Last updated: 29/07/2026
This notice describes how personal data is processed in connection with GRADO Security, the cloud platform for occupational health and safety (HSE) management operated by GRADO TECH Srls. It is issued pursuant to Arts. 13 and 14 of EU Regulation 2016/679 (GDPR), supplements the general privacy notice published on the GRADO Tech website, and clarifies the applicable privacy roles when client company data is hosted on the platform under a service contract, consulting engagement, commercial agreement or activation carried out also through authorised partners.
GRADO Security is SaaS software: client companies independently enter and manage their own data on the platform. The role of GRADO TECH Srls varies depending on context:
This section applies to personal data that the client company (or a safety consultant, RSPP, occupational physician, partner or other party authorised by it) enters, uploads or generates on GRADO Security in connection with its business and workers. Such data remains under the exclusive control and availability of the client company as data controller, is not transferred to GRADO TECH Srls as its own data, and remains under the controller's responsibility; GRADO TECH Srls only hosts, stores and makes it available according to the contract and received instructions.
For the data described in this Part A:
The controller must provide its workers and data subjects with a GDPR-compliant privacy notice (Arts. 13–14) and have a valid legal basis for each processing activity, including those relating to occupational safety (Italian Legislative Decree 81/2008) and, where applicable, special categories of data (e.g. medical visits).
Depending on features activated by the company, the platform may process, among others, the following data entered or generated by the controller:
GRADO TECH Srls processes Part A data exclusively on behalf of the controller and limited to the following technical purposes:
The legal basis for processing by the controller (purposes, lawfulness, information to data subjects) is determined by the controller. Processing by GRADO TECH Srls as processor is based on performance of the service contract and the Art. 28 GDPR agreement (Art. 6(1)(b) GDPR), and where necessary on legitimate interest in platform security (Art. 6(1)(f) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
Retention periods for Part A data are determined by the data controller, in compliance with applicable law (including occupational safety and training documentation obligations). GRADO TECH Srls retains data for the duration of the contract and thereafter for the period strictly necessary for orderly service termination, recovery at the controller's request or legal obligations. Upon termination of the contractual relationship, data is returned or deleted as provided in the contract and Art. 28 agreement, unless otherwise documented by the controller or required by law.
GRADO TECH Srls does not freely access, consult or use content entered by client companies on GRADO Security without a lawful and documented basis. Access to client data by authorised GRADO TECH Srls personnel is permitted only in the cases below, in compliance with the principles of necessity, data minimisation and confidentiality:
Any access to client data content by GRADO personnel is limited to authorised staff, subject to confidentiality obligations, logged where technically possible and limited to the duration of the intervention. In the absence of controller instructions or a legal obligation, GRADO TECH Srls does not review content for its own purposes, does not sell client company data and does not disclose it to third parties for marketing, profiling or independent commercial exploitation.
The platform records relevant operations (audit logs, user access, data changes) to enable the controller to monitor activities carried out by users authorised by it. Logs and evidence relating to GRADO TECH Srls technical assistance interventions are retained for the time necessary to manage the contractual relationship, security, intervention traceability and defence against disputes, generally no longer than 12 months unless legal obligations or defence needs require otherwise.
This section applies to personal data collected directly by GRADO TECH Srls in connection with registration, free trial, subscription, billing, commercial and contractual communications and management of platform administrative accounts, independently of data entered by the company about its workers.
The data controller for Part C data is GRADO TECH Srls, registered office Corso Umberto I, 7 — 66050 San Salvo (CH), Italy. VAT IT02868240694. Email: info@gradotech.it — Phone: +39 378 421 3717.
Performance of contract or pre-contractual measures (Art. 6(1)(b) GDPR); compliance with legal obligations (Art. 6(1)(c) GDPR); legitimate interest in security and relationship management (Art. 6(1)(f) GDPR); consent for optional marketing activities (Art. 6(1)(a) GDPR), revocable at any time.
Data relating to workers and other parties entered by the company on GRADO Security is processed by the data controller (the client company or workspace manager). Therefore:
The controller is responsible for providing its workers with a complete and up-to-date privacy notice on processing carried out via GRADO Security.
