Privacy Policy

In accordance with Regulation (EU) 2016/679 (GDPR)

1. Data Controller

The Data Controller for personal data is Felice Caricati, located at via val seriana 4, Monza, email: privacy@quote-o-matics.cloud.

2. Personal Data Collected

The service collects the following categories of personal data:

  • Registration data: email address and password (hash).
  • Usage data: access logs, IP address, browser type and operating system, pages visited and interactions with the service.
  • Authentication data: passkey credentials and session tokens.

3. Purpose and Legal Basis for Processing

Personal data is processed for the following purposes:

  • Service provision (legal basis: contract performance, Art. 6.1.b GDPR) — account registration, authentication, quote creation and management.
  • Security and abuse prevention (legal basis: legitimate interest, Art. 6.1.f GDPR) — infrastructure protection and prevention of unauthorized access.
  • Legal compliance (legal basis: legal obligation, Art. 6.1.c GDPR) — tax, accounting obligations or judicial authority requests.

4. Technical Cookies Used

The site uses only technical cookies necessary for the operation of the service. No profiling or third-party cookies are used for advertising purposes.

CookiePurposeDuration
sb-*-auth-tokenAuthentication session (Supabase)Session / 1 year
passkey-challengePasskey challenge verificationSession

These cookies are essential for the operation of the site and do not require user consent under Art. 122 of the Privacy Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018).

5. Data Retention

Personal data is retained only for as long as necessary for the purposes for which it was collected:

  • Account data: until the user deletes the account or requests deletion.
  • Access logs: up to 12 months from the event registration.
  • Tax/accounting data: for the period required by applicable law (up to 10 years).

6. Data Subject Rights

Under Articles 15-22 of the GDPR, users have the right to:

  • Access — obtain confirmation of data processing and access their data.
  • Rectification — update or correct inaccurate data.
  • Erasure — request deletion of their personal data.
  • Portability — receive their data in a structured, commonly used and machine-readable format.
  • Objection — object to processing for legitimate reasons.
  • Complaint — lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).

7. Contact

To exercise the above rights or for any questions regarding personal data processing, please contact the Data Controller at: privacy@quote-o-matics.cloud.

Last updated: February 2026