Privacy Policy
Last updated: 9 September 2026
This policy explains how personal data of users of the analytically.it website and of the Analytically service (the “Service”) is collected and processed, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian law.
Contents
1. Data Controller
Badea Vlad
Via Nicolo Tartaglia 47, 25126 Brescia (BS)
VAT number: 1234567890
E-mail: info@analytically.it
No Data Protection Officer (DPO) has been appointed, as the legal conditions for a mandatory appointment are not met. For any data protection request please use the e-mail address above.
2. Personal data processed
2.1 Data provided for registration and account use
- E-mail address, provided at sign-up. An internal username is automatically derived from it and used to attribute the records you create (menus, stock, recipes, etc.).
- Password, stored only in hashed form. On first login with a temporary password you must set your own.
- Operator accounts: if you, as the account owner, create accounts for your staff, you process their names/identifiers and permissions through the Service. In that case you act as an independent controller towards your staff.
2.2 Billing data (paid plans)
To issue the electronic invoice for the subscription, mandatory in Italy, we collect: entity type (individual/company), full name or company name, address, ZIP, city, province, country, tax code and/or VAT number, SDI recipient code or PEC. A discount code may be entered. Issued invoices (PDF and XML) are retained as required by law.
2.3 Payment data
Payments are handled by Stripe and PayPal. Card or account details are entered directly on those providers’ secure pages: Analytically never receives or stores card numbers. We process transaction and subscription identifiers, amount, outcome and payment status.
2.4 Content entered while using the Service
While using the Service you enter data about your business (menus, recipes, stock and restocking, cash movements, bookings and any end-customer contact details). This content is processed on your behalf; you are its controller and Analytically acts as processor solely to provide the Service.
2.5 Support data
If you use the “Contact us” form or write by e-mail, we process your name, e-mail address and the content of your request in order to reply.
2.6 Data collected automatically
- Server logs: IP address, date and time, requested pages, browser user agent, generated by the hosting infrastructure for security and diagnostics.
- Technical and session cookies: see section 4.
- Campaign attribution parameters (UTM, gclid, fbclid, referrer, landing URL) on the advertising landing page: used browser-side by measurement tags and not stored on our servers.
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Account creation, provision of the Service and support, sending service e-mails (credentials, trial expiry reminders, receipts and invoices) | Performance of a contract or pre-contractual measures — Art. 6(1)(b) |
| Issuing invoices, retaining accounting records and tax compliance (incl. transmission to the Italian Interchange System) | Legal obligation — Art. 6(1)(c) |
| Service security, fraud and abuse prevention, technical logs, single-device session management | Legitimate interest in protecting the Service — Art. 6(1)(f) |
| Traffic statistics and advertising campaign measurement on the landing page (e.g. Meta Pixel), via non-technical cookies | Consent, given through the cookie banner — Art. 6(1)(a) |
| Replying to messages sent through the contact form | Pre-contractual measures / legitimate interest in replying — Art. 6(1)(b) / (f) |
| Establishing, exercising or defending legal claims | Legitimate interest — Art. 6(1)(f) |
Providing registration and billing data is necessary to activate and keep the account: without it the Service cannot be provided. Providing data for statistical/advertising purposes is optional and consent can be withdrawn at any time.
4. Cookies and similar technologies
| Name | Type / purpose | Duration |
|---|---|---|
analytically_lang | Technical: stores the chosen language | 1 year |
PHPSESSID | Technical: browsing/login session identifier | Session |
analitically-theme (localStorage) | Technical: remembers light/dark theme. Not a cookie, never sent to the server | Persistent on device |
Meta Pixel cookies (e.g. _fbp) | Third-party, statistical/advertising, only on the landing page and only after consent | Up to 3 months |
Technical and session cookies do not require consent. Non-technical cookies are set only after explicit consent through the banner; consent can be changed or withdrawn at any time using the button below or by deleting cookies in your browser settings.
5. Processing methods and security
Data is processed with electronic tools, applying technical and organisational measures appropriate to reduce the risk of destruction, loss, unauthorised access or unlawful processing: encrypted transmission (HTTPS), passwords stored as hashes, access limited to authorised staff, automatic session close after a period of inactivity and, when the same credentials are used from a new device, close of the previous session. No automated decision-making producing legal effects under Art. 22 GDPR is carried out.
6. Recipients and processors
For the purposes above, data may be processed by the following parties, acting as processors under Art. 28 GDPR or as independent controllers:
- Aruba S.p.A. — website and data hosting and electronic invoicing service.
- Italian Revenue Agency (Agenzia delle Entrate) — Interchange System (SDI), recipient of electronic invoices by law.
- Stripe Payments Europe, Ltd. — card payment processing.
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — PayPal payment processing.
- E-mail (SMTP) provider — delivery of service e-mails.
- Meta Platforms Ireland Ltd. — Meta Pixel on the landing page (consent only).
- Google Ireland Ltd. — web font delivery (Google Fonts) and, where enabled, analytics/advertising services (Google Analytics / Google Ads).
Data may also be disclosed to public authorities, advisers and professionals to the extent necessary to comply with legal obligations or defend a right. Data is not disseminated or sold to third parties for their own marketing purposes.
7. Transfers outside the EU
Hosting and data storage take place within the European Union. Some providers (in particular Stripe, PayPal, Meta and Google) may also process data outside the European Economic Area. In such cases the transfer relies on a European Commission adequacy decision or on the Standard Contractual Clauses adopted by the Commission, with supplementary measures where needed. A copy of the safeguards in place can be requested from the Controller.
8. Retention period
- Account data and entered content: for the duration of the relationship. On account closure the data is deleted or anonymised, except what must be kept by law.
- Incomplete sign-ups and expired, inactive trial accounts: removed automatically at periodic intervals.
- Invoices and accounting records: 10 years, under Art. 2220 of the Italian Civil Code and tax law.
- Server technical logs: for the time technically necessary, as a rule no longer than 12 months.
- Support contact data: for the time needed to handle the request and a limited period afterwards for support continuity.
- Proof of consent to non-technical cookies: until withdrawal and in line with the Italian DPA’s guidance.
9. Your rights
Within the limits of Arts. 15–22 GDPR, you have the right to:
- access your personal data and obtain a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data erased (“right to be forgotten”), where applicable;
- obtain restriction of processing;
- receive your data in a structured, commonly used, machine-readable format (portability) and transmit it to another controller;
- object to processing based on legitimate interest;
- withdraw any consent at any time, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with the supervisory authority (in Italy, the Garante per la protezione dei dati personali — garanteprivacy.it).
To exercise these rights, write to info@analytically.it. The request is free of charge and answered without undue delay and in any case within one month.
10. Children’s data
The Service is aimed at professionals and businesses (management of bars and venues) and is not intended for anyone under 18. We do not knowingly collect children’s data. A parent or guardian who believes a minor has provided data may contact us to have it removed.
11. Changes to this policy
This policy may be updated to reflect legal or Service changes. The current version is published on this page with the last-updated date; where relevant, registered users are notified by e-mail or within the Service.
12. Contact
For any question about this policy or the processing of personal data: info@analytically.it.
See also the Terms & Conditions.
↑ Back to top