01
Data controller
The data controller is Matteo Feduzi (VAT number 02721960413), a sole proprietor running the PrismaWind project, based at Via Polidoro Virgili 1C, 61033 Fermignano (PU), Italy. For any request about your data, write to us at [email protected].
02
What data we collect
We only collect the data we need, based on how you interact with the site:
Browsing data
IP address, browser and device type, pages visited and access date, collected automatically by the site’s systems.
Data collected by analytics and marketing tools
When you give consent, the tools listed below collect information about your browsing through cookies and similar identifiers: pages viewed, clicks, where the visit came from and, in the case of Microsoft Clarity, pointer movements and scrolling on the pages, which it uses to build heatmaps and session recordings.
Waiting list and communications
Your email and, if you provide it, your name, when you sign up to be notified when sales open and, only if you consent, for news and offers.
Contact requests
The data you give us when you write to us (email and message content), so we can reply to your request.
Live chat
If you open the live chat: what you write in the conversation and, if you provide them, your name and email, managed through tawk.to.
Account
If you create an account to manage your purchases: email, password (which we never store in plain text), active plan, licenses and downloads you have made.
Purchases
The data needed to manage the order, license, billing and payment, if you purchase a plan or a product.
Security logs
Access to the restricted area and sensitive operations on the site, with date, time, IP address and action taken: they help us detect intrusion attempts and reconstruct what happened.
Sites running our plugins and themes
Every installation of the PrismaWind products periodically asks our server whether an update exists and verifies the licence. In that request we receive the site address, the list of installed PrismaWind products with their version, the WordPress and PHP version, the language of the installation, whether it is a multisite network, and the country the request comes from. We also record downloads of our .zip files, with product, date, country and the site or domain they came from. IP addresses are not kept: for each download we only store an encrypted, non-reversible fingerprint of the address, and its key changes every day, so two downloads made on the same day stay distinguishable without anyone being able to reach the person behind them or follow them over time. This data lets us deliver the right updates, keep licences working, and know which WordPress and PHP versions our software has to keep running on. The legal basis is our legitimate interest in maintaining and improving the product (art. 6.1.f GDPR); you can object at any time by writing to us, and we erase everything concerning your site.
03
Why we use your data and on what basis
- To send you the sales-opening notice and, if you gave consent, marketing communications: the legal basis is your consent, which you can withdraw at any time.
- To measure how the site is used and show you relevant ads through the analytics and marketing tools: the legal basis is your consent, given through the cookie banner and revocable whenever you want.
- To reply to you through live chat: the conversation relies on our legitimate interest in providing you with support; the cookie that recognizes you from one page to another during the conversation only starts with your consent.
- To manage accounts, purchases, licenses and support: the legal basis is the performance of the contract.
- To keep the site secure and working, security logs included: the legal basis is our legitimate interest in protecting the service from unauthorized access.
- To meet legal obligations, such as tax and accounting requirements.
04
When data is mandatory
You don’t have to give us anything to read the site. In other cases the data is needed to do what you ask us, and without it we can’t do it:
Contact form
Without an email and a message we can’t reply to you. The name is optional: it only lets us address you by name.
Waiting list
Without an email we can’t notify you when we open sales. The name is optional.
Live chat
Without a message we can’t help you in the conversation. Name and email are optional.
Account and purchases
Billing and payment data are required by tax law: without them we can’t issue the invoice or grant the license.
Analytics and marketing cookies
They are always optional. If you decline them the site works just the same and you don’t lose any function.
06
Profiling and automated decisions
When you give consent to the marketing tools, Meta, LinkedIn, Google Ads, Reddit and Microsoft Advertising can group you into audience segments based on the pages you visited, to show you more relevant ads on their platforms. This is profiling for advertising purposes, and it stops the moment you withdraw consent from the cookie banner.
We don’t make automated decisions that produce legal effects on you or that affect you in a similarly significant way: no system decides on its own whether to sell you a license, at what price, or whether to give you support. We don’t assign you scores and we don’t use your data to assess aspects of your person beyond the advertising just described.
07
Who we share data with
We don’t sell your data. We share it only with the providers who let us deliver the service: the email platform (MailerLite), our hosting provider, the payment providers when you make a purchase (Stripe and PayPal), the live chat provider (tawk.to) and the providers of the analytics and marketing tools listed above (Google, Meta, Microsoft, LinkedIn and Reddit). Most of these providers process the data as a processor, only on our behalf and for the purposes described here. For Meta Pixel and Reddit Pixel we are instead joint controllers together with the provider for the data collected through the pixel, as established by European case law (Court of Justice of the EU, Fashion ID case, C-40/17): the details are in the cookie policy.
08
Transfers outside the European Union
Some providers, such as MailerLite, Meta, Google, Microsoft, LinkedIn, Reddit and tawk.to, may also process data in the United States or in other countries outside the European Union. In these cases the transfer takes place with the safeguards required by the GDPR, such as the standard contractual clauses approved by the European Commission or the provider’s adherence to the EU-US Data Privacy Framework.
09
How long we keep the data
Each piece of data stays with us only for as long as needed for the purpose we collected it for. The time varies depending on the legal basis:
Data processed with your consent
The email on the waiting list, the marketing communications you signed up for and the data collected by the analytics and marketing tools stay until you withdraw consent or unsubscribe; for third-party tools the individual providers’ own timeframes also apply, listed in the cookie policy.
Data processed for our legitimate interest
The technical and security logs we use to protect and run the site stay for as long as they serve that purpose; write to us at [email protected] if you want to know how long the retention lasts in a specific case.
Contractual and tax data
Account, order, license and billing data stay for the duration of the contract and then for the period required by tax and accounting law, generally ten years.
Data about the sites running our products
A site’s record is deleted twenty-four months after the last update check we received, so a site that stops using our products disappears on its own. Download data is kept for twelve months. The deletion is carried out by an automated job that runs every day.
If a law or an order from the authorities requires us to keep it longer, we comply with that term.
10
Your rights
On the data we process, you have the same rights the GDPR grants to everyone in Europe. To exercise them, write to [email protected]: we reply within the legal deadlines, usually one month.
Access
You can ask us to confirm that we process your data and get a copy, with source, purpose and categories of recipients.
Rectification
If a piece of data is incomplete or wrong, you can ask us to correct it.
Erasure
You can ask us to delete your data when it’s no longer needed for the purpose we collected it for, when you withdraw consent or object to the processing, unless we must keep it for a legal obligation.
Restriction
You can ask us to temporarily suspend the use of a piece of data, for example while we check an inaccuracy you reported to us: in the meantime we only store it, without processing it for anything else.
Objection
When we process a piece of data for our legitimate interest, such as the security of the site, you can object at any time; we stop processing it unless we have legitimate grounds that override yours.
Portability
For data we process with your consent or to perform a contract, you can ask us for it in a machine-readable format or have it transferred to another provider.
Withdrawal of consent
You can withdraw it whenever you want, without affecting the processing already carried out before the withdrawal.
Complaint
If you believe we have processed your data incorrectly, you can turn to the Italian Data Protection Authority (Garante) or to a court.
11
Changes to this policy
We may update this notice when the services we use change, the tools installed on the site change or the rules we must follow change. The date at the top of the page shows the last revision, and it only changes when the text changes.
If the change substantially affects how we process your data — a new purpose, a new provider, a processing activity that requires your consent — we tell you before it takes effect, with a notice on the site and, if you have an account or are on the waiting list, by email. When the change concerns a processing activity based on consent, we ask for your consent again: the old one doesn’t cover new purposes.
