Last updated: July 22, 2026
This information notice (hereinafter, the “Notice”) is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the “GDPR”) and to Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018 (hereinafter, the “Italian Privacy Code”). It governs the processing of personal data of natural persons (hereinafter, the “Data Subjects”) carried out through the website https://www.wiselyst.com (hereinafter, the “Website”).
The Website is not directed at minors, and the Controller does not knowingly collect personal data relating to persons under the age of fourteen (14).
1. Data Controller
The data controller, within the meaning of Article 4(7) GDPR, is:
Wiselyst S.r.l., with registered office at Via Nino Bixio 92, 95125 Catania (CT), Italy, VAT No. (P.IVA) 05754250875 (hereinafter, the “Controller” or the “Company”).
The Controller may be contacted for any matter relating to the processing of personal data at the following address: privacy@wiselyst.com.
The Controller has not designated a Data Protection Officer, the conditions set forth in Article 37 GDPR not being met.
2. Categories of data processed, purposes and legal bases of the processing
2.1 Navigation data and cookies
In brief: our servers automatically record basic technical data (such as IP addresses) to keep the Website running and secure. We keep it only as long as needed.
In the course of their ordinary operation, the computer systems and software procedures underlying the Website acquire certain personal data the transmission of which is implicit in the use of Internet communication protocols. Such data include, by way of example, IP addresses, browser type, the addresses of the pages requested, and the date and time of the request.
- Purpose: to ensure the proper functioning, maintenance and security of the Website.
- Legal basis: the legitimate interest of the Controller in operating and securing the Website, pursuant to Article 6(1)(f) GDPR. The Controller has assessed such processing by means of a legitimate interest assessment, available upon request.
- Retention period: the time strictly necessary to fulfil the aforementioned purposes, without prejudice to any longer retention required for the ascertainment of unlawful conduct.
Subject to the Data Subject’s prior consent, the Controller further employs analytics cookies and similar technologies, as set out in Section 8 of this Notice.
2.2 Contact form
In brief: if you contact us through the form, we use your details only to reply to you, and we keep the correspondence for up to 12 months.
Where the Data Subject makes use of the contact form available on the Website, the Controller processes the data provided therein (name, e-mail address and the contents of the communication) for the sole purpose of responding to the request submitted. Such communications are delivered to the Controller’s electronic mail system, supplied by a third-party provider acting as data processor; no autonomous database of submissions is maintained.
- Purpose: to respond to requests and enquiries submitted by the Data Subject.
- Legal basis: the performance of pre-contractual measures taken at the Data Subject’s request, pursuant to Article 6(1)(b) GDPR.
- Retention period: twelve (12) months from the conclusion of the correspondence, save where a contractual relationship is established.
The provision of such data is optional; however, failure to provide it will render it impossible for the Controller to respond.
The form is protected against automated submissions as set out in Section 2.5.
2.3 Recruitment and job applications
In brief: we keep your application for 24 months. AI tools help us organise and summarise applications, but every decision is made by a person.
Where the Data Subject submits an application for a position through the Website, the Controller processes the data provided (identification and contact details, curriculum vitae, cover letter and any further information voluntarily supplied) for the purposes of assessing the application and managing the selection process. Applications are stored in the Controller’s applicant tracking system, hosted on cloud infrastructure located within the European Union.
Certain positions are published on the platform join.com, operated by JOIN Solutions AG. Where the Data Subject applies for a position published by the Controller through that platform, the Controller acts as data controller and JOIN Solutions AG processes the application data as a data processor on the Controller’s behalf, pursuant to Article 28 GDPR and to the data processing agreement entered into between the parties. Where, conversely, the Controller receives a candidate profile through the talent pool operated by JOIN Solutions AG on the basis of the consent given by the Data Subject to that platform, the Controller assumes the capacity of data controller upon receipt of such data, and this Notice shall apply thereto.
- Purpose: personnel search and selection.
- Legal basis: the performance of pre-contractual measures taken at the Data Subject’s request, pursuant to Article 6(1)(b) GDPR. Pursuant to Article 111-bis of the Italian Privacy Code, the consent of the Data Subject is not required for the processing of personal data contained in curricula vitae spontaneously transmitted for recruitment purposes. Data Subjects are requested to refrain from including special categories of personal data within the meaning of Article 9 GDPR in their application, save where strictly relevant thereto.
- Retention period: twenty-four (24) months from receipt of the application, upon expiry of which the data shall be erased, save where an employment or collaboration relationship is established or a further application is submitted.
Should an application nonetheless contain special categories of personal data within the meaning of Article 9 GDPR, such data shall not be taken into account for the purposes of the selection and shall be erased, save where their processing is strictly necessary and lawful under Article 9(2)(b) GDPR and Article 111-bis of the Italian Privacy Code.
