Privacy policy
Last updated: June 2026
Introduction
We process personal data solely within the framework of the GDPR and Italian data protection law (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018). Below we set out the nature, scope and purpose of that processing.
1. Controller
2. Visiting the website (hosting & server logs)
The website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). When you visit it, the infrastructure processes technically necessary data (including IP address, time, requested resource and browser/device details) in order to deliver the site and keep it secure.
The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Processing takes place in the USA on the basis of the EU standard contractual clauses.
3. Contact form
If you use the contact form, we process the data you provide (name, email address, message) together with the time of your enquiry and – from the request headers – the country/region it came from (your IP address is not stored), in order to deal with your enquiry.
The legal basis is the initiation or performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). By submitting the form you confirm that you have read this privacy policy; for that purpose we store the version of the privacy notice and the time of your consent.
Enquiry data is stored in a database run by our service provider Neon Inc.; notifications about new enquiries are sent by email via Resend (Resend Inc., USA). The data is deleted as soon as it is no longer needed to deal with the enquiry and no statutory retention obligations apply.
4. Protection against spam and abuse
To protect our forms and sign-in areas against bots and abuse we use the Arcjet service (US). Request metadata is processed for this (including IP address, request frequency and, on forms, the email address given, to check that it is valid). The legal basis is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
5. Error and performance analysis (Sentry)
We use Sentry (Functional Software, Inc., USA) to detect technical errors. Personal content (e.g. name, email, message body) is filtered out before transmission; what is processed is essentially technical error data. The legal basis is our legitimate interest in error-free operation (Art. 6(1)(f) GDPR).
6. Cookies and consent management
We use technically necessary cookies and – only with your consent – cookies for two further purposes: analytics/audience measurement and marketing/advertising. You can allow or refuse the two categories independently of each other. We store your consent decision in a first-party cookie (rp_consent, valid for about 180 days).
We use Google Consent Mode v2: all non-essential categories are set to “denied” by default. The marketing signals ad_storage, ad_user_data and ad_personalization are set to “granted” only where you consent to the Marketing category; the analytics signal analytics_storage only where analytics consent has been given. For as long as there is no such consent, the services concerned are not loaded.
Only where marketing consent has been given do we set an attribution cookie (rp_attribution, valid for about 90 days), stored first-party, holding the origin details of your first visit (UTM parameters, Google/Meta click IDs gclid/fbclid, referrer, entry page). The click IDs (gclid/fbclid) are therefore assigned to the Marketing category. This data is used internally to attribute enquiries and is not passed on to third parties.
You can change or withdraw your consent at any time with effect for the future: .
7. Analytics services (only with consent)
Where consent has been given, we process usage data with the following services. In each case the legal basis is your consent (Art. 6(1)(a) GDPR; § 25(1) TTDSG or the corresponding Italian provision), which you can withdraw at any time.
- Vercel Web Analytics & Speed Insights (Vercel Inc., USA) – data-minimising audience and performance measurement.
- Google Analytics 4 (Google Ireland Ltd.) – where enabled.
- Microsoft Clarity (Microsoft Ireland) – where enabled.
- Ahrefs Web Analytics (Ahrefs Pte. Ltd., Singapore) – cookieless audience measurement, where enabled.
These services may involve a transfer to third countries (in particular the USA, and Singapore in the case of Ahrefs) on the basis of the EU standard contractual clauses or the EU-US Data Privacy Framework.
8. Marketing & advertising (only with consent)
Where marketing consent has been given, we use – if enabled – advertising and remarketing services to measure how effective our campaigns are and to show you relevant advertising. In each case the legal basis is your consent (Art. 6(1)(a) GDPR; § 25(1) TTDSG or the corresponding Italian provision), which you can withdraw at any time with effect for the future.
- Google Ads (Google Ireland Ltd.) – conversion tracking and remarketing, including evaluation of click IDs (gclid), where enabled.
- Meta Pixel (Meta Platforms Ireland Ltd.) – conversion measurement and remarketing, including evaluation of click IDs (fbclid), where enabled.
Only once you consent are the advertising signals of Google Consent Mode v2 (ad_storage, ad_user_data, ad_personalization) set to “granted” and the services named above loaded. These services may involve a transfer to the USA (on the basis of the EU standard contractual clauses or the EU-US Data Privacy Framework).
9. Recipients / processors
We use carefully selected service providers as processors: Vercel (hosting, analytics), Neon (database), Resend (email delivery), Arcjet (abuse protection), Sentry (error analysis), Upstash (caching). Data processing agreements under Art. 28 GDPR are in place with each of them.
10. Transfers to third countries
Where data is transferred to third countries (in particular the USA), we rely on the EU standard contractual clauses and – where applicable – on the EU-US Data Privacy Framework.
11. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and data portability (Art. 20), as well as the right to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent you have given at any time with effect for the future.
To exercise your rights, a message to the contact details given in section 1 is enough.
12. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority is in particular the Italian data protection authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy (www.garanteprivacy.it). You can also contact the supervisory authority where you habitually reside.
Know where you stand today.
The analysis shows how visible your business is in search and AI answers – and which three levers work first.
Get my free analysis