Privacy Policy

Deklara Services — Management and submission of electricity excise declarations

Pursuant to Arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR). Last updated:

Download PDF

1. Data Controller

Limeon S.r.l. (hereinafter "Controller") provides the following information on the methods and purposes of processing your Personal Data in the context of providing the management and electronic submission services for electricity excise declarations via the Deklara portal.

Limeon S.r.l.
Via Mercato Vecchio 19, 39042 Bressanone (BZ), Italy
VAT: IT03161350214

2. Data Protection Officer (DPO)

The Controller has appointed a Data Protection Officer pursuant to Art. 37 GDPR, reachable at: dpo@limeon-energy.it.


3. Categories of Personal Data Processed

Limeon S.r.l. will process the Personal Data you provide or that are lawfully collected for the purpose of entering into and managing the contract for Deklara services. In particular, the following categories are processed:

  • Identification and personal data: name, surname, place and date of birth, tax code, VAT number, address.
  • Contact data: phone and mobile numbers, e-mail address, certified e-mail address (PEC).
  • Plant and excise declaration data: plant registration data (electrical plant) — type, location, ADM licence/authorisation number; semi-annual electricity consumption data (H1 and H2) for the preparation of declarations pursuant to Arts. 52-54 TUA (D.Lgs. 504/1995); outcome of electronic submissions to the ADM and related receipts.
  • Option Zero — ADM Delegation: data of the ADM Delegation granted by the Customer to Limeon S.r.l.
  • Option Solo — p12 Certificate: data relating to the management of the digital signature certificate (exclusively identifying metadata; Limeon does not store private keys).
  • Payment data: managed by Stripe Payments Europe, Ltd. as an independent controller. Limeon does not store credit card numbers or IBAN details.
  • Technical usage data: portal access logs, IP addresses, session data and other technical data necessary for security and proper operation.

4. Purposes of Processing

  • Management of purchase orders and related administrative activities, complaint handling, pre-litigation and litigation procedures.
  • Provision of Deklara services: portal management, preparation and electronic S2S submission of excise declarations to the ADM on behalf of the Customer, archiving of submitted declarations.
  • Mandate management (Option Zero only): Limeon acts as agent pursuant to Art. 1703 of the Italian Civil Code based on consumption data provided by the Customer and the ADM Delegation granted.
  • Payment processing via Stripe: transmission of data necessary to process subscription fees and renewals.
  • Compliance with applicable legal obligations, including provisions of the TUA, CAD (D.Lgs. 82/2005) and tax regulations.
  • Provision of technical and commercial support services (customer care).
  • Improvement of the quality of services offered.
  • Subject to consent: profiling based on usage preferences and/or purchasing choices, in order to propose personalised offers.
  • Subject to consent: sending promotional and commercial communications by e-mail, SMS or phone.

5. Lawful Basis for Processing

  • Contract performance(Art. 6(1)(b) GDPR): conclusion and management of the Deklara services contract; pre-contractual measures at the data subject's request.
  • Consent (Art. 6(1)(a) GDPR): profiling and commercial communications; non-essential analytical cookies.
  • Legal obligation (Art. 6(1)(c) GDPR): compliance with obligations under the TUA, CAD, tax regulations and EU legislation.
  • Legitimate interest (Art. 6(1)(f) GDPR): sending informational communications, system maintenance and security.
  • Protection of vital interests (Art. 9(2)(c) GDPR).

6. Data Processing and Recipients

Personal Data are processed both manually and using IT systems, in compliance with the principles of lawfulness, fairness and transparency. Data may be disclosed to:

  • Limeon employees and collaborators designated as Authorised Persons for processing.
  • Public administrations and supervisory authorities, including: Customs and Monopolies Agency (ADM), Revenue Agency (Agenzia delle Entrate), Tax Registry, Energy, Networks and Environment Regulatory Authority (ARERA).
  • Stripe Payments Europe, Ltd., as independent controller of payment data (see stripe.com/privacy).
  • Cloud, storage, technology infrastructure and electronic communications service providers, acting as data processors pursuant to Art. 28 GDPR.
  • Legal, tax and commercial advisors and firms.

The data subject may be contacted by phone or e-mail by a market research company conducting a service quality survey on behalf of ARERA. The necessary data will be processed in accordance with the GDPR.

In the context of the Option Zero service, where the Customer uploads consumption data relating to their own customers or employees, Limeon S.r.l. acts as a data processor (Art. 28 GDPR) on behalf of the Customer, who remains the data controller. The relevant Data Processing Agreement (DPA) accessible on the portal applies.


7. Data Processors (Art. 28 GDPR)

A data processing agreement (DPA) compliant with Art. 28 GDPR is concluded with each service provider processing data on behalf of Limeon. The updated list of data processors is available upon request by writing to support@deklara.it.


8. Transfer of Personal Data

Personal Data are processed exclusively within the European Union and stored on servers located in the European Union. Any transfers to third countries take place on the basis of Standard Contractual Clauses (SCC) approved by the European Commission.


9. Retention Period

Personal Data are retained for the period necessary to achieve the purposes for which they are processed. In particular:

  • Excise declarations and consumption data: for the period required by applicable tax and customs regulations (D.Lgs. 26/1995, Art. 61; Italian Civil Code Art. 2220 — minimum 10 years) and, upon termination, for the applicable statute of limitations. Early deletion is not permitted.
  • Account data: duration of the contract plus the applicable statute of limitations from closure.
  • Digital signature certificate (.p12) — Option Solo: deleted immediately after signing or upon session closure. Private keys are never stored.
  • Payment data: only the Stripe customer reference and subscription status; card data managed by Stripe (PCI DSS).

10. Data Subject Rights (Arts. 15-22 GDPR)

  • Access (Art. 15): copy of personal data being processed.
  • Rectification (Art. 16): correction of inaccurate data or completion of incomplete data.
  • Erasure (Art. 17): where applicable; not exercisable for data subject to the ten-year tax retention obligation.
  • Restriction (Art. 18): restriction of processing where the legal requirements are met.
  • Portability (Art. 20): receipt of personal data in a structured, commonly used and machine-readable format.
  • Objection (Art. 21): to processing based on legitimate interest or for marketing purposes.
  • Not to be subject to automated decision-making (Art. 22), including profiling.
  • Withdrawal of consent: at any time, without retroactive effect on prior processing.

To exercise your rights: follow the instructions available at www.limeon-energy.it in the privacy section, or write to dpo@limeon-energy.it. Response within 30 days. You have the right to lodge a complaint with the Italian Data Protection Authority (Garante).


11. Data Security

Measures adopted: AES-256 encryption for digital signature certificates, TLS/HTTPS for all transmissions, RBAC access control, mandatory 2FA for the Pro plan, principle of least privilege for internal operators.


12. Cookies and Tracking Technologies

The portal uses strictly necessary technical cookies for operation and, with consent, analytical cookies. The full list of active cookies and instructions for managing them are available in the Cookie Policy.


13. Contact

Limeon S.r.l. — Deklara
Via Mercato Vecchio 19, 39042 Bressanone (BZ), Italy
VAT IT03161350214
DPO: dpo@limeon-energy.it
Support: support@deklara.it