Ordinary use of GRADO Security mainly concerns identification, organisational and document data relating to occupational safety. In some cases, however, the platform may host data falling within the special categories under Art. 9 GDPR, in particular where the controller uploads copies of fitness-for-work assessments or health surveillance documents already delivered to the worker. The platform is not intended for the systematic collection of medical records or excessive health data: the controller must limit storage to data that is relevant and necessary. The controller remains solely responsible for the lawfulness of such processing, adoption of any additional security measures and the information provided to data subjects; GRADO TECH Srls processes such data solely on behalf of the controller and according to its documented instructions.
GRADO Security may offer generative AI and automation features, for example to verify certificates and related deadlines, suggest risks and PPE consistent with work cycles, job roles, assignments, machinery or work areas, and identify documentary or operational inconsistencies. Use of such features is activated by the controller and content sent to AI engines is processed solely to provide the requested function. For these services, GRADO TECH Srls may rely, to the extent strictly necessary, on the following third-party providers, acting as sub-processors or technical service providers depending on the applicable contractual setup: OpenAI OpCo, LLC / OpenAI Ireland Ltd (privacy: openai.com/privacy; enterprise: openai.com/enterprise-privacy); Anthropic, PBC (privacy: anthropic.com/privacy); Google LLC (privacy: policies.google.com/privacy). Client data is not resold and is not used by GRADO TECH Srls to train its own models or for independent purposes; any processing by AI providers takes place under their applicable business/enterprise terms and DPAs and, where provided, with exclusion of content use for training their models.
Data may be processed by appointed processors or sub-processors bound by Art. 28 GDPR agreements or equivalent contractual safeguards where applicable, including: Aruba S.p.A. (Via San Clemente 53, 24036 Ponte San Pietro (BG), Italy — VAT 01573850516), as provider of infrastructure services connected to the platform — Aruba GDPR, Aruba privacy notice; email and certified email (PEC) services; any AI service providers activated by the controller for specific features, to the extent strictly necessary to deliver the requested function: OpenAI OpCo, LLC / OpenAI Ireland Ltd (privacy), Anthropic, PBC (privacy), Google LLC (privacy); professional advisors or authorities where required by law. An updated list of sub-processors relevant to the service is available on request at info@gradotech.it or attached to the contract.
Data is processed primarily within the European Economic Area, including through Aruba S.p.A. (Italy). More information: aruba.it/gdpr. If specific optional AI features activated by the controller involve processing by OpenAI, Anthropic or Google and, as a result, transfers to third countries (for example the United States), such transfers take place only where adequate safeguards under the GDPR are in place, such as adequacy decisions (including, where applicable, the EU-US Data Privacy Framework), European Commission Standard Contractual Clauses or other lawful instruments. Specific information on transfers connected to AI services is provided in the contract, the DPA or on request.
GRADO TECH Srls implements appropriate technical and organisational measures to protect data processed on GRADO Security: multitenant segregation between client companies, TLS encryption, irreversible password hashing, role-based access control and least privilege, backups, monitoring and compliance with ISO/IEC 27001:2024 standards. In the event of a personal data breach affecting data processed on behalf of the controller, GRADO TECH Srls will inform the controller without undue delay, as required by Art. 33 GDPR and the contract.
The controller warrants that data entered on GRADO Security is lawful, relevant, accurate and not excessive for the pursued purposes; that it has the rights, lawful bases and authorisations required (including for worker data, uploaded documents and any fitness-for-work assessments); that it correctly configures user roles and permissions; that it adopts organisational measures required by occupational safety law; and that it uploads only information that is strictly necessary to the platform's purposes. GRADO TECH Srls is not responsible for the controller's organisational decisions, risk assessments, the substantive or legal accuracy of content entered by the controller, instructions given to GRADO TECH Srls, or the privacy notice the controller must provide to its data subjects. This notice does not constitute legal advice.
This notice may be updated to reflect regulatory, contractual or service changes. Any amendments will be published on this page with the date of the last update.