Personal data processing notice
This English translation is provided for convenience only; in case of discrepancy, the Italian version prevails.
Pursuant to Articles 13-14 of Regulation (EU) 2016/679 (“GDPR”). Last updated: 23 July 2026.
1. Data controller
Unleaf Advisoring S.R.L.S. — Registered office: Via Sebino 11, 00199 Roma (RM), P.IVA/C.F. 17905611004.
PEC: company@pec.unleaf.it — privacy requests: privacy@unleaf.it
The controller has not appointed a Data Protection Officer (DPO), as the conditions making the appointment mandatory are not met.
2. Data we process
- Access request data: first and last name, email, organisation, requested role, optional free-text message, outcome of the evaluation. The reserved area has no open registration: applicants fill in a form that the controller evaluates.
- Account data: email, password (stored exclusively as a hash by our authentication provider, Supabase — we never see it in clear text), assigned role.
- Two-factor authentication (MFA): if enabled, a TOTP secret is generated and stored by Supabase; we never see the secret nor the codes from your authenticator app.
- AI assistant usage log (audit log): for each question asked to the assistant we keep your account identifier (email), the question text, the generated answer, the cited sources, the role, the AI model used and the date/time — for traceability, security, enforcement of the monthly usage cap and periodic answer quality review.
- Notifications and preferences: editorial series visibility preferences, in-app service notifications and their read status.
- Technical navigation data: IP address, browser type, pages visited, collected automatically by the hosting infrastructure for the operation and security of the site. The controller does not keep its own archive of these logs.
The site does not use analytics tools (e.g. Google Analytics), advertising cookies, tracking pixels or social plugins.
3. Purposes and legal bases
- Evaluating access requests to the reserved area — pre-contractual measures taken at the data subject’s request (art. 6.1.b).
- Providing the authenticated service (login, dashboard, AI assistant, notifications, preferences, export) — performance of the contract with the registered user (art. 6.1.b).
- Security, traceability, abuse prevention and enforcement of the monthly usage cap (audit log, rate limiting) — legitimate interest of the controller (art. 6.1.f); the legitimate interest assessment is documented internally.
- Periodic review of the quality of the assistant’s answers on samples of recorded interactions — legitimate interest in improving and securing the service (art. 6.1.f).
- Technical operation, security and diagnostics of the infrastructure (hosting technical logs) — legitimate interest of the controller in the operation and security of the service (art. 6.1.f).
4. How data is processed — no profiling
Data is processed with IT tools and adequate technical and organisational measures (see §9). The monthly usage cap is an automated threshold count, not profiling: it does not produce legal or similarly significant effects and does not constitute automated decision-making within the meaning of art. 22 GDPR. The modulation of answers based on the account role is a content-ordering preference, not an evaluation of the person.
5. Use of artificial intelligence
The Portal’s assistant is a generative AI system (Regulation (EU) 2024/1689 — “AI Act”): users are informed in the interface and in a dedicated transparency page (the AI notice) describing how it works, its limits and responsibilities.
- The question text, the context passages retrieved from the corpus and the previous messages of the same conversation are sent to OpenAI to generate the answer; for API customers OpenAI states retention of no more than 30 days (subject to legal obligations or exceptions for specific endpoints documented by OpenAI) and no use for model training by default.
- Question and answer are recorded in the audit log (see §2 and §10).
- Answers are generated automatically and may contain errors: they are not professional advice and must be verified against the cited sources.
Recommendation: do not include in your questions personal data (your own or third parties’) that is not necessary, nor confidential or classified information: the free text of the question is kept in the audit log and transmitted to the AI provider as described above.
6. Cookies
Only technical session cookies are used, set by the authentication provider (Supabase) exclusively for logged-in users. No cookie is set for anonymous visitors; no consent banner is required, as these are strictly necessary cookies under the Garante’s Guidelines (10/06/2021). The interface language (Italian/English) is determined by the URL path, not by a cookie. Details in the cookie notice.
7. Recipients and processors
- Supabase — authentication, database, audit log, notifications, access requests. Data hosted in an EU region.
- Vercel — application hosting and delivery (US provider).
- OpenAI — receives the question text (and the retrieved passages) to generate embeddings and the assistant’s answers (contracting entity for EEA customers: OpenAI Ireland Ltd; processing on US infrastructure).
- Aruba (EU provider) — sending of transactional emails (invitations, password reset, alerts).
Data is not sold or disclosed to third parties for marketing purposes, nor disseminated.
8. Transfers outside the EU
- OpenAI: the contracting entity for EEA customers is OpenAI Ireland Ltd; onward transfers to the US take place on the basis of standard contractual clauses (SCC) or adequacy decisions, as provided in the applicable Data Processing Addendum.
- Vercel (US): certified under the EU-U.S. Data Privacy Framework (including the UK Extension) and the Swiss-U.S. DPF; its DPA also incorporates the SCC.
- Supabase: Portal data resides in an EU region; the DPA covers with SCC the transfers of account/support data to the Singapore contracting entity.
9. Security measures (summary)
Access upon approval with roles (RBAC); passwords checked against known compromised credentials; TOTP MFA available; database-level data isolation (Row Level Security: each user only accesses their own data); traffic encryption (HTTPS/TLS); traceability of interactions with the assistant; automatic abuse limitation.
10. Retention period
| Data | Retention |
|---|---|
| Access requests | 12 months from the decision (or from submission, if no decision is taken) — automatic monthly deletion |
| Account data, MFA, preferences, notifications | Duration of the relationship; deleted with the account |
| Assistant audit log — full text of questions and answers | 90 days, then automatic anonymisation (daily job) |
| Assistant audit log — pseudonymised metadata (sources, role, timestamps, outcome) | 12 months, then automatic deletion (daily job) |
| Question text held by OpenAI | ≤ 30 days, subject to legal obligations (OpenAI statement for API customers) |
| Hosting technical logs | No archive of our own; retention of the Vercel platform |
11. Your rights
You may exercise at any time the rights under arts. 15-22 GDPR (access, rectification, erasure, restriction, portability, objection) by writing to privacy@unleaf.it. Our internal procedure provides for a reply within one month. You also have the right to lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it).
12. Changes
This notice may be updated; the current version is always published on this page with the last-updated date shown above.