- Home
- Privacy policy
Privacy policy
How we handle the personal data of people who visit this site, under Articles 13 and 14 of Regulation (EU) 2016/679.
Draft: we wrote this text ourselves and a lawyer has not reviewed it yet. The review happens before go-live.
Data controller
The data controller is Luigi Garone, a natural person, who publishes this site under the name Cryptoverso. There is no company today: once there is one, its identifying details — legal name, registered office, VAT number and company register entry — will appear at the foot of every page and on the home page, as Article 2250 of the Italian Civil Code requires, and this policy will say who the controller is from that moment.
While the controller is a natural person, the details that identify them are a name and a contact address, and they belong here: Article 2250 applies to companies, and publishing company rows that do not exist yet would be false information, not extra caution.
The address to write to about any matter concerning personal data is info@cryptoverso.net. It is the same address used to exercise the rights listed below, and the requests that arrive there are read by the controller.
We have not appointed a data protection officer, because none of the cases listed in Article 37 of the Regulation applies to us. If we ever appoint one, this policy will carry their contact details.
Purposes of processing and legal basis
We process personal data only to run this site and to keep it safe. Specifically:
- serving the site: delivering the pages you request, remembering the language you chose and keeping the site reachable. The legal basis is our legitimate interest in providing the service you asked for, under Article 6(1)(f) of the Regulation;
- security and diagnostics: detecting abuse, automated attacks and malfunctions through the technical logs kept by our hosting provider. The legal basis is again legitimate interest, and it is an interest shared by us and by every reader;
- measuring traffic and analysing how the site is used: understanding which pages are read and in what way, with Google Analytics 4 inside Google Tag Manager and with Microsoft Clarity. Here the legal basis is your consent — Article 6(1)(a) of the Regulation and Article 122 of the Italian code — and it is a purpose distinct from the technical ones above: without consent none of those tools is loaded, and no data is collected;
- legal obligations: keeping what a rule of law requires us to keep, for as long as it requires. The legal basis is compliance with a legal obligation, Article 6(1)(c).
There is no contact form on this site today, so we collect no names, no email addresses and no messages. When a form is added, whatever you type into it will be used only to answer you, the legal basis will be steps taken at your request prior to entering into a contract, and this policy will be updated before the form goes live rather than afterwards.
We do not process personal data for marketing purposes and we do not build profiles of our readers. The measurement tools are configured with the advertising fields denied at all times, even for people who accept statistics: their description, cookie by cookie, is in the cookie policy.
Categories of data processed
The only data we process today is navigation data, produced by the plain technical fact that a browser asks a server for a page:
- the IP address the request comes from;
- the date and time of the request, the address of the page requested and the server response code;
- the type and version of the browser and operating system, as the browser itself declares them;
- the referring page, when the browser sends one.
This is the data that appears in the technical logs of any web server. We do not use it to identify individuals and we do not combine it with anything else.
If you consent to the measurement tools, the data those tools collect is added to it:
- statistics: the pages seen and the order they were seen in, where the visit came from, the language, the type of device and of browser;
- session recording: pointer movements, clicks and scrolling, with masking applied to text, form fields and images. The visit is replayed, which is why it is a consent category separate from statistics.
Without your consent none of this data exists at all, because none of the tools that collect it is ever loaded.
We process no special categories of personal data within the meaning of Article 9 of the Regulation, and we never ask about anyone’s wealth, holdings or risk appetite: collecting data about a person’s situation and handing back guidance on financial instruments would be a reserved activity, and we do not carry it out.
What the site stores on your device — one technical cookie for the language, one reading preference, the record of your cookie choice and, for those who consent, the cookies set by Google and by Microsoft — is described in full, name by name, in the cookie policy, reachable from the foot of every page.
Who receives the data
Personal data is never disseminated and never handed to anyone for commercial purposes. It is processed on our behalf, by processors within the meaning of Article 28 of the Regulation, by:
- Google Ireland Ltd., with Google LLC, for Google Tag Manager and Google Analytics 4: only if you consent to statistics;
- Microsoft Corporation, for Microsoft Clarity: only if you consent to session recording;
- the hosting and content delivery provider, which operates the servers this site is served from and the related technical logs;
- the transactional email provider, once there is anything to send;
- professionals who assist us on accounting, tax and legal matters, within the limits of their respective engagements.
The first two are named in full rather than by category, because they are third parties that receive data straight from the reader’s browser: that is a difference which deserves a name rather than a label. Without your consent they receive nothing at all, because their tools are never even loaded.
