Courtesy translation. This English version is provided for convenience only. The Italian text at /it/privacy-policy.html is the only authoritative version: in case of any discrepancy, the Italian text prevails.

Privacy Notice

Privacy notice provided pursuant to Article 13 of EU Regulation 2016/679 (GDPR) to users of the diginetic.it website and the Aura portal hosted on the same domain.

In summary. This website does not use profiling cookies, does not use statistical analysis or tracking tools, does not load resources from third-party servers and does not send commercial communications. The only cookie used is the portal’s technical session cookie, which is necessary for authentication. For this reason, there is no cookie consent banner, nor is one required: further details can be found in the Cookie Policy.

1. Data Controller

Ge.Co. sas
Via XX Settembre 174 — 05100 Terni (TR), Italy
VAT No. 01208500551
Email: info@diginetic.it
PEC: geco@pec.it

The Data Controller has not appointed a Data Protection Officer (DPO): such an appointment is not mandatory under Article 37 of the GDPR, as the Data Controller is not a public authority and does not, as its main activity, carry out large-scale systematic monitoring or large-scale processing of special categories of data. Any requests regarding personal data should be addressed to the contact details provided above.

2. What data do we process, and in what contexts?

2.1 Viewing public pages

Simply browsing the website’s pages does not require any data and does not involve creating an account. The IT systems hosting the website (reverse proxy and application server) record, solely for operational and security purposes, standard log data: IP address, date and time of the request, requested resource, response code, browser type and operating system (user agent). This data is not linked to identified users and is not used for profiling browsing behaviour.

The website loads only resources hosted on its own domain (style sheets, scripts, fonts, images): the user’s browser does not contact any third-party servers whilst browsing.

Measuring visits

The Data Controller measures visits to the website to understand which content is viewed and through which channels visitors arrive. The measurement is carried out entirely by the server: no cookies are installed or read, no measurement scripts are executed in the browser, and no third-party services (such as Google Analytics or similar) are used. Geographical location is also derived from a database installed on the Data Controller’s server: the user’s IP address is not disclosed to any third party.

Data processed. For each page viewed, the following are recorded:

  • the page address, the date and time;
  • the referring site (if arriving via an external link) and any campaign parameters present in the link;
  • approximate country, region and city, and the name of the organisation or network operator, derived from the IP address and not from the user;
  • the type of device (computer, telephone, tablet);
  • a non-reversible daily identifier, obtained by applying a cryptographic function to the IP address, browser and a random value that changes daily and is then destroyed. It serves solely to count unique visitors and to reconstruct the path of a single visit. Once the day is over, the identifier can no longer be traced back to any address, not even by the Data Controller.

IP addresses are not retained in any form, not even in truncated form: they are used only for the duration of processing the individual request.

Legal basis: the Data Controller’s legitimate interest (Article 6(1)(f) of the GDPR) in understanding the trends and origins of Traffic to its website. Processing is limited to what is necessary, does not involve profiling, does not feed into advertising and is not disclosed to anyone. Retention: details of individual visits are automatically deleted after 7days; only aggregated data remains (number of page views and visitors per day, per page, by source and by country), which does not allow any individual to be identified. The data subject may object to the processing in accordance with Article 21 of the GDPR by writing to the contact details set out in §9.

2.2 Registration on the Aura portal

To create an account, we collect:

  • email address (mandatory; this identifies the account and receives the verification message);
  • passwords, stored exclusively as an Argon2 hash: the plaintext value is never stored nor known to the Data Controller;
  • institution or organisation (optional);
  • two-factor authentication: the TOTP secret, stored in encrypted form at rest, and recovery codes, stored only as hashes. The portal does not request or process telephone numbers: the second factor is an authentication app (TOTP), not an SMS;
  • account technical details: creation date, email verification status, date of last login, number of failed login attempts and, where applicable, the expiry date of any temporary account lockout.

2.3 Access request for the service

Anyone requesting access to Aura must complete an application form providing: organisation, role, use case (mandatory), country and website (optional). The request is accompanied by the status (pending/approved/rejected), the date of submission, the date of the decision, the identifier of the decision-maker and any internal notes.

The request is assessedby a person: there are no automated decisions regarding this assessment (see §8).

2.4 Usage of the service

For the provision of the service and the billing of usage, the portal records the following for each request made: request ID, client ID, date and time, model used, role, number of incoming and outgoing tokens, corresponding cost and any API key used. Technical system events (such as the switch to a fallback model in the event of an error) and the balances/quotas associated with the account are also recorded.

