Privacy Policy

This policy, pursuant to European Regulation no. 679/2016 (hereinafter referred to as the “Regulation” or “GDPR”), describes the processing by TG Soft S.r.l. of personal data relating to the use of the website, provided by the user and deriving from the use of its products

1) DATA CONTROLLER
The Data Controller is TG Soft S.r.l (hereinafter also referred to as “TG Soft” or “Controller”) with registered office in Via Enrico Fermi, 2, 35030 Selvazzano Dentro (PD) – ITALY. VAT number/Tax code: IT 03296130283 Telephone: 049.4950030 Email: info@tgsoft.it or segreteria@tgsoft.it

2) TYPES OF PROCESSED DATA

  1. BROWSING DATA
    During navigation on our site, some data is collected automatically, such as the IP address, the user agent (which contains information about the browser and operating system), the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, and the time of the request. This data is necessary to ensure the full functionality and security of the site, therefore its provision is necessary and not optional. Without it, the use of web services would be impossible. The data could also be used to ascertain responsibility in the event of hypothetical computer crimes against the site. The Data Controller therefore processes the aforementioned data based on its legitimate interest in ensuring the security and proper working of the site.

  2. COOKIES
    Cookies are text files that sites visited by users send to their terminals and which are transmitted back to the sites the next time they visit. For more information please see our COOKIE POLICY.

  3. DATA VOLUNTARILY PROVIDED BY THE USER
    Data provided by the user (in particular: name, surname, address, tax code, VAT number, email address, telephone number) in any way, such as through registration on the website, subscription to the newsletter or sending requests to company email addresses for:
    • requests for quotations concerning TG Soft products/services;
    • requests for TG Soft products/services reseller lists;
    • direct purchase orders for TG Soft products/services;
    • activation of Licences for the software marketed by TG Soft either directly from the public activation page or through the relevant reseller from the Reseller Reserved Area;
    • subscription to TG Soft's Newsletter by users, customers, resellers and potential resellers. It will always be possible to unsubscribe directly from the Newsletter itself.

    No credit card data are processed, they are managed directly by SELLA BANK.

  4. DATA OBTAINED FROM TG SOFT PRODUCTS AND SERVICES
    In order to guarantee its services and thus fulfill its contractual obligations, TG Soft collects the data listed below, deriving from the use of its products.

    PRODUCTS FOR PC AND SERVER PROTECTION
    Vir.IT eXplorer PRO:
    Suite AntiVirus, AntiSpyware, AntiMalware and AntiRansomware, CryptoMalware protection.
    Vir.IT eXplorer Lite:
    Reduced version (therefore interoperable with other AV or Internet Security software installed on PCs/servers) and free version of Virus, Spyware and Malware identification & removal features of Vir.IT eXplorer PRO.
    Vir.IT Console Client/Server:
    Console for centralized control of updates and security settings for individual machines.
    Vir.IT CLOUD Console ed EDR:
    Console that allows cloud monitoring, via a web platform, of user machines running the Vir.IT eXplorer PRO suite. EDR provides additional data for threat monitoring.

    ANDROID PROTECTION PRODUCTS:
    VirIT Mobile Security PRO:
    Anti-Malware software for Android device protection against malware and other unwanted threats, with an advanced heuristic approach (Permission Analyzer) for privacy protection.
    VirIT Mobile Security Lite:
    free version of Vir.IT Mobile Security PRO.

    DATA CONCERNING: Vir.IT eXplorer Lite, Vir.IT Mobile Security Lite e Vir.IT Mobile Security PRO:
    With regard to Vir.IT eXplorer Lite, VirIT Mobile Security Lite and VirIT Mobile Security PRO, the data processed by the Data Controller concerns (in addition to personal and contact details of the licence forVirIT Mobile Security PRO):
    • system identification data, such as IP and operating system, MAC address, device name etc, and mobile device identification IDs, necessary for the product version to be compatible with the IT equipment and to manage threats and updates;
    • applications installed, to check for any malicious applications;
    • concerning Vir.IT eXplorer Lite also the list of startup programs. A change in the programs that start with the PC may, in fact, be due to malicious software that has penetrated the device;
    • suspicious files submitted automatically or by the user, or apps that the user wishes to have analysed because they are considered potentially dangerous.

