1. Data controller
The controller is Abbasi Salman, an Italian individual business (ditta individuale) providing IT consultancy services.
- VAT number (P. IVA): 14280420960
- Business address: Via Edoardo Bassini 49, Milano (MI), Italy
- Email: [email protected]
No Data Protection Officer has been appointed because one is not currently required for this small-scale processing. Privacy requests can be sent directly to the email above.
2. Personal data processed
Depending on how you use the website, the following data may be processed:
- Contact data: name, email address, enquiry category, message and submission time.
- Security data: IP address used transiently for abuse prevention and reCAPTCHA verification, an hourly one-way IP hash for rate limiting, browser user-agent, reCAPTCHA action and risk score.
- Technical and aggregate analytics: page, referrer, device, browser and approximate country data supplied through privacy-focused Vercel Web Analytics. Analytics are not linked to contact-form records.
- Theme preference: the light/dark preference is stored locally in your browser and is not submitted with the contact form.
Please do not include special-category data, identity documents, passwords, banking information or confidential third-party information in the message field.
3. Purposes and legal bases
- Responding to job, contract, freelance and general enquiries: steps requested before a possible contract, Article 6(1)(b) GDPR, and legitimate interests in professional communication, Article 6(1)(f).
- Protecting the form, infrastructure and users from spam, fraud and abuse: legitimate interests in service security, Article 6(1)(f).
- Meeting legal obligations and handling or defending legal claims: Article 6(1)(c) and, where applicable, Article 6(1)(f).
- Understanding aggregate site performance and improving the portfolio: legitimate interests in operating and improving the website, Article 6(1)(f).
Providing contact-form data is voluntary, but the required fields and security verification are necessary to receive and respond to an enquiry.
4. Recipients and service providers
Data is accessed only when necessary by the controller and service providers acting under their applicable terms and data-processing arrangements:
- Google Cloud / Firebase: secure database storage and reCAPTCHA Enterprise risk assessment.
- Resend: delivery of the contact notification email.
- Vercel: website hosting, server logs and aggregated Web Analytics.
- Professional advisers or public authorities where disclosure is required by law or necessary for a legal claim.
Personal data is not sold and is not used for direct marketing or behavioural advertising.
5. International transfers
Some providers may process data outside the European Economic Area, including in the United States. Where Chapter V GDPR applies, transfers are handled using an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful safeguard stated in the provider's data-processing terms. You may request further information about the relevant safeguards from the controller.
6. Retention periods
- Contact submissions and associated notification copies: no longer than 12 months from submission, then deleted, unless they become necessary for a contract, a legal obligation or the establishment, exercise or defence of legal claims.
- Rate-limit records: expire approximately two hours after creation and contain a one-way hash rather than the plain IP address.
- Provider security logs and anonymous analytics: retained according to the provider's configured retention period and only for as long as needed for security, service operation and aggregate reporting.
- Contractual, invoicing or accounting records: if an enquiry leads to work, relevant records are moved out of the contact-enquiry workflow and retained for the period required by Italian law.
Firestore contact records are assigned an expiry timestamp one calendar year after submission. Once the configured TTL policy reaches that timestamp, deletion is normally completed shortly afterwards.
7. Cookies and similar technologies
Vercel Web Analytics is configured as cookie-free aggregated analytics. Google reCAPTCHA is loaded only when you engage with the contact form and may set the necessary _GRECAPTCHA cookie to perform risk analysis. Google's Privacy Policy and Terms apply to that service.
8. Your GDPR rights
Subject to the conditions and exceptions in applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Requests should be sent to [email protected]. Identity verification may be requested where reasonably necessary.
You also have the right to lodge a complaint with the Garante per la protezione dei dati personali or another competent EU supervisory authority. The controller will normally respond to a rights request within one month.
9. Automated security assessment
reCAPTCHA produces an automated risk score used to distinguish likely human submissions from abuse. A low score may prevent the form from being delivered. This security assessment does not produce legal or similarly significant effects. If a legitimate enquiry is blocked, you can contact the controller directly by email.
10. Security and policy updates
Reasonable technical and organisational safeguards are used, including encrypted transport, server-side validation, access-controlled database credentials, rate limiting, security headers and restricted service accounts. No online system can guarantee absolute security.
This notice may be updated when the website, providers or legal requirements change. The effective date at the top identifies the current version.