Legal

Privacy Policy

Privacy Policy

Last updated: July 2026

This privacy policy (the “Privacy Policy”) contains important information about the personal data collected when you visit this website and the other sites and domains owned or controlled by Made to Sell S.r.l. (collectively, the “Websites”) — including the third-level domains of the SellingExperience.com platform, a Learning Experience System (LXS) developed and operated directly by Made to Sell S.r.l. — as a registered or unregistered user, and describes how such data is used. Where applicable, it also explains how data provided by the user or collected through corporate communication tools, or during other contacts with the Company, is processed.

Acceptance

By visiting the Website, using its services or interacting with the Company and/or the linked Websites, you confirm that you have read and understood this Policy and accept that the Company collects, uses, stores, transmits and discloses the personal data gathered through the Websites in accordance with it. If you do not accept these terms, please do not use the Website and do not submit personal data.

1. Processing of personal data

“Personal Data” means any information that allows the user (or a third party whose data the user provides) to be identified, directly or indirectly. Processing is carried out in compliance with Regulation (EU) 2016/679 (“GDPR”) and, where applicable, national data protection law (Italian Legislative Decree 196/2003 as amended). The Company reserves the right to carry out further processing where required by law or in the context of civil, criminal or administrative investigations or proceedings.

2. Personal data collected

2.1 Source of the data. The Company collects personal data only when the user voluntarily provides it, for example: making an information request, a purchase or a service subscription; opening or editing an account on the SellingExperience.com platform; taking part in an event, survey, webinar or training initiative; sending a comment, application or question; subscribing to the newsletter; exchanging communications by e-mail, SMS or other electronic messages. If the user provides third parties' data, they must ensure those parties are informed and have authorised its use.

2.2 Types of data. Identifying information (first name, last name, job role, company); contact information (e-mail, phone, postal address); billing and payment data, where applicable; data related to the use of the training services and the platform (course progress, assessment results), used solely for the purposes described.

3. Purposes and legal basis of processing

3.1 Service delivery and contract management. Data provided when requesting or purchasing a service is used to manage and perform the contractual relationship and pre- and post-sales support, meet accounting, tax and administrative obligations, prevent fraud and communicate with the user. Legal basis: performance of a contract or pre-contractual measures (Art. 6.1.b GDPR) and compliance with legal obligations (Art. 6.1.c GDPR). Providing the data is necessary; refusal makes it impossible to supply the service.

3.2 Specific user requests. Data provided when the user requests information, registers for an event or creates an account is used to follow up on the request and manage the newsletter subscription. Legal basis: pre-contractual measures at the data subject's request (Art. 6.1.b GDPR) or the Company's legitimate interest in responding to requests (Art. 6.1.f GDPR).

3.3 Marketing, CRM and profiling. Data provided via the Company's forms or collected during interaction with the Websites may be entered into the CRM system to send newsletters and commercial communications and to personalise communications based on the user's profile, where specific consent has been given. Legal basis: free, specific and revocable consent (Art. 6.1.a and Art. 7 GDPR). Entry into the CRM is optional; refusal does not prevent use of the services but means personalised marketing cannot be received. Consent may be withdrawn at any time with effect for the future (see point 8).

4. Disclosure of personal data

The Company shares data with its affiliates and with third parties providing services on its behalf (hosting, technical and IT services, web analytics, marketing support), appointed as data processors under Art. 28 GDPR, who receive only the data needed and may not use it for their own purposes. Data may also be disclosed to third parties: (i) where required by EU or national law; (ii) in legal proceedings; (iii) in response to legitimate requests from authorities; (iv) to protect the rights, safety or property of the Company, its users or the public; (v) in the context of extraordinary corporate transactions. An up-to-date list of processors can be requested at the contacts in point 12.

5. Protection of minors' privacy

The Website is aimed at a professional audience and its services are intended for people aged 18 or over. The Company does not deliberately collect data of minors under 18 and, should it become aware of having collected it unintentionally, will delete it.

6. Storage, accessibility and transfer of data

Processing is carried out mainly by electronic means, through selected providers operating within the European Union and, in some cases, outside it. CRM data is managed in Italy by trained internal staff bound by confidentiality, accessible on a “need to know” basis. Where data is transferred outside the European Economic Area, the Company adopts the safeguards under Chapter V GDPR (in particular the Standard Contractual Clauses, or adequacy decisions) to ensure a level of protection equivalent to the EU's.

7. Security and confidentiality of data

The Company has adopted appropriate technical and organisational measures to protect data from accidental loss and unauthorised access, use, alteration and disclosure, including secure transmission protocols (HTTPS/TLS), credential controls and perimeter security (firewalls). Users are nonetheless advised to keep their software updated, keep their credentials confidential and change their password periodically. In the unlikely event of a breach, the Company will inform data subjects as required by law.

8. Data subject rights and managing choices

8.1 Your rights. At any time and free of charge you may: access your data; obtain its rectification, updating or erasure; obtain restriction of processing; receive your data in a structured format and transmit it to another controller (portability); object to processing in the cases provided for; not be subject to solely automated decisions, including profiling. You have the right to lodge a complaint with the data protection authority. To exercise these rights: privacy@madetosell.it or a letter to the address in point 12.

8.2 Accuracy and updating of data. You are invited to check and update your data regularly; if registered, you can do so from your account settings or by contacting the Company (point 12).

8.3 Direct marketing and profiling. To withdraw consent to the use of data for marketing, CRM and/or profiling, you may write to the contacts in point 12 or manage your account preferences, without affecting the lawfulness of processing carried out before withdrawal.

9. Data retention

Data is kept for the duration of the commercial relationship and for as long as necessary for the purposes described. It is then kept only to meet legal obligations (e.g. 10 years for accounting and tax purposes) or for the establishment, exercise or defence of a legal claim. CRM data (point 3.3) is kept until the account is closed or consent is withdrawn; profiling and marketing data for a limited, proportionate period, after which it is deleted or anonymised.

10. Cookies and similar technologies

The Website uses cookies and similar technologies to work correctly and, subject to consent, for statistical purposes. For details on the types of cookies, their purposes and how to manage preferences, please refer to the Cookie Policy (madetosell.eu/cookiepolicy), which is an integral part of this Policy.

11. Links, partner sites and advertisers

The SellingExperience.com platform and its third-level domains are owned and directly controlled by Made to Sell S.r.l. and are among the “Websites” subject to this Policy. The Website may contain links to other Company sites or, occasionally, to third-party partner sites: data provided on such sites is subject to their own policies, not this one.

12. Data controller and contacts

The data controller is Made to Sell S.r.l., with registered office at Via di Pratignone 11, 50019 Sesto Fiorentino (Florence – Italy). For questions, requests or to exercise the rights in point 8: privacy@madetosell.it.

13. Updates to this policy

The Company may amend, supplement or update this Policy at any time, publishing the revised version on this page and updating the “Last updated” date. In case of material changes it may provide additional notices; any new purposes will be subject, where required, to explicit consent.

Document updated July 2026 (previous version: February 2021).