    DATA CONCERNING: Vir.IT Explorer PRO, Vir.IT Console Client/Server, Vir.IT CLOUD Console and EDR
    The following data is collected from Vir.IT eXplorer PRO, Vir.IT Console Client/Server and Vir.IT CLOUD Console ed EDR in addition to the licence data:
    • telemetric information about the antivirus product to monitor its operation and use and facilitate its development
    • device identification data such as IP, Operating System, device and username, and MAC address, necessary for the product to be compatible with the IT system and for managing threats and updates;
    • threat data: If a threat is detected on a device, information about it is sent to TG Soft. This allows us to analyse the threats, their sources and patterns of infection, in order to offer the user a high quality of protection;
    • URLs visited: this information allows us to create lists of harmless and harmful websites, blocking navigation on dangerous sites;
    • Operating System processes: New malware can often only be identified by its suspicious behaviour. Therefore the product analyses data on processes running on the device. In this way, processes reporting malicious activity can be identified at an early stage and their damaging consequences, such as the destruction of user data, can be prevented;
    • list and change of startup programmes to check for any suspicious files that startup with the computer;
    • suspicious files: if a suspicious file is detected on a device, it can be automatically sent for further analysis to our Anti Malware Research Centre;
    • E-mail: Virit eXplorer Pro scans e-mail messages and uses the relevant data (and metadata) to protect the user from infected attachments, spam and fraud;
    • any suspicious files sent by the user. Files sent by the user through TG Soft's Submission Service may be anonymous or accompanied by the email address of the sender, who can thus receive a direct reply;
    • in case of remote assistance, in addition to the licence data, the computer system data necessary to manage the operation of the antivirus and to identify and eliminate cyber threats will be processed. A brief description of these operations will be given in the CUSTOMER AREA of the TG Soft Site that can be consulted by the user.

3) PURPOSE AND LEGAL BASIS OF THE PROCESSING
The personal data processed by the Data Controller will be used for the following purposes:

  1. to execute the contract, including the pre-contractual phases (Art. 6, par. 1, letter b of the GDPR), allowing, among other things: customer access to the CUSTOMERS Area 24 hours a day for the entire period of assistance for the products/services purchased and automatic or manual updating of the software products under licence; telephone and remote;
  2. to fulfil a legal obligation of the Controller such as tax obligations arising from the contract (legal basis Art. 6(1)(c) GDPR);
  3. to exercise legitimate interests of the holder (legal basis Art. 6(1)(f) GDPR) such as:
    • ensuring the security of the site and prevent or detect fraudulent activities and abuse;
    • developing the company's products to ensure ever greater protection for users;
    • exercising the right of defence in court;
    • sending to existing customers commercial communications by email regarding services and products similar to those they have already used, as provided for in Article 130, paragraph 4 of Legislative Decree No. 196/2003. The person concerned may object to such processing at any time.
  4. only with the specific and separate consent of the data subject, which can be revoked at any time, the data provided by the customer/user will be processed for marketing purposes (legal basis: Articles 6(1)(a) and 7 of the GDPR) to send newsletters, commercial communications and/or advertising material on products or services offered by the Data Controller, via email.

4) METHODS OF DATA PROCESSING
Personal data is subject to both paper and electronic and/or automated processing. Specific security measures are observed to prevent loss, destruction, modification, blocking, copying of data, unlawful or incorrect use and accidental or unauthorised access. No automated decision-making process or profiling will be applied to the collected data

5) RETENTION PERIOD
Personal data will be processed for the time necessary to achieve the purposes for which it is collected, and for the additional period necessary to fulfil legal obligations, or to comply with orders issued by Public Authorities.
Data linked to pre-contractual stages and data linked to marketing activities will be kept for 6 years after collection.
In the event of conclusion of the contract, data required for administrative-accounting purposes, in compliance with invoicing regulations, will be processed for 10 years from the date of contract termination.

