How SoftLab IT collects, uses and protects personal information when you use our website, contact us or interact with our digital services.
Last updated: 21 September 2026
1. Introduction
SoftLab IT (“SoftLab IT”, “we”, “us” or “our”) respects your privacy and is committed to handling personal information responsibly.
This Privacy Policy explains how we collect, use, disclose and protect information when you visit softlabit.com, submit an enquiry, communicate with us, or interact with our services.
Where applicable, we process personal data in accordance with relevant data-protection requirements, including the General Data Protection Regulation (GDPR) for individuals in the European Economic Area (EEA).
We believe in transparency and autonomy: we do not treat merely browsing our website as blanket consent for all data processing activities. Consent is requested and relied upon only where consent is the applicable and appropriate legal basis under relevant data-protection law.
2. Information We Collect
Depending on how you interact with our website and digital channels, we may collect information in two primary ways:
A. Information You Provide Directly
When you request a quotation, book a discovery call, fill out a contact form, apply for an opportunity, or communicate with us directly, you may voluntarily provide:
Name: Your first name and surname.
Email address: Your personal or business email address for correspondence.
Phone or WhatsApp number: Contact telephone numbers provided for direct calls or WhatsApp messages.
Company or restaurant/business name: Business trade name, company entity, or establishment name.
Country & City: Your geographic location, restaurant location, or country of operation.
Project & service requirements: Scope details, digital feature requirements, technology preferences, or meeting notes.
Budget or timeline selections: Estimated budget ranges, desired kickoff dates, or implementation schedules.
Enquiry form submissions: Messages and specific requests submitted through our contact and consultation forms.
Other voluntary communications: Information contained in email exchanges, resumes/CV submissions, support requests, or customer feedback.
B. Information Collected Automatically
When you navigate through softlabit.com, certain technical and usage details may be recorded automatically by our servers or authorized analytics/diagnostic tools, subject to your consent preferences and device settings:
IP address: Internet Protocol address, used for network routing and approximate geographic region.
Browser & device information: Browser type and version, device category (desktop, mobile, tablet), screen resolution, and language settings.
Operating system: Device operating system and platform details.
Referring source: The website, search query, or digital link that referred you to our site.
Pages visited: Specific URL paths, navigation sequences, entry and exit pages.
Timestamps: Date, time, and session duration of visits and interactions.
Approximate location: Coarse city or country-level location derived from technical routing data.
Element interactions: Clicks on navigation links, tab switches, expandable FAQ interactions, and form interaction timestamps.
Campaign & UTM parameters: Campaign referral tags (such as utm_source, utm_medium, utm_campaign) where present in the URL.
Performance & diagnostic data: Page load speed metrics, server response times, and front-end diagnostic signals.
3. How We Use Information
We use collected information for legitimate, specified business and technical purposes, including:
Responding to enquiries: Reviewing your business requests, answering technical questions, and scheduling introductory calls.
Preparing quotations & proposals: Evaluating technical specifications, architectural feasibility, and commercial estimates for software engineering projects.
Communicating about requested services: Sending relevant follow-ups, meeting confirmations, or clarification questions regarding your enquiry.
Delivering and supporting contracted services: Performing software engineering, system integration, deployment, and ongoing technical support under client agreements.
Improving website usability & performance: Optimizing layout, navigation hierarchy, loading speeds, and overall user experience.
Understanding visitor engagement: Evaluating aggregate traffic patterns, popular solutions, and audience engagement across different regions.
Measuring marketing & campaign performance: Understanding which marketing channels, advertisements, or referral sources are effective.
Detecting abuse & technical issues: Protecting our infrastructure, preventing spam form submissions, monitoring server uptime, and mitigating security threats.
Maintaining business records: Preserving commercial correspondence, audit trails, and administrative records.
Complying with legal obligations: Meeting applicable regulatory, statutory, accounting, or dispute-resolution requirements.
Important: Submitting a contact or quotation enquiry form does not automatically authorize SoftLab IT to enroll you in unsolicited promotional email blasts or recurring marketing newsletters.
4. Legal Bases for Processing (EEA / GDPR)
For individuals located within the European Economic Area (EEA), the General Data Protection Regulation (GDPR) requires a valid legal basis for each processing activity. Depending on the context and purpose, we process personal data under one or more of the following legal bases:
Pre-contractual steps or performance of a contract (Art. 6(1)(b) GDPR): When you submit an enquiry, ask for a consultation, or request a proposal, processing your information is necessary to take steps at your request prior to entering into a contract, or to perform a contracted agreement.
Legitimate interests (Art. 6(1)(f) GDPR): We may process personal data where necessary for our legitimate business interests—such as ensuring network and website security, preventing fraud, maintaining business correspondence, and optimizing site functionality—provided that these interests are balanced against and do not override your fundamental rights and freedoms.
