Legal · Rechtliches · Note Legali

Privacy Policy & Legal Notice

Last updated:

Privacy Policy Language

Legal Notice (Impressum)

Demitas SRL

Address: Sotria 35, 39046 Ortisei (BZ), Italy

VAT / P.IVA: IT03345820215

Tax Code (Codice Fiscale): 03345820215

REA Number: BZ-252174

Share Capital: EUR 10.000,00 i.v.

DUNS Number: 302550258

Email: info@demitas.io

Certified Email (PEC): demitasgmbh@legpec.it

Legal form: Società a responsabilità limitata (SRL)

Represented by: Daniel Demetz, Administrator (Legal Representative) and Daniel Mahlknecht, Administrator

Place of Registration: Camera di Commercio di Bolzano

Content Responsibility

The content of this website is provided with care but without guarantee of accuracy or completeness. We assume no liability for the content of external links. The operators of linked pages are solely responsible for their content.

Privacy Policy

The protection of your personal data is important to us. This Privacy Policy explains what data we collect via this website, how we use it, who processes it on our behalf, how long we keep it, and your rights under the EU General Data Protection Regulation (GDPR) and the Italian Privacy Code (Codice Privacy, D.Lgs. 196/2003).

1. Data Controller

The controller responsible for data processing on this website is Demitas SRL (see Legal Notice above). Contact: info@demitas.io. We have not appointed a Data Protection Officer; the conditions of Art. 37 GDPR do not apply to our processing activities. For all data-protection requests, please contact us at info@demitas.io.

2. Data We Collect

When you submit our contact form, we collect: your name, email address, optional company name, and the message you provide. Required fields: name, email address, message. Optional field: company name. Without the required fields we cannot respond to your inquiry; providing additional information is voluntary.

The lawful basis is Art. 6(1)(f) GDPR (legitimate interest in receiving, evaluating, and responding to business inquiries). We have weighed this interest against the rights and freedoms of data subjects and concluded that, given (i) the data subject voluntarily initiates contact, (ii) only minimal data is collected, and (iii) no profiling occurs, the processing is proportionate (balancing test per EDPB Guidelines 1/2024).

3. How We Process Your Contact Form Submission

Our contact form is processed by Web3Forms, a form-handling service operated from India. When you submit the form, the following data is transmitted to Web3Forms servers for delivery to our email address: name, email address, company name (if provided), and message content. Web3Forms operates on cloud infrastructure (currently AWS) and retains form submissions in accordance with their privacy policy (currently 30 days on the free tier or up to 1 year on the paid tier) before automatic deletion.

International transfer (India): India does not have an EU adequacy decision under Art. 45 GDPR. The transfer is therefore conducted under Art. 46 GDPR Standard Contractual Clauses; where no Data Processing Agreement is available, we rely on Art. 49(1)(b) GDPR (transfer necessary for the performance of a contract with the data subject, or to take pre-contractual steps at the data subject's request — submitting the inquiry form constitutes such a request).

Web3Forms' privacy policy: https://web3forms.com/privacy.

4. Hosting and Server Logs

This website is hosted by Hostinger International Ltd. on infrastructure located in Germany (primary server) with backups in France. Both endpoints are within the European Union, so the data transfer is intra-EU and no Art. 46 GDPR Standard Contractual Clauses are required for the host.

When you visit this website, Hostinger automatically collects technical data for security and operational purposes: IP address, browser type and version, date and time of access, and pages requested. This data is used solely for security, abuse prevention, and operational diagnostics. The lawful basis is Art. 6(1)(f) GDPR (legitimate interest in operating a secure, reliable website). Hostinger acts as our data processor under Art. 28 GDPR.

Hostinger's Data Processing Agreement: hostinger.com/legal/dpa; privacy policy: hostinger.com/legal/privacy-policy.

5. Cookies and Tracking

This website does not use tracking cookies, analytics cookies, advertising cookies, or any profiling technologies. We do not use Google Analytics, Meta Pixel, or any similar service. We do not load any third-party scripts that could set cookies on your device.

We may use functional/technical storage strictly necessary for website operation (for example, the URL hash that remembers which privacy-policy tab you selected). Under the Italian Garante's Cookie Guidelines (10 July 2021) and Art. 122 of the Italian Privacy Code (Codice Privacy, D.Lgs. 196/2003), such strictly-necessary technical storage does not require user consent and does not trigger a cookie banner. Accordingly, this website does not display a cookie banner.

6. Fonts

The typefaces used on this site (Lora, Inter Tight, JetBrains Mono) are served from our own hosting at demitas.io. When you load this site, your browser does not connect to Google Fonts, Adobe Fonts, or any other third-party font service. No font-related data is transmitted to any third party.

7. Your Rights Under GDPR

You have the following rights under the EU General Data Protection Regulation (GDPR):

  • Right of access (Art. 15 GDPR) — to know what data we hold about you
  • Right to rectification (Art. 16 GDPR) — to correct inaccurate data
  • Right to erasure (Art. 17 GDPR) — to request deletion of your data
  • Right to restriction (Art. 18 GDPR) — to limit processing in certain cases
  • Right to data portability (Art. 20 GDPR) — to receive your data in a portable format
  • Right to object (Art. 21 GDPR) — to object to processing based on legitimate interests
  • Right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, garanteprivacy.it)

To exercise any of these rights, please contact us at info@demitas.io.

8. Data Retention

We retain contact form data for 12 months after the last meaningful exchange unless (i) the inquiry leads to an ongoing business relationship, in which case we retain it for the duration of that relationship plus the legally-mandated record-retention period under Italian law (typically 10 years for accounting documents under Art. 2220 of the Italian Civil Code), or (ii) you ask us to delete it earlier. Server logs are retained by our hosting provider per their data-processing agreement.

9. Data Security

We use appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. All data transmission between your browser and this website is encrypted via HTTPS (TLS).

10. Changes to This Policy

We may update this Privacy Policy and Legal Notice to reflect changes in our services, the law, or our processors. The current version is always available at https://demitas.io/privacy.html with a "Last updated" date clearly indicated. Material changes will be summarised at the top of the page for a reasonable period after the change.