Qonflate

Privacy

What this website does with data — which is very little — set out plainly, with the legal basis for each part.

Last updated

This site was built to need as little of your data as possible. It sets no cookies, runs no analytics, embeds nothing from third parties and keeps no log of who visits. The one place you can hand over personal data is the contact form, and what happens to it is described below. This notice is given under articles 13 and 14 of Regulation (EU) 2016/679 (the GDPR) and the Italian Personal Data Protection Code, Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Controller

The data controller is Qonflate Sas di Johannes Koecher & C. - Qonflate KG des Johannes Koecher & Co., Via Armonia 44, 39012 Merano (BZ), Italia. Write to jk@qonflate.com or, for formal correspondence, to the certified address qonflate@pec.it. The company is not required to appoint a data protection officer under article 37 GDPR and has not done so; the addresses above reach the person responsible directly.

What is processed, and why

Connection data

When a page is requested, the web server receives the technical data any request carries: your IP address, the address of the page, the time, and the identification string of your browser. This is used only to deliver the page and to protect the server from abuse, on the basis of the controller’s legitimate interest in running a secure service (article 6(1)(f) GDPR). The server keeps no access log. Technical errors are recorded without personal data. The transport is encrypted (TLS).

The contact form

If you write through the form, the controller processes your name, your email address, the text of your message and the language you wrote in, for the sole purpose of answering you. The legal basis is article 6(1)(b) GDPR — steps taken at your request before entering into a contract — and, where no contract is in view, the legitimate interest in replying to someone who asked (article 6(1)(f)).

Three technical measures protect the form from automated abuse, all on the basis of article 6(1)(f):

  • your IP address is held in the server’s memory for at most ten minutes to limit how many messages one address can send, and is not written anywhere;
  • the form carries the time at which it was shown, so a submission faster than a person could type is refused;
  • a proof-of-work check (ALTCHA) asks your browser to solve a small computational puzzle. The puzzle and its solution contain no personal data, and the widget is configured not to collect interaction signals.

Your message is transmitted as an email to the controller’s mailbox through an email delivery service acting as processor under article 28 GDPR, and it is not stored on the web server. Providing the data is voluntary; without a name and an address there is simply no way to answer.

Your display preference

If you switch the site between its light and dark drawing, the choice is saved in your browser’s local storage under the key qf-theme. It never leaves your browser, identifies nobody and is strictly necessary to honour a setting you chose, so it requires no consent (article 122 of the Code, as read in the Garante’s guidelines of 10 June 2021 on cookies and other tracking tools).

What is not done

No cookies are set, first-party or otherwise. No analytics, advertising, social-network plug-in, embedded video, external font or content delivery network is used: every request a page makes goes to this domain. No profile of you is built and no automated decision is taken about you.

Retention

  • Connection data: for the duration of the request; it is not stored.
  • Rate-limit records: at most ten minutes, in memory.
  • Contact messages: for as long as needed to handle and follow up on your enquiry, and no longer than twenty-four months, unless a contract follows — in which case correspondence is kept with the contract’s records for the ten years required by article 2220 of the Italian Civil Code.

Recipients and transfers

Data may be seen by the hosting provider, Contabo GmbH (Aschheim, Germany), which operates the server in the European Union under a processing agreement, and by the email delivery service that carries messages from the contact form. Data is not sold, not shared for marketing and not transferred outside the European Economic Area. Public authorities receive data only where the law obliges the controller to provide it.

Your rights

Under articles 15 to 22 GDPR you may ask for access to your data, for it to be rectified or erased, for its processing to be restricted, for a copy in a portable format, and you may object to processing based on legitimate interest. Write to either address above; answers are given within one month (article 12(3)). If you believe your rights have been infringed you may lodge a complaint with the supervisory authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it (article 77), or bring proceedings before the courts (article 79).

Minors

This site addresses professionals and companies. It does not knowingly collect data from anyone under fourteen, the age at which a minor may consent to information-society services in Italy.

Changes

The date at the top of this page marks the last substantive change. If what the site does with data changes, this page changes with it before the new processing begins.