At Giovanni Londi Web Design & Development, your privacy is of utmost importance.
This Privacy Policy outlines how we collect, use, and protect your personal information
in compliance with the General Data Protection Regulation (GDPR).
Last updated: November 2025
1. Data Controller
The Data Controller is Giovanni Londi, Maastricht, Netherlands.
2. Categories of Data Collected
We collect the following categories of data:
2.1. General Website and Contact Data
- Name, email address, phone number
- Project details you voluntarily provide
- Communication and correspondence
- Billing and contractual data
2.2. Technical Data
- IP address, browser type, device information
- Access logs for security and diagnostics
2.3. Automation Services Data
If you use our workflow automation services (email automations, document processing,
personal assistant automations, etc.), we may process:
- Data retrieved via OAuth 2.0 or API tokens
- Calendar data
- Email metadata (not content unless required by the automation)
- Documents and files processed through your workflows
- Automation workflow metadata (timestamps, task logs, execution errors)
We only access data strictly necessary for the requested automation.
3. Purposes and Legal Bases (GDPR Art. 6)
- 3.1. To respond to inquiries
Legal basis: Art. 6(1)(b) – performance of pre-contractual steps
- 3.2. To deliver requested services and automations
Legal basis: Art. 6(1)(b) – performance of a contract
- 3.3. To improve website functionality and security
Legal basis: Art. 6(1)(f) – legitimate interest
- 3.4. To comply with legal obligations (billing, tax, record-keeping)
Legal basis: Art. 6(1)(c)
- 3.5. Optional analytics or marketing (if enabled)
Legal basis: Art. 6(1)(a) – consent
4. Automation Services & Data Protection
When providing automation workflows:
- Secure Authentication: OAuth 2.0, API keys, app passwords
- Revocable Access: You may revoke access at any time
- Encrypted Processing: All data exchanged is processed via encrypted channels
- Minimal Data Access: Only the data required for your requested automation is processed
- EU-based infrastructure: Primary storage and processing kept within GDPR jurisdiction
- Auditing & Logging: Access to user data is limited, logged, and audited
We never request or store your main account passwords.
5. Third-Party Providers (Processors)
We use trusted service providers, including:
- Formspree (contact form)
- Hosting providers and cloud infrastructure
- Automation API providers (depending on workflow)
- Logging and monitoring tools
All providers are bound by GDPR-compliant Data Processing Agreements (DPAs).
6. International Data Transfers
If any provider stores or processes data outside the EU:
- Transfers are protected by Standard Contractual Clauses (SCCs)
- Equivalent GDPR safeguards are applied
- Providers undergo security and privacy assessments
7. Data Retention
- Contact inquiries: up to 12 months
- Project and contractual data: 10 years (legal obligation)
- Automation workflow data: retained only as needed for service delivery
- Technical logs: 30–90 days
Data is deleted or anonymized after the retention period.
8. Your Rights Under GDPR
You may request:
- Access to your data
- Correction of incorrect or incomplete data
- Deletion (Right to be forgotten)
- Restriction of processing
- Data portability
- Objection to certain processing
- Withdrawal of consent at any time
You may file a complaint with:
Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
https://autoriteitpersoonsgegevens.nl/
9. Cookies and Tracking
We use only essential cookies and privacy-friendly analytics (if used):
- No advertising cookies
- No third-party trackers
- Cookies are minimized and configured for GDPR compliance
A separate Cookie Policy may be provided if the site expands its tracking technologies.
10. Security Measures
We implement:
- TLS/SSL secure data transmission
- User authentication and access control
- Encrypted storage
- Security audits and monitoring
- Secure backup and recovery procedures
11. Automated Decision-Making
We do not engage in automated decision-making producing legal or significant effects.
Workflow automations only execute user-defined actions.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services or legal requirements.
Updated versions will be posted on this page.
13. Contact
For privacy inquiries, to exercise your GDPR rights, or for concerns about how your
data is handled, please contact us: