Privacy Policy
Last updated
This notice explains what personal data we collect when you visit this website, write to us, or work with us, why we collect it, and what rights you have. It is provided under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended).
1. Who is responsible for your data
The data controller is:
Choie
Milan, Italy
VAT number IT02039950478
info@choie.co
We have not appointed a Data Protection Officer, as we are not required to. For any question about this notice or your data, write to the address above.
2. What data we collect and why
When you visit the website
Our hosting provider records standard technical data when a page is requested: your IP address, browser type, the pages you visit, the time of the request, and the referring page. This is used to deliver the site, keep it secure, and diagnose faults. The legal basis is our legitimate interest in running a secure, working website (Article 6(1)(f) GDPR).
Cookies and analytics
We use Google Analytics 4, provided by Google Ireland Limited, to understand how visitors use the site: which pages are viewed, for how long, and from which country and device type. It runs only if you allow it in the banner shown on your first visit. The legal basis is your consent (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code). Withholding consent has no effect on your use of the site.
When allowed, Google Analytics sets these cookies on this domain:
- _ga — distinguishes visitors. Lasts 2 years.
- _ga_* — keeps the session state. Lasts 2 years.
Google Analytics 4 does not log or store IP addresses. Data may be processed by Google LLC in the United States under the EU-US Data Privacy Framework. Google's own use of the data is described in its privacy policy. You can also block the tag with the Google Analytics opt-out add-on.
Your choice is saved in your browser's local storage (not a cookie) for six months, after which we ask again. You can change it at any time via “Cookie preferences” in the footer. Rejecting after having accepted stops further tracking and removes the cookies above.
We do not use advertising or social media trackers, and we do not combine analytics data with any other data we hold about you.
When you write to us
The contact form asks for your name, email address, optionally your company, the kind of help you need, and whatever you choose to tell us about your project. You can also contact us directly by email. We use this information to reply and to discuss working together. The legal basis is taking steps at your request before entering a contract (Article 6(1)(b) GDPR). Form messages are delivered to us by Resend, operated by Plus Five Five, Inc. (United States), under its privacy policy.
When you book a call
“Book an intro call” opens a scheduling window provided by Cal.com, Inc. (United States). It loads only when you click the button. To book, you give your name, email address, and optionally a note; Cal.com also records your time zone. We use this to hold the call and to send the calendar invitation. The legal basis is taking steps at your request before entering a contract (Article 6(1)(b) GDPR). Cal.com processes this data on our behalf and under its own privacy policy; the scheduling window may set cookies needed for it to function.
When we work together
If you become a client, we process the data needed to run the project and the business relationship: contact details of you and your team, company details, billing address, VAT number, the contents of our written scope and correspondence, and the material you share for the work. The legal basis is performance of the contract (Article 6(1)(b) GDPR) and compliance with our legal obligations, including tax and accounting law (Article 6(1)(c) GDPR).
When you pay
Payments are handled by Stripe. When you pay an invoice or use online checkout, your card or bank details go directly to Stripe. We never see or store full card numbers. We receive confirmation of the payment, the amount, your name and email, and the last four digits of the card. Stripe processes this data as our processor for the payment itself, and as an independent controller for its own purposes such as fraud prevention and legal compliance, as described in the Stripe Privacy Policy. Our contracting entity is Stripe Payments Europe, Ltd., Ireland.
3. Who receives your data
We share personal data only with the people and services needed to do the work:
- Stripe, for payment processing, as described above.
- Google Ireland Limited, for analytics, only with your consent, as described above.
- Cal.com, Inc., for scheduling intro calls, as described above.
- Plus Five Five, Inc. (Resend), for delivering contact-form messages to our inbox.
- Vercel Inc., which hosts this website and records the technical data described above.
- Our email and productivity providers, which store the messages and files we exchange.
- Our accountant and professional advisers, bound by professional secrecy, for invoicing and tax.
- Public authorities, where the law requires it.
We do not sell personal data and we do not share it for advertising.
4. Transfers outside the European Economic Area
Some of the providers above are based in, or store data in, the United States. Where that happens, transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework for certified companies, or on Standard Contractual Clauses approved by the Commission, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
5. How long we keep your data
- Website runtime logs available to us through Vercel: normally 3 days. Relevant records may be kept longer when needed to investigate a security or service incident.
- Enquiries that do not lead to a project: 12 months after our last exchange, then deleted.
- Contracts, invoices, and payment records: 10 years from the end of the financial year, as required by Article 2220 of the Italian Civil Code and tax law.
- Project files and correspondence: for the duration of the project and up to 24 months after it ends, unless a longer period is agreed or needed to handle a dispute.
6. Your rights
Under Articles 15 to 22 GDPR you can ask us to:
- confirm whether we hold data about you and give you a copy;
- correct data that is inaccurate or incomplete;
- delete your data, where there is no legal reason for us to keep it;
- restrict how we use it while a question is resolved;
- give you your data in a portable format, where processing is based on contract;
- stop processing based on legitimate interest, where your situation justifies it.
To exercise any of these rights, email info@choie.co. We reply within one month. We may ask you to confirm your identity first.
If you believe we have handled your data unlawfully, you can lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, at garanteprivacy.it, or with the authority in the EU country where you live or work.
7. Automated decisions and children
We do not make decisions about you based solely on automated processing, and we do not profile you. Our services are aimed at businesses and adults. We do not knowingly collect data from anyone under 18. If you think a minor has sent us data, tell us and we will delete it.
8. Security
We use reputable providers, encrypted connections, two-factor authentication on our accounts, and access limited to the people who need it. No system is perfectly secure. If a breach affects your rights, we will notify you and the Garante as the law requires.
9. Changes to this notice
We update this notice when our practices or the law change. The date at the top shows the current version. Material changes affecting current clients will be communicated directly.