The form is protected against automated submissions as set out in Section 2.5.
2.3.1 Use of artificial intelligence systems in the selection process
The Controller may avail itself of artificial intelligence tools (namely, services supplied by Anthropic by means of API) as an aid in the review of applications, including for the purposes of summarising and organising application materials. No decision concerning an application is adopted by exclusively automated means: each application is reviewed, and each decision is adopted, by a natural person. Accordingly, Data Subjects are not subject to decisions based solely on automated processing within the meaning of Article 22 GDPR.
2.4 Marketing communications
In brief: we only send newsletters if you have expressly agreed, and you can unsubscribe at any time with one click.
The Controller shall send newsletters or promotional communications solely where the Data Subject has given prior, explicit and specific consent thereto, pursuant to Article 6(1)(a) GDPR and Article 130 of the Italian Privacy Code. Consent may be withdrawn at any time, free of charge, by means of the unsubscribe link contained in each communication or by written notice to privacy@wiselyst.com, without prejudice to the lawfulness of the processing carried out prior to such withdrawal.
- Purpose: the sending of newsletters and promotional communications relating to the Controller’s services.
- Legal basis: the consent of the Data Subject, pursuant to Article 6(1)(a) GDPR and Article 130 of the Italian Privacy Code.
- Retention period: the data processed for marketing purposes shall be retained until withdrawal of consent and, in any event, for no longer than twenty-four (24) months from collection, upon expiry of which consent shall be re-requested or the data erased.
2.5 Protection of forms against automated submissions
In brief: the forms on this Website are protected against bots by a Cloudflare tool. It loads only once you start filling in a form, and it installs nothing on your device.
The forms made available on the Website — namely the contact form referred to in Section 2.2 and the application form referred to in Section 2.3 — are protected by Cloudflare Turnstile, a service supplied by Cloudflare, Inc. The tool is loaded solely once the Data Subject begins to fill in a form, and not upon the mere visiting of the Website.
For such purpose, the tool collects certain technical signals relating to the browser and to the interaction, including the IP address, the TLS fingerprint, the user-agent header and further technical characteristics of the terminal equipment employed. In the configuration adopted by the Controller, the tool does not install cookies, nor does it store information upon the terminal equipment of the Data Subject.
- Purpose: to prevent the automated, fraudulent or abusive submission of forms, and to protect the security and availability of the Controller’s communication channels.
- Legal basis: the legitimate interest of the Controller in protecting the Website and its communication channels against automated abuse, pursuant to Article 6(1)(f) GDPR. The Controller has assessed such processing by means of a legitimate interest assessment, available upon request.
- Retention period: the verification token generated is of single use and of limited validity. The retention of the signals collected by the supplier is governed by the privacy policy of the latter, referred to below.
Cloudflare, Inc. acts as data processor pursuant to Article 28 GDPR in respect of the processing carried out to protect the Website. The same supplier further processes the signals collected, as an autonomous data controller, for the purpose of improving the effectiveness of its own bot-detection service, on the basis of its own legitimate interest. For further information, see https://www.cloudflare.com/turnstile-privacy-policy/.
3. Recipients of the data
The personal data shall be processed by personnel of the Controller duly authorised and instructed pursuant to Article 29 GDPR, and may be communicated to:
- suppliers of services acting as data processors pursuant to Article 28 GDPR, belonging to the following categories: providers of electronic mail and productivity services; providers of cloud hosting and infrastructure services (with regard to the applicant tracking system, located within the European Union); providers of web analytics and tag management services; and providers of artificial intelligence services (namely, Anthropic, with regard to the assisted review of applications referred to in Section 2.3.1);
- providers of anti-bot and website security services (namely, Cloudflare, Inc.), in respect of the protection of the forms referred to in Section 2.5;
- JOIN Solutions AG (join.com), in its capacity as data processor pursuant to Article 28 GDPR, in respect of applications submitted for positions published by the Controller on its platform;
- public authorities and bodies, where communication is required by law or by order of the competent authority.
An updated list of the data processors engaged by the Controller may be requested at the address indicated in Section 1.
The personal data shall not be sold, nor shall it be communicated to third parties for their own marketing purposes.
4. Transfer of data outside the European Economic Area
Certain suppliers engaged by the Controller — including the providers of web analytics services, the provider of anti-bot and website security services (Cloudflare) and the provider of artificial intelligence services (Anthropic) — are established in the United States of America. Any transfer of personal data to countries outside the European Economic Area shall take place on the basis of an adequacy decision of the European Commission — including the EU–U.S. Data Privacy Framework, where the recipient is duly certified thereunder — or, in the absence thereof, on the basis of the Standard Contractual Clauses adopted by the European Commission, supplemented by additional measures where necessary, in accordance with Articles 44 to 49 GDPR.
