Cloud Services Transparency

Last updated: 06/05/2024

Net Service S.p.A., in full transparency towards its Customers regarding its Cloud services, with reference to the protection of processed personal data, the related protection techniques adopted, and the security measures implemented in cloud environments, hereby declares the following:


All user accounts relating to our cloud services may be requested through our Service Desk, whose contact details are specified in the individual contracts signed with the Customer.


Encryption is used exclusively in communication protocols through TLS 1.2. Backups are carried out using backup techniques that make them immutable and encrypted by default with AES-XTS 128-based encryption. Net Service is also available to provide full support to enable the Customer to implement its own encryption techniques, where compatibility is allowed and security is ensured with the pre-existing service technology.


The procedures for managing security incidents in the provision of SaaS and cloud services allocate responsibilities as follows: the cloud service user opens a ticket with our Service Desk (see above), which takes charge of the incident, proceeds with its resolution, and notifies the Customer of the outcome.


Net Service is subject to independent third-party audits regarding the compliance of its cloud service delivery both with the applicable mandatory regulations and with the requirements of the ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 standards, for which it is certified. These certifications are published on its corporate website.


The data centers used for cloud services are located in Siziano (PV) and are certified according to ISO/IEC 27017 and ISO/IEC 27018 standards, whose validity is periodically verified.


All personal data relating to cloud services will remain available for an additional period of 30 days from the end date of the service or contract. After this period, such data will be deleted from the primary servers and from all backup copies, including any copies created for business continuity purposes.


With reference to the services provided, Net Service is responsible for the security of the infrastructure, both physical and logical, while the Customer is responsible for the proper use of the credentials assigned for accessing the services and for reporting any security events that may have an impact on the service.


Customer data managed within cloud services are subject to daily continuous incremental backup policies with a 15-day retention period, unless otherwise specified in the individual contracts. Every six months, restore tests are carried out on the data in environments with the same protection levels as the production environments, in order to verify the correctness of the backup process. At the end of the data extraction process, the extracted data are deleted.


In the event of technical vulnerabilities affecting cloud-delivered services, Net Service undertakes to patch systems and applications promptly. Such events are notified to the Customer by email communication with at least five days’ notice prior to the activity, except in cases of greater urgency.


The security measures adopted by Net Service in the provision of SaaS services include:

 

  • use of market-leading Cloud Service Providers, at least TIER 4, holding ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 certifications;
     
  • supervision of the services by the IT Manager;
     
  • logical protection of cloud environments through system isolation;
     
  • secure deletion of virtual environments and no reuse of resources allocated to individual instances.

When using other cloud service providers, Net Service undertakes to incorporate into the service agreements any additional requirements requested by the Customer under the service contract, where such requirements are more stringent than those currently in place.