Privacy Policy – AEC UPS Cloud

Last updated: 25 September 2026

This Privacy Policy explains how AEC International S.r.l. processes the personal data of users of the AEC UPS Cloud platform (web application and related services, the "Service"), and of the people who receive its alarm notifications, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and Italian Legislative Decree 196/2003 as amended ("Privacy Code").

1. Data Controller

AEC International S.r.l.
Via Nerviano 55, 20045 Lainate (MI), Italy
VAT No.: IT12520320156
Email: privacy@aecups.com
Website: www.aecups.com

2. Our role

AEC International S.r.l. is the controller of the data of the Service's user accounts and of the security and access logs.

For the personal data that a customer enters in the Service about other people — the people it designates to receive alarm notifications, the contacts of its sites, and any personal data contained in the messages sent by its UPS equipment — AEC International S.r.l. acts on behalf of the customer, as processor under Art. 28 GDPR, according to the data processing agreement that is part of the service contract. For these data the customer is the controller.

3. Personal data we process

  • Account data: first and last name, email address (which is also your sign-in name), company name, the company's contact phone number, password (stored only in hashed form) and your language preference.
  • Alert recipients: name and email address of the people a customer designates to receive alarm notifications, whether they confirmed the address, and the record of the messages sent to them.
  • Device and installation data: UPS serial numbers, model, installation site and address, alarms, events, daily reports and status data transmitted by connected devices. These data refer primarily to equipment; they are personal data only insofar as they can be linked to an identified or identifiable person (e.g. the contact person responsible for a site).
  • Messages from the UPS network cards: the emails and SNMP traps sent by the network cards are stored as received. Besides technical data they contain the UPS name set on the card, the card's address in the customer's network and, if the installer filled them in, the installation position and an administrator phone number. Our configuration sheet asks installers to leave those two fields empty and not to include the customer's name in the UPS name.
  • Technical and usage data: IP address, browser and device type, operating system, access logs, date and time of access, actions performed within the Service.
  • Communications: the notifications we send (subject and text, kept as a record of what was delivered) and the content of support requests exchanged with us.

We do not intentionally collect special categories of data (Art. 9 GDPR). Please do not enter such data in the Service.

4. Purposes and legal bases of processing

PurposeLegal basis
Creating and managing user accounts, providing the Service (remote monitoring, alarms, notifications, reports) Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Sending alarm notifications to the recipients designated by the customer Performance of the contract with the customer (Art. 6(1)(b) GDPR), on the customer's instructions
Technical support, maintenance and warranty services on UPS equipment Performance of a contract (Art. 6(1)(b) GDPR)
Security of the platform, prevention of fraud and abuse, access logging Legitimate interest of the Controller (Art. 6(1)(f) GDPR)
Improvement of the Service and of our products, using aggregated or pseudonymised data Legitimate interest of the Controller (Art. 6(1)(f) GDPR)
Compliance with legal, tax and accounting obligations; responding to requests from authorities Legal obligation (Art. 6(1)(c) GDPR)
Establishment, exercise or defence of legal claims, including keeping a record of the notifications sent Legitimate interest of the Controller (Art. 6(1)(f) GDPR)

Providing account data is necessary to use the Service; without it we cannot create your account.

5. Processing methods and security

Data are processed with electronic tools, by authorised personnel bound by confidentiality, applying appropriate technical and organisational measures (Art. 32 GDPR), including encrypted connections (HTTPS/TLS), password hashing, role-based access control, logging and regular encrypted backups. No decision producing legal effects is based solely on automated processing, including profiling (Art. 22 GDPR).

6. Recipients of personal data

Personal data may be disclosed to:

  • service providers acting as data processors under Art. 28 GDPR: the provider that delivers our email notifications and the provider that stores our backups (encrypted before they leave our servers), both located in the European Union, and IT maintenance providers where they need access to the systems to perform their services;
  • authorised service partners and technicians engaged for installation, maintenance and support of the equipment;
  • professional advisors, public authorities and judicial authorities, where required by law.

Within the Service, the administrators of a customer see the users and alert recipients of their own company. Personal data are not sold and are not disseminated.

7. Data location and transfers

The Service runs on servers owned and managed directly by AEC International S.r.l., located in Italy. Email notifications are delivered through a provider located in the European Union, and encrypted backups are stored with a provider located in the European Union. Personal data are not transferred to countries outside the European Economic Area.

8. Retention period

  • Account data: for the duration of the contract. When the contract ends the account is suspended for 30 days and then scheduled for deletion; account data are deleted within 60 days of the end of the contract;
  • Alarms: for the duration of the contract;
  • Events and daily reports: 36 months;
  • Messages from the UPS network cards (emails and SNMP traps) and measurements: 13 months;
  • Messages from network cards that cannot be attributed to any UPS: up to 90 days;
  • Notifications sent (recipient, subject and text): 13 months;
  • Audit log of the actions performed in the Service: 36 months; technical system logs: 30 days;
  • Invitations that were not accepted: 90 days after they expire;
  • Support requests and communications: 3 months from the closure of the request;
  • Contractual, accounting and tax records: 10 years, as required by Italian law (Art. 2220 Italian Civil Code).

Deleted data remain in encrypted backups until the backups are rotated, for at most 12 months, and are not restored into the Service. Retention may be extended where necessary to establish, exercise or defend legal claims.

9. Cookies and similar technologies

The Service uses only technical cookies strictly necessary for its operation: the session cookie that keeps you signed in and the cookie that protects forms against cross-site request forgery. Your language choice is saved in your account, not in a cookie. The Service uses no analytics or advertising cookies and no local storage. Technical cookies do not require consent under Art. 122 of the Privacy Code.

10. Your rights

Under Articles 15–22 GDPR you have the right to:

  • access your personal data and obtain a copy;
  • request rectification of inaccurate or incomplete data;
  • request erasure of your data ("right to be forgotten");
  • request restriction of processing;
  • receive your data in a structured, commonly used, machine-readable format (data portability);
  • object at any time to processing based on legitimate interest;
  • where a processing is based on your consent, withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

Alert recipients can stop receiving notifications at any time with the link at the bottom of every message.

To exercise your rights, write to privacy@aecups.com. We will reply without undue delay and in any case within one month of receipt, extendable by two further months where necessary (Art. 12 GDPR). For data we process on behalf of a customer (section 2), we forward your request to the customer and assist it in answering.

11. Right to lodge a complaint

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the EU Member State where you habitually reside or work.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be published in the Service with the date of the last update. Where changes are material, we will notify users by email or through a notice in the Service.