Privacy Policy
In accordance with Regulation (EU) 2016/679 (GDPR)
1. Data Controller
The Data Controller for personal data is Felice Caricati, located at via val seriana 4, Monza, email: privacy@quote-o-matics.cloud.
2. Personal Data Collected
The service collects the following categories of personal data:
- Registration data: email address and password (hash).
- Usage data: access logs, IP address, browser type and operating system, pages visited and interactions with the service.
- Authentication data: passkey credentials and session tokens.
3. Purpose and Legal Basis for Processing
Personal data is processed for the following purposes:
- Service provision (legal basis: contract performance, Art. 6.1.b GDPR) — account registration, authentication, quote creation and management.
- Security and abuse prevention (legal basis: legitimate interest, Art. 6.1.f GDPR) — infrastructure protection and prevention of unauthorized access.
- Legal compliance (legal basis: legal obligation, Art. 6.1.c GDPR) — tax, accounting obligations or judicial authority requests.
4. Technical Cookies Used
The site uses only technical cookies necessary for the operation of the service. No profiling or third-party cookies are used for advertising purposes.
| Cookie | Purpose | Duration |
|---|---|---|
| sb-*-auth-token | Authentication session (Supabase) | Session / 1 year |
| passkey-challenge | Passkey challenge verification | Session |
These cookies are essential for the operation of the site and do not require user consent under Art. 122 of the Privacy Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018).
5. Data Retention
Personal data is retained only for as long as necessary for the purposes for which it was collected:
- Account data: until the user deletes the account or requests deletion.
- Access logs: up to 12 months from the event registration.
- Tax/accounting data: for the period required by applicable law (up to 10 years).
6. Data Subject Rights
Under Articles 15-22 of the GDPR, users have the right to:
- Access — obtain confirmation of data processing and access their data.
- Rectification — update or correct inaccurate data.
- Erasure — request deletion of their personal data.
- Portability — receive their data in a structured, commonly used and machine-readable format.
- Objection — object to processing for legitimate reasons.
- Complaint — lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).
7. Contact
To exercise the above rights or for any questions regarding personal data processing, please contact the Data Controller at: privacy@quote-o-matics.cloud.
Last updated: February 2026