Privacy & Cookies
How we handle your personal data, under EU Regulation 2016/679 (GDPR). Trust is part of the product: no tricks, no fine print.
01 Data Controller
CIAOBOB di Sulpizi Massimo (sole proprietorship) — Civitanova Marche (MC), Italy. VAT 02544850445 — REA FM-298197. PEC: ciaobob@pec.it · Email: info@ciaobob.it. The Controller determines the purposes and means of processing the personal data collected through this site.
02 Data we collect
Data you provide: name, email and message sent through the contact form.
"Ask B0B" chat (AI demo): the messages you type in the chat and, only if you tick the consent box, the name, email and conversation you forward as a callback request.
Checklist sign-up: your email, your name if you provide it, plus the date and IP address of the moment you gave consent — the latter two exist to demonstrate that consent was given (Art. 7.1 GDPR).
Technical data tied to a request of yours: when you submit the form or leave your details with B0B we record your IP address and browser type as an anti-abuse measure, for up to 90 days.
Visit statistics: page, language and source, in aggregated form and with no IP address or user agent (see the Cookies section).
Cookies and local storage: see the dedicated section.
03 Purposes and legal basis
Responding to requests you send via the contact form or the B0B chat — legal basis: pre-contractual measures (Art. 6.1.b GDPR).
Running the "Ask B0B" demo and generating the assistant's replies — legal basis: delivery of the service you request by interacting with the chat. B0B makes no automated decisions producing legal effects concerning you (Art. 22 GDPR): it is only a conversational tool.
Improving the site through aggregated statistics collected by our own servers, with no cookies and no personal data — legal basis: legitimate interest (Art. 6.1.f).
Sending you the checklist you requested and the informational emails that come with it — legal basis: your consent (Art. 6.1.a). Four emails over two weeks, then the sequence ends. Every message carries a one-click unsubscribe link that works without writing to us and without explanations; you may also withdraw consent by replying to any of the emails. Withdrawal does not affect the lawfulness of earlier sends.
Complying with legal obligations.
04 Cookies
We only use essential technical cookies required for the site to work (session and form protection): they need no consent, which is why you will not see a consent banner. We use no profiling cookies, host no third-party trackers and share no data with advertising networks.
Visit statistics are collected by our own servers, not by third-party scripts: no cookies, no external trackers, no IP address or user agent stored. Visitors are counted through a pseudonymous identifier that changes every day and cannot be used to recognise you over time or to reconstruct your identity. Aggregated data is kept for at most 400 days. Legal basis: legitimate interest in understanding how the site is used (Art. 6.1.f GDPR).
The site stores some technical preferences on your device through the browser's local storage (for example the light/dark theme). They stay on your device, are never sent to us and can be cleared from your browser settings.
05 Data retention
Contact data is kept for as long as necessary to handle your request and to comply with legal obligations, and in any case no longer than 12 months from the last contact. A conversation attached to a request sent via B0B is kept no longer than 6 months. Technical data (IP address, user agent) no longer than 90 days. Once these terms expire, data is deleted or anonymized.
Checklist subscriber data is kept for as long as you stay subscribed. If you unsubscribe, we keep only your address and the unsubscribe date so that we never write to you again by mistake; everything else is deleted.
If the request leads to a professional relationship, contact data is kept for the duration of that relationship and for the following ten years, the term Italian law sets for accounting records (Art. 2220 of the Italian Civil Code) — legal basis: performance of the contract and legal obligations (Art. 6.1.b and 6.1.c GDPR). The shorter terms above for conversations and technical data still apply in this case.
06 Sharing and transfers
We do not sell your data. It may be processed by technical providers (hosting, email) appointed as data processors, in compliance with the GDPR. No transfer outside the European Union takes place without adequate safeguards.
07 Security
We adopt appropriate technical and organizational measures: encryption in transit (TLS 1.3) and at rest (AES-256), least-privilege access and audit logs, in line with the Security section of the site.
08 Your rights
You have the right to access, rectification, erasure, restriction, portability and objection (Art. 15–22 GDPR), as well as the right to lodge a complaint with the data protection authority. To exercise your rights, write to info@ciaobob.it: we reply within the legal terms.
09 Changes
This policy may be updated over time. The last-updated date is shown at the top; please review it periodically.