The named list of the other suppliers is published together with the final controller details, and is available on request.
Transfers outside the European Economic Area
Google and Microsoft may process data in the United States. Both of them state that they adhere to the EU–US Data Privacy Framework and that they apply, in addition or as an alternative, the standard contractual clauses approved by the European Commission.
We report what the two providers state, and we do not certify it ourselves: checking those statements is part of the legal validation still to be done, and writing a safeguard here as established fact would be a stronger claim than we can support today. If you do not consent to the measurement tools, this transfer does not happen at all, because no data leaves your browser for those providers.
The other suppliers listed above may likewise process data in countries outside the European Economic Area. When that happens, the transfer takes place only where one of the safeguards in Chapter V of the Regulation applies: an adequacy decision of the European Commission, or standard contractual clauses approved by the Commission. The safeguard that applies to each of them is stated in the list published together with the final controller details.
Retention period
We do not keep personal data for longer than the purpose it was collected for requires. The criteria are these:
- server technical logs are kept for as long as security and diagnostics require, following the hosting provider’s retention policy, and are then deleted or anonymised;
- any data supplied in a future contact request will be kept for as long as it takes to handle the request and, if a relationship follows, for the duration of that relationship;
- data collected by the measurement tools stays with the respective providers for the period set in the configuration of the Google Analytics 4 property and of the Clarity project. It is a configuration value, and we state it as such: the period actually set is written down alongside the configuration and changes with it, whereas naming a duration here that the provider would not apply would be a reassuring sentence and nothing more;
- the record of your cookie choice stays in your browser for up to six months, after which you are asked to choose again. You can delete it sooner, from your browser settings;
- whatever a rule of law requires us to keep — accounting and tax records first of all — stays for the period that rule sets.
We state criteria rather than a single figure in months, because a retention period picked at random is a false statement: Article 13 expressly allows criteria where the period cannot be determined in advance.
Your rights
Anyone visiting this site may exercise the following rights, within the limits set by Articles 15 to 22 of the Regulation:
- access to your personal data and to information about how it is processed;
- rectification of inaccurate data and completion of incomplete data;
- erasure of your data, in the cases listed in Article 17;
- restriction of processing, in the cases listed in Article 18;
- portability of data processed by automated means on the basis of consent or of a contract;
- objection to processing based on legitimate interest, on grounds relating to your particular situation;
- withdrawal of consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Withdrawing consent to the measurement tools does not require writing to us: it is done from the “Cookie preferences” control at the foot of every page of this site. It is the same control the consent is given with, not a copy and not a different procedure, and that is why withdrawing costs exactly the one click that consenting cost.
One limit we state rather than leave unsaid. The proof of a consent given before having an account lives in the browser of the person who gave it — it is the record described in the cookie policy — and not with us: if you asked us what you consented to, and when, today we would not be able to show it. For people who create an account the record already exists on our side, append-only and readable from the profile page; for consent given without an account it will come, and we name no date, because a date here would be a forecast dressed up as a commitment.
Requests go to the data controller, at the address info@cryptoverso.net given at the top of this policy. We answer within one month of receiving them, as Article 12 requires.
Complaint to the supervisory authority
Anyone who believes that the processing of their personal data infringes the Regulation has the right to lodge a complaint with the Garante per la protezione dei dati personali, the Italian supervisory authority, following the procedure set out on the authority’s own site.
The right to go to court is unaffected. A complaint to the Garante is not a precondition: the two routes are independent of each other.
Whether providing data is mandatory
The navigation data described above is not provided voluntarily: it is generated by the way network protocols work, and without it the server could not answer a request at all. Not processing it would mean not serving the site.
There is no field to fill in anywhere on the site today, so there is nothing you have to give us. When a contact form exists, the fields we genuinely need in order to reply will be marked as required, and declining to fill them in will have one consequence only: we will not be able to reply.
Automated decision-making
We carry out no automated decision-making about individuals, including profiling, within the meaning of Article 22 of the Regulation.
We say so explicitly because on a quantitative research site it is the question a careful reader asks: the algorithms we publish work on historical market series, not on our readers’ data, and none of their results produces legal effects or similarly significantly affects a person.
Updates to this policy
This policy changes when the processing it describes changes — a contact form, a measurement tool, a new supplier — and never merely to make it look better. The revision date at the top of the page is the date of the last substantive change.
The Italian and English versions say the same thing. Should a discrepancy ever emerge, the Italian version prevails, because it is the language of the controller and of the applicable law.