API keys are stored only as salted hashes, together with the prefix required to identify them, the label chosen by the user and the relevant dates; the full value of the key is displayed only once at the time of generation and cannot be retrieved thereafter.

Content of queries. The portal’s database records the usage metadata listed above, but not the text of the questions posed to the service or the responses generated. The processing of content submitted within the Aura service is governed by the service contract and the relevant data processing agreements entered into with the user organisation.

2.5 Access security

To counter unauthorised access attempts, the portal maintains a counter of attempts per IP address in volatile memory (not in a database), over a rolling 15-minute window, and temporarily blocks the account following repeated failed attempts. Actions carried out by administrators on the portal (for example, the approval of a request) are recorded in an internal log that retains the author, action, references and date.

2.6 Invitations

Access may be granted by invitation. The following details of the invitation are retained: the code hash, any recipient’s email address, an internal note, the assigned access level, the dates of creation, expiry, usage or revocation, and the author of the invitation.

2.7 Integration of external applications (MCP/OAuth)

For users connecting a compatible client to the service, the portal retains the client’s registration data, the hashes of authorisation codes and tokens, the requested scopes, the redirect URIs and their respective expiry times. Tokens in plain text are not retained.

2.8 Contact form

The contact form published on the Contact page collects: first name, surname and email address (mandatory, used to reply to you), organisation or company and subject (optional), and the text of the message. The content is delivered by email to the Data Controller’s inbox and is not stored in any database: it exists solely within the correspondence, just like an email you might have sent to us directly.

The form contains a hidden anti-spam field that the user cannot see and must not fill in, and a technical limit on the number of submissions from the same link. There is no external form collection service and no data is transmitted to third-party platforms.

2.9 Email communications

The Data Controller sends only service-related emails: verification of the email address at the time of registration, notification of the outcome of access requests, and replies to messages received. No newsletters are sent, nor are any commercial communications sent; the contact form does not trigger any subscription.

2.10 Payments

The payment function is not currently active and no payment data is collected or transmitted. Should it be activated, payments would be handled by a specialist provider (Stripe) acting as an independent data controller/processor for payment data; card details would not, in any case, pass through the Data Controller’s systems. This privacy notice will be updated prior to activation.

2.11 Data we do not process

The website and portal do not process: special categories of data (Article 9 of the GDPR), judicial data (Article 10 of the GDPR), geolocation data, telephone numbers, or data relating to minors (the service is intended for professionals and organisations, not for persons under the age of 18).

3. Purposes and legal bases

PurposesDataLegal basis
Providing the Aura portal and service: account creation and management, authentication, key issuance and management, and consumption accounting §2.2, §2.4, §2.7 Art. 6.1.b — performance of the contract or pre-contractual measures requested by the data subject
Assess the request for service authorisation and communicate the outcome §2.3, §2.6 Art. 6.1.b — pre-contractual measures
Responding to messages sent via the contact form or by email §2.8, §2.9 Art. 6.1.b — pre-contractual measures where the request relates to the service; Art. 6.1.f — legitimate interest in responding to those who write to us in other cases
Please check the email address provided §2.2, §2.9 Article 6(1)(b) — performance of a contract
Ensuring the security of the website and portal: preventing unauthorised access, diagnostics, log of administrative operations, technical logs §2.1, §2.5 Article 6(1)(f) — the Data Controller’s legitimate interest in the security of its systems and users’ data (balanced interest: this involves a minimum amount of data, retained for the time strictly necessary and not used for other purposes)
To comply with accounting, tax and legal obligations Identification and accounting data Article 6(1)(c) — legal obligation
Defending a legal right in court Data relevant to legal proceedings Article 6(1)(f) — legitimate interests

No consent is required because none of the processing operations described are based on Article 6(1)(a): there are no cookies or tools requiring consent, nor are any promotional communications sent.

4. Nature of the provision of data

The provision of data marked as mandatory (email, password, and for authorisation requests: organisation, role, use case) is necessary to create an account and gain access to the service: without this information, the relationship cannot be established. Other data is optional and failure to provide it has no consequences.

