— Legal · Privacy

Privacy notice

What we collect when you visit naniza.io or get in touch, why we collect it, and how you can control your data. Written in plain English, aligned with the GDPR.

Updated · October 4, 2026

01 — Data controller

The data controller is Naniza Srl, registered office at [registered address pending], VAT / Tax ID [pending], registered with the Italian Companies Register under no. REA [pending].

For any request about your personal data you can write to hello@naniza.io. Naniza has not appointed a Data Protection Officer (DPO) because the conditions of Art. 37 GDPR do not apply.

02 — Data we collect

We collect the data needed to reply, provide requested resources, and manage the commercial relationship. We do not buy data from brokers or enrich contacts with external sources.

  • Contact form (/contact): name, work email and — optionally — website and a free-text note with your context.
  • Creative Framework whitepaper form: full name, work email, website, and campaign source. We record the contact source and lead stage in Attio.
  • If you accepted the Marketing category in the consent banner, we may associate Meta _fbc and _fbp identifiers or the click ID with the lead and send Meta the lead event and any move to Qualified. Email and name are normalized and SHA-256 hashed before transmission; hashing does not make the data anonymous.
  • Technical request data: IP address, browser user-agent and referrer of the originating page, stored with the message for security and anti-spam.
  • Email correspondence: if you reply by email, we keep the exchange in our mail systems.
  • Server logs: our hosting provider records technical logs (IP, response times) for operational and security purposes, retained for a limited period.

03 — Purposes and legal bases

We process your data to:

  • Reply to your request and arrange the free meeting or follow-up — legal basis: pre-contractual measures at your request, Art. 6(1)(b) GDPR.
  • Comply with legal obligations (tax, accounting, contractual) if you become a client — legal basis: legal obligation, Art. 6(1)(c) GDPR.
  • Pursue our legitimate interests — site security, abuse prevention, anti-spam — legal basis: Art. 6(1)(f) GDPR.
  • Measure leads and qualified leads from Meta campaigns and optimize those campaigns, only if you accepted the Marketing category — legal basis: consent, Art. 6(1)(a) GDPR.

We do not send newsletters without an explicit subscription or make automated decisions about your access to services. If you accept Marketing, Meta may process the received data for advertising attribution and optimization under its own terms.

04 — Recipients and processors

To run the site and handle requests we use external providers. Their roles, contractual safeguards, and transfers depend on the service:

  • Vercel Inc. — site hosting and technical logs (United States, with EU Standard Contractual Clauses).
  • Cloudflare — secure receipt, processing, and forwarding of leads.
  • Attio — CRM where we record contacts, source, and commercial stage.
  • Slack and Notion — internal notifications and request management.
  • Meta Platforms Ireland — if you consent to Marketing, receives lead and qualified-lead events through Pixel or Conversions API with matching identifiers.
  • Email provider for replies and conversation archives [provider to be confirmed].
  • External advisors (accountant, lawyer) only for contacts that become clients.

05 — Transfers outside the EU

Some of the providers above are based in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Details are in the relevant Data Processing Agreements, available on request.

06 — How long we keep data

Contact-form requests are kept for as long as needed to reply and for 24 months after, so we can pick the thread up if you come back. After that they are deleted.

The Worker keeps matching identifiers used for Meta CRM events for no more than 180 days, unless you request earlier deletion.

If you become a client, contract-related data is kept for 10 years after the relationship ends, as required by Italian civil and tax law.

Server logs have a shorter retention (typically 30 days), managed by the hosting provider.

07 — Your rights

As a data subject you can exercise the rights granted by Arts. 15-22 GDPR at any time:

  • Access to your data and a copy of what we process.
  • Rectification of inaccurate data or completion of incomplete data.
  • Erasure ("right to be forgotten") in the cases provided by law.
  • Restriction of processing.
  • Objection to processing based on legitimate interest.
  • Portability of the data you provided to us.
  • Withdrawal of consent, where processing is based on consent, without affecting the lawfulness of prior processing.

To exercise these rights, write to hello@naniza.io. We reply within 30 days.

If you believe the processing breaches the GDPR, you can file a complaint with the Italian Data Protection Authority — garanteprivacy.it.

08 — Changes to this notice

We update this notice when the tools we use or the law change. The date at the top reflects the latest revision. For substantial changes, we will reach out by email where possible.