Privacy policy
Last updated: 7 October 2026
1. Data controller
Simone Scaffidi D., ICT Consultant, Piazza Merendino 6, Capo d'Orlando (ME), Italy — Tax code SCFSMN83R25G377C — VAT no. IT03507360836 — email info@simonescaffidi.it — PEC simone.scaffididomianello@widipec.it.
2. Scope
This policy covers (a) the website segnapresenze.com and (b) the web platform app.segnapresenze.com (the "Platform"). For employee data managed in the Platform, we act as data processor (Art. 28 GDPR) on behalf of the client company, which is the controller (see section 4).
3. Data processed through the website
- Browsing data: IP address, date and time, requested page, user agent, logged by the servers for operation and security.
- Data you provide by emailing or messaging us on WhatsApp (name, email, phone, message content).
- Statistics on visits, collected with Google Analytics 4 only if enabled and only with your consent through the banner (see Cookie Policy).
4. Data processed through the Platform
The Platform processes, on behalf of clients and on their instructions, data of employees and operators: first and last name, badge code, assigned site, department and contract, clock-in records (date, time, device, direction), leave requests, hour balances, operation log, and email and role of operators with access. Each client relationship is governed by a data processing agreement (Art. 28 GDPR). Employees wishing to exercise their rights should first contact their employer (controller), who may rely on our assistance.
5. Purposes and legal bases
- Replying to information or demo requests and pre-contractual steps — Art. 6(1)(b) and (f) GDPR.
- Security, abuse prevention and technical operation — legitimate interest, Art. 6(1)(f).
- Visit statistics — consent, Art. 6(1)(a) GDPR and Art. 122 of Italian Legislative Decree 196/2003.
- Providing the service to clients — performance of the contract and controller instructions (Art. 28 GDPR).
- Accounting and tax obligations — legal obligation, Art. 6(1)(c).
6. Retention
Contact requests: as long as needed to reply and manage any resulting relationship, then for statutory periods. Browsing data: only as long as strictly necessary for security and operation. Platform data: for the duration of the client contract; on termination it is returned or deleted as set out in the agreement with the client.
7. Recipients and sub-processors
- Railway Corp. — application and database hosting (including infrastructure outside the EEA).
- GitHub, Inc. — source code hosting; contains no personal data of Platform users.
- Google LLC — statistics (Google Analytics 4), only if enabled and with consent.
- Meta Platforms, Inc. — WhatsApp, only if you choose to contact us that way.
Data is not sold or shared with third parties for marketing. Only authorised, confidentiality-bound persons have access, plus advisers or authorities where required by law.
8. Transfers outside the EEA
When a provider processes data outside the European Economic Area, the transfer relies on the safeguards of Arts. 44 et seq. GDPR (adequacy decision, e.g. the EU-US Data Privacy Framework, or the European Commission's standard contractual clauses).
9. Your rights
You may request access, rectification, erasure, restriction, portability and object to processing by writing to info@simonescaffidi.it. You may withdraw consent to statistics cookies at any time from the "Manage cookies" link at the bottom of the page. You have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or your local authority.
10. Changes
This policy may be updated; the date above shows the latest version.