Updated June 22, 2026
Privacy Policy
The ROAR Experience Intelligence Platform
This privacy policy aims to provide all the information regarding the processing of personal data carried out by Roar CX S.r.l when the User browses the website (as better specified below).
1. Introduction – who are we?
Roar CX S.r.l., with registered office at Piazza Cardinale Salvatore Pappalardo 23, 95131 Catania, Tax Code/VAT No. 06128100879 (hereinafter, the “Controller”), owner of the website www.roarcx.com (hereinafter, the “Website”), in its capacity as data controller of the personal data of users browsing the Website (hereinafter, the “Users”), hereby provides this privacy notice pursuant to Article 13 of Regulation (EU) 2016/679 of 27 April 2016 (hereinafter, the “Regulation” or the “Applicable Law”).
2. How to contact us?
The Controller places the utmost importance on the right to privacy and the protection of the personal data of its Users. For any information relating to this privacy notice, Users may contact the Controller at any time using the following methods:
- by sending a registered letter with return receipt to the Controller’s registered office at Piazza Cardinale Salvatore Pappalardo 23, 95131 Catania;
- by sending an e-mail to: info@roarinc.com.[DPO1]
Users may also contact the Controller’s Data Protection Officer (DPO), whose contact details are set out below: Shibumi S.r.l., at the following e-mail address: dpo@roarinc.com.[DPO2]
3. What do we do? – Processing purposes
By browsing the Website, the User may view the services and activities offered by the Controller, obtain information regarding the customer experience solutions provided, complete the CX Risk Assessment questionnaire in order to receive a customised model of the company’s risk, and contact the Controller through the tools made available for that purpose (hereinafter, the “Service”).
This Website and any services that may be offered through it are intended for individuals who are at least 18 years of age. The Controller does not therefore collect personal data relating to individuals under the age of 18. At the request of Users, the Controller will promptly delete any personal data inadvertently collected relating to individuals under the age of 18.
In relation to the activities that may be carried out through the Website, the Controller collects Users’ personal data. In particular, Users’ personal data will be lawfully processed by the Controller for the following purposes:
a) provision of the Service, namely for the purpose of:
- (i) enabling the User to browse the Website. For this purpose, the User’s data collected by the Controller include all personal data the transmission of which is implicit in the use of Internet communication protocols, which the IT systems and software procedures used to operate the Website acquire during their normal operation, including: the IP addresses or domain names of the computers used by the Users, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, and the numerical code indicating the status of the response given by the server (successful, error, etc.). These data are used solely for the purpose of obtaining anonymous statistical information on the use of the Website and to ensure its proper functioning;
- (ii) enabling the User to obtain a customised model of the company’s risk by completing the CX Risk Assessment questionnaire. For this purpose, the only personal data collected by the Controller is the User’s email address.
Without prejudice to what is provided elsewhere in this privacy notice, under no circumstances shall the Controller make the Users’ personal data accessible to other Users and/or third parties.
b) handling of the User’s requests, the User’s personal data are processed by the Controller for the purpose of handling their request(s) relating to the receipt of information and details regarding the Controller’s activities (for example, through the “Contact Us” form). The User’s data processed by the Controller for this purpose may include: identification data (such as first name and surname), contact details (such as telephone number and email address), as well as any further data of the User, where applicable, requested in the fields contained in the form made available on the Website and/or voluntarily provided by the User in the free-text fields of such form. The provision of personal data for this processing purpose is optional but necessary, since failure to provide such data will make it impossible for the User to submit their contact request to the Controller;
c) administrative and accounting purposes, namely for carrying out activities of an organisational, administrative, financial and accounting nature, such as internal organisational activities and activities functional to the performance of contractual and pre-contractual obligations;
d) compliance with legal obligations, namely to fulfil obligations laid down by applicable law, regulations, orders of competent authorities, or European legislation.
The provision of personal data for the processing purposes indicated above is optional but necessary, as failure to provide such data will make it impossible for the User to contact the Controller and/or to receive the customized model of the company’s risk following completion of the CX Risk Assessment questionnaire.
4. Additional processing purposes
4.1 Newsletter Subscription
The User’s e-mail address may be processed by the Controller for the purpose of sending a periodic newsletter containing information on developments in the business sector in which the Controller operates, as well as updates relating to the Website and/or the Services offered by the Controller through the Website.
Failure to provide consent shall in no way affect the possibility of (i) browsing the Website and/or (ii) making a request to the Controller.
Where consent has been given, the User may withdraw it at any time by submitting a request to the Controller in accordance with the methods set out in paragraph 8 below.
