Privacy Policy
Last updated: 2026-06-24
This Privacy Policy explains how CodeCraft Solutions (“CodeCraft”, “we”, “us”, “our”) collects, uses, and protects your personal data when you visit codecraftssolutions.com or engage our services.
Data controller (Titolare del trattamento): CodeCraft Solutions, established in Italy.
Registered address: Via Giacomo Leopardi, 2, 81028 Santa Maria a Vico, Italy.
Data contact: legal@codecraftssolutions.com
We process your personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and applicable Italian data-protection law (Legislative Decree no. 196/2003 as amended by Legislative Decree no. 101/2018).
1. Data We Collect
1.1 Enquiry and contact form data
When you submit a quote request or contact form, we collect your name, email address, phone number (if provided), and the contents of your message. We use this data to respond to your enquiry, produce a project scope, and manage our client relationship. Lawful basis (GDPR): legitimate interests / pre-contractual steps.
1.2 Service delivery data
If you become a client, we collect additional information necessary to deliver the agreed service — for example, server access credentials (handled securely and deleted after handover), project specification details, and billing information. Lawful basis (GDPR): performance of contract.
1.3 Analytics data (Google Analytics 4 — consent-gated)
If you accept analytics cookies, we use Google Analytics 4 to collect anonymised data about how visitors use this website — pages visited, session duration, device type, and country-level location. IP addresses are anonymised. Google Analytics 4 data is processed by Google LLC under a Data Processing Agreement. We do not use this data to identify you personally. Lawful basis (GDPR): consent (you may withdraw at any time via the “Manage cookie preferences” link in our footer). For US visitors: you may opt out via your browser settings or Google’s opt-out tools.
1.4 Technical / server log data
Our web hosting provider automatically records standard server logs — IP address, browser type, referring URL, and page requested. These logs are used solely for security monitoring and technical troubleshooting. They are retained for a maximum of 30 days. Lawful basis (GDPR): legitimate interests (security).
1.5 Cookie data
See our Cookie Policy for a full breakdown of cookies used on this site.
2. How We Use Your Data
We use your personal data only for the purposes listed above. We do not sell your data. We do not share your data with third parties for their own marketing purposes.
Third parties we share data with:
- Resend — our transactional email service provider. Data processed under Resend’s Data Processing Agreement.
- Google LLC (Google Analytics 4) — analytics processing, consent-gated. Subject to Google’s Privacy Policy and standard contractual clauses.
- Our web hosting provider — server infrastructure. Data processed under a Data Processing Agreement.
3. Data Retention
| Data type | Retention period |
|---|---|
| Enquiry / contact form data | 2 years from last contact, unless you become a client |
| Client project data | 5 years from project completion (contractual record-keeping) |
| Analytics data | 14 months (GA4 default, not extended) |
| Server logs | 30 days |
4. Your Rights
If you are located in the EU, EEA, or UK, you have the following rights under the GDPR or equivalent legislation:
- The right to access the personal data we hold about you
- The right to rectification of inaccurate data
- The right to erasure (“right to be forgotten”) where we have no legal basis for continued retention
- The right to restriction of processing
- The right to data portability
- The right to object to processing based on legitimate interests
- The right to withdraw consent at any time (for consent-based processing, including analytics cookies)
- The right to lodge a complaint with a supervisory authority (in Italy: the Garante per la protezione dei dati personali — www.garanteprivacy.it)
If you are located outside the EU/EEA, you may have equivalent rights under your local data-protection law; you may exercise them using the same contact details below.
To exercise any of these rights, email: legal@codecraftssolutions.com. We will respond without undue delay and in any event within one month of your request, as required by the GDPR. You also have the right to lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it).
5. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include HTTPS encryption on all pages, secure handling of credentials, and access controls on data storage.
6. International Transfers
CodeCraft Solutions is based in Italy (EU), and your personal data is controlled from within the European Union. Some of our service providers (including Resend and Google) may process data on servers located in the United States or other countries outside the EU/EEA. Where that occurs, such transfers are covered by appropriate safeguards under Chapter V of the GDPR — including the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework.
7. Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has submitted data to us, contact legal@codecraftssolutions.com and we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect any changes. Continued use of the site after a material change constitutes acceptance of the updated policy.
9. Contact
For all privacy-related enquiries, data subject rights requests, or complaints:
Email: legal@codecraftssolutions.com
Post: Via Giacomo Leopardi, 2, 81028 Santa Maria a Vico, Italy