tech website. Not everything shown in Reflow is stored on GRADO TECH Srls servers: FIR forms and registers remain in the public RENTRI system.
GRADO Reflow is provided as SaaS. The role of GRADO TECH Srls varies by context:
This section applies to data that the customer organisation (or a person authorised by it) enters, uploads or generates on GRADO Reflow. Such data remain under the control and responsibility of the controller; GRADO TECH Srls only hosts them, stores them securely and makes them available under the contract and the instructions received.
For the data described in this Part A:
The controller must provide data subjects with a GDPR-compliant privacy notice and have a valid legal basis for each processing operation, including those relating to RENTRI credentials and work documents.
The application database may store, among other items:
GRADO TECH Srls processes Part A data exclusively on behalf of the controller: provision and hosting of Reflow, execution of documented instructions, IT security and technical support within the limits of Part B. It does not use customer-organisation data for marketing, commercial profiling, resale or independent analytics.
The legal basis of the processing by the controller is determined by the controller (typically performance of waste-traceability legal obligations and of the contractual relationship with operators). Processing by GRADO TECH Srls as processor is based on performance of the service contract and the Art. 28 GDPR agreement.
Retention periods for Part A data are determined by the controller. As a rule: emergency FIR forms and files until deletion by the customer or end of service; encrypted credentials until revocation, replacement or termination; coding caches a few hours / at most about one day; audit logs generally 24 months, unless longer obligations apply. At the end of the relationship, data are returned or deleted under the contract.
GRADO TECH Srls does not freely access, consult or use workspace content without a lawful, documented basis. Access by authorised staff is allowed only in the following cases:
Each access is limited to authorised staff, subject to confidentiality and confined to the duration of the intervention. GRADO TECH Srls does not sell the data and does not use the RENTRI certificate on its own initiative: calls to the public APIs occur only on the authenticated user’s initiative, with the operator’s certificate.
This section applies to personal data collected to provide the application: accounts, authentication, security logs and technical preferences.
The controller for Part C data is GRADO TECH Srls, registered office Corso Umberto I, 7 — 66050 San Salvo (CH), Italy. VAT IT02868240694. Email: info@gradotech.it — Tel. +39 378 421 3717. Website: www.gradotech.it.
Providing the service and authenticating users (performance of a contract, Art. 6.1.b GDPR); securely storing credentials and logs (security obligations and, where applicable, legal obligations, Arts. 6.1.c and 32 GDPR); preventing abuse and ensuring continuity of the service (legitimate interest, Art. 6.1.f GDPR). We do not process marketing data, we do not profile users for advertising, and we do not sell lists to third parties.
You may request access, rectification, erasure, restriction, portability and objection, within the limits of the law.
For data that exist only on RENTRI, the request must be addressed to the competent public controller, not to GRADO TECH Srls.
Reflow queries the official RENTRI APIs (api.rentri.gov.it / demo environment) using the operator’s digital certificate, stored encrypted. Responses (FIR forms, registers, master data, outcomes) are shown in session. Live FIR and register content remains on RENTRI.
For RENTRI data, privacy rights are exercised with the competent public controller, according to the notices on the RENTRI portal (rentri.gov.it).
We use only technical cookies (or equivalent storage) for authentication and appearance preferences. We do not use advertising profiling cookies or third-party marketing trackers.
Data may be known by authorised staff of GRADO TECH Srls for support and maintenance; by Aruba S.p.A. (Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy — VAT 01573850516), as infrastructure provider — Aruba GDPR; by the RENTRI / MASE system only for API calls that the authenticated user makes with their own certificate. An updated list is available on request at info@gradotech.it.
Processing normally takes place in Italy / the European Union. Any transfers to third countries occur only where adequate GDPR safeguards are in place.
GRADO TECH Srls implements appropriate technical and organisational measures: multi-tenant segregation, TLS, irreversible password hashing, optional MFA, AES-256-GCM encryption of RENTRI credentials, role-based access control, backups, audit logs and ISO/IEC 27001:2024 compliance. In the event of a breach affecting data processed on behalf of the controller, GRADO TECH Srls will inform the controller without undue delay.
This notice may be updated to reflect regulatory, contractual or service changes. Any material amendments will be published on this page (and made available via API) with the date of the last update; Reflow will then request a new acceptance.