Privacy Policy
This policy explains what Arcanode collects when you use this website, why we collect it, how long we keep it, and the rights you have over it. It is written to be read, not to be hidden in legalese.
1. Who is responsible for your data
The data controller is Arcanode, VAT number (P.IVA) IT02755170467, with registered office at Corte Panicale, 55041 Camaiore (LU), Italy. You can reach us at any time at [email protected] or by post at the registered office. This is policy version 1.0, published on 2 September 2026.
2. What we collect, and the legal basis
- Contact form (name, email address, optional phone number, message): used to answer your request and prepare a demo. Legal basis: consent (Art. 6(1)(a) GDPR) and pre-contractual measures (Art. 6(1)(b)).
- Consent evidence (timestamp, policy version, locale, user agent, salted hash of your IP): kept to prove consent was given, as EU law requires. Legal basis: legal obligation (Art. 6(1)(c)).
- Lead attribution (UTM parameters, referrer, page, locale, coarse device class): included in the internal email to our sales team so we know which channels work. Never sold or shared. Legal basis: legitimate interest in measuring our marketing (Art. 6(1)(f)).
- Security logs (IP address, request rate, spam-check outcome): used to stop abuse of the contact form. Legal basis: legitimate interest (Art. 6(1)(f)).
- Analytics (aggregated page views): we self-host a cookieless analytics tool (Umami) on our own server. It sets no cookies, stores no personal identifiers and cannot track you across sites; under Italian Garante guidance no consent banner is therefore required. Legal basis: legitimate interest (Art. 6(1)(f)); you may object at any time (section 6).
3. Cookies and local storage
This website sets no cookies of any kind. It stores one entry in your browser's local storage — the campaign parameters of the link that brought you here (for example ?utm_source=linkedin) — for at most 90 days, solely so a later demo request can be attributed to the right channel. You can remove it at any time by clearing site data in your browser.
4. How long we keep it
- Lead emails and their attribution: 24 months from the last contact.
- Consent evidence: 36 months, then deleted.
- Security logs: 30 days.
- Aggregated analytics: 12 months.
5. Who receives your data
Your message is delivered to our own mail server (mailcow), hosted in the European Union on infrastructure we operate. We use no third-party email-marketing service, no CRM, no advertising platform and no data broker. Your data is not transferred outside the European Economic Area and is never sold.
6. Your rights
You may ask us at any time for: access to your data (Art. 15 GDPR); rectification (Art. 16); erasure (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); and objection to processing based on legitimate interest, including the analytics described above (Art. 21). You may withdraw form consent at any time with effect for the future (Art. 7(3)), without affecting the lawfulness of processing before withdrawal. Write to [email protected]. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), under Art. 77 GDPR.
7. How we protect it
All connections use TLS. Internal mail delivery upgrades to TLS via STARTTLS and refuses plaintext. IP addresses in consent records are hashed with a salt rotated quarterly. The contact form is rate-limited and protected by an invisible spam challenge (Cloudflare Turnstile) that sets no advertising cookies.
8. Automated decision-making
We do not profile you, and no decision about you is made solely by automated means.
9. Changes to this policy
If we change how we process data we publish a new version here with a new version number and date. The consent you give on the contact form records the version you accepted.