Privacy notice
Information on the processing of personal data on digicompany.org. Updated: 21 September 2026.
Data controller
Emanuele Di Giamberardino, Via Padova 33, 00161 Rome, Italy. For information and to exercise your rights: gestore.dg@gmail.com.
Contact form
We collect your name, email, requested service and message to respond to enquiries. You may also provide your company, phone number, town or city, expected dates and collection and delivery locations. Required fields are necessary to submit the enquiry; the others are optional. Avoid including irrelevant data or particularly sensitive information.
Enquiries remain with the controller and are not forwarded to other businesses for commercial handling. The form does not subscribe you to a newsletter.
Client area
We process your email, account identifier and information needed for authentication and password recovery, as well as documents and contracts uploaded by the administrator, file names, categories, dates and their assignment to a client. These data enable personal access and document viewing. The assigned client and administrator can view and download documents; only the administrator can upload them.
Technical providers and security
The website uses Sites for hosting, Supabase for authentication, document storage and technical handling of enquiries, and Google Gmail for email delivery and management. This technical processing is distinct from commercial forwarding of enquiries, which does not take place.
These services may process technical connection and security data. The spam protection system uses a fingerprint of the email address and the date of the submission attempt. The message is sent to the controller’s mailbox and is not stored in the spam protection table.
Retention
- Enquiries that do not proceed: 12 months after the enquiry is closed.
- Accounts: active for as long as needed to use the client area.
- Documents: removed from the portal within 12 months after the relationship ends, except for copies that may need to be retained separately for specific obligations, with restricted access.
The controller manages retention deadlines; there is no general automatic deletion process. Spam protection records older than two days are deleted when a subsequent sending reservation is executed: this is not scheduled deletion within 48 hours.
Rights and contact
Where and as provided by the GDPR, you may request access, rectification, erasure, restriction and portability of your data and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Write to gestore.dg@gmail.com. The usual response period is one month, subject to extensions permitted by the GDPR; information needed to verify the requester’s identity may be required. You may lodge a complaint with the Italian Data Protection Authority.
Virtual assistant
The chat provides predefined automatic answers about services published on this website. Questions and answers stay in the memory of the page: the chat does not send them to an artificial intelligence service or save them in cookies or browser local storage. The conversation is cleared when the page is reloaded or left, or when you select “New conversation”.
Only when you press “Send to our team” are the name, email, optional phone number, service and details entered in the form transmitted through the contact form system and delivered to the controller. The full chat history is not forwarded. You can edit the message before sending it. The recipients and retention periods described for contact form enquiries apply. Do not enter passwords or particularly confidential information.
Cookies and session technologies
Browser local storage (localStorage) is distinct from cookies. The client area uses it to maintain the access requested by the user through Supabase.
- Name:
sb-jqqpxfbdmyrxixfnfrxs-auth-token. - Purpose: to store and renew the authentication session for access to your documents; the website code does not use it for advertising or profiling.
- Duration: localStorage has no automatic expiry of its own. The session may be renewed; the library removes the data on sign-out, or you can remove it by clearing website data in your browser. The authentication service manages the validity of session credentials.
- Management: use “Sign out” in the client area, especially on shared devices. Clearing website data may require you to sign in again.
No advertising scripts, Google Analytics or profiling pixels were found in the code and live pages checked on 17 September 2026. Tools strictly necessary for the service requested do not require prior consent but must be described in the notice. See the Italian Data Protection Authority’s cookie guidance.
Checks of hosting responses on 17 September 2026 for the Home, Contact, Client Area, Privacy and Transport pages detected the technical cookie __cf_bm, provided by Cloudflare to distinguish automated traffic and protect the website. It is set on digicompany.org with Secure and HttpOnly attributes. According to Cloudflare, it expires after 30 minutes of continuous inactivity and is not an advertising cookie. Cookie data may also be processed in the United States under the provider’s terms. See the Cloudflare documentation and its privacy notice. These findings describe the pages and conditions observed: protections activated under different conditions require further checks. If non-essential tools requiring consent are introduced, they must be blocked until the user makes a choice.
Information still under review
This notice is being completed regarding the legal bases for each purpose, applicable agreements with technical providers, international transfers, retention of logs and backup copies, and any changes to technologies added by the hosting provider. We therefore do not claim that storage is exclusively within the European Economic Area or that the privacy review is complete. Contact the controller for clarification.
