LEGAL

Privacy Policy

These public marketing pages set no cookies, run no third-party analytics, and load no resources from third-party servers — nothing you do here is measured by anyone but us, and nothing is shared. A few features do keep notes in your own browser's local storage; that stays on your device, and every one of them is named below. Separately, we operate a password-protected client portal at portal.giovanninitech.com for the clients we work with, and that portal does store data on our servers — it has its own section further down, as does the contact form. Beyond those, we process as little of your data as technically possible.

Controller

Giovannini Tech Solutions – Inh. Fabio Giovannini (address: see Imprint — being completed before launch). Privacy contact: privacy@giovanninitech.com. See the Imprint for full operator details.

Hosting & server logs

The site is served as static files via Amazon Web Services (S3 + CloudFront, AWS EMEA SARL). When you access a page, the delivery infrastructure technically processes your IP address and standard request metadata (URL, timestamp, user agent) to deliver the content and defend against abuse. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating the site securely. We do not merge these logs with other data or use them to identify visitors; they are retained only for a short period.

All of our storage and processing — this site, the client portal, and the files behind it — runs in the AWS region eu-central-1 (Frankfurt, Germany). AWS acts as our processor under the AWS Data Processing Addendum, which forms part of the AWS Service Terms and applies to our whole account.

No cookies, no tracking on the marketing pages

The public pages of giovanninitech.com set no cookies and include no third-party tracking, tag managers, embedded videos, maps, or fonts. Every asset is served from our own domain, so browsing here triggers no request to anyone else. The only cookies anywhere on this domain are the strictly-necessary session cookies of the client portal and of our own administration console, described below; neither is ever set on these pages. Because we run no analytics or advertising, there is no consent banner to click.

Contact form

When you send the contact form, the details you enter — name, email address, company, and your message, together with the time of submission — are transmitted to us and stored on our servers. That is simply how we are able to read and answer an enquiry. Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract) and, for general enquiries, Art. 6(1)(f) GDPR (our legitimate interest in responding). Submissions are deleted after 12 months, earlier on request.

The form posts to our own domain and is handled by our own infrastructure in Frankfurt — no form service, no CRM, no CAPTCHA, and therefore still no third-party request. If the transmission fails, your entries remain in your browser's local storage so nothing is lost, and we offer you a plain email address instead.

Browser-local storage

Some parts of this site keep notes in your own browser's local storage. None of it is a cookie, none of it is transmitted to us or to anyone else, and none of it leaves your device. In the interest of being exact rather than reassuring, here is the complete list — three keys:

  • gt_diagnostic_result — the Operational Leverage Diagnostic stores your answers and your result here so the page can show it to you and, if you choose, attach a summary to the contact form. The diagnostic is entirely browser-local: we never receive your answers.
  • gt_leads — a fallback copy of a contact-form submission, written only if sending it to us fails, so that your message is not lost while you retry or email us instead.
  • gt_analytics — a counter of which pages were opened and which buttons were pressed in this browser. It is a leftover proof-of-concept stub: it is never read, never sent anywhere, and no profile is built from it. It is disclosed here because it writes to your device, which is what matters under § 25 TDDDG, and not because anyone looks at it.

You can remove all of it at any time by clearing your browser's site data for giovanninitech.com, and nothing on the site will stop working.

Client portal

Clients we work with receive a personal account on portal.giovanninitech.com. There is no self-registration: accounts exist only because we created one for you. For each client we store the company name, a contact name, a contact email address, a cryptographic hash of the chosen passphrase (never the passphrase itself), the proposals, invoices and deliverables belonging to the engagement, and timestamps of portal activity such as logins and downloads. Legal basis: Art. 6(1)(b) GDPR — performance of the contract between us, and the record-keeping that goes with it.

Your email address is used to sign in, and for nothing else. We send you nothing at that address — no notifications, no newsletter, no product announcements, no marketing, ever. The portal deliberately has no outbound email at all; access links are handed to you personally. If that changes, this page changes first.

The portal sets exactly one cookie, named __Host-gt_portal. It holds your signed session so that you stay logged in; it is bound to the portal subdomain, sent only over HTTPS, not readable by JavaScript, and not sent with cross-site requests. It contains no tracking identifier, and no third party can read it. Because it is strictly necessary for a service you explicitly requested, it needs no consent under § 25(2) TDDDG — which is why the portal has no cookie banner either. Logging out deletes it. Our own administration console uses an equivalent cookie on a separate subdomain that clients and visitors cannot reach.

Besides that cookie, the portal remembers one preference in your browser's local storage: gt_theme, holding whether you chose the light, dark or system appearance. It stays on your device, is never transmitted to us, and clearing your site data removes it. That is the portal's only browser-side storage.

Retention: invoices and their metadata are never deleted automatically — German commercial and tax law requires them to be kept for the statutory retention period (currently up to ten years), and the portal may hold the only copy. Portal access itself is not permanent: you can ask us to revoke it at any time, and we archive accounts once an engagement ends. Revoking access invalidates the session immediately; records we are legally required to keep survive it.

IP addresses

We process the IP address of requests to the contact form and to the portal in order to count attempts per address and block abuse — spam submissions, brute-force login attempts (Art. 6(1)(f) GDPR, our legitimate interest in a working, secure service). These counters are short-lived and expire automatically. In addition, if we switch on the optional acceptance feature for an individual proposal, accepting that proposal stores the IP address, the time, and the browser user agent alongside the accepted document, as evidence of the declaration (Art. 6(1)(b) and (f) GDPR). That happens only on proposals where the feature is enabled, and only if you accept.

Email contact

If you email us, we process your address and the content of your message to answer you (Art. 6(1)(b) or (f) GDPR). Emails are handled by our mail provider (Zoho Mail, EU data centers) and kept only as long as the correspondence requires — or longer where retention rules apply.

Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR), and the right to complain to a supervisory authority (Art. 77 GDPR). If you have only read the public pages, there is usually nothing we could even look up about you. If you have used the contact form or have a portal account, write to privacy@giovanninitech.com — we will tell you what is stored, correct it, export it in a machine-readable form, or delete it, within one month and free of charge. Where an invoice must be retained by law, we restrict its processing instead of deleting it and say so explicitly.

Last updated: 27 July 2026. See also the Imprint.