Privacy Policy

Last updated: July 21, 2026

1. Introduction

Veil Energy S.r.l. (“Veil Energy”, “we”, “our”, or “us”) is committed to protecting users’ privacy and ensuring that the processing of personal data is carried out in a transparent, secure manner and in compliance with the applicable data protection legislation, including Regulation (EU) 2016/679 (“GDPR”).

This Privacy Policy describes how we collect, use, store and protect the personal data of users who visit the website www.veil-energy.eu (the “Website”), interact with our digital content, request information about our services, participate in our events, or receive communications from us.

The purpose of this Privacy Policy is to provide clear information regarding the processing of personal data and the rights granted to data subjects.

2. Data Controller

The Data Controller is:

Veil Energy S.r.l. Via A. Pacinotti 12 – A. Pacinottistraße 12 39100 BolzanoBozen Italy

For any request relating to the processing of personal data or to exercise your rights under the applicable data protection legislation, you may contact the Data Controller at:

Email: info@veil-energy.eu

Veil Energy has implemented appropriate technical and organisational measures to ensure the protection of the personal data processed within the scope of its business activities.

2.1 Data Protection Officer (DPO)

Pursuant to Article 37 of the GDPR, the appointment of a Data Protection Officer (DPO) is mandatory where processing is carried out by a public authority, where the core activities of the Data Controller consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of the large-scale processing of special categories of personal data or data relating to criminal convictions and offences.

Following an assessment of its processing activities, Veil Energy has determined that none of the above circumstances applies to its business. The processing activities carried out by Veil Energy mainly concern professional contact data processed within the context of B2B commercial relationships and do not involve regular and systematic large-scale monitoring of data subjects or the large-scale processing of special categories of personal data.

Accordingly, Veil Energy has not appointed a Data Protection Officer (DPO).

Nevertheless, any request relating to the protection of personal data may be addressed directly to the Data Controller using the contact details provided in Section 2 of this Privacy Policy.

Veil Energy reserves the right to reassess this decision should its processing activities materially change in the future.

3. What Personal Data We Collect

During the course of our activities, we may collect different categories of personal data depending on how users interact with Veil Energy.

3.1 Identification and Contact Data

We may collect personal data provided directly by users, including:

  • first and last name;
  • email address;
  • telephone number;
  • job title;
  • company name;
  • information relating to the user’s professional position.

These data are generally provided when the user:

  • completes a contact form;
  • requests information about our services;
  • requests a product demonstration;
  • downloads content;
  • subscribes to our newsletter;
  • registers for events or webinars;
  • uses digital tools made available by Veil Energy.

3.2 Information Regarding the Company and Professional Interests

In the context of our B2B activities, we may collect information regarding:

  • the company represented;
  • the industry sector;
  • company size;
  • the contact’s role;
  • interests in our solutions;
  • needs expressed by the user.

This information allows us to better understand users’ professional needs and provide more relevant communications and content.

3.3 Data Collected Automatically While Browsing

When a user visits the Site, we may collect certain technical information through analytics tools and tracking technologies, including:

  • IP address (where available);
  • information about the browser and device used;
  • pages visited;
  • duration of the visit;
  • how the user interacts with the Site;
  • information related to browsing events.

This data is used primarily to ensure the proper functioning of the Site, improve its performance, and understand how users interact with our content.

For more information on the technologies used during browsing, please refer to our Cookie Policy.

3.4 Data Related to Interactions with Digital Communications

When we send communications via email, newsletters, or other digital communications, we may collect information regarding your interactions with those communications. For example:

  • opening emails;
  • clicking on links contained in the communications;
  • date and time of interactions;
  • technical information regarding the device or email client used.

This data allows us to understand the effectiveness of the communications we send, improve the quality of our content, and provide more relevant information to recipients.

4. How We Collect Personal Data

Personal data may be collected through:

  • our website;
  • online forms and information request forms;
  • newsletters and marketing communications;
  • webinars and digital events;
  • simulators, quizzes, and interactive tools;
  • direct requests sent via email or other communication channels;
  • interactions with our digital content.

