Last updated · 2 September 2026

Privacy policy

This notice describes how CM CUBE S.R.L. processes the personal data of visitors to cmcube.it. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Data controller

The data controller is CM CUBE S.R.L., registered office at Via Cerere 41, 00175 Rome (RM), Italy — entered in the Rome Companies Register under tax code and registration number 18663971002, REA RM-1798964, VAT number 18663971002, share capital € 10,000.00 fully paid up.

For any matter concerning personal data you may write to info@cmcube.it or to the certified address cmcube@namirialpec.it, which is useful when a request needs a legally certain date.

Data protection officer

CM Cube has not appointed a data protection officer, because none of the conditions that would make the appointment mandatory under Article 37(1) GDPR applies: the company is not a public authority, its core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and it does not process special categories of data or data relating to criminal convictions and offences on a large scale.

Data protection requests should therefore be addressed directly to the controller, at the addresses given above.

Scope of this notice

This notice covers the cmcube.it website, an informational site presenting the company and its product lines. The site has no registration, no restricted areas, no contact forms, no online purchases, no comments and no downloads conditional on identification.

Linked sites, in particular lexmap.it and onelogic.it, have their own privacy notices, to which we refer you.

Personal data we process

The site processes two categories of data, and no others.

Browsing data

These are the data that internet communication protocols generate by their very nature on every page request: IP address, date and time of the request, address of the requested resource, request method and outcome, response size, browser and operating system type, and the referring page where present. They are not collected in order to identify anyone, but they could allow identification if combined with data held by third parties.

Data you send us

If you write to info@cmcube.it we process your email address and whatever the message contains: name, organisation, contact details, and the substance of your request. The site sends nothing on your behalf: mail links open the mail program installed on your own device.

Purposes of processing and legal bases

Serving the site

Browsing data are used to deliver the requested pages, to check that the site works, and to derive statistical information in aggregate form, which identifies no one. Legal basis: the controller's legitimate interest in keeping the site working and available (Article 6(1)(f) GDPR).

Site security

The same data make it possible to detect and counter abuse, intrusion attempts and other harmful conduct, and may be used to establish liability in the event of computer crimes committed against the site. Legal basis: legitimate interest (Article 6(1)(f); recital 49 GDPR expressly recognises network and information security as a legitimate interest).

Replying to messages

Data contained in messages are used to read, assess and answer the request. Legal basis: steps taken at the data subject's request prior to entering into a contract, where the message concerns a demo or a possible collaboration (Article 6(1)(b)); legitimate interest in handling correspondence in all other cases (Article 6(1)(f)).

Whether providing data is required

Browsing data are technically inseparable from a web page request: there is no way to visit the site without generating them.

Writing to CM Cube, by contrast, is entirely optional, and the only consequence of not doing so is that we cannot reply.

Cookies and tracking tools

This site sets no cookies of its own and uses no tracking tools: no analytics, no advertising pixel, no social network plugin, no profiling or testing tool. Even the typefaces are served from the site's own domain, so a visit generates no requests to third parties.

For this reason no consent is requested and no banner is shown: Article 122 of the Italian Personal Data Protection Code requires consent only for non-technical tools, which are not present here.

The hosting infrastructure may set, for its own operational needs, cookies strictly necessary to deliver the pages: these are technical cookies, exempt from consent and not used for profiling. You can in any case always block or delete cookies from your browser settings.

Automated decision-making and profiling

There is no automated decision-making, including profiling, within the meaning of Article 22 GDPR. The site builds no profiles of its visitors and takes no decisions concerning them.

Recipients of the data

Data are not disseminated, not sold, and not disclosed to third parties for marketing purposes.

They may be processed, as processors appointed under Article 28 GDPR or as independent controllers depending on their role, by:

  • the hosting provider, which hosts the site on cloud infrastructure located in the European Union;
  • the email provider operating the info@cmcube.it mailbox;
  • the provider of the certified email service;
  • advisors and professionals assisting the company, to the extent necessary;
  • the competent authorities, where disclosure is required by law.

An up-to-date list of processors can be requested at the addresses given above.

Transfers outside the EEA

Data are hosted on infrastructure located in the European Union. Should a provider process them outside the European Economic Area for support or service continuity purposes, the transfer takes place on the basis of an adequacy decision of the European Commission or of the standard contractual clauses provided for by Article 46 GDPR, together with any supplementary measures required.

Retention periods

Browsing data are kept for the technical time needed to operate and secure the site, and in any case for no longer than twelve months, save for any further retention needed to establish liability in the event of computer crimes committed against the site.

Email messages and the data they contain are kept for twenty-four months from the last contact. If the exchange gives rise to a contractual relationship, the documents forming part of it follow the retention periods laid down by law, in particular the ten-year period under Article 2220 of the Italian Civil Code.

Security measures

All connections to the site use HTTPS with TLS encryption. The site is published as a set of static pages: there is no user database, and no server-side application code that processes personal data. Access to the mailbox is restricted to the people who need it.

Your rights

Within the limits set by the GDPR you may at any time request:

  • access to your personal data and a copy of them (Article 15);
  • rectification of inaccurate data and completion of incomplete data (Article 16);
  • erasure of your data (Article 17);
  • restriction of processing (Article 18);
  • data portability, where processing is automated and based on contract or consent (Article 20);
  • to object to processing based on legitimate interest, on grounds relating to your particular situation (Article 21): this covers browsing data and the handling of correspondence.

Requests go to info@cmcube.it or to the certified address cmcube@namirialpec.it. They are free of charge and answered within one month, extendable by a further two months where a request is particularly complex (Article 12(3)).

Lodging a complaint

If you believe that the processing of your data infringes the law, you may lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — garanteprivacy.it, or seek a judicial remedy.

The site links to external sites, in particular lexmap.it and onelogic.it. Once you leave cmcube.it this notice no longer applies: the destination sites have their own notices and their own controllers.

Changes to this notice

This notice may be updated to reflect changes to the site, to the services used, or to applicable law. The date shown at the top of the page is that of the current version; material changes will be flagged on this same page.