Datenschutzerklärung
Version 2 · Gültig ab 2. August 2026
Last updated: 2026-08-02 — Version: 2.0
1. Who we are
Vertexa is the data controller responsible for processing your data on this platform — a service run by a sole operator through the domain vertexa.it.com. Privacy contact: vertexa237@gmail.com, which is the address of record for any request concerning your data.
2. Data we collect
Account data (email, irreversibly hashed password, language preference); contact data (optional name and WhatsApp number); project data (service type, description, proposed budget, attachments); communications (per-project chat messages, support form messages); financial data (project amounts, payment status, manual confirmation notes); technical data (IP address, browser and device type, access logs, timestamps); consent records (time, IP and version of the Terms and Quote you accepted); usage data (which funnel steps you completed or abandoned).
We do not collect payment card numbers or special-category data (health, religious, political, biometric). Please do not send us such data.
3. Purposes and legal bases
Creating and operating your account, reviewing your request, issuing the Quote, delivering the project and sending lifecycle notifications — performance of a contract. Confirming payments and keeping financial records — legal obligation and legitimate interest. Proving your acceptance of the Terms and the Quote — legitimate interest (legal defence). Platform security and abuse prevention — legitimate interest. Usage analytics — your consent. Publishing your testimonial or project in our portfolio — your explicit, recorded consent.
4. Cookies
Essential cookies (session, language preference, CSRF protection) are always active. Analytics cookies are set only with your consent via the consent banner and may be withdrawn at any time. We use no advertising cookies and never sell your data.
5. Who sees your data
We do not sell or rent your data. We share it only with service providers acting on our instructions under processing agreements. This is the complete, actual list as at this version:
| Role | Provider | Processing location |
|---|---|---|
| Database | Neon (managed PostgreSQL) | European Union — Frankfurt |
| File and attachment storage | No external provider. Files sit on the platform's own server, in a private directory outside the web root, readable only through a route that re-checks your authorisation on every request | With the platform server |
| Email delivery | No provider engaged | — |
| Payment gateway | None engaged. Every payment is confirmed manually and no card data ever reaches us | — |
| Authorities | Only where legally compelled | As applicable |
Express commitment: we will not introduce any new provider (hosting, email, storage or payment gateway) into the processing of your data before publishing a new version of this policy naming it and its processing location. The version number and effective date are shown at the top of this page, and earlier versions are retained.
Future employees: each will receive access limited to their assigned projects only and will be bound by a confidentiality undertaking.
6. International transfers
Your data may be stored or processed on servers outside your country. For transfers from the European Economic Area we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Retention
Account data: while the account is active plus 12 months. Project chats: until the warranty period ends, after which you may delete them yourself at any time. Attachments and previews: with their project, deleted with the chat. Financial and audit records: 7 years from the date of the transaction — the customary retention period for accounting records, extended where a longer statutory period applies. Consent records: for the term of the agreement plus the applicable limitation period. Technical logs: up to 12 months.
8. Security
Passwords are stored using irreversible hashing; traffic is encrypted over HTTPS; attachments sit outside the web root and are streamed only through a route that re-checks your ownership of the project on every request — a copied link is useless to anyone else, and useless to you once signed out; previews are watermarked on the server before storage; access follows least-privilege; all administrative actions are logged; backups run regularly. No system is 100% secure. If a breach threatens your rights, we will notify you and the competent supervisory authority within the statutory period.
9. Your rights
You have the right to access, rectify, erase, restrict processing, object to processing, receive your data in a machine-readable format, withdraw consent at any time without retroactive effect, and lodge a complaint with your competent supervisory authority. To exercise these rights, contact vertexa237@gmail.com. We respond within 30 days and may ask you to verify your identity. Note that deleting data tied to an active project may prevent us from completing it, and some financial records cannot be deleted due to legal obligations.
10. Children
The platform is not directed at anyone under 18 and we do not knowingly collect their data. If we learn we have, we delete it promptly.
11. Changes
We may update this policy; the version number and effective date are displayed. Material changes are notified by email and by an on-site notification.
12. Contact and complaints
- Email:
vertexa237@gmail.com— the address of record for any request or complaint concerning your data. - Site:
vertexa.it.com - We operate online and do not receive visitors at premises. You retain the right to lodge a complaint with the competent supervisory authority in your country.