Privacy policy
Last revised: 18 September 2026
We use Cloudflare Web Analytics to understand page visits and site performance, without measurement cookies or persistent identifiers in the browser. Data you voluntarily send through the contact form follows the rules described in the privacy policy.
The data controller
DEEXMA LABS - SOCIETÀ A RESPONSABILITÀ LIMITATA (single-member limited liability company), Via Romualdo Marenco 28, 00124 Rome (RM), Italy — Tax code / VAT no. 18654381005, REA RM-1798329.
For any matter concerning personal data: PEC (certified email) [email protected]. No DPO has been appointed: the company’s size and processing activities do not require one.
The contact form
If you submit the form we process: first and last name, business email, company (optional) and the description of the process you tell us about. Name, email and description are necessary: without them we cannot reply, and failing to provide them only means we cannot handle the request. The mandatory checkbox confirms that you have read this notice: it is not consent, and it is not the legal basis for the processing.
Requests you send are received by the site’s functions hosted on Cloudflare Pages and stored in Cloudflare D1. The database is accessible only to authorised personnel through the provider’s reserved tools. A copy of the request, with the contact details and the message, is sent through Cloudflare’s email service to the company mailbox so that we can reply; it is therefore also processed by the business email providers.
Purposes and legal bases: replying to and assessing the request. When you write on your own behalf, this concerns pre-contractual measures taken at your request (Art. 6(1)(b) GDPR); when you write on behalf of a company, the basis is legitimate interest (Art. 6(1)(f)) in handling the commercial contacts you initiate — processing you may object to at any time using the objection described below.
Retention in the site database: 12 months from submission of the request; if a collaboration begins, the data becomes part of the contractual relationship and is kept for its duration and for the statutory periods that follow (10 years for administrative and accounting records). No profiling: requests are read by a person.
A courtesy we ask of you: in the free-text field describe processes, not people. We do not need — and you should not enter — third parties’ personal data (employees, clients) or special categories of data: the workflow is enough for a first assessment.
The second checkbox — optional and never pre-selected — concerns receiving email communications about Deexma Labs’ services and case studies, at most once a month. Legal basis: consent (Art. 6(1)(a) GDPR; Art. 130 of the Italian Privacy Code). It can be withdrawn at any time, as easily as it was given: via the link in every communication or by writing to the PEC, with immediate effect and without affecting the lawfulness of prior processing. Consent is kept together with its proof and the request for a maximum of 12 months, unless withdrawn earlier.
Submitting the form is protected by anti-abuse measures without a visible CAPTCHA: a honeypot field for bots and a single-use technical token of limited validity, which is not used to recognise you between visits. At submission the system may process your IP address in pseudonymised form (hash) for the sole purpose of limiting bulk submissions, kept for a maximum of 30 days. Legal basis: legitimate interest (Art. 6(1)(f)) in the security of the service.
Interactive AI surfaces
The home demo, the lab’s search and audit functions and the request-drafting assistant in the contact section, when interactive mode is configured, process the free text you choose to send, on your own initiative. Outputs are produced by an artificial intelligence system and are marked as such in the notice next to the surfaces. If interactive mode is not configured, the surfaces show only pre-computed examples or fixed-question guided paths, without artificial intelligence, and send no text to external services.
The assistant in the contact section only drafts a summary of your request: in the guided path without AI the draft is created and stays in your browser, while in AI mode the answers and the draft pass through the systems described in this section solely to generate them, and are not stored. In either case the conversation is not kept and the draft does not become a request until you decide to submit the form, after reading it and editing it if needed: from then on the request follows the rules of the section “The contact form”, including 12-month retention.
Purposes and legal basis: providing the demonstration or assistance requested and showing you the generated answer. The processing is necessary to perform the service requested by the data subject (Art. 6(1)(b) GDPR).
Categories of recipients: language-model providers, to which the text is transmitted to generate the answer and which act as processors or independent controllers under their respective applicable terms.
Processing by those providers takes place outside the European Union. The transfer is subject, where applicable, to the safeguards under Chapter V GDPR; you may ask the controller for information about the applicable safeguards and a copy of them.
The controller does not keep the texts sent or the answers generated. It records only a technical event with the purpose of the request, the pseudonymised hash of the IP address, the date and a prudent token budget reserved for the request. Text logging is disabled. The technical event is deleted at the first daily cleanup after 48 hours from the request, and in any case within 30 days for security, usage-limit control and abuse-prevention purposes.
As indicated next to the fields, do not enter personal data of your own or of third parties, or special categories of data: non-personal content is enough to try the surfaces.
Hosting, recipients and technical logs
The public site is delivered through Cloudflare Pages, a service of Cloudflare, Inc., which acts as processor under Art. 28 GDPR pursuant to its own Data Processing Addendum. Pages and static assets are served through the provider’s global network. When a user accesses the site, Cloudflare processes the technical data needed to route and protect traffic — including IP address, routing data and system information — and may make some of it available to the controller as technical logs. Legal basis: legitimate interest in the security and operation of the site (Art. 6(1)(f) GDPR); retention follows the service terms and the criterion of necessity with respect to delivery and security.
Categories of recipients: hosting and infrastructure service providers, acting as processors. Cloudflare, Inc. delivers the public site, runs the functions that receive requests and stores data in Cloudflare D1, under its own Data Processing Addendum. The publishing configuration provides for a database with European Union jurisdiction; this constraint concerns the database and does not geographically limit the global network of the functions. We do not sell or transfer data to third parties for their own purposes.
Transfers outside the EU: for hosting and infrastructure services, processing may take place outside the Union, covered by the safeguards of Chapter V GDPR (standard contractual clauses included in the providers’ DPAs and, where applicable, adequacy decisions). You may ask the controller for a copy of the safeguards.
Cloudflare Web Analytics
The site loads a small Cloudflare script to measure page views, visit sources, loading times and Core Web Vitals. According to the provider documentation, Web Analytics uses no cookies or localStorage for measurement and does not fingerprint visitors.
The browser downloads the script from static.cloudflareinsights.com and sends metrics to cloudflareinsights.com. We add no contact-form data, AI conversation texts or custom events to the beacon. The statistics can be viewed by the controller in the Cloudflare dashboard; details about the provider and transfers are in the privacy policy.
We do not use Cloudflare Web Analytics for advertising or profiling and we keep no measurement preferences in the browser.
Your rights
Within the limits of Articles 15-22 GDPR you may exercise at any time, by writing to the controller’s PEC (or, when active, via the contact form), the rights of:
- access to the data concerning you and information about their processing;
- rectification of inaccurate or incomplete data;
- erasure, in the cases provided for;
- restriction of processing;
- portability, for data you have provided and that is processed by automated means on the basis of a contract or consent;
- objection to processing based on legitimate interest, for reasons relating to your particular situation;
- objection to promotional communications: at any time, without any reason, with immediate effect;
- withdrawal of consent, for processing based on it, without affecting the lawfulness of prior processing.
We reply within one month of the request; the period may be extended by two months for complex or numerous requests, in which case we inform you within the first month with the reasons (Art. 12 GDPR). If you believe that processing infringes the law, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
No automated decisions
We do not profile or make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals (Art. 22 GDPR).
Minors
This site is aimed at companies and professionals. We do not knowingly collect data of children under 14; if you believe this has happened, write to us and we will erase it.
Changes to this notice
If processing changes — a new tool, a new provider, a new purpose — this page is updated before the change becomes operational, with the revision date at the top. Previous versions are available on request.