Privacy policy
Last updated: August 11, 2026.
This document describes the processing of personal data carried out through the website performa.example (hereinafter, “the Site”) pursuant to Regulation (EU) 2016/679 (GDPR).
Data controller
The data controller is:
- Legal entity:
[COMPANY NAME — TO BE COMPLETED] - Registered address:
[REGISTERED ADDRESS — TO BE COMPLETED] - VAT / Tax ID:
[VAT NUMBER — TO BE COMPLETED] - Contact email:
[CONTROLLER EMAIL — TO BE COMPLETED]
Note: fields in square brackets are placeholders to be filled with the definitive data before the site goes live.
Data Protection Officer (DPO)
[If designated: DPO name + email. If not required: remove this section or state "The Controller has not designated a DPO as the conditions for mandatory designation under Article 37 GDPR do not apply."]
Data collected
The Site is a static marketing site requiring no registration and offering no data-collection form. In particular:
- No contact form: communication happens exclusively via direct email to the Controller (a
mailto:link that opens the user’s email client). - No profiling cookies.
- No third-party cookies (Google Analytics, social plugins, etc.).
- No behavioral tracking.
The data that may be processed are limited to:
- Server technical logs: collected automatically by the hosting infrastructure (GitHub Pages), including IP address, user agent, timestamp, requested resource. This data is processed for technical and security purposes and is retained according to the policy of GitHub, Inc. (hosting provider).
- Content of email communications: if the user chooses to write to the Controller via
mailto:, the data contained in the email (name, email address, message text) will be processed to answer the request.
Legal basis of processing
- Technical logs: legitimate interest of the Controller in the security of the infrastructure (Article 6(1)(f) GDPR).
- Email communications: pre-contractual measures at the request of the data subject (Article 6(1)(b) GDPR).
Purposes of processing
Data collected is processed exclusively for:
- Ensuring the operation and security of the Site.
- Responding to information requests received via email.
- Evaluating the possible establishment of a commercial relationship with the data subject.
Data is not used for automated marketing, profiling or transfer to third parties.
Method of processing
Processing is carried out with electronic tools, using logic strictly related to the purposes above. Adequate technical and organizational security measures are in place to prevent loss, unauthorized access, alteration or destruction of the data.
Data retention
- Technical logs: retained for the period defined by the hosting provider’s policy (GitHub Pages).
- Contact emails: retained for the time necessary to handle the request and for the period required to document business correspondence, in any case no longer than 24 months unless a contractual relationship is established.
Recipients of the data
Data may be shared with:
- Hosting provider: GitHub, Inc. (as technical processor), which hosts the Site on GitHub Pages infrastructure.
- Competent authorities in the event of a legal obligation.
Data is not transferred to third parties for commercial purposes.
Extra-EU data transfers
GitHub Pages hosting is provided by GitHub, Inc. (a US company). Technical data may therefore be transferred to the United States. The transfer takes place in accordance with the Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-US Data Privacy Framework.
Rights of the data subject
The data subject has the right, at any time, to:
- Obtain confirmation of whether or not data concerning them is being processed (right of access — Article 15 GDPR).
- Request rectification of inaccurate data or completion of incomplete data (Article 16).
- Request erasure of data (right to be forgotten — Article 17).
- Request restriction of processing (Article 18).
- Request data portability (Article 20).
- Object to processing (Article 21).
- Lodge a complaint with the competent supervisory authority in their EU Member State (list available at edpb.europa.eu).
Requests can be sent to the Controller at the email address indicated at the top of this document.
Cookies
The Site does not use cookies, either first- or third-party, except for strictly technical cookies that the hosting infrastructure may set to ensure basic platform functioning. For this reason, there is no cookie banner: no cookies subject to prior consent are present.
If in the future analytics services or third-party cookies were introduced, this notice would be updated and a consent-collection mechanism compliant with applicable ePrivacy guidance would be activated.
Changes to this notice
The Controller reserves the right to modify this notice at any time, communicating changes through the Site. The date of the last update is shown at the top of this document.
For questions or requests, please write to the Controller at the email indicated above.