In some cases, data may be provided directly by the data subject; in other cases, it may be collected automatically through technological tools or in our digital communications.

5. Purposes of Processing and Legal Bases

We process personal data exclusively for the purposes described in this privacy policy, using it in a lawful and transparent manner and limiting processing to what is necessary to provide the requested services, improve our offerings, and comply with legal obligations.

The main purposes of processing and their respective legal bases are set forth below.

5.1 Handling Requests and Providing Requested Services

We use personal data for the following activities, each specifically linked to its corresponding legal basis, avoiding the cumulative overlap of multiple legal bases for the same activity:

Activities based on the implementation of pre-contractual measures taken at the request of the data subject (Art. 6, para. 1, subparagraph b, GDPR):

  • responding to requests for information sent voluntarily by the user through the Website;
  • handling requests for contact, demos, or further information about our products and services;
  • providing materials and quotes requested by the user in view of the possible conclusion of a contract;
  • organizing business meetings expressly requested by the user.

Activities based on the Data Controller’s legitimate interest (Art. 6, para. 1, letter f, GDPR):

  • internal technical and organizational management of received requests (assignment, tracking, and archiving in the CRM);
  • prevention of abuse, fraud, or misuse of the Website’s contact forms;
  • ensuring the security of the information systems used to manage requests.

With regard to the activities listed above, Veil Energy has weighed its legitimate interests against the fundamental rights and freedoms of the data subjects, concluding that the impact on the data subjects’ privacy is minimal and reasonably expected within the context of a professional relationship initiated at the data subject’s own initiative. The data subject may object to such processing at any time by contacting Veil Energy using the contact information provided in Section 2.

5.2 Management of Marketing Communications and Newsletters

With the data subject’s consent, Veil Energy may use contact information to send:

  • newsletters;
  • updates on our services;
  • informational content;
  • invitations to events and webinars;
  • marketing communications regarding our solutions.

The legal basis for the processing is the data subject’s consent (Art. 6, para. 1, subpar. a, GDPR).

The data subject may withdraw consent at any time by using the unsubscribe link at the bottom of the communications received or by contacting Veil Energy.

5.3 Communications to Existing Customers and Business Contacts

In the context of B2B business relationships, for the purpose of determining the applicable legal basis, Veil Energy distinguishes between the following categories of recipients:

Existing customers: individuals who have already purchased Veil Energy products or services as part of an established contractual relationship. Veil Energy may send these individuals communications regarding its products and services similar to those already purchased, based on the Data Controller’s legitimate interest (Art. 6, para. 1, letter f, GDPR), in accordance with the so-called “soft opt-in” principle set forth in Article 130, paragraph 4, of the Personal Data Protection Code (Legislative Decree 196/2003), provided that: (i) the contact address was provided by the customer in connection with the sale of a product or service; (ii) the communications concern services similar to those covered by the original sale; (iii) the data subject is informed, at the time of collection and upon each subsequent communication, of the possibility to object easily and free of charge.

Potential business contacts (prospects): individuals who have interacted with Veil Energy (e.g., via forms, events, or content downloads) without having entered into a contractual relationship. For these individuals, sending commercial communications requires the data subject’s specific consent pursuant to Article 6(1)(a) of the GDPR and Article 130 of the Privacy Code.

Every communication includes the option to opt out of receiving further communications, either by clicking the unsubscribe link provided or by contacting Veil Energy using the contact information listed in Section 2.

6. Marketing Automation, CRM, and Personalized Communications

To manage relationships with users, customers, and prospects, Veil Energy uses digital customer relationship management (CRM) and marketing automation tools, specifically the HubSpot platform, which acts as a Data Processor pursuant to Article 28 of the GDPR based on a specific Data Processing Agreement entered into with Veil Energy.

