securityportal
Sign in

Personal data processing notice

Draft pending legal review. This text has not yet been validated by counsel; do not treat it as final.

This English translation is provided for convenience only; in case of discrepancy, the Italian version prevails.

Pursuant to Articles 13-14 of Regulation (EU) 2016/679 (“GDPR”). Last updated: 23 July 2026.

1. Data controller

Unleaf Advisoring S.R.L.S. — Registered office: Via Sebino 11, 00199 Roma (RM), P.IVA/C.F. 17905611004.
PEC: company@pec.unleaf.it — privacy requests: privacy@unleaf.it

The controller has not appointed a Data Protection Officer (DPO), as the conditions making the appointment mandatory are not met.

2. Data we process

The site does not use analytics tools (e.g. Google Analytics), advertising cookies, tracking pixels or social plugins.

3. Purposes and legal bases

4. How data is processed — no profiling

Data is processed with IT tools and adequate technical and organisational measures (see §9). The monthly usage cap is an automated threshold count, not profiling: it does not produce legal or similarly significant effects and does not constitute automated decision-making within the meaning of art. 22 GDPR. The modulation of answers based on the account role is a content-ordering preference, not an evaluation of the person.

5. Use of artificial intelligence

The Portal’s assistant is a generative AI system (Regulation (EU) 2024/1689 — “AI Act”): users are informed in the interface and in a dedicated transparency page (the AI notice) describing how it works, its limits and responsibilities.

Recommendation: do not include in your questions personal data (your own or third parties’) that is not necessary, nor confidential or classified information: the free text of the question is kept in the audit log and transmitted to the AI provider as described above.

6. Cookies

Only technical session cookies are used, set by the authentication provider (Supabase) exclusively for logged-in users. No cookie is set for anonymous visitors; no consent banner is required, as these are strictly necessary cookies under the Garante’s Guidelines (10/06/2021). The interface language (Italian/English) is determined by the URL path, not by a cookie. Details in the cookie notice.

7. Recipients and processors

Data is not sold or disclosed to third parties for marketing purposes, nor disseminated.

8. Transfers outside the EU

9. Security measures (summary)

Access upon approval with roles (RBAC); passwords checked against known compromised credentials; TOTP MFA available; database-level data isolation (Row Level Security: each user only accesses their own data); traffic encryption (HTTPS/TLS); traceability of interactions with the assistant; automatic abuse limitation.

10. Retention period

DataRetention
Access requests12 months from the decision (or from submission, if no decision is taken) — automatic monthly deletion
Account data, MFA, preferences, notificationsDuration of the relationship; deleted with the account
Assistant audit log — full text of questions and answers90 days, then automatic anonymisation (daily job)
Assistant audit log — pseudonymised metadata (sources, role, timestamps, outcome)12 months, then automatic deletion (daily job)
Question text held by OpenAI≤ 30 days, subject to legal obligations (OpenAI statement for API customers)
Hosting technical logsNo archive of our own; retention of the Vercel platform

11. Your rights

You may exercise at any time the rights under arts. 15-22 GDPR (access, rectification, erasure, restriction, portability, objection) by writing to privacy@unleaf.it. Our internal procedure provides for a reply within one month. You also have the right to lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it).

12. Changes

This notice may be updated; the current version is always published on this page with the last-updated date shown above.