Privacy notice
This notice explains how toffler.dev handles the personal data of people who visit the website or receive a message from us, under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). Parts in [square brackets] must be completed before publishing.
1. Data controller
toffler.dev, VAT no. [number], [address], email [email protected].
2. What data we process
- Business contacts: first and last name, profession or role, practice or business name, professional email address and phone number.
- Website visitors: browsing data (pages viewed, referral source, for example the
utm_source=cardparameter on our printed QR codes) in aggregated form, using Cloudflare Web Analytics (no cookies). - People who write to us or reply: the content of their message.
3. Where the data comes from
Business contacts come from public sources: the professional's or business's own website and [public registers or professional directories โ specify]. We do not buy address lists.
4. Purposes and legal basis
- Introducing toffler.dev's AI automation services in a first introductory message: the controller's legitimate interest (Art. 6(1)(f) GDPR) in contacting professionals and local businesses with offers relevant to their work.
- Answering requests and managing any business relationship: pre-contractual steps or performance of a contract (Art. 6(1)(b)).
- Website statistics: legitimate interest (Art. 6(1)(f)), as the statistics are aggregated and collected without cookies.
We make no automated decisions with legal effects on you, and we do not sell your data.
5. Recipients
The controller and technical service providers (hosting, email, analytics) process the data: Cloudflare (hosting and access statistics), Proton (email). Any transfer outside the European Economic Area relies on the safeguards the GDPR requires (for example standard contractual clauses): [specify, if applicable].
6. How long we keep data
- Contacts we wrote to who never replied: at most [12] months from the message, then we delete them.
- Contacts who reply or become clients: for the duration of the relationship and as the law requires.
- If you object, we keep only your email address on a suppression list, solely so we never contact you again.
- Browsing data: [period].
7. Your rights
At any time you can ask for access, rectification, erasure, restriction and portability, and you can object to the processing (Arts. 15-22 GDPR). We always honour an objection to direct marketing. Just reply "NO" to our email or write to [email protected]; we answer within one month.
8. Complaints
You have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
9. Cookies
The site does not use cookies or tracking tools that require consent. Access statistics are collected with Cloudflare Web Analytics, without cookies and in aggregate form. If you visit the site by scanning the QR code on our business card, the address carries the parameter utm_source=card: it only tells us the visit came from the card and contains no personal data.
10. Updates
Last updated: 7 October 2026.