Skip to content
matt88.it
  • Home
  • Software
    • All software
    • Vistario
    • Sentinelux
    • Bashloom
  • Projects
    • All projects
    • Home Energy Meter
    • Bashloom
    • Oriqo
    • Cabinet Edge
  • Services
    • All services
    • IoT & edge software
    • Monitoring dashboards
    • Automation & APIs
  • About
  • Contact

Home / Privacy Policy

Legal documentation / personal data

Privacy Policy

Transparent information about technical data, Contact form submissions, first-party traffic analytics and the infrastructure used by the site.

Last updated
1 September 2026
Document status
Current technical configuration
Analytics model
First-party, diagnostic and without analytics cookies
On this page
matt88 / legal registerEN
Privacy PolicyCurrent technical configuration
010203
READABLETRACEABLEMINIMISED

On this page

  1. 01 Data controller
  2. 02 Technical browsing data
  3. 03 First-party analytics, acquisition and traffic classification
  4. 04 Purposes and legal basis for technical data
  5. 05 Contact form and email
  6. 06 Browser and administration storage
  7. 07 Infrastructure and recipients
  8. 08 Rights and changes

This notice describes how matt88.it processes data in its current configuration, including the Contact form, the first-party analytics system and the protected administration area.

01

Data controller

The data controller is Matteo D’Urso, owner of matt88.it.

Privacy requests can be submitted to the public info@matt88.it address shown on the Contact page.

02

Technical browsing data

Hosting, delivery and security systems process the data needed to return pages, protect the service and diagnose faults.

  • IP address and request timestamp
  • requested path, response status and technical errors
  • user agent, browser, operating system, device category and referrer
  • country, region, city and time zone estimated by Vercel from the IP address

IP geolocation is approximate and may be affected by VPNs, proxies, mobile networks or corporate infrastructure.

03

First-party analytics, acquisition and traffic classification

Each eligible load of a public route creates a page view and updates daily, per-page, geographic, referrer and client-family aggregates. For likely human visitors, the system also aggregates the acquisition channel and landing page while excluding ordinary internal navigation.

The system records selected commercially meaningful interactions in aggregate form, including clicks towards Contact, the first start of the form, successful brief submissions, GitHub inbound and outbound activity, and clicks towards software repositories or releases. Name, email, organisation, message text, budget range and other free-form Contact content are not copied into analytics.

Traffic events receive a probabilistic classification as likely human, likely bot or unknown. Classification uses technical signals such as user agent, navigator.webdriver, Sec-Fetch headers and request frequency; it is not automated decision-making producing effects on the data subject.

Server-side HMAC identifiers estimate visitors and sessions. The visitor identifier changes each day and the session identifier uses windows of about 30 minutes. No analytics cookie or browser identifier is written.

Purposes are security, diagnostics, understanding abnormal traffic, technical measurement of the service and internal assessment of which pages or evidence generate interest in a possible project. Data is not used for advertising, behavioural marketing, individual commercial profiling or cross-site tracking.

Encrypted IP address
Stored in recent traffic diagnostic events for no more than 7 days and shown only in the authenticated Admin area; conversion events do not create a second raw log containing IP addresses.
User agent and referrer
Stored in recent traffic diagnostic events for no more than 7 days; query strings and fragments are removed from referrers.
HMAC identifiers
Network, daily visitor and session identifiers; the server secrets are required to relate them to the source data.
Temporary lead attribution
After a click towards Contact, the daily visitor HMAC may link a later successful submission to its source page server-side for up to one hour. The temporary key is not written to the browser and contains no Contact form data.
Conversion aggregates
Counts by event, source, engagement mode, acquisition channel and landing page; daily aggregates are retained for up to 400 days and overall aggregates until manual deletion or migration.
Daily unique sets
Estimated visitors and sessions are retained for up to 120 days.
Daily traffic aggregates
Page views and daily technical dimensions are retained for up to 400 days.
Overall aggregates
Retained until manual deletion or migration.

IP addresses, user agents and online identifiers may constitute personal data. Detailed diagnostic events are restricted to the protected administration area; the acquisition dashboard exposes aggregates rather than personal brief content.

04

Purposes and legal basis for technical data

Technical and analytics data is processed for the controller’s legitimate interests in protecting the site, identifying automated or abusive traffic, diagnosing faults, internally assessing page use and understanding the effectiveness of surfaces that lead to project enquiries under Article 6(1)(f) GDPR.

Data minimisation, pseudonymisation, encryption, aggregation, environment separation and limited retention are applied. Data subjects may object where provided by law.

05

Contact form and email

The form processes data voluntarily supplied to assess and respond to an enquiry about a potential project or service.

Name, email address and message are required. Organisation, preferred engagement mode, project type, current state, timeframe and indicative budget range are optional and are used only to provide context for the initial review of the enquiry.

The legal basis is taking steps at the data subject’s request prior to entering into a contract under Article 6(1)(b) GDPR. Brief data is not used for marketing or profiling.

The enquiry is delivered to info@matt88.it. The visitor receives an automatic confirmation and subsequent replies are handled manually. After successful delivery, an analytics submission counter is incremented with only the language and selected engagement mode, if any; name, email, organisation, message, budget and other brief contents are not duplicated.

Retention
For the time needed to assess, answer and document the enquiry; longer only where a contractual relationship, legal obligation or legal-protection need arises.
Abuse prevention
An HMAC identifier derived from the network address is stored in Redis for about one hour solely to limit abuse; the message content is not stored in Redis.
Recipients
The controller and technical providers required for hosting, rate limiting, first-party analytics and email delivery.
Automated decisions
No profiling or automated decision-making; enquiries are reviewed manually.

Do not submit passwords, tokens, private keys, unnecessary personal data, confidential code or details that could facilitate unauthorised access.

06

Browser and administration storage

The site uses limited first-party storage for interface and operational functions. The analytics system, including aggregate conversion measurement, does not create cookies or localStorage values to identify visitors.

matt88_locale
Technical cookie remembering the language for 12 months; SameSite=Lax.
matt88:color-scheme
localStorage value containing light or dark until changed or removed.
matt88_legal_ack and matt88:legal-ack
Technical cookie and localStorage value set to v2 that record acknowledgement of the information banner for 12 months.
countBypass
Optional localStorage value set from the protected Admin area; when true, this browser does not send traffic or conversion analytics requests.
matt88_admin_session
HttpOnly, SameSite=Strict signed session cookie used only after successful admin authentication; maximum duration 8 hours.

countBypass remains local to the browser and its value is not transmitted; it only controls whether analytics requests are sent.

07

Infrastructure and recipients

Vercel delivers the site and provides IP-geolocation headers. Upstash Redis stores traffic and conversion aggregates, encrypted recent diagnostic events and temporary rate-limit or attribution tokens. The mail server associated with info@matt88.it handles email delivery.

Data is not sold, used for advertising or combined with information about activity on other sites.

Vercel Privacy Notice Vercel Data Processing Addendum Upstash Privacy Policy Upstash Data Processing Agreement
08

Rights and changes

Where the GDPR applies, data subjects may request access, rectification, erasure, restriction or object where provided by law and may lodge a complaint with the competent authority.

This notice will be reviewed before enabling advertising, third-party embeds, payments or non-essential terminal tracking technologies.

Regulation (EU) 2016/679

Related documents

Review the other legal and technical notices

Cookies Legal notice Open the Contact page

© 2026 matt88.it

  • Software
  • Projects
  • Services
  • About
  • Contact
  • Privacy
  • Cookies
  • Legal notice