As at the date of this Notice, Google LLC is certified under the EU–U.S. Data Privacy Framework, as verifiable on the official list maintained at https://www.dataprivacyframework.gov. Transfers to Anthropic, PBC take place on the basis of the Standard Contractual Clauses adopted by the European Commission, incorporated into the data processing addendum entered into with such provider. Cloudflare, Inc. is likewise certified under the EU–U.S. Data Privacy Framework; the data processing addendum entered into with such provider further incorporates the Standard Contractual Clauses adopted by the European Commission, which shall apply in the event that such certification ceases to be effective. The Data Subject may obtain a copy of the safeguards adopted by submitting a request to the Controller.
5. Rights of the Data Subject
Pursuant to Articles 15 to 22 GDPR, the Data Subject has the right to:
- obtain access to their personal data and a copy thereof (Article 15);
- obtain the rectification of inaccurate data and the completion of incomplete data (Article 16);
- obtain the erasure of their data, where the conditions therefor are met (Article 17);
- obtain the restriction of the processing (Article 18);
- receive their data in a structured, commonly used and machine-readable format (Article 20);
- object to the processing on grounds relating to their particular situation (Article 21);
- withdraw consent at any time, where the processing is based on consent, without prejudice to the lawfulness of the processing carried out prior to such withdrawal (Article 7(3)).
Such rights may be exercised by written request addressed to privacy@wiselyst.com. The Controller shall respond without undue delay and, in any event, within one month of receipt of the request.
The Data Subject further has the right to lodge a complaint with the competent supervisory authority — in Italy, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it) — or with the supervisory authority of the Member State of their habitual residence or place of work.
6. Nature of the provision of data
Save as otherwise specified in this Notice, the provision of personal data is optional; however, failure to provide the data required for the purposes set out in Sections 2.2 and 2.3 shall render it impossible for the Controller to respond to the request or to consider the application, as the case may be.
7. Modalities of the processing
The processing shall be carried out by electronic and manual means, in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality set forth in Article 5 GDPR, and with the adoption of technical and organisational measures adequate to the risk pursuant to Article 32 GDPR.
8. Cookie policy
This section applies to cookies and to similar tracking technologies, including local storage, pixels and software development kits (hereinafter jointly referred to as “cookies”). Cookies are small text files stored on the Data Subject’s terminal equipment upon visiting a website. In accordance with the GDPR, Article 122 of the Italian Privacy Code and the Guidelines on cookies and other tracking tools adopted by the Garante on 10 June 2021, the Website employs the following categories of cookies.
8.1 Technical cookies (no consent required)
Cookies strictly necessary for the operation of the Website and for the storage of the Data Subject’s preferences regarding cookies. Such cookies are installed without the Data Subject’s consent, as permitted by Article 122 of the Italian Privacy Code.
| Category | Purpose | Duration |
|---|---|---|
| Essential / session cookies | Operation and security of the Website | Session |
| Consent preference cookies | Storage of the choices expressed regarding cookies | 12 months |
8.2 Analytics cookies (consent required)
Subject to the prior consent of the Data Subject, expressed by means of the cookie banner, the Website employs:
- Google Analytics (supplied by Google Ireland Ltd.), for the purpose of measuring, in aggregate form, the use of the Website by visitors;
- Google Tag Manager, for the management of the scripts and tags present on the Website; this tool does not itself collect personal data but governs the loading of the aforementioned instruments.
| Cookie | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
_ga |
Google Ireland Ltd. (third party) | Analytics | Distinguishing visitors | 24 months |
_ga_<ID> |
Google Ireland Ltd. (third party) | Analytics | Persisting session state | 24 months |
For further information on the processing carried out by Google, see https://policies.google.com/privacy.
Such cookies are installed solely upon the Data Subject’s acceptance through the cookie banner. In the absence of consent, only technical cookies shall be employed, without prejudice to the Data Subject’s ability to browse the Website.
8.3 Management of preferences
The Data Subject may modify or withdraw their consent at any time through the cookie settings link available in the footer of the Website. Cookies may further be deleted or blocked through the settings of the browser employed; the blocking of technical cookies may impair the functionality of the Website.
The consent preferences expressed by the Data Subject are recorded by the Controller’s consent management system for the purposes of demonstrating consent pursuant to Article 7(1) GDPR.
9. Amendments to this Notice
The Controller reserves the right to amend this Notice in order to reflect legislative or operational developments. The version in force, bearing the relevant date, shall at all times be published on this page. In the event of material amendments affecting job applicants or other identified Data Subjects, the Controller shall, where feasible, inform them directly.