IOD21.iod21 / legal
Log inAccedi

Draft, not in force. To be reviewed by the privacy consultant before launch (GDPR art. 13, records of processing, data processing agreements with the providers listed below).

Bozza da far rivedere al consulente privacy prima del lancio (art. 13 GDPR, registro dei trattamenti, nomine dei fornitori).

Privacy note

Version 0 · October 2026 · Controller: IOD21 Srl · information@iod21.com (registered address to be added)

What we collect

  • Creator applications: name, email, link and description you send with the form, to reply to you.
  • Creator accounts: login email, public name, payment provider and account id, kit content and review history.
  • Buyers: the email that receives the unlock code (received from the creator's checkout), a keyed hash of the code and of each computer. We do not see card or payment details.
  • Security logs: events without personal data; IP addresses only as keyed hashes, for rate limits.

Cookies

Only a strictly necessary session cookie after you log in (HttpOnly, not readable by scripts). No analytics, no advertising cookies.

Providers

Supabase (database and login, EU region), Vercel (hosting), Resend (email with the code). Creators use their own Stripe or Polar account as independent controllers for their sales.

How long

Applications: 12 months. Accounts: while active, then as required by tax law for invoicing data. Security logs: to be defined (proposal: 12 months).

Your rights

Access, correction, deletion, restriction, portability, objection, and complaint to the Italian Data Protection Authority (Garante). Write to information@iod21.com.