Compliance with legal obligations (Art. 6(1)(c) GDPR): Where applicable statutory laws or regulatory mandates require us to retain records, respond to lawful requests, or fulfill data-protection duties.
Consent (Art. 6(1)(a) GDPR): Where required by applicable law, we rely on your prior, freely given, specific, and informed consent. This applies in particular to the activation of non-essential analytics cookies, session-replay technologies, and advertising measurement tags.
5. Contact Forms & Project Enquiries
When you submit a contact or project enquiry form on softlabit.com (such as our general contact form, digital restaurant solution request, or quotation form), we use the information provided primarily to review your request, respond to you, and take steps requested by you in connection with a potential business relationship.
No automatic marketing subscription: Submitting an enquiry does not add your email address or phone number to any promotional newsletter list or automated advertising campaigns.
Form privacy notice: Privacy acknowledgement text presented on our forms serves to inform you about this Privacy Policy before submission. It is an informational notice, not a promotional marketing opt-in.
Separate marketing consent: Any recurring promotional marketing, if offered in the future, must be requested and managed separately with clear opt-in and opt-out options.
Proportional data collection: We request only the fields necessary to understand your inquiry and facilitate professional communication.
6. Cookies and Similar Technologies
A cookie is a small text file placed on your device by a website. SoftLab IT may use cookies, local storage, and similar technologies for several categories of functionality:
Essential / Strictly Necessary Cookies: Required for the core operation of the website, such as remembering your consent preferences (e.g. _sl_consent), session routing, and security. These cannot be switched off in our systems.
Analytics Cookies: Help us measure visitor volume, identify high-interest pages, and assess how visitors navigate our site to improve technical performance.
Advertising & Measurement Technologies: Used to assess the performance of advertising campaigns, measure conversion events, and ensure campaigns are relevant.
Where required by applicable law, non-essential cookies and similar technologies are used in accordance with the visitor’s consent choices.
We provide a built-in consent mechanism that allows visitors to accept or decline non-essential cookies. You can review, update, or withdraw your cookie preferences at any time by clicking the button below or using the "Cookie Preferences" link in the footer of any page:
Additionally, most web browsers allow you to manage or block cookies through browser settings. Please note that disabling essential cookies may impact certain website functions.
7. Google Analytics 4 and Google Tag Manager
SoftLab IT uses Google Tag Manager (GTM) to deploy and manage website measurement tags. Through GTM, we may configure Google Analytics 4 (GA4), a web analytics service provided by Google LLC (or Google Ireland Limited for users in the EEA).
Google Analytics 4 helps us understand how visitors interact with softlabit.com by collecting aggregate and event-based metrics, including:
Page views, session starts, and scroll depth.
Traffic acquisition sources and referrers.
Device category, operating system, and browser version.
Key interaction events (such as contact button clicks, external link clicks, and navigation interactions).
Campaign attribution parameters.
Google Consent Mode: Where implemented, our site uses Google Consent Mode (Consent Mode v2) to dynamically communicate your consent choices to Google tags. When analytics storage is not consented to, Google tags operate in a privacy-preserving mode that avoids writing or reading analytics cookies from your device.
For further information on Google’s data handling practices, please review the Google Privacy Policy ↗.
8. Microsoft Clarity
We use Microsoft Clarity to better understand how visitors interact with our website and to improve usability and user experience.
Depending on consent and configuration, Clarity may collect interaction and diagnostic information such as page visits, clicks, scrolling, mouse movement, device/browser information and website performance information. Clarity can also generate session-replay and heatmap insights.
Privacy Protections: Sensitive form-field content should remain masked in accordance with the configured Clarity privacy settings. Clarity does not record actual video of you or capture camera feeds; it reconstructs on-page interface interactions (session replay/interaction playback) to identify usability bottlenecks, broken links, or confusing layouts.
For visitors in regions where consent is required, including the EEA, Clarity cookie functionality is managed in accordance with applicable consent signals and our cookie-consent implementation.
SoftLab IT may use Meta advertising technologies provided by Meta Platforms, Inc. (and Meta Platforms Ireland Ltd.), such as the Meta Pixel and Conversions API, to:
Measure the effectiveness of digital marketing campaigns across Meta platforms.
Understand website visits and key actions originating from Meta advertisements.
Measure aggregate website events (such as page visits or enquiry completions).
Support campaign attribution, conversion deduplication, and optimization.
Create or measure advertising audiences where legally permissible and consented to.
Consent Control: Use of advertising cookies and technologies is subject to applicable consent choices where required. By default, marketing technologies remain disabled for new visitors until affirmative consent is provided. If marketing consent is declined or if a Global Privacy Control (GPC) signal is detected, marketing measurement cookies (such as _fbp and _fbc) are not activated.
To learn more about Meta’s data privacy practices or manage your ad preferences on Meta services, visit the Meta Privacy Policy ↗.
