Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
00Legal · version 2.4 · in force from 1 June 2026

Privacy Policy

How we process the personal data of those who visit the site, those who contact us and those who use the application, pursuant to articles 13 and 14 of Regulation (EU) 2016/679.

In brief

  • The data stays within the European Union and is not shared with third parties for marketing purposes.
  • The application’s activity log is kept for five years, because it serves to demonstrate the client’s diligence.
  • The newsletter requires separate consent, revocable from every message.
  • We do not use advertising profiling cookies. Audience measurement runs only with your consent, with IP anonymisation, and we do not sell or share the data for advertising.
  • The content uploaded to cases does not feed model training.

1. Data controller

The data controller is Intarmour® di Simone Nogara, with registered office at Via Morazzone 4, 22100 Como (CO), Italia, P. IVA IT03817020138. For any request concerning processing: privacy@cranotify.eu. The company has appointed a data protection officer, reachable at the address dpo@cranotify.eu.

2. Categories of data subjects and data processed

We process data relating to three categories of data subjects: site visitors, people who contact us for commercial or support purposes, and users of the application authorised by client companies.

Site visitors Technical connection data strictly necessary for security and operation (truncated IP address, device type, pages requested).
Commercial contacts First name, last name, role, company, email address, phone if provided, message content.
Application users Access credentials, profile and role data, log of actions performed (author, time, object), addresses of the devices used for access.
Data in cases Content uploaded by the client, which may include contact details of those reporting a vulnerability. For this the client is the controller and the company acts as processor.

3. Purposes and legal bases

Provide the service Performance of the contract, art. 6(1)(b). Includes authentication, case management, deadline calculation, activity log.
Respond to requests Performance of pre-contractual measures, art. 6(1)(b), and legitimate interest in managing commercial contacts, art. 6(1)(f).
Security and abuse prevention Legitimate interest, art. 6(1)(f), and processing security obligations, art. 32.
Newsletter and communications Consent, art. 6(1)(a), given separately and revocable at any time.
Accounting and tax obligations Legal obligation, art. 6(1)(c).

4. Retention periods

Activity log 5 years from the recording of the entry, in line with the evidentiary need connected to the obligations of Reg. (EU) 2024/2847.
Case data and attachments For the duration of the contract and 90 days after termination, except for export or a request for early deletion.
Commercial contacts 24 months from the last exchange, unless a contractual relationship is opened.
Newsletter subscription Until consent is withdrawn; proof of withdrawal is kept for one year.
Connection data 30 days, except for investigations into security incidents.

5. Recipients and sub-processors

The data is processed by authorised personnel and by suppliers acting as processors pursuant to art. 28 GDPR, including the cloud infrastructure provider with data centres in the European Union, the payment service provider, the transactional email service provider and — only when the client uses the AI drafting assistant — an artificial-intelligence service (Amazon Bedrock, running Anthropic Claude models) that generates drafts from the text the client submits, with the inference carried out within the European Union (Milan); that text does not leave the European Union. The assistant produces drafts to be reviewed and does not make automated decisions with legal effect (art. 22 GDPR). On the public website, and only after the visitor grants consent, an audience-measurement provider (Google Analytics) processes aggregate usage data with IP anonymisation. The up-to-date list of sub-processors, with location and purpose, is available on request and attached to the data processing agreement.

We do not transfer data outside the European Economic Area to deliver the service: hosting, database, backups, email, payments, AI assistance and error monitoring all stay in the EU. The single exception is website measurement (Google Ireland Ltd.), which runs only with your consent and whose non-EEA transfers rest on standard contractual clauses. Should another transfer become necessary, it would rest on an adequacy decision or on standard contractual clauses, with prior notice to customers.

6. Rights of the data subject

You may request access, rectification, erasure, restriction and portability of the data, object to processing based on legitimate interest and withdraw at any time the consents given. Requests should be sent to privacy@cranotify.eu: we reply within thirty days, extendable in the cases provided for by art. 12(3).

If the data concerns the use of the application by a client company, the request should be addressed to the latter as controller: we forward it and assist the client in responding. The right to lodge a complaint with the Garante per la protezione dei dati personali remains unaffected.

7. Security measures

Encryption in transit and at rest, two-step authentication, least-privilege roles, logging of administrative actions, environment separation, encrypted backups with periodic restore testing. Vulnerabilities in our applications can be reported to security@cranotify.eu in accordance with our coordinated disclosure policy.

8. Automated decision-making

We do not make fully automated decisions that produce legal effects on data subjects. Deadline calculation and the proposed descriptive draft are support tools: the qualification of the event and the filing remain human acts, as described in the AI Notes.

9. Changes

Substantial changes are communicated to clients with at least thirty days’ notice and the version in force is always indicated at the top of this page. Previous versions are available on request.

Data controller: Intarmour® di Simone Nogara, Via Morazzone 4, 22100 Como (CO), Italia · privacy@cranotify.eu · Data protection officer: dpo@cranotify.eu. Complaint to the authority: Garante per la protezione dei dati personali, Piazza Venezia 11, Roma.