Through HubSpot, we process, in particular, the following data for the purposes indicated:

  • identification and contact information (name, email, company, role), to organize and manage contacts within the CRM;
  • data related to requests submitted via forms, to manage received requests and associate them with the relevant contact;
  • data on interactions with communications (see Section 7 – Email Tracking) and with the Website, to send relevant informational and marketing communications, schedule email campaigns, and analyze user interactions with our content;
  • lead scoring (see Section 8), to prioritize sales efforts and improve the relevance of communications.

The use of these tools allows us to provide content that is more aligned with users’ expressed interests and to improve the quality of our communications. The processing carried out through HubSpot is not based on a single general legal basis applicable to the entire platform, but rather on the legal basis specifically applicable to each purpose, as indicated in Section 5 (precontractual measures, consent, or legitimate interest, as applicable).

7. Email Tracking

Communications sent through our marketing tools (specifically via HubSpot) may include email tracking technologies, such as invisible tracking pixels and personalized links, which allow us to track user interactions with the emails received.

For example, we may track:

  • email opens;
  • clicks on links in the communications;
  • the date and time of interactions;
  • technical information regarding the device or program used to read the emails.

Legal basis: The processing of email tracking data is based on the same legal basis applicable to the sending of the communication to which the tracking refers, namely the data subject’s consent (Article 6(1)(a) of the GDPR) for communications to potential business contacts (prospects), or the Data Controller’s legitimate interest (Article 6(1)(f) of the GDPR) for communications sent to existing customers under the soft opt-in principle, in accordance with the distinction outlined in Section 5.3.

This information is used exclusively to:

  • evaluate the effectiveness of our communications;
  • understand which content is most relevant;
  • improve the quality and frequency of our mailings;
  • avoid irrelevant communications.

The monitoring of email interactions is not used to make automated decisions that produce legal effects or similarly significant effects on the data subject pursuant to Article 22 of the GDPR.

The information collected through email tracking is retained for the period specified in Section 15 and is processed in compliance with applicable laws regarding the protection of personal data and electronic communications.

8. Lead Scoring and Automated Processes

Veil Energy may use lead scoring systems—that is, automated mechanisms that assign a level of interest to contacts based on their interactions with our digital content and services.

For example, the score may take into account activities such as:

  • opening or interacting with emails;
  • visiting certain pages on the Website;
  • downloading content;
  • filling out forms;
  • participating in webinars;
  • using interactive tools.

The score is calculated automatically by the HubSpot platform based on rules predefined by Veil Energy (for example, a higher score for repeatedly opening communications, visiting pages related to specific products or services, or filling out forms with high commercial value) and is used internally by the sales team exclusively to prioritize contacts.

Lead scoring is used exclusively to:

  • better understand users’ interests;
  • organize sales activities;
  • provide more relevant communications;
  • improve the user experience.

Lead scoring does not involve fully automated decision-making that produces legal effects or significantly affects the data subject within the meaning of Article 22 of the GDPR: the score serves solely as an internal tool to support the sales team, which evaluates the most appropriate means of contact on a case-by-case basis, without the score automatically determining access to, denial of, or the terms of a service.

9. Workflows and Automated Communications

Veil Energy may use automated workflows to manage certain communications based on actions taken by users.

For example, automated communications may be triggered by:

  • filling out a form;
  • requesting information;
  • registering for an event;
  • downloading content;
  • using digital tools.

These processes are designed to provide faster responses, improve the user experience, and deliver content tailored to users’ expressed interests.

10. Website Analytics Tools

To understand how users interact with our Site and to continuously improve its functionality and content, we use digital analytics tools.

10.1 Google Analytics 4

We use Google Analytics 4 (GA4), a web analytics service provided by Google, to collect aggregated information about how the Site is used.

The information collected may include:

  • pages visited;
  • navigation patterns;
  • events generated during the visit;
  • technical information about the device.

Google Analytics is used in accordance with the consent settings required by applicable law.

For more information, please refer to the Cookie Policy.

10.2 Hotjar

We use Hotjar to better understand user behavior on the Site and improve the browsing experience.

Hotjar may collect information regarding how users interact with the pages, such as:

  • mouse movements;
  • interactions with page elements;
  • general browsing behavior.