10. UTM and Campaign Attribution
When you arrive at our website through a promotional link, external partnership, or search result, the destination URL may include standardized UTM parameters, such as:
utm_source: Identifies the platform or site where the link was published (e.g., google, linkedin, facebook).
utm_medium: Identifies the marketing medium (e.g., cpc, social, referral, email).
utm_campaign: Identifies the specific marketing initiative or product campaign.
utm_content: Differentiates between links pointing to the same URL within an advertisement.
utm_term: Identifies paid search keywords or campaign identifiers.
These parameters are used solely to measure campaign performance and traffic channels. They do not by themselves require visitors to disclose their personal identity or name.
11. Data Sharing and Service Providers
We do not sell, rent, or trade personal information to third parties.
We do not sell personal information to advertisers.
To operate our global website and deliver our services, we may share information with trusted third-party service providers who assist us under strict confidentiality and data-protection obligations, including:
Cloud & Hosting Providers: Infrastructure providers that host our website, application APIs, and secure database systems.
Analytics Providers: Providers such as Google and Microsoft that assist in measuring aggregate website performance and usability.
Advertising & Measurement Partners: Platforms such as Meta that assist in measuring advertising effectiveness where consent is granted.
Communication & Messaging Services: Providers facilitating email delivery, inquiry routing, or WhatsApp business communications.
Legal & Professional Advisors: Legal, accounting, or audit professionals when necessary for legal compliance or dispute defense.
12. International Data Transfers
Because SoftLab IT operates globally and serves international clients, personal information may be stored or processed by service providers in countries outside your country of residence, including outside the European Economic Area (EEA).
Where applicable, international transfers are handled using legally recognized safeguards or other mechanisms permitted under applicable data-protection law, such as standard contractual clauses, adequacy decisions, or vendor data-protection addenda designed to maintain an equivalent level of protection for your personal data.
13. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including responding to enquiries, maintaining business records, fulfilling contractual obligations and meeting legal requirements.
Business Enquiries: Retained for the duration needed to evaluate, respond, and engage in requested commercial discussions, and for a reasonable period thereafter to facilitate follow-ups.
Client Contracts: Retained for the duration of the contracted engagement and subsequently in accordance with statutory limitation periods and accounting obligations.
Analytics & Diagnostic Logs: Retained in accordance with standard platform data-retention configurations or until consent is withdrawn.
When personal information is no longer needed, we securely delete, anonymize, or isolate it from further processing.
14. Data Security
We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration or disclosure. These measures include encrypted HTTPS/TLS data transmission, role-based access restrictions, cryptographic hashing of identifiers where applicable, and regular software maintenance.
However, no internet transmission or electronic storage system can be guaranteed to be completely secure. We encourage you to take precautions when transmitting sensitive information over public networks.
15. Your Privacy Rights
Depending on your location and applicable data-protection legislation (including the GDPR for individuals in the European Economic Area), you may be entitled to exercise certain rights regarding your personal information:
Right of Access: You may request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification: You may request the correction of inaccurate or incomplete personal information.
Right to Erasure (“Right to be Forgotten”): You may request the deletion of your personal data where retention is no longer justified.
Right to Restriction of Processing: You may request that we temporarily restrict the processing of your data under certain statutory conditions.
Right to Object: You have the right to object to processing based on legitimate interests at any time.
Right to Data Portability: Where applicable, you may receive your provided personal data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent: Where processing is based on your consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Right to Lodge a Complaint: You have the right to submit a complaint to a competent data-protection supervisory authority.
Please note that the availability of these rights depends on the specific legal basis of processing and the statutory exceptions provided by applicable law. To exercise any of these rights, please contact us at info@softlabit.com.
16. Italy / EEA Users
If you are located in Italy or another country in the European Economic Area, you may exercise the rights available under the GDPR. You may also lodge a complaint with the competent data-protection supervisory authority.
For individuals residing in Italy, the competent national supervisory authority is:
Garante per la protezione dei dati personali Piazza Venezia, 11 - 00187 Roma, Italia Website: www.garanteprivacy.it ↗
17. Third-Party Links
Our website may contain links to third-party websites, external client projects, social media platforms, or external partner resources. SoftLab IT is not responsible for the privacy practices, content, or policies of those third-party websites. We encourage you to review the privacy policies of any third-party websites you visit.
18. Children's Privacy
Our website and business services are intended for businesses and professional users and are not designed for children. We do not knowingly seek to collect personal information from children through our business enquiry forms. If you believe that personal data of a minor has been submitted to us unintentionally, please contact us so we can promptly delete the information.
19. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect technological developments, service enhancements, or evolving legal and regulatory requirements. When updates occur, we will revise the “Last updated” date at the top of this page. We encourage you to review this Policy periodically to stay informed about our data-protection practices.
20. Contact Us
For questions about this Privacy Policy or requests concerning your personal information, please contact us at: