Legal
Privacy Policy
Last updated: August 17, 2026
Drafted with care to ensure transparency toward users and broad protection for the controller, in line with Regulation (EU) 2016/679 ("GDPR"). It is not a substitute for legal advice: before final publication in production we recommend a review by a qualified professional, particularly if the services described below change or regulatory requirements evolve.
1. Data controller
The controller for personal data collected through this Site is:
0XBUSINESS SRL
Piazza del Popolo 18, 00187 Roma (RM) — Italy
VAT: IT16920451008 — Tax ID: 16920451008
REA: 1684139 — Certified email (PEC): 0xbusiness@legalmail.it
To exercise the rights described in section 8, or for any question about how we process your data, please get in touch via the Contact page or the certified email above.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data (collection, storage, use, disclosure, erasure).
- Controller: the entity that determines the purposes and means of processing (0xBusiness, for data collected through this Site).
- Processor: a third party that processes data on behalf of the controller, under its instructions (Art. 28 GDPR).
- Data subject: the natural person the personal data relates to.
3. Data we collect
3.1 Data you provide voluntarily
Through the form on the Contact page we collect: name, email address, phone number (optional), company (optional), and the content of the message sent. Submitting the form requires your explicit consent to the Terms & Conditions and this notice.
3.2 Data collected when booking a call
The Contact page offers a booking calendar provided by Cal.com, a third-party service. The calendar is only loaded after you explicitly click to confirm: before that, no data is shared with Cal.com. Once loaded and used to book a call, Cal.com processes the data required for the booking (name, email, time zone, and possibly your IP address) under its own privacy policy.
3.3 Browsing and statistics data
For aggregate traffic statistics we use Umami, an open-source web analytics tool that doesn't use cookies and doesn't collect personally identifiable data (no IP address is stored, no unique user identifier is used). See section 12 for more detail.
3.4 Technical data collected automatically
The Site's systems and software collect, as part of normal operation, certain data whose transmission is inherent to internet communication protocols (e.g. IP address, browser type, operating system, request timestamp). This data is used solely for IT security purposes and is not associated with identifiable individuals, except where necessary to establish liability in connection with computer crimes.
3.5 Special categories of data
We do not request or intentionally collect special categories of data (Art. 9 GDPR: racial or ethnic origin, political/religious opinions, health, genetic or biometric data, sex life). If such data is voluntarily entered in the message field of the contact form, we will delete it immediately without further use.
4. Purposes and legal bases of processing
| Purpose | Legal basis | Data processed |
|---|---|---|
| Responding to information or quote requests | Art. 6(1)(b) GDPR — pre-contractual measures at the data subject's request | Name, email, phone, company, message |
| Managing a call booking | Art. 6(1)(b) GDPR — pre-contractual measures; Art. 6(1)(a) — consent to load the Cal.com widget | Name, email, time zone |
| IT security and fraud/abuse prevention | Art. 6(1)(f) GDPR — legitimate interest | IP address, technical logs |
| Contractual, accounting and tax obligations | Art. 6(1)(c) GDPR — legal obligation | Identification and billing data |
| Establishing, exercising or defending a legal claim | Art. 6(1)(f) GDPR — legitimate interest | Data relevant to the dispute |
When we rely on legitimate interest, we have verified that the interest pursued is legitimate, that processing is necessary and proportionate, and that your rights and fundamental freedoms are not overridden. You may object at any time via the Contact page.
5. Data retention
We keep personal data only for as long as necessary for the purposes it was collected for:
| Type | Retention period |
|---|---|
| Contact requests not followed by a business relationship | 24 months from the last contact |
| Data of clients with an active contractual relationship | Duration of the relationship + 10 years, for accounting and tax obligations |
| Security logs | 12 months |
| Security backups | 90 days |
At the end of the periods above, data is either permanently deleted or anonymized in aggregate form so it can no longer be traced back to an identifiable person.
6. Recipients and processors
Data may be disclosed to third-party providers acting as processors (Art. 28 GDPR), contractually bound to process data solely on behalf of 0xBusiness and under its instructions:
| Provider | Purpose | Location |
|---|---|---|
| Hosting/infrastructure provider | Serving the Site | EU / non-EU |
| Neon (PostgreSQL database) | Storing data collected through the contact form | EU / US depending on the selected region |
| Mailgun | Internal email notifications for new contact requests | US |
| Cal.com | Managing call bookings (only after your consent) | US |
| Umami | Aggregate, anonymous traffic statistics (no personal data processed) | EU |
We do not sell or share your data with third parties for their own commercial purposes. Data may also be disclosed to legal, tax or accounting advisors bound by professional secrecy, and to public authorities when required by law.
7. International transfers
Some of the providers listed in section 6 are based in the United States. In such cases, transfers outside the European Economic Area rely on appropriate safeguards under Chapter V of the GDPR, such as the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) and, where applicable, the provider's participation in the EU-U.S. Data Privacy Framework.
8. Your rights
Under Articles 15-22 of the GDPR, as a data subject you have the right to:
- access your data and obtain a copy (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- request erasure of your data, unless retention is necessary for legal obligations or for the establishment, exercise or defense of a legal claim (Art. 17);
- restrict processing in specific circumstances (Art. 18);
- receive, in a structured format, data provided on the basis of consent or a contract and transmit it to another controller (portability, Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7.3).
You can exercise these rights free of charge via the Contact page or the certified email in section 1. We will respond within 30 days of receiving the request, extendable by a further 60 days for complex requests, with a reasoned notice.
9. Data security
We adopt technical and organizational measures appropriate to the risk (Art. 32 GDPR), including: encryption of communications via HTTPS/TLS, hosting on professional infrastructure with access controls, periodic backups, and access to the content administration panel restricted to authorized personnel via individual credentials. No system can guarantee absolute security: we apply the measures reasonably available to reduce the risk of unauthorized access, loss, or improper disclosure of data.
10. Personal data breaches
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, the controller notifies the competent supervisory authority within 72 hours of becoming aware of the breach (Art. 33 GDPR) and, where the risk is high, informs the affected data subjects without undue delay (Art. 34 GDPR).
11. Automated decision-making
We do not use your data to make decisions based solely on automated processing, nor for profiling activities that produce legal effects or significantly affect you (Art. 22 GDPR).
12. Cookies and tracking technologies
The Site only uses technical cookies strictly necessary for its operation. No profiling or advertising cookies are used.
For traffic statistics we use Umami, which does not use cookies or equivalent technologies and does not collect data that would allow direct or indirect identification of individual visitors. For this reason its use does not require prior consent under ePrivacy rules.
The booking calendar provided by Cal.com may set its own technical cookies, but is only loaded after you explicitly click to confirm on the Contact page.
13. Children
The Site is aimed at a professional audience (businesses and their representatives) and is not intended for anyone under 16. We do not knowingly collect data from minors. If a parent or guardian believes a minor has provided personal data through the Site, please contact us to request its immediate deletion.
14. Links to third-party sites
The Site may contain links to third-party websites. 0xBusiness is not responsible for the privacy practices or content of such sites. We encourage you to review their respective policies before providing any personal data.
15. Changes to this notice
This notice may be updated over time, including to reflect regulatory changes or changes to the services described. The last-updated date is shown at the top of this page. Substantial changes will be clearly highlighted on the Site.
16. Complaints to the supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) if you believe the processing of your data infringes applicable law.
17. Contact
For any request regarding this notice or the processing of your personal data, please get in touch via the Contact page or by certified email at 0xbusiness@legalmail.it.