Public website privacy notice
Last updated: 20 July 2026. This notice covers the public website. Future application features will provide specific notices before data are collected.
1. Public information for the early-access website
This page is published for the Accord.ia early-access website. The website does not currently enable checkout, subscriptions, or paid contracts.
Formal company details, including legal name, registered office, VAT number, REA registration, and certified email (PEC), will be added as soon as they are available and confirmed. For website information, contact support@accordia.tech; this is a support channel and is not presented as a PEC address or formal service address.
2. What this notice covers
This notice covers browsing accordia.tech and using the waiting list, newsletter, and contact form. It does not govern accounts, a marketplace, payments, calls, transcripts, or other future platform features. Specific information will be shown where data are collected before those features launch.
Third-party websites and services reached through links apply their own notices.
3. Data we process and where they come from
| Category | Examples | Source |
|---|---|---|
| Technical and security data | IP address, browser, device, requested page, date and time, logs, errors, and anti-abuse signals | browser, network, and security systems |
| Waiting list and contacts | email, name where requested, role, area, category, message, and submission metadata | information entered by the user |
| Newsletter | email, subscription choice, consent evidence, unsubscribe status, and essential interactions | information entered by the user and the email system |
| Preferences and consent | language, displayed currency, analytics choice, and banners already handled | browser and user choices |
| Optional analytics | pages, events, visit source, pseudonymous identifiers and, only where enabled, masked replay | collected only after consent |
| Form security | Turnstile token and verification result | Cloudflare Turnstile when the user interacts with a form |
We do not ask users to submit sensitive information, identity documents, or unnecessary third-party data through public forms.
4. Why we process data and the legal basis
| Purpose | Legal basis | What happens if data are not provided |
|---|---|---|
| Deliver pages, remember requested choices, and protect the website | legitimate interests in security and reliable delivery; terminal access limited to the technical exemptions under Article 122 | some pages or preferences may not work |
| Reply to a contact or record an early-access request | steps requested before a contract or responding to the request | we cannot handle the message or request |
| Send the newsletter | consent | no newsletter; other content remains available |
| Measure website and campaign use with Amplitude | consent | no effect on use of the website |
| Prevent spam and abuse in forms | legitimate interests in security and, where strictly necessary, necessity for the requested service | the form may not be submitted |
| Meet obligations or protect rights | legal obligation or legitimate interests in legal claims | depends on the request or applicable obligation |
Where we rely on legitimate interests, we limit data to what is necessary and balance our needs against people's rights.
5. Recipients and service providers
Data may be accessible to authorised staff and providers that support hosting, security, email delivery, form handling, optional measurement, and assistance. The website can currently be configured with Cloudflare and Turnstile, Brevo, Amplitude, and server-side observability.
Each active service's privacy role, processing region, subprocessors, and actual retention must be confirmed in the provider register; this notice will be updated when those details are available. Data may also be disclosed to advisers or authorities where required by law or needed to protect rights.
6. Transfers outside the EEA
Some providers may process data outside the European Economic Area. Each active provider must have documented processing locations, applicable adequacy decision, standard contractual clauses, and any supplementary measures; this notice will be updated with confirmed details.
We do not present a transfer safeguard as confirmed until the production provider register is complete.
7. Retention
We retain data only for as long as needed for the stated purpose, taking account of open requests, consent evidence, security, legal obligations, and legal claims. Numerical periods have not yet been approved and are not invented here.
| Category | Deletion or review criterion |
|---|---|
| Waiting list | withdrawal or closure of the early-access phase, except minimal evidence of the request and objections |
| Newsletter | unsubscribe or withdrawal; minimal suppression data may remain to avoid contacting someone who objected |
| Contacts | closure and reasonable follow-up of the request, then only what is needed for obligations or claims |
| Security logs | a period proportionate to risk; longer only for documented incidents or obligations |
| Optional analytics and replay | approved provider settings, consent withdrawal, and minimisation |
| Browser preferences | until changed by the user or site data are cleared |
The retention register must be completed with periods, owners, and deletion events for every system; this notice will be updated when the periods are approved.
8. Newsletter, analytics, and cookies
The newsletter and non-essential analytics require separate choices. Consent can be withdrawn without retrospective effect through the unsubscribe link for email and through cookie controls when available.
Analytics and any replay remain off until the user accepts. Technology, purpose, and duration details appear in the Cookie Policy.
9. Automated decisions and children
The public website does not make decisions based solely on automated processing that produce legal or similarly significant effects. Optional metrics help us understand website use; they do not decide access to a service.
The website is not designed to collect children's data. We do not publish an unapproved age threshold. Before registered-user features open, eligibility, verification, and suitable notices must be defined. A person with parental responsibility may ask us to check or delete data submitted improperly.
10. Security and third-party data
We use proportionate technical and organisational safeguards, including encryption in transit, access controls, rate limiting, anti-bot checks, and error monitoring. No system is risk-free.
Anyone submitting another person's data must have a lawful reason and share only what is necessary.
11. Rights and complaints
Where the GDPR applies, people may request access, correction, erasure, restriction, portability, objection, and withdrawal of consent. They may always object to direct marketing. We may request reasonable information to verify the requester.
People may also complain to the Italian Data Protection Authority or the competent authority where they live, work, or where an alleged infringement occurred. Formal rights-request contacts will appear here only after company details are verified.
12. Updates and legal references
We update this notice when forms, providers, purposes, or obligations change. The dated version published here is the applicable one; material changes will be communicated appropriately.
- Regulation (EU) 2016/679, particularly Articles 12-14 and 15-22
- Italian Data Protection Code, including Article 122
- Italian Data Protection Authority guidelines on cookies and tracking tools dated 10 June 2021