Caricamento...
Caricamento...
Data Controller: Gitogi Srl, Piazza IV Novembre 4, 20124 Milano — VAT No. 14288420962
Data Controller Contact: info@gitogi.com | Certified Email (PEC): pec@pec.gitogi.com
A Data Protection Officer (DPO) has not yet been designated; the appointment is planned. In the meantime, the controller is directly reachable at the contact details provided.
We collect personal data that you voluntarily provide through our contact forms, the AI Readiness assessment, newsletter subscription, resource downloads, and interactions with our AI chatbot. Data may include: first name, last name, email, company name, role, profession, firm size.
Your data is processed for the following purposes:
| Purpose | Legal Basis | Retention |
|---|---|---|
| Responding to contact requests | Art. 6(1)(b) (performance of contract) | 12 months if not converted |
| AI Readiness Assessment | Art. 6(1)(a) (consent) | 30 days if not converted |
| Newsletter delivery | Art. 6(1)(a) (consent, double opt-in) | Until unsubscription + 3 months |
| Free guide downloads | Art. 6(1)(b) (performance of contract) | 12 months |
| Marketing communications | Art. 6(1)(a) (separate consent) | Until withdrawal + 3 months |
| Automated lead scoring | Art. 6(1)(f) (legitimate interest) | 24 months of inactivity |
| AI Chatbot | Art. 6(1)(a) (consent) | 90 days |
| Consent registry (GDPR audit) | Art. 6(1)(c) (legal obligation) | 5 years |
| AI audit log (AI Act) | Art. 6(1)(c) (legal obligation) | 5 years |
We use an automated scoring system (lead scoring) to classify contacts based on their level of interest, pursuant to Art. 22 GDPR.
The system is rule-based (not machine learning) and relies exclusively on behavioural signals: email type, declared profession, firm size, completed assessment, downloaded guides, newsletter subscription.
We do not use sensitive data (Art. 9 GDPR) in score calculation.
You have the right to:
For more details, please see the AI Transparency page.
The chatbot on this website is a generative artificial intelligence system based on third-party Large Language Models (LLMs) provided by OpenAI and Anthropic.
Data is retained for the time strictly necessary to fulfil the purposes for which it was collected, as indicated in the table in section 2. At the end of the retention period, data is automatically deleted through scheduled weekly/monthly processes.
The following providers act as data processors pursuant to Art. 28 GDPR:
| Provider | Service | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, CDN (Amplify) | Frankfurt, EU | DPF + SCCs + data in EU |
| Supabase Inc. | PostgreSQL Database, Authentication | Frankfurt, EU | Data in EU |
| Resend Inc. | Transactional email delivery | USA | DPF + SCCs |
| OpenAI Inc. | AI Chatbot (response generation); text embeddings for RAG vector search | USA | DPA + SCCs |
| Anthropic PBC | AI Chatbot (alternative provider) | USA | DPA + SCCs |
| Stripe Inc. | Payments | USA/Ireland | DPF + SCCs |
| Sentry (Functional Software) | Error monitoring, session replay (inputs masked) | USA | DPF + SCCs |
| Google LLC | Analytics (GA4) | USA | DPF + user consent |
| PostHog Inc. | Analytics, heatmaps | Frankfurt, EU | Data in EU |
| Upstash Inc. | Rate limiting (Redis) | EU | Data in EU |
We do not sell or share your data with third parties for marketing purposes.
Some of our sub-processors are based in the USA. Data transfers to the USA are legitimised by the Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by specific Data Processing Agreements (DPAs).
You have the right to:
You can exercise your rights:
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it).
For our cookie policy, please refer to our Cookie Policy.
For detailed information on the use of artificial intelligence on this website, please see the AI Transparency page, drafted in compliance with EU Regulation 2024/1689 (AI Act).
Last updated: 1 March 2026