5. Retention period

DataRetention
Accounts and authentication data (§2.2) For the entire duration of the relationship; deleted within 30 days of the request for erasure or the termination of the relationship
Authorisation requests and invitations (§2.3, §2.6) 24 months from the decision, to demonstrate the correctness of the admission process
Usage and consumption data (§2.4) 24 months from registration; data required for invoicing is retained in accordance with tax regulations
Record of administrative operations (§2.5) 24 months
Messages from the contact form and correspondence (§2.8) 24 months from the last contact, unless the relationship continues
Web server log files (§2.1) No longer than 30 days, unless they need to be retained for a longer period to investigate a security incident or for an investigation by the supervisory authority
Details of website visits (§2.1) 7 days, followed by automatic deletion. Aggregated data, which does not relate to identifiable individuals, is retained indefinitely
Counting of login attempts per IP address (§2.5) 15 minutes (volatile memory, no persistence)
Accounting and tax documents 10 years, as required by law

6. To whom we disclose data

The data is not disclosed and is not transferred to third parties for their own purposes. It is accessible to the Data Controller’s authorised staff and to the following suppliers, who act as data processors pursuant to Article 28 of the GDPR on the basis of data processing agreements (DPAs) drawn up by them:

SupplierServicePlace of processing
Hetzner Online GmbH Hosting of the website, the portal and the database Germany (EU)
Brevo (Sendinblue SAS) Sending of service emails and delivery of messages via the contact form France (EU)
GoDaddy (Secureserver) Domain inbox (messages sent to @diginetic.it addresses) Outside the EU — see §7

The data may also be disclosed to the Data Controller’s accounting, tax and legal advisers and, where required by law or by an order from the Authority, to the competent bodies.

7. Transfers to third countries

The infrastructure hosting the website, the portal and the database is located entirely within the European Union (Germany), as is the email delivery service (France). Browsing the website does not involve any transfer of data to third countries, as no external resources are loaded.

The domain’s incoming email service is provided by a US-based provider: emails sent voluntarily to @diginetic.it addresses may therefore be processed outside the European Union. The transfer takes place on the basis of the standard contractual clauses approved by the European Commission and the EU-US adequacy decision (EU-US Data Privacy Framework), in accordance with the provider’s terms and conditions. Anyone wishing to avoid such a transfer may use the certified email (PEC) address indicated in §1.

8. No automated decision-making processes

The Data Controller does not make decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect the data subject (Article 22 of the GDPR). In particular, admission to the service is decided by a person. The Aura service is a support tool: the responses it generates do not constitute decisions by the Data Controller regarding the user.

9. Rights of the data subject

Within the limits set out in the Regulation, the data subject has the right to:

  • Sign in to access their data and obtain a copy thereof (Article 15);
  • to rectify inaccurate data or complete incomplete data (Article 16);
  • to obtain the erasure of data (Article 17);
  • restrict processing (Article 18);
  • to receive data in a structured format and to transmit it to another data controller (Article 20);
  • object to processing based on legitimate interest (Art. 21).

Requests should be sent to info@diginetic.itor to the certified email address (PEC)geco@pec.it, stating the email address associated with the account. The Data Controller will respond without undue delay and in any event within one month of the request; this period may be extended by two months in particularly complex cases, provided the data subject is informed (Article 12 of the GDPR). The exercise of these rights is free of charge.

9.1 Account deletion

The portal does not currently have a self-deletion function: to close your account and have your data deleted, simply send a request to from the account’s email addressinfo@diginetic.it. The Data Controller will act within 30 days, deleting the account, API keys, authorisation request data and usage data, and revoking access. Only data required to be retained by law (in particular, accounting and tax documents) and data necessary for the establishment or defence of a legal claim will be retained.

10. Complaints to the Supervisory Authority

Anyone who believes that the processing of their data infringes the Regulation may lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or bring the matter before the courts.

11. Cookies

The use of cookies and on-device storage technologies is described in detail in the Cookie Policy, which forms an integral part of this notice.

12. Security

The Data Controller implements technical and organisational measures appropriate to the risk (Art. 32 GDPR): encrypted transmission via HTTPS with HSTS, passwords protected using the Argon2 derivation function, mandatory two-factor authentication, second-factor secrets encrypted at rest, API keys stored only as hashes, temporary lockout following repeated failed attempts, request limits per IP address, protection against cross-site requests (CSRF), browser security headers, and separate, audited administrative access.

13. Amendments

This privacy notice may be updated to reflect changes to the service or legislation. The current version is always published on this page with the date of the last update; substantial changes will be communicated to users who have signed up by email.

Last updated: 25 July 2026 — Version: 2.0