Privacy and cookie notice
Draft pending review.
Notice pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR). Last updated: 2026-10-04.
Data controller
Fracat, Italia. Email: info@fracat.it.
Data processed, purposes and legal bases
Browsing data. The server records IP address, date and time, requested page and user agent in technical logs to ensure the security and operation of the website (legitimate interest, Art. 6.1.f). Logs are kept for up to 30 days, unless needed to investigate abuse.
Contact form. Name, email and message are used only to answer your request (pre-contractual measures, Art. 6.1.b) and kept for 24 months after the last contact.
Orders. Name, email, company (if provided) and project description are used to manage the order and the contract (Art. 6.1.b) and for tax obligations (legal obligation, Art. 6.1.c). Accounting data is kept for 10 years as required by tax law.
Payments. Payment takes place on the payment provider's page (Stripe). Card data is collected directly by Stripe and is never transmitted to or stored by this website; we only receive the outcome and a transaction identifier.
Providing data is optional, but without it we cannot answer your request or fulfil the order. No profiling or automated decision-making takes place.
Recipients
Data may be processed, as data processors, by the server hosting provider and the email service provider. Stripe Payments Europe Ltd. processes payment data as an independent controller. Any transfer outside the European Economic Area relies on the safeguards of Art. 44 et seq. GDPR.
Your rights
You may at any time request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest (Arts. 15-22 GDPR) by writing to info@fracat.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
Cookies
This website uses no profiling cookies and no third-party analytics or tracking tools, and fonts are self-hosted. For this reason no cookie banner is shown. The private administration area only uses technical session and security cookies (sessionid, csrftoken), set only for authorized users who log in. Stripe's payment page, on an external domain, is subject to Stripe's privacy notice.