Privacy
Privacy policy
Last updated:
This policy explains which personal data we collect when you visit this website or write to us, why we use it, how long we keep it and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 (“Privacy Code”), as amended by Legislative Decree 101/2018.
In short: we use no cookies, analytics, advertising or profiling, and we never sell or hand over your data to anyone. We only process the technical data needed to show you the website and whatever you send us by email.
1. Data controller
- TOVAN — Antonio Filippelli and Thomas Orrico
- Email: info@tovandev.com
For any question about this policy or to exercise your rights, write to info@tovandev.com. We have not appointed a data protection officer (DPO), as none of the cases in which Article 37 GDPR makes it mandatory apply.
2. Which data we process, why and on what legal basis
2.1 Browsing data
Like any website, the servers hosting it automatically log some technical data on every visit: IP address, date and time of the request, requested page, response code, browser and operating system (user agent), referring site.
- Purpose: showing you the website, keeping it running and secure, preventing abuse and cyber attacks, investigating possible offences.
- Legal basis: our legitimate interest in the security and proper functioning of the website (Article 6(1)(f) GDPR).
- Retention: for the period set by the hosting provider and in any case no longer than 30 days, unless needed longer to investigate an offence at the request of the authorities.
We do not use this data to identify you, for statistics or for profiling.
2.2 Data you send us by email
The website has no forms: you contact us from your own email client, including when you send the message prepared by the “Your project” configurator. We then process your email address, name and any other data you choose to include (for example company, phone number, project description).
- Purpose: replying to you, preparing a quote, handling negotiations and any resulting engagement.
- Legal basis: steps taken at your request prior to entering into a contract and, if an engagement follows, performance of the contract (Article 6(1)(b) GDPR); compliance with legal obligations, such as tax rules (Article 6(1)(c)).
- Retention: up to 24 months from the last contact if no engagement follows; if one does, for its duration and then for 10 years, as required by Italian civil and tax law (Article 2220 of the Civil Code).
Please do not send us special categories of data (for example health data) or data about other people without informing them: we do not need it to answer your request.
2.3 Configurator and terminal
The “Your project” configurator and the interactive terminal run entirely in your browser: what you choose or type is not sent to us or to anyone else. The configurator’s message only reaches us if you decide to send it from your email client (see 2.2). The “Copy” button uses your device’s clipboard and transmits nothing.
2.4 Browser storage
The website stores a single technical value in the browser’s session storage, so that the loading animation is not shown again on every page. It is not a cookie, contains no personal data and is deleted when you close the tab. Details are in the cookie policy.
3. Whether you must provide data
Browsing data is necessary to show you the website. Writing to us is optional, but without your contact details we cannot reply.
4. How we process data
We process data electronically, with technical and organisational measures appropriate to protect it against unauthorised access, loss or disclosure: the website is served over HTTPS only, with security headers (including a strict Content Security Policy) and no third-party resources. Fonts are hosted on our own server: your visit does not contact Google Fonts or any other external service.
We do not make decisions based solely on automated processing, including profiling (Article 22 GDPR).
5. Who we share data with
Data is processed by the controller and by authorised, trained staff. We also rely on providers that process it on our behalf as processors (Article 28 GDPR), bound by a contract:
- Cloudflare, Inc. (United States), which hosts the website and logs browsing data;
- the provider of our email mailbox, which receives and stores messages;
- if an engagement follows, our accountant or tax advisor, for legal obligations.
We may disclose data to public authorities when required by law. We do not publish, sell or use it for marketing.
6. Transfers outside the European Union
Cloudflare, Inc. is based in the United States, so browsing data may be processed outside the European Economic Area. Cloudflare participates in the EU-U.S. Data Privacy Framework: the transfer is therefore based on the European Commission’s adequacy decision of 10 July 2023 (Article 45 GDPR) and, in addition, on the Commission’s standard contractual clauses (Article 46 GDPR). You can ask us for a copy of these safeguards at the address in section 1.
7. Your rights
At any time, free of charge, you can ask us to:
- confirm whether we process your data and give you a copy (access, Article 15);
- correct or complete it (rectification, Article 16);
- delete it (Article 17), unless the law requires us to keep it;
- restrict its processing (Article 18);
- give it to you in a structured, machine-readable format (portability, Article 20);
- stop processing based on legitimate interest, on grounds relating to your particular situation (objection, Article 21).
Write to info@tovandev.com: we will reply within one month (Article 12). We may ask for information to verify your identity.
If you believe the processing infringes the GDPR, you can lodge a complaint with the Italian Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it) or with the supervisory authority of the EU country where you live or work, or go to court (Articles 77 and 79 GDPR).
8. Links to other websites
The website contains a few links to external websites, such as the Italian Data Protection Authority’s. They are not embedded: until you open them, those websites receive no data. Once you open them, processing is governed by their own privacy policies.
9. Children
The website is aimed at businesses and professionals. We do not knowingly collect data from children under 14 (Article 2-quinquies of the Privacy Code).
10. Changes to this policy
We may update this policy, for example if we add new services to the website. The date of the last update is shown at the top of the page. If changes concern processing that requires your consent, we will ask for it before starting.
This is a translation: in case of discrepancy, the Italian version prevails.