DATA RELATED TO THE USE OF PRODUCTS
The retention period for personal data resulting from the use of our products will be 3 months, with the exception of system identification data, which will be retained for the duration of the licence agreement. Personal data obtained from remote assistance will be retained for the following 10 years in relation to the Data Controller’s legitimate interest in defense in court.
This is without prejudice to cases in which the retention of data for a subsequent period is necessary for any disputes, requests from the competent authorities or in accordance with applicable legislation.

6) DATA RECIPIENTS
The data provided by the user may be accessed, in compliance with GDPR guarantees by:

  • the Controller's employees and collaborators as authorised to process the personal data;
  • companies and/or professional firms that support the Data Controller in keeping accounts (statutory management obligations) and managing employees (recruitment, payroll, etc.) or other entities such as hosting service providers, suppliers, credit institutions, and professional firms for outsourcing activities;
  • for customers not acquired directly by the Controller, each direct reseller of the products/services marketed by the Controller through him/her shall be allowed to consult the data entered at the time of activation of the user licence and any changes thereto;
  • only the Data Controller, assisted by authorised employees or collaborators, will have access to the data derived from the use of TG Soft products and browsing data. These data may also be stored and managed through hosting services.

The data may also be communicated to persons and authorities whose right to access the personal data of users is expressly recognised by law, regulations or measures issued by the competent authorities.

7) DATA TRANSFER
Personal data will be stored on servers located within the European Union and managed by the Data Controller and/or hosting companies. The data will not be transferred outside the European Union. Where necessary, the Data Controller shall have the right to move the location of the servers to Italy and/or the European Union and/or non-EU countries. In the event of data transfer outside the EU, the Data Controller guarantees that this will be done in accordance with the applicable legal provisions.

8) NATURE OF DATA PROVISION
The provision of data by the user for the purposes referred to in point 3 (A and B) is necessary for the conclusion and execution of the contract and the performance of related services, as well as to ensure compliance with applicable legislation. In case of point 3 (C), processing is not mandatory and the user may object to such processing pursuant to Article 21 of the GDPR, unless the Data Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject or for the establishment, exercise, or defense of legal claims. With regard to commercial communications via email relating to services and products similar to those already used, the user has the right to refuse such processing by exercising their right to object initially or at the time of each commercial communication. The provision of data for Marketing Purposes point 3 (D) is optional. The data subject may therefore decide not to provide any data or to withdraw consent to the processing of the data provided: in this case, he/she will not be able to receive newsletters, commercial communications, and advertising material relating to the Services offered by the Data Controller.

9) RIGHTS OF THE DATA SUBJECT
According to the GDPR, the user concerned by the processing of personal data has the right to:

  • obtain confirmation from the controller as to whether or not personal data relating to him/her are being processed and, if so, obtain access to the personal data and information provided (art. 15);
  • obtain from the data controller the rectification of inaccurate or outdated personal data (art. 16);
  • obtain the erasure of his/her personal data in the specified cases (art. 17);
  • obtain from the controller the restriction of processing in the specified cases (art. 18);
  • to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and to transmit those data to another controller, in the specified cases (art. 20);
  • where processing is based on consent, it will be possible to withdraw it at any time (art. 7);
  • OPPOSE to processing on grounds relating to his or her particular situation, where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party. The data subject may then object to the processing, without special justification, if the personal data are processed for direct marketing purposes (art. 21 );
  • lodge a complaint with a supervisory authority (art.77).

Any requests to exercise the rights of the data subject may be addressed to the Controller via the following contact details: TG Soft S.r.l. Via Enrico Fermi, 2, 35030 Selvazzano Dentro (PD) – Tel: 049.4950030 Email: info@tgsoft.it o segreteria@tgsoft.it.

10) MINORS
The Site, the products and the Services of the Owner are intended for users over 18 years and will not knowingly collect data from minors.

11) CHANGES TO THE POLICY
This Policy is subject to change. We therefore recommend that you check it regularly and refer to the most up-to-date version.

Vir.IT eXplorer PRO is certified by the biggest international organisation: