Website: https://hitechstories.com/
Last updated: 15 September 2026 17:14:33
Data Controller
Giuseppe CORDONE
, Via Ivrea, 34 – 00184 – Rome – Italy
privacy@hitechstories.com
Data, purposes and legal bases
The website processes personal data for the following purposes:
– Website operation and security: technical data, such as IP address, browser information, date and time of requests and event logs, to make content available, diagnose problems and prevent unauthorised access. The legal basis is the data controller’s legitimate interest in ensuring the availability and security of the website, limiting processing to what is necessary.
– Responding to communications: name, email address and information contained in messages, to reply to questions and enquiries. Processing is based on the legitimate interest in managing correspondence or, for enquiries regarding services, on the implementation of pre-contractual measures requested by the data subject.
– Collection and management of testimonials: name, role and company, email address, text of the testimonial and information relating to consent, to receive, review and manage contributions. Receipt and review are based on the legitimate interest in managing contributions sent voluntarily; the publication of the text and authorised identifying details is based on consent. The email address is not published.
– Newsletter, if requested: email address, name (if provided) and stated preferences, for sending editorial updates and any promotional communications described in the subscription form. The legal basis is consent, which may be withdrawn at any time. Submitting a testimonial does not constitute subscription to the newsletter.
We confirm that the newsletter is active and that these processing activities correspond to the actual operations carried out.
Data retention
Data is retained according to different criteria
:- Technical and log data: for [actual duration to be verified in the hosting and security settings], except where targeted retention is necessary to investigate an incident.
– Correspondence: until the request is resolved and for [a period to be defined] thereafter, where necessary to document the response or the correspondence exchanged.
– Newsletter: until unsubscription or termination of the service. After unsubscribing, only the minimum data necessary to comply with the objection to further communications and to document the consent previously given may be retained, for [a period and criteria to be defined].
– Unpublished testimonials: for [period to be defined] from receipt or the conclusion of the assessment.
– Published testimonials: for the authorised period of use, with periodic verification of relevance, and until consent to publication is revoked, if applicable. Documentation of authorisation may be retained separately for as long as necessary to protect the data subject’s rights.
– Backups: any remaining copies are deleted or overwritten in accordance with the retention cycle of [actual duration].
In the event of disputes or specific obligations, only the necessary data may be retained for a longer period, with restricted access.
Recipients of the data
The data may be processed by the data controller and by persons authorised to carry out editorial, administrative or technical activities, within the limits of their respective duties.
The service providers used include:
Hostinger: hosting and website infrastructure services, in accordance with the plan and features actually activated.
Kit: data collection via forms, management of testimonials and, where active, management of the newsletter.
Hostinger: receipt and management of communications.
Hostinger as a provider of maintenance, backup, security or CDN services: exclusively for the services actually used.
When acting on behalf of the data controller, service providers are bound by data processing agreements. Their roles must be distinguished from any processing carried out for their own purposes.
Authorised testimonials are made available to website visitors and may be indexed by search engines. Data may also be disclosed to the authorities where required by law.
Kit publishes a specific data processing agreement at: https://kit.com/dpa
International transfers
The use of Kit involves the processing of data outside the European Economic Area, in particular in the United States. Kit states that it uses infrastructure in the United States and other countries and describes the safeguards applicable to international transfers in its documentation. Kit Privacy Policy: https://kit.com/privacy
For the service used by the data controller, the transfer is based on the use of APIs developed by the provider.
For Hostinger and other providers, data localisation, access from abroad and sub-processors apply. The location of the server in Europe, on its own, does not preclude international access or transfers.
Data subjects may request information on the applicable safeguards and on how to obtain a copy by contacting the data controller using the contact details provided in the privacy notice.
Provision of data
Viewing the content does not require subscription to the newsletter or the submission of a testimonial. Certain technical data is necessary for communication with the website and for its operation.
In the forms, mandatory fields are clearly marked. Failure to provide the necessary data may prevent the form from being submitted or the request from being processed.
To receive the newsletter, you must provide a valid email address and give the required consent. Failure to subscribe does not restrict access to freely available content.
Submitting testimonials is optional. Consent to publication is separate from the receipt of the submission: without such consent, the testimonial will not be published. Any additional data, such as role and company, is processed in accordance with the instructions on the form.
Automated decision-making and profiling
The website does not use automated decision-making that has significant effects, although it may use profiling systems.
The data controller does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject. Individual profiles are not created to assess or predict users’ interests, preferences or behaviour.
Before using the website, you should check the ‘Open and Click Tracking Kit’ for any behaviour-based segmentation and automation, as well as any advertising tools. If these functions are active, their purposes and how they work must be described: the absence of significant automated decision-making does not imply the absence of profiling.
Data obtained from other sources
The Data Controller may also receive or collect certain personal data indirectly, i.e. without it being provided directly by the data subject.
In particular, this category may include technical and usage data generated whilst browsing, such as IP address, device and browser information, date and time of requests, URL or referring page (referrer), pages requested, technical information relating to the connection, and any data associated with cookies or similar technologies, to the extent that such tools are actually used on the website.
Possible sources of such data are:
the hosting infrastructure and its technical and security logs;
WordPress and the technical components actually active on the website;
security, anti-spam, caching, CDN or other technical service providers that may be used;
traffic measurement and analysis tools, only if actually installed and active;
external websites, search engines or platforms from which the user accesses hitechstories.com, limited to the technical information transmitted through normal web browsing.
The website does not intend to collect special categories of personal data from third parties, nor to enrich user profiles using external sources, unless this is expressly introduced and adequately documented.
The actual type of data collected indirectly depends on the current technical configuration of hitechstories.com and the third-party services in use. Any significant changes to the website’s configuration will result in a review of this policy.
Rights and how to exercise them
In the cases and to the extent provided for by Regulation (EU) 2016/679 (GDPR), the data subject may exercise the rights set out in Articles 15–22 of the Regulation vis-à-vis the Data Controller.
In particular, the data subject may request access to their personal data and obtain a copy of it, request its rectification or updating, erasure where the conditions are met, restriction of processing and, where applicable, data portability. They may also object to processing where this is based on the Data Controller’s legitimate interests.
Where processing is based on consent, the data subject may withdraw their consent at any time. Such withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
In the case of processing carried out for direct marketing purposes, where applicable, the data subject may object at any time to the processing of their personal data for that purpose.
Requests may be submitted to the Data Controller using the contact details set out in this Privacy Policy. Before acting on a request, the Data Controller may request the information reasonably necessary to verify the identity of the data subject, where there are doubts as to their identity.
Requests are processed within the timeframes set out in the GDPR, normally within one month of receipt; this period may be extended by a further two months in particularly complex cases or where there is a high volume of requests, in which case the data subject will be informed in accordance with the provisions of the legislation.
The exercise of these rights is generally free of charge. In the cases provided for in Article 12 of the GDPR, where requests are manifestly unfounded or excessive – in particular due to their repetitive nature – the Data Controller may request a reasonable contribution towards costs or refuse to comply with the request.
The data subject also has the right to lodge a complaint with the Data Protection Authority or, where applicable, with another competent supervisory authority under the GDPR, without prejudice to the right to seek redress through other administrative or judicial remedies provided for by law.
Kit
HiTechStories uses Kit, a service provided by Kit, Inc., to collect and manage testimonials submitted via the dedicated form.
The data includes name, email address, role and company (if provided), the text of the testimonial and information relating to consent to publication. It is used to review the submission, manage any communications with the author and publish the testimonial only with prior authorisation. The email address is not published.
The collection and review of this data are based on the data controller’s legitimate interest in managing voluntarily submitted contributions; publication is based on consent, which may be withdrawn by contacting the data controller. Submitting a testimonial does not automatically result in subscription to the newsletter.
For data processed on behalf of the data controller, Kit operates in accordance with its own data processing agreement and may use subcontractors. The service involves international transfers, including to the United States; the applicable safeguards are described in the ‘International Transfers’ section of this policy and in Kit’s contractual documentation.
Retention periods are set out in the ‘Data Retention’ section of this privacy notice.
Subject to specific consent, separate from newsletter subscription, the opening of messages and clicks on links are tracked using tracking pixels and links. This information may be linked to the subscriber’s email address and is used to assess interest in the content.
Where authorised by specific consent, this information is also used to identify interests and personalise subsequent communications, including through the automated segmentation of subscribers.
Refusing or withdrawing these consents does not prevent you from receiving the newsletter without tracking or personalisation. Withdrawal may be requested via the data controller’s contact details. Interaction data is retained for 120 months or until a request for erasure is made.