Hotjar is not used to directly identify users or collect unnecessary personal information.

Hotjar is used only with the user’s prior consent via the cookie management tools, where required by applicable law.

11. Interactive Digital Services, Forms, Simulators, and Online Content

Veil Energy provides users with various digital tools, interactive content, and other informational resources.

When a user utilizes these tools, we may collect personal data provided voluntarily, such as:

  • first and last name;
  • email address;
  • company;
  • professional role;
  • information regarding professional needs or interests expressed during the interaction.

The data collected through these tools is used to:

  • provide the requested service or content;
  • process any results or evaluations requested by the user;
  • provide in-depth information regarding Veil Energy solutions;
  • better understand users’ interests and needs;
  • improve our digital tools and the content we offer.

If the user consents to receiving marketing communications, the data may also be used for subsequent informational and commercial communications as described in this privacy policy.

12. Webinar and Online Events

Veil Energy may organize webinars, online events, and informational initiatives through third-party digital platforms.

To manage these events, we may collect data such as:

  • first and last name;
  • email address;
  • company;
  • professional role;
  • information regarding participation in the event.

We currently use Contrast as our platform for managing webinars and digital events.

The data is used to:

  • manage registration and participation in events;
  • send organizational information;
  • provide event-related materials;
  • analyze participation and improve future initiatives.

Data processing may be based on the data subject’s consent or on the implementation of pre-contractual measures taken at the data subject’s request, depending on the nature of the event.

13. Sharing of Personal Data and Parties Involved in Processing

Veil Energy does not sell, rent, or transfer personal data to third parties for commercial purposes unrelated to its own activities.

However, personal data may be shared with parties that support Veil Energy in managing its activities, including:

  • technology service providers;
  • CRM and marketing automation platforms;
  • hosting and digital infrastructure service providers;
  • website analytics tool providers;
  • providers of digital event platforms;
  • consultants, partners, or professionals who support Veil Energy.

These parties process data exclusively in accordance with Veil Energy’s instructions and, when required by law, are designated as Data Processors pursuant to Article 28 of the GDPR.

Among the main technology providers used are:

  • HubSpot for CRM, contact management, marketing automation, and digital communications;
  • CookieYes and Google Analytics 4 for analyzing website traffic and usage;
  • Hotjar for analyzing user experience;
  • Contrast for managing webinars and digital events.

The list of providers may be updated periodically based on changes in the services used by Veil Energy.

14. Transfer of Personal Data to Countries Outside the EEA

Some technology providers used by Veil Energy may have their headquarters or infrastructure located outside the European Economic Area (EEA). In such cases, Veil Energy ensures that data transfers are carried out in compliance with Articles 44 et seq. of the GDPR, by implementing appropriate safeguards. The following table summarizes, for each relevant provider, the destination country and the safeguard applied:

Provider Country Safeguard applied
Provider Country Safeguard applied
Google (Google Analytics 4) – Google LLC / Google Ireland Ltd. USA European Commission Standard Contractual Clauses, supplemented by additional technical and organizational measures adopted by Google
HubSpot – HubSpot Inc. / HubSpot Ireland Ltd. USA European Commission Standard Contractual Clauses
Hotjar Ltd. (Contentsquare) Malta/UE (Possible intra-group transfers to third countries) European Commission Standard Contractual Clauses, where applicable
CookieYes Limited UK European Commission Adequacy Decision for the United Kingdom
Contrast UE European Commission Standard Contractual Clauses

Veil Energy periodically reviews the safeguards implemented by its suppliers to ensure an adequate level of personal data protection.

