Privacy Policy
This page explains what happens to personal data when you visit iotique.it or get in touch with us, as required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Last updated · 29 July 2026
Who is responsible
The data controller is IoTique — Igloo Srl, VAT IT02583980228, Piazza Giannantonio Manci 17, 38123 Trento (TN), Italia.
- Email: hello@iotique.it
- Phone: +39 331 997 2179
We are a small team and are not required to appoint a Data Protection Officer, so privacy requests go straight to the address above and are handled by us.
What we collect
- What you send us. If you email or call us, we receive whatever you choose to share — typically your name, email address, phone number, company and the content of your message. This site has no contact form and no account system, so nothing is collected that you did not deliberately send.
- Navigation data. Our web servers record what every browser transmits automatically: IP address, date and time of the request, the URL requested, the HTTP response code and the user agent. These logs exist to serve pages and to spot abuse.
- Cookies and analytics. Only the essentials, unless you accept analytics. The full list is in the cookie policy.
Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Answering your enquiry and scoping possible work | Art. 6(1)(b) — steps taken at your request before a contract, and Art. 6(1)(f) — our legitimate interest in responding to business enquiries |
| Running, securing and troubleshooting the website | Art. 6(1)(f) — our legitimate interest in a site that works and is not abused |
| Measuring how the site is used | Art. 6(1)(a) — your consent, which you can withdraw at any time |
| Meeting accounting, tax and other legal obligations | Art. 6(1)(c) — compliance with a legal obligation |
We do not use personal data for automated decision-making or profiling, we do not build advertising audiences, and we never sell or rent it.
Who else sees it
Your data stays with us and with a short list of suppliers who process it on our written instructions under Article 28 GDPR:
- Infrastructure, hosting and email providers that operate the servers behind this site and our mailboxes.
- Google Ireland Limited, for Google Analytics — only if you have accepted analytics cookies.
- Accountants, lawyers and public authorities, where a legal obligation or the defence of a legal claim requires it.
Transfers outside the EEA
The website is served from infrastructure located in the European Union. If you accept analytics, Google may process the resulting data in the United States. Those transfers rely on the EU–US Data Privacy Framework adequacy decision and, as a fallback, on the European Commission's Standard Contractual Clauses. We enable IP anonymisation, so your address is truncated by Google before it is stored.
How long we keep it
| Data | Retention |
|---|---|
| Enquiry correspondence | Up to 24 months from our last exchange. If we end up working together, for the length of the contract plus the statutory limitation period. |
| Server logs | Up to 30 days in normal operation; longer only while investigating a specific security incident. |
| Analytics data | Up to 14 months, the shortest retention Google Analytics 4 offers. |
| Your cookie choice | 6 months, then we ask again. |
Your rights
Articles 15 to 22 GDPR give you the right to ask us for:
- access to the personal data we hold about you, and a copy of it;
- correction of anything inaccurate or incomplete;
- erasure, where we no longer have a reason to keep it;
- restriction of processing, while a dispute is resolved;
- portability, in a structured, machine-readable format;
- objection to processing based on our legitimate interest.
Where processing rests on consent, you can withdraw it at any time without affecting what was lawful beforehand — for analytics, use the cookie policy page. To exercise any right, write to hello@iotique.it. We reply within one month.
If you think we have got it wrong, you can lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the authority in your country of residence.
Security
The site is served exclusively over HTTPS. Access to the systems that hold correspondence and logs is limited to the people who need it, and protected by individual accounts and multi-factor authentication.
Changes to this policy
If this policy changes we update the date at the top of the page. When a change materially affects how we handle your data, we will say so on the site rather than leave you to notice.