The User may also easily object to further communications by clicking on the appropriate consent withdrawal link included in each e-mail containing the newsletter. Once consent has been withdrawn, the Controller will send the User an e-mail confirming that the consent has been withdrawn[DPO1] .
5. Legal basis for processing
Provision of the Service (as described in paragraph 3(a) above): the legal basis for the processing is Article 6(1)(b) of the Regulation, namely that the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.
Handling of the User’s requests (as described in paragraph 3(b) above): the legal basis for the processing is Article 6(1)(b) of the Regulation, namely that the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.
Administrative and accounting purposes (as described in paragraph 3(c) above): the legal basis for the processing is Article 6(1)(b) of the Regulation, insofar as the processing is necessary for the performance of a contract and/or in order to take steps at the User’s request prior to entering into a contract.
Compliance with legal obligations (as described in paragraph 3(d) above): the legal basis for the processing is Article 6(1)(c) of the Regulation, insofar as the processing is necessary for compliance with a legal obligation to which the Controller is subject.
Newsletter Subscription (as described in paragraph 4.1 above): the legal basis for the processing is Article 6(1)(a) of the Regulation, namely the User’s consent to the processing of their personal data for one or more specific purposes. For this reason, the Controller requests the User’s specific, free and optional consent in order to pursue this processing purpose.
6. Processing methods and data retention period
The Controller will process Users’ personal data by means of manual and IT tools, using logic strictly related to the relevant purposes and, in any event, in such a way as to ensure the security and confidentiality of such data.
The personal data of the Website’s Users will be retained for the period strictly necessary to fulfil the primary purposes illustrated in paragraph 3 above, or in any event for as long as necessary to protect the interests of both the Users and the Controller in civil proceedings.
In the case referred to in paragraph 4.1 above, the User’s e-mail address will be retained for the period strictly necessary to fulfil the purpose described therein and, in any event, until the User withdraws their consent.
7. Transmission and dissemination of data
The User’s personal data may be transferred outside the European Union and, in such case, the Controller will ensure that the transfer takes place in compliance with the Applicable Law and, in particular, in accordance with Articles 45 (Transfers on the basis of an adequacy decision) and 46 (Transfers subject to appropriate safeguards) of the Regulation.
The Controller’s employees and/or collaborators entrusted with managing the Website and handling Users’ requests may become aware of Users’ personal data. Such persons, who have been instructed accordingly by the Controller pursuant to Article 29 of the Regulation, will process Users’ data exclusively for the purposes indicated in this privacy notice and in compliance with the provisions of the Applicable Law.
In addition, third parties that may process personal data on behalf of the Controller as Data Processors may become aware of Users’ personal data, including, by way of example, providers of IT and logistics services functional to the operation of the Website, outsourcing or cloud computing service providers, and professionals and consultants.
Users have the right to obtain a list of any data processors appointed by the Controller by submitting a request to the Controller in accordance with the methods indicated in paragraph 8 below.
8. Rights of the data subjects
Users may exercise their rights granted by the Applicable Law by contacting the Controller as follows:
- by sending a registered letter with return receipt to the Controller’s registered office at Piazza Cardinale Salvatore Pappalardo 23, 95131 Catania;
- by sending an e-mail to: info@roarinc.com.[DPO1]
Users may also contact the Controller’s Data Protection Officer (DPO), whose contact details are set out below: Shibumi S.r.l., at the following email address: dpo@roarinc.com.[DPO2]
Pursuant to the Applicable Law, Users have:
a) the right to withdraw consent at any time, if the processing is based on their consent;
b) the right of access to personal data;
c) (where applicable) the right to data portability (the right to receive all personal data concerning them in a structured, commonly used and machine-readable format), the right to restriction of processing of personal data, the right to rectification and the right to erasure (“right to be forgotten”);
d) the right to object:
i. in whole or in part, for legitimate reasons to the processing of personal data concerning them, even if relevant to the purpose of collection;
ii. in whole or in part, to the processing of personal data concerning them for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication;
e) if they consider that the processing of their personal data is in breach of the Regulation, the right to lodge a complaint with a supervisory authority (in the Member State in which they have their habitual residence, in the Member State in which they work or in the Member State in which the alleged breach has occurred). The Italian Supervisory Authority is the Garante per la protezione dei dati personali, located in Piazza Venezia n. 11, 00187 – Rome (http://www.garanteprivacy.it/).
The Controller is not responsible for updating all links viewed in this Privacy Policy, therefore, whenever a link does not work and/or is not updated, the Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to such link.