15. Data Retention Period

Veil Energy retains personal data only for the period necessary to achieve the purposes for which it was collected. The retention periods, broken down by category of processing, are as follows:

  • data related to requests for information that did not result in a contractual relationship: retained for 24 months from the last relevant contact, after which it is deleted or anonymized, unless the user expresses a different and more recent interest;
  • data processed based on consent for marketing purposes targeting potential business contacts (newsletters, commercial communications): retained until consent is withdrawn or, in the absence of withdrawal, for a maximum period of 24 months from the data subject’s last active interaction with our communications, after which consent is requested again;
  • data relating to actual customers and contractual relationships: retained for the duration of the contractual relationship and, thereafter, for the ordinary statute of limitations period provided for by applicable law (10 years pursuant to Article 2946 of the Italian Civil Code for contractual claims); accounting and tax documentation is retained for 10 years pursuant to Article 2220 of the Italian Civil Code and applicable tax regulations;
  • data collected via cookies and the Website’s analytics/tracking tools: retained for the periods specified in the Cookie Policy;
  • data related to lead scoring and email tracking: retained for the same retention period as the CRM contact to which they refer, unless consent is revoked.

In the absence of specific requirements, Veil Energy deletes or anonymizes personal data when it is no longer necessary for the purposes for which it was collected.

16. Security of Personal Data

Veil Energy adopts a security approach based on the principle of accountability set forth in Articles 5(2) and 24 of the GDPR, aimed at ensuring that the measures taken can be demonstrated internally, including as part of the company’s ISO/IEC 27001 certification process.

The technical and organizational measures adopted include, among others:

  • maintaining a record of processing activities pursuant to Article 30 of the GDPR;
  • internal access management policies based on the principle of least privilege and appropriate authentication mechanisms;
  • encryption of data in transit (e.g., via the TLS protocol) and, where applicable, of stored data;
  • procedures for managing security incidents and personal data breaches, including the notification timelines to the Data Protection Authority and data subjects as provided for in Articles 33 and 34 of the GDPR;
  • conducting data protection impact assessments (DPIAs) in the cases provided for in Article 35 of the GDPR;
  • periodic training of personnel involved in the processing of personal data;
  • selection of suppliers based on a preliminary assessment of the data protection safeguards they offer and the execution of agreements appointing them as Data Processors pursuant to Article 28 of the GDPR;
  • backup and business continuity procedures.

The measures described above are documented internally and reviewed periodically to ensure the protection of personal data against unauthorized access, accidental loss, improper disclosure, unauthorized modification, and destruction of data.

Although Veil Energy takes all reasonable measures to protect personal data, no computer system can guarantee absolute security.

17. Rights of Data Subjects

As a data subject, you have the right to exercise the rights set forth in Articles 15–22 of the GDPR, including:

  • to obtain confirmation of the existence of personal data concerning you;
  • to access your personal data;
  • to request the rectification of inaccurate data;
  • to request the erasure of data when provided for by law;
  • to request the restriction of processing;
  • object to the processing of personal data;
  • receive personal data in a structured, machine-readable format, where applicable;
  • withdraw previously given consent.

To exercise these rights, you may submit a request to: info@veil-energy.eu

Veil Energy will respond to requests without undue delay and, in any case, within one month of receiving the request, in accordance with Article 12, paragraph 3, of the GDPR. This deadline may be extended by two months, taking into account the complexity and number of requests; in such a case, Veil Energy will inform the data subject of the extension and the reasons for it within one month of receiving the request.

The data subject also has the right to lodge a complaint with the competent data protection authority if he or she believes that the processing of his or her data violates applicable law.

18. Cookies

The Site uses cookies and similar technologies to ensure the Site functions properly, improve the browsing experience, and analyze content usage.

Information regarding the cookies used, their purposes, duration, and how to manage your preferences is available in our Cookie Policy.

19. Updates to This Policy

Veil Energy may periodically update this Privacy Policy to reflect changes in regulations, organizational structure, or the services used.

The updated version will always be available on the Website, with the date of the last update indicated.

We encourage users to check this page periodically to stay informed about how Veil Energy protects personal data.

20. Contact Information

If you have any questions regarding this Privacy Policy or the processing of personal data, please contact:

Veil Energy S.r.l. Via A. Pacinotti 12 – A. Pacinottistraße 12 39100 BolzanoBozen Italy Email: info@veil-energy.eu