Privacy Policy
In short: the site automatically records some technical browsing data (such as the IP address) for security and to keep the service running properly, and keeps it from 4 to 10 weeks, depending on the log. The same IP address is also used to limit overly frequent requests from the same device. Below you will find the details, the other ways your data is handled, and your rights.
This notice explains which personal data this site processes, why, on what legal basis and for how long, in line with the GDPR (Regulation (EU) 2016/679). The controller, that is, whoever decides how the data is used, is named at the bottom of the page together with the details for contacting them.
This information concerns the site br1brown.it and not other sites, pages or services reachable through links.
Data processed and purposes
Browsing data
When you visit the site, the systems that run it automatically receive and record some technical data that your browser sends: this is an unavoidable effect of how the Internet works. This data includes the IP address of the device used, recorded in full (neither anonymised nor truncated), the date and time of the request, the address (URL) of the page or resource requested, the type of request sent to the server (for example reading a page), the numeric code showing the outcome of the request (successful, error, etc.), the size of the response, the page you came from (referrer), and the type of browser, operating system and device you use (user-agent). The error logs contain only the IP address of the device used, recorded in full (neither anonymised nor truncated), the date and time of the request, the address (URL) of the page or resource requested, and the page you came from (referrer).
This data is needed to run the site, to protect it (by detecting abuse, automated scans and cyberattacks) and to work out what went wrong when something breaks. It is recorded by the server that routes requests to the site (the so-called reverse proxy). The server also remembers the IP address for no longer than 1 minute, in order to limit overly frequent requests from the same device.
The controller processes it because it has a legitimate interest (Art. 6(1)(f) GDPR) in keeping the site available and defending it from abuse and cyberattacks, such as a flood of requests that would make it unreachable for other users.
This data is not kept indefinitely: the technical records of requests (the logs) remain on the server for no more than 4 weeks, error logs (which cover only requests that produce an error or a warning) remain on the server for no more than 10 weeks, and the logs of the site's applications have a limited size and are overwritten on rotation. Deletion is automatic, except where required for the investigation of criminal offences by the judicial authorities.
The site is hosted by OVH SAS, which processes this data on the controller's behalf as processor (Art. 28 GDPR). The servers are located in France, within the European Union.
Contacting us by email
The optional, explicit and voluntary sending of email to the addresses shown on this page involves acquiring the sender's address, needed to reply, and any other personal data contained in the message (for example your name or what you wrote). The controller uses them only to reply to you. If your request concerns a service or a contract, it uses them to follow up on it (Art. 6(1)(b) GDPR); in all other cases it does so because it has a legitimate interest in replying to you (Art. 6(1)(f) GDPR). It keeps them for as long as needed to handle the request and, if a relationship results, for as long as the relationship lasts.
Writing to the controller is your choice: without your data, however, a reply is not possible. Your message passes through the email or messaging provider you use, which handles it under its own terms.
Profiling
Only if you accept them from the cookie banner, the site uses the tools listed in the Cookie Policy to show you content tailored to your interests. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time from the preferences panel in the Cookie Policy.
Cookies and browser storage
The site uses cookies and other browser storage. The full list, what each item is for, how long it lasts and the choices you can make are in the Cookie Policy.
Third-party services
To display some content the site connects to external services: images.credential.net (images), api.github.com (data requests), widget.spreaker.com (embedded content), open.spotify.com (embedded content), embed.podcasts.apple.com (embedded content), and www.youtube.com (embedded content). When this happens, your browser sends those services your IP address and some technical information, and each service handles them under its own rules.
The site does not ask for access to your device's location, camera or microphone.
Recipients
Data is not sold. It is processed by the controller and, on its behalf and under its instructions, by OVH SAS (which hosts the site) and the providers of the tools listed in the Cookie Policy: these are the so-called processors (Art. 28 GDPR), that is, parties that use the data only to carry out the service entrusted to them.
Whether providing data is mandatory
Browsing data is recorded automatically when you visit the site. Everything else you provide by your own choice, for example by writing to the controller: if you choose not to, the controller cannot follow up the request it would be needed for.
Automated decision-making
No decision producing legal effects concerning you, or similarly affecting you, is taken solely by automated means (Art. 22 GDPR).
Your rights
At any time you can ask the controller to give you access to your data and a copy of it (Art. 15), to correct inaccurate data (Art. 16), to erase it (Art. 17) or to restrict its processing (Art. 18). You can ask to receive the data you provided in a machine-readable format (Art. 20), object to processing based on legitimate interest (Art. 21) and withdraw a consent you have given, without affecting the validity of what was done before the withdrawal (Art. 7(3)).
To exercise them, write to the controller using the details at the bottom of this page. You will receive a reply within one month of the request, extendable by two further months if the request is complex or requests are numerous; if the controller has reasonable doubts about your identity, it may ask you for the information needed to confirm it (Art. 12(3) and (6)).
Browsing data is not linked to a name or an account: as a rule the controller cannot trace an IP address back to a person. For this reason, if you want to exercise your rights over this data, give the controller your IP address and the approximate day and time of your visit: it needs them to find your data in the logs. Without these details the controller is not required to collect further information just to identify you (Art. 11 GDPR).
If you consider that the processing of your data infringes the Regulation, you have the right to lodge a complaint with the data protection supervisory authority of the country where you live, work or where the alleged infringement took place (Art. 77 GDPR), or to seek a judicial remedy (Art. 79 GDPR). In Italy the supervisory authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).
Changes to this notice
The controller may update this notice when the site or the law changes: the version in force is always the one published on this page.