Privacy Policy
This website uses no tracking cookies and no third-party analytics. This notice explains how we process personal data in accordance with the GDPR (Regulation (EU) 2016/679) and applicable data-protection law.
Last updated: July 2026
1. Data controller
The controller of your personal data is [RAGIONE SOCIALE], with registered office at [SEDE LEGALE], VAT number [P.IVA], certified email (PEC) [PEC]. For any question about this notice or the processing of your data, you can write to us at info@privateai24.com.
2. What data we collect
We collect only the data you choose to give us. We do not build profiles and we do not track your behaviour across the web.
- Contact form: your name, email address and the content of your message.
- Newsletter: your email address (only if you subscribe).
- Essential technical data: minimal server logs (such as IP address and timestamp) that our infrastructure records to keep the service secure and prevent abuse. These logs are not used for analytics or profiling.
- Language preference: a value stored locally in your browser so the site remembers your language. This is not a tracking cookie (see the Cookie Policy).
We use no tracking cookies and no third-party analytics — no Google Analytics, no advertising pixels, no behavioural profiling.
3. Purposes and legal bases (Art. 6 GDPR)
- Reply to your requests — to answer messages sent via the contact form. Legal basis: performance of pre-contractual measures at your request and our legitimate interest in responding (Art. 6(1)(b) and (f) GDPR).
- Send the newsletter — only where you have subscribed. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- Keep the service secure — to prevent abuse and protect the infrastructure. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
- Comply with the law — for accounting and tax obligations relating to paid services. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
4. Retention period
- Contact requests: for the time needed to handle your request and up to 24 months afterwards, unless a longer period is required to establish or defend a legal claim.
- Newsletter: until you unsubscribe or withdraw consent.
- Technical/security logs: for a limited period, generally no longer than 12 months.
- Accounting records: for the period required by applicable tax law.
5. Recipients and sub-processors
We keep third parties to a minimum. Where a supplier processes personal data on our behalf, it is bound by a data-processing agreement under Art. 28 GDPR and acts only on our instructions. The categories of sub-processors are listed in our Sub-processors page. In the on-premise configuration, no external sub-processors are involved. We never sell your personal data and we do not disclose it to undisclosed third parties.
6. Transfers outside the EU
By default, your data is processed and stored within the European Union. A transfer outside the EU can occur only if you explicitly choose the optional Confidential Computing configuration, where the processing hardware may be located outside the EU. In that case the transfer is governed by appropriate safeguards under Chapter V GDPR — the European Commission's Standard Contractual Clauses (SCC) — combined with technical measures that keep data encrypted and isolated during processing. No transfer takes place without such safeguards.
7. Your rights
Under Articles 15–22 GDPR you have the right to:
- Access — obtain confirmation and a copy of your data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — have your data deleted ("right to be forgotten").
- Restriction — limit how we process your data.
- Objection — object to processing based on legitimate interest.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, without affecting prior processing.
To exercise any of these rights, write to info@privateai24.com. You also have the right to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali).
8. Security
We apply appropriate technical and organisational measures: encryption in transit (TLS) and at rest, access controls, data minimisation and network isolation. No certification is currently declared as obtained; ISO 27001 and SOC 2 processes are pianificate.
9. We do not train AI on your data
Your data is never used to train, fine-tune or improve AI models — neither ours nor those of any third party. Your content is processed only to deliver the service you requested and is not shared with public AI clouds.
10. Changes to this notice
We may update this notice to reflect changes in the service or the law. The current version is always the one published on this page, with its update date.
Questions about your privacy? Write to info@privateai24.com.