back to the site

privacy notice · arts. 13–14 gdpr · cookies · legal notices

Your privacy, without the complications.

This page says — in plain words — what we do with your data when you visit z‑32.it. And above all what we do not do.

document updated 5 August 2026 · English translation provided for convenience — in case of any discrepancy the Italian version prevails

cookieszero
trackingzero
advertisingzero
your dataonly if you write to us

01The data controller

Z‑32 is a trading name of CSF, which is the controller of the data collected through this site.

controller
CSF — registered office: Latina, Italy
vat no.
03372330591
privacy contact
amministrazione@z‑32.it
phone
380 193 2116 · 380 238 4325 (Mon–Fri, 9am–7pm)

02What we process, why, and for how long

Browsing this site requires no personal data at all. We process something only in three cases, each one started by you.

If you write or call us

The contact form at the foot of the main page sends nothing to our servers: it prepares a message in your own mail app, and you are the one who sends it. We process what you tell us — name, contact details, message content — only once it reaches our inbox or our phone, for the sole purpose of replying to you and handling any relationship that follows (art. 6.1.b GDPR, pre-contractual measures at your request). We keep the correspondence for as long as it takes to handle the request; if a contract follows, for the periods required by law for contractual and tax records.

If you talk to the Living Agent

Above the input field we say it plainly, but it is worth repeating here: you are talking to an artificial-intelligence system, not to a person. The messages you send are transmitted to our systems, on servers inside the European Union, and processed with AI models to generate the reply (art. 6.1.b GDPR).

The conversation is kept. We keep it for three reasons, all stated here: traceability — the AI Act asks that an AI system stay reconstructable and open to human oversight, and we want to be able to demonstrate that, not merely claim it; security — spotting and blocking abuse of the chat; market analysis — understanding, in aggregate, what businesses actually ask us. All three rest on our legitimate interest (art. 6.1.f); for market analysis we work on anonymised texts, stripped of anything that could lead back to a person.

The chat is public and needs no sign-up: we don't ask for your name, we don't create an account, we don't link conversations to one another or to a profile. We do not profile you, we do not market to you, and we take no automated decisions producing legal effects (art. 22). To generate the replies we rely on AI service providers, who process the messages as processors and strictly within our instructions.

For how long. We keep conversations for 12 months, then delete them. All that remains are anonymous traces — usage records and aggregate data about the chat: what kinds of request come in, in which sector, how often — and those we keep with no expiry date: they no longer refer to anyone, they are no longer personal data, and the GDPR does not apply to them (recital 26). Technical logs follow instead the rules described just below. The test we hold ourselves to is simple and checkable: if a trace could still lead back to you, it would not be anonymous — and it would then share the fate of all the rest, deleted at 12 months.

A good rule: treat the chat like a conversation at an office reception desk. If you type in your name or other details about yourself, they stay in the text of the conversation: for sensitive or confidential data, use email.

Technical logs

The server notes down the requests it receives: page asked for, date and time, outcome, kind of browser and referring site. It is there to tell us how much this site is read and to catch faults — nothing else can tell us, since we use no third-party statistics. The IP address is truncated before it is written down: of an IPv4 address the first three parts out of four are kept, of an IPv6 address the first three out of eight. What remains is the network you come from, not you — these logs cannot lead back to a person. Legal basis: art. 6.1.f GDPR (legitimate interest). Retention: 30 days, then rotated and deleted automatically.

The chat also has an anti‑abuse counter. Anyone who reads the code of this page can have a program write to the agent, and every reply has a cost: so we count how many messages come from each address and stop above a certain threshold. Here the IP address is used in full, but only as the key of that count: it is written to no log, it is never set beside the content of the conversations, and the counter expires on its own within 24 hours. Legal basis: art. 6.1.f GDPR (legitimate interest in not having our systems used at our expense).

03Where the data lives

The site and the chat systems are hosted on a dedicated server inside the European Union (Hetzner Online GmbH, Germany), acting as processor. Browsing the site involves no transfer of data outside the EU: text, images and typefaces are all served from this server, and the contact form doesn't even go through it.

There is one exception, and you deserve to know it: to generate the chat replies we rely on OpenRouter, which routes the text of your message to the AI model that produces the answer. When the model provider operates outside the European Union, the transfer takes place under the safeguards of Chapter V of the GDPR (arts. 44–49) — in particular the European Commission's standard contractual clauses. You can ask for a copy by writing to amministrazione@z‑32.it.

Those two are our only processors — Hetzner for the infrastructure, OpenRouter for generating the replies — plus our mailbox provider, if you write to us by email. The up-to-date list is always available on request.

05Your rights

At any time you can exercise the rights set out in arts. 15–22 of the GDPR:

  • access — to know whether and which of your data we process;
  • rectification and erasure — to correct them or have them deleted;
  • restriction and objection — to limit or block the processing;
  • portability — to receive them in a machine-readable format.

A single email to amministrazione@z‑32.it: we reply within the time limits set by the GDPR. If you believe a processing operation breaks the law, you also have the right to lodge a complaint with the Italian Data Protection Authority.

Providing data is always optional: the whole site can be read without leaving anything behind.

06Legal notices

Z‑32 · Digital Transformation and AI Integration is a trading name of CSF · VAT IT03372330591 · registered office: Latina, Italy · amministrazione@z‑32.it · 380 193 2116.

The contents of this site — text, graphics, the agent and its animations — belong to the controller: all rights reserved. Trade marks mentioned belong to their respective owners.