// Legal Document
Privacy & Cookie Policy
This notice describes how personal data of users visiting the website lapsense.net (the "Site") is processed. It is provided pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended ("Privacy Code") for the Site only, and not for any other websites that may be reached via links.
1. Data Controller
The Data Controller is the company listed below. For any request concerning the processing of personal data (exercise of rights, clarifications, complaints), please use the contact details provided.
- Company name
- NEXILICA SRL
- Brand
- LapSense is a brand operated by Nexilica Srl.
- Registered office
- Viale Ciro Menotti, 83 — 41121 Modena (MO), Italia
- VAT number
- IT04179460367
- Italian fiscal code
- 04179460367
- REA registration
- MO-449445
- Share capital
- € 10.000,00 i.v.
- Certified email (PEC)
- nexilica@trustpec.it
- Privacy contact email
- info@lapsense.net
2. Data Protection Officer (DPO)
The Controller has not appointed a Data Protection Officer pursuant to Article 37 GDPR, as the conditions for mandatory appointment do not apply. For any matter concerning the protection of personal data, please contact the Controller directly using the details above.
3. Types of data processed
The Site processes the following categories of personal data:
Browsing data
IP address, user agent, pages visited, timestamps, referrer. This data is automatically collected by our hosting provider (Cloudflare) in technical logs for security, abuse mitigation, diagnostics and compliance with legal obligations.
Cookie preferences
The choice expressed via the cookie banner (accept, reject, granular preferences) is stored in the user's browser localStorage. It is not transmitted to the server.
Analytics data (subject to consent)
Only where the user has given explicit consent to the 'Analytics' category, the Site uses Google Analytics 4 (property G-PNDFYHKF6J) to collect aggregated usage statistics: pages viewed, session duration, device type, country of origin. Data is processed with anonymised IP (anonymize_ip), in Consent Mode v2 with default 'denied', with Google Signals and Advertising Features disabled and ads_data_redaction enabled. No data is used for profiling or advertising purposes.
Data voluntarily provided
When the user fills in the contact form or signs up to the beta waitlist, the data entered in the form fields is collected (e.g. email address, optional message). Submission requires explicit consent and acceptance of this notice. For the waitlist, the email address must be confirmed via a link sent by email (double opt-in).
The Site does not use profiling cookies or behavioural advertising technologies. The only analytics service in use is Google Analytics 4, activated only after the user's explicit consent, configured in anonymised mode and without Google Signals. Fonts and icons are hosted directly from our own domain (self-hosted).
4. Purposes of processing and legal bases
Personal data is processed for the following purposes:
| Technical operation of the Site, security, mitigation of abuse and cyber attacks | Legitimate interest of the Controller (Art. 6.1.f GDPR) in safeguarding the security of its infrastructure |
| Storage of the user's cookie preferences | Legitimate interest of the Controller (Art. 6.1.f GDPR) and compliance with regulatory obligations on cookie consent (Directive 2002/58/EC and the Italian Garante guidelines of 10 June 2021) |
| Responding to requests submitted via the contact form | Performance of pre-contractual measures at the request of the data subject (Art. 6.1.b GDPR) |
| Beta waitlist subscription and subsequent notification at product launch | Explicit consent of the data subject (Art. 6.1.a GDPR), revocable at any time |
| Aggregated statistical analysis of Site usage (Google Analytics 4 in anonymised mode) | Explicit consent of the data subject (Art. 6.1.a GDPR and Art. 122 Italian Privacy Code), given via the consent manager and revocable at any time |
5. Processing methods
Processing is carried out using electronic tools, adopting technical and organisational measures appropriate to guarantee the security, confidentiality, integrity and availability of the data (Art. 32 GDPR), including: encrypted HTTPS/TLS transmission, restricted access to authorised personnel, environment segregation, automatic threat mitigation at CDN level.
6. Retention period
Data is retained for the time strictly necessary to pursue the purposes set out above:
- Navigation and security logs: maximum 30 days, save for extensions for the purpose of investigating unlawful conduct
- Cookie preferences in the browser: 6 months from the user's choice, after which the banner is shown again as required by the Garante guidelines
- Data submitted via the contact form: for the time needed to respond and for the following 12 months, unless the data subject requests otherwise
- Beta waitlist data: until the commercial launch of the product and for the following 30 days, after which data of those who have not become customers is deleted
- Analytics data (Google Analytics 4): 2 months for user/event-level data (the minimum retention period offered by Google), after which data associated with the _ga cookie is automatically deleted
7. Recipients and external Data Processors
Data may be processed, on behalf of the Controller, by the following parties appointed as Data Processors pursuant to Art. 28 GDPR:
Cloudflare, Inc.
- Role / service provided
- Hosting (Cloudflare Workers), CDN, sicurezza, mitigazione DDoS, inoltro email in entrata (Email Routing), storage iscrizioni waitlist (D1 Database), protezione anti-spam form (Turnstile)
- Location and transfers
- Sede USA con datacenter globali (anche UE). Trasferimento extra-UE coperto da Standard Contractual Clauses (SCC) della Commissione Europea e dal Data Processing Addendum di Cloudflare.
- More information
- https://www.cloudflare.com/privacypolicy/
Resend, Inc.
- Role / service provided
- Invio email transazionali (conferma iscrizione waitlist, risposte form contatti, notifiche di servizio)
- Location and transfers
- Sede USA, infrastruttura di invio nella regione EU (Francoforte) selezionata in fase di setup per minimizzare l'esposizione dei dati. Trasferimento extra-UE coperto da certificazione EU-US Data Privacy Framework (DPF) e Standard Contractual Clauses (SCC) incluse nel Data Processing Addendum di Resend.
- More information
- https://resend.com/legal/privacy-policy
Google Ireland Limited / Google LLC
- Role / service provided
- Statistiche aggregate di traffico web (Google Analytics 4, property G-PNDFYHKF6J). Caricato esclusivamente previo consenso esplicito dell'utente alla categoria "Analytics" del consent manager. Configurazione: Consent Mode v2 con default 'denied', anonimizzazione IP attiva, ads_data_redaction attivo, url_passthrough attivo, Google Signals e Advertising Features disattivati.
- Location and transfers
- Titolare del trattamento per i servizi UE: Google Ireland Limited (Dublino, Irlanda). Possibili trasferimenti negli USA verso Google LLC, coperti da certificazione EU-US Data Privacy Framework (DPF) e Standard Contractual Clauses (SCC).
- More information
- https://policies.google.com/privacy
In addition, data may be disclosed to public authorities, judicial authorities and supervisory bodies in compliance with legal obligations.
8. Transfers of data outside the EU
Some Data Processors (in particular Cloudflare, Google and Resend) are entities based in the United States and may process data in datacenters located outside the European Union. Such transfers take place on the basis of the Standard Contractual Clauses (SCC) adopted by the European Commission with Implementing Decision (EU) 2021/914 and — for Google and Resend — also on the basis of the EU-US Data Privacy Framework (DPF) certification, adopted by the European Commission's Adequacy Decision of 10 July 2023, ensuring an adequate level of protection pursuant to Arts. 44-49 GDPR.
9. Rights of the data subject
At any time, the data subject has the right to exercise the following rights provided by Arts. 15-22 GDPR against the Controller:
- Right of access to their personal data (Art. 15)
- Right to rectification of inaccurate or incomplete data (Art. 16)
- Right to erasure ("right to be forgotten", Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object to processing (Art. 21)
- Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
To exercise these rights, simply send a request to the Controller's email address listed at the beginning of this document. The Controller will respond without undue delay and in any case within 30 days.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) if they consider the processing to be in breach of applicable rules.
10. Cookies and similar technologies
The Site uses technical cookies and localStorage entries strictly necessary for the operation of the Site and for the management of consent, pursuant to Art. 122 of the Italian Privacy Code, which do not require prior consent. The Site also uses, exclusively after the user's explicit consent given via the consent manager, third-party analytics cookies from Google Analytics 4 in anonymised configuration (Consent Mode v2 with default 'denied', anonymize_ip enabled, Google Signals disabled). No profiling or behavioural advertising cookies are installed.
Manage or withdraw consent
The user can change or withdraw their cookie preferences at any time by clicking the consent manager icon located at the bottom left of every page of the Site. Withdrawal of consent does not affect the lawfulness of processing based on consent given before withdrawal.
It is also possible to block cookies directly from the browser settings; however, this may compromise the proper functioning of the Site.
List of localStorage entries used
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
silktideCookieChoice_* | lapsense.net (first-party) | Memorizza le preferenze di consenso cookie scelte dall'utente | Tecnico | Persistente in localStorage fino a revoca o scadenza dopo 6 mesi |
silktideCookieBanner_* | lapsense.net (first-party) | Memorizza lo stato del banner (mostrato/chiuso) per evitare di riproporlo a ogni pageview | Tecnico | Persistente in localStorage fino a revoca o scadenza dopo 6 mesi |
stcm-consent-timestamp | lapsense.net (first-party) | Timestamp della scelta di consenso, usato per forzare il ri-prompt dopo 6 mesi come da Linee Guida Garante 2021 | Tecnico | 180 giorni dalla scelta |
_ga | Google LLC (third-party) | Google Analytics 4 — distingue gli utenti unici a fini di statistica aggregata. Impostato esclusivamente dopo consenso alla categoria 'Analytics'. | Analitico (terza parte) | 2 anni |
_ga_PNDFYHKF6J | Google LLC (third-party) | Google Analytics 4 — mantiene lo stato di sessione per la property. Impostato esclusivamente dopo consenso alla categoria 'Analytics'. | Analitico (terza parte) | 2 anni |
11. Changes to this notice
The Controller reserves the right to amend this notice at any time, notifying users via this page and indicating the date of the last update. Users are invited to consult this page periodically.