Privacy Policy
Last updated: [insert date]
This Privacy Policy describes how GFX-OVER (“we,” “us,” or “our”) collects, uses, and protects personal data of visitors to www.gfx-over.com (the “Website”) and users of the GFX-OVER app, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection law (Legislative Decree 196/2003, as amended).
1. Data Controller
The Data Controller is:
GFX-OVER
Email: gfx-over@gfx-over.com
2. What Data We Collect
We may collect the following categories of personal data:
- Contact data: if you email us (e.g., via gfx-over@gfx-over.com), we receive your email address and any information you choose to include in your message.
- Technical data: standard server log data (IP address, browser type, pages visited, date/time of access), collected automatically when you browse the Website, typically for security and hosting purposes.
- App account data: if you download and use the GFX-OVER app, the only personal data required to create an account is your email address. This is used solely to let you sign up, log in, and manage your account. Account creation and deletion are fully self-service: you can delete your account and associated data directly within the app at any time, without contacting us.
We do not collect or process any special category data (e.g., health, biometric, or other sensitive data as defined by Art. 9 GDPR). We do not currently use cookies or tools for advertising or profiling purposes. See our Cookie Policy for details on the cookies in use.
3. Why We Process Your Data (Purposes and Legal Basis)
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to your inquiries sent via email | Art. 6(1)(b) – pre-contractual/contractual measures, or Art. 6(1)(f) – legitimate interest in handling correspondence |
| Operating and securing the Website (server logs) | Art. 6(1)(f) – legitimate interest in Website security and proper functioning |
| Creating and managing your app account (email-based sign-up/login, self-service deletion) | Art. 6(1)(b) – performance of a contract (app terms of use) |
| Complying with legal obligations | Art. 6(1)© – legal obligation |
4. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described above:
- Email correspondence: retained for as long as necessary to handle your request and for a reasonable period afterward (typically up to 2 years), unless a longer period is required by law.
- Server logs: typically retained for a short period (e.g., up to 6–12 months) for security purposes, unless a longer retention is required to investigate a security incident.
- App account data (your email address): retained for as long as your account remains active. If you delete your account through the app, your email address and associated data are deleted automatically and immediately, without the need to contact us. We do not retain backups of deleted account data beyond what is strictly necessary for security or fraud-prevention purposes, typically no more than 30 days.
5. Data Recipients and Transfers
Your data may be shared with:
- Hosting and infrastructure providers that host the Website and/or app backend, acting as data processors under Art. 28 GDPR.
- IT service providers supporting email and app functionality.
We do not sell your personal data to third parties. If any provider is located outside the European Economic Area, the transfer will be carried out under appropriate safeguards (e.g., EU Standard Contractual Clauses), as required by Chapter V GDPR. [Update this section if/when you select specific hosting/email providers outside the EEA, e.g., Google, Apple, or US-based services.]
6. Your Rights
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Request rectification of inaccurate data (Art. 16)
- Request erasure of your data (“right to be forgotten”) (Art. 17)
- Request restriction of processing (Art. 18)
- Object to processing carried out on the basis of legitimate interest (Art. 21)
- Request data portability (Art. 20)
- Lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or another competent supervisory authority
To exercise any of these rights, contact us at: gfx-over@gfx-over.com
7. Children’s Privacy
The Website and app are not directed at children under the age of 16. We do not knowingly collect personal data from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when it was last revised. We encourage you to review this page periodically.
9. Contact
For any questions about this Privacy Policy or our data practices, contact us at: gfx-over@gfx-over.com
This document is a template and does not constitute legal advice. Before publishing, please fill in the bracketed placeholders ([Your Full Name], [Your Address], dates) and review with a qualified privacy professional, especially once Google Analytics, advertising tools, or specific hosting/app providers are confirmed.
