Privacy and cookies
How we handle your data.
This notice explains what personal data stygeon.com processes, why, for how long, and what your rights are (Article 13 of Regulation (EU) 2016/679, “GDPR”).
Last updated:
In short
- The site uses no cookies, analytics or profiling tools.
- We use the data you send us (name, email, message) only to reply to you.
- We don’t sell data and don’t send newsletters or promotional emails.
- You can ask us at any time to see or delete your data.
What data we process and why
Browsing data. Like any website, the hosting service logs technical data about requests (IP address, date and time, page requested, browser type). This is needed to run the site and protect it from abuse. Legal basis: our legitimate interest in keeping the site secure (Art. 6(1)(f) GDPR). We don’t use it to identify you. It is kept for the period set by the hosting provider and no longer than needed for these purposes.
Messages you send us through the contact form or by email: name, email address, website address (optional) and the text of your message. We use them to reply and, if you ask, to prepare a proposal. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). Without name, email and message we cannot reply; the website is optional.
If you become a client, the data needed for the relationship is processed to perform the contract (Art. 6(1)(b) GDPR) and to meet tax and accounting obligations (Art. 6(1)(c) GDPR).
How long we keep it
- Messages from people who don’t become clients: 12 months after the last exchange, then we delete them.
- Client data: for the duration of the relationship and, for accounting records, the period required by law (10 years, Art. 2220 of the Italian Civil Code).
- Browsing data: for the period set by the hosting provider, limited to what is needed for security.
Who we share data with
Data is processed by us and, on our behalf, by providers acting as processors (Art. 28 GDPR):
- Our website hosting provider (server network inside and outside the EU, with the safeguards described below).
- Our email service provider (data centre in the EU).
We don’t sell data or pass it to third parties for marketing. We may disclose it to authorities only when required by law.
Transfers outside the European Union
Some providers may process data outside the EU. Where this happens, transfers rely only on GDPR safeguards: a European Commission adequacy decision (Art. 45, for example the EU-U.S. Data Privacy Framework for participating companies) or standard contractual clauses (Art. 46). You can ask us about the safeguards in place at info@stygeon.com.
We only write to you to reply to your messages or about ongoing work. We don’t send newsletters or promotional emails.
Children, automated decisions and security
- Our services are aimed at businesses and professionals. We don’t knowingly collect data from children under 14.
- We make no decisions based solely on automated processing and do no profiling.
- The site is served over HTTPS only, and access to data is limited to those who need it to reply to you or work with you.
Your rights
At any time you can ask us to access your data, correct it, delete it, restrict its processing, object to processing based on legitimate interest and, where applicable, receive it in a portable format (Arts. 15–22 GDPR). Write to info@stygeon.com: we reply within one month (Art. 12(3) GDPR).
If you believe the processing does not comply, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, garanteprivacy.it) or with the authority of the EU country where you live or work.
Changes
If we change how we process data, we update this page and the date above.
Data controller
The data controller is Mohammad Kariman, trading as Stygeon, based at Milano, Italia. Contact: info@stygeon.com. No data protection officer (DPO) has been appointed, as one is not required for this activity.