Campaign Krynos · privacy policy
Privacy Policy
This page explains, pursuant to Regulation (EU) 2016/679 (GDPR), what personal data we collect when you join the campaign, why we use it and how long we keep it. The short version: we process your email address and the technical payment references; your card number never passes through and is never stored on our systems — it is handled by Stripe alone. If you request an invoice, we also process the tax details needed to issue it. No marketing, no sharing of data with third parties.
1. What data we process
- The email address you enter in the pledge form.
- The technical payment references generated by Stripe: the identifiers of the customer, of the payment method and of the transaction (if any), together with the amount and the status of the pledge. They are not your card number: they are codes that allow Stripe to carry out the charge you authorised.
- The text and the date/time of the declarations you accept when pledging: the conditional charge mandate and the consent to immediate delivery with acknowledgement of the loss of the right of withdrawal.
- The data needed for delivery and service: the recovery and download tokens (stored only in encrypted form, as hashes), their expiry dates, the number of downloads made, the dates on which service emails were sent and any technical errors.
- Invoicing data, only if you request an invoice through the dedicated portal: type of invoice holder (individual or business), first and last name or company name, Italian tax code (codice fiscale), VAT number, SDI recipient code, PEC (certified email) address and full postal address, together with the amounts and VAT details of the transaction. This data is kept in a dedicated archive, separate from the pledge records.
- Technical security data: your IP address, used to limit repeated form submissions and prevent abuse, and the technical identifiers of the payment events notified by Stripe (which contain no personal data).
2. Why we use it and on what legal basis
- To manage your pledge and the contract (Art. 6(1)(b) GDPR): recording your pledge, carrying out the charge when the campaign closes if the threshold is reached, delivering the software to you and sending you service emails only — pledge confirmation, a reminder 48 hours before the campaign closes, the campaign outcome and the download link — and handling any invoice request, including sending your personal access link to the invoicing portal.
- To comply with legal obligations (Art. 6(1)(c) GDPR): in particular issuing the requested invoice, transmitting it to the Italian Interchange System (Sistema di Interscambio) and retaining invoices and accounting records.
- For our legitimate interest (Art. 6(1)(f) GDPR): security and abuse prevention (IP-based rate limiting of submissions, anti-spam field) and keeping proof of the declarations made, to protect the rights of both parties.
We do no marketing, profiling or newsletters; no data is sold or transferred to third parties for commercial purposes. The charge at the close of the campaign happens automatically, but only in execution of the mandate you expressly granted when pledging.