SKIP TO CONTENT
Leonardo Parisi
LEGAL

Privacy Policy

LAST UPDATED2 August 2026

This page explains which personal data I collect through imleo.it, why I collect it and what rights you have. It is the notice required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

01Data controller

The data controller is Leonardo Parisi, VAT number 03356630214, established at Via Palermo 46, 39100 Bolzano (BZ), Italy, working as a freelance developer.

You can reach me at any time at parisii.leonardo@gmail.com or by certified email at parisileonardo15@pec.it. No Data Protection Officer has been appointed, as the legal conditions requiring one do not apply.

02Data I collect

I only collect what I need to reply to you and to keep the site running. There are no accounts, no newsletter, no profiling and no sale of data to third parties.

  • What you type into the contact form: name, email address, the project type you picked and the text of your message.
  • The language you were browsing in, stored with the message so I can reply in your language.
  • Technical details of the request: an encrypted version (SHA-256 hash with a secret key) of your IP address, used only to count submissions in quick succession and block abuse. The plain IP address is never kept.
  • Technical logs generated automatically by the hosting provider for security and diagnostics.
  • Aggregated, anonymous traffic statistics, collected without cookies and without persistent identifiers.

03Why I process it, and on what legal basis

  • To answer enquiries sent through the form or by email, and to prepare a quote where relevant: pre-contractual measures taken at your request, Art. 6(1)(b) GDPR.
  • To protect the site from automated submissions and abuse, through rate limiting and an anti-bot honeypot field: legitimate interest, Art. 6(1)(f) GDPR.
  • To understand in aggregate which pages work, with no cookies and no profiling: legitimate interest, Art. 6(1)(f) GDPR.
  • To meet tax and legal obligations, should the enquiry turn into an engagement: legal obligation, Art. 6(1)(c) GDPR.

04How long I keep it

  • Messages received through the form: they arrive in my mailbox and stay there for up to 24 months from our last exchange, then they are deleted. If the enquiry becomes an engagement, the data required by accounting and tax rules is kept for 10 years.
  • Anti-abuse data tied to rate limiting: it lives in the server's temporary memory for a few minutes and is never stored anywhere.
  • System logs held by the hosting provider: for their own technical retention period, usually a few days.

05Who processes data on my behalf

A few selected providers keep the site running. They act as processors under Art. 28 GDPR. Data is not disclosed to anyone else and is never published.

  • Vercel Inc. — website hosting and content delivery network.
  • Resend (Plus Five Five, Inc.) — the service that delivers the email generated by the form to my mailbox.
  • Google Ireland Ltd. — provider of the mailbox where I receive and keep your messages.
  • Public authorities, where disclosure is required by law.

06Transfers outside the European Union

Some providers are based in the United States. Transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the provider's certification under the EU-U.S. Data Privacy Framework, together with supplementary measures such as encryption in transit.

07Cookies and analytics

The site uses strictly technical cookies only, which do not require prior consent under Art. 122 of the Italian Privacy Code — which is why you see no banner. Traffic statistics are collected in aggregate, without cookies and without persistent identifiers.

Typefaces are served directly from this site: your browser makes no request to Google servers to display them.

The full detail is in the Cookie Policy.

08Your rights

You can exercise the rights granted by Articles 15-22 GDPR at any time by writing to the addresses above. I reply within 30 days.

  • Access the data concerning you and obtain a copy of it.
  • Ask for it to be corrected if it is inaccurate or incomplete.
  • Ask for it to be erased — for instance once a message is no longer needed.
  • Ask for processing to be restricted, or object to processing based on legitimate interest.
  • Receive your data in a structured, machine-readable format (portability).
  • Lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it), or your local supervisory authority, if you believe the processing breaches the law.

09Security

The site is served over encrypted HTTPS only. Messages are stored in no database: they travel from the form straight to my mailbox, which is protected by a password and two-step verification. Service keys stay on the server and are never part of the code sent to your browser. Your IP address is only ever handled in an encrypted, non-reversible form.

10Children

The site addresses professionals and companies and is not intended for children under 14. I do not knowingly collect data from children: if you notice that this has happened, write to me and I will delete it.

11Automated decision-making

There is no profiling and no automated decision-making producing legal effects concerning you.

12Changes to this notice

If the site changes tools or purposes, I update this page along with the last-updated date at the top. It is worth re-reading it from time to time.

ContactLeonardo Parisi — VAT 03356630214 · Via Palermo 46, 39100 Bolzano (BZ), Italy · Phone +39 345 735 4180 · Email parisii.leonardo@gmail.com · Certified email parisileonardo15@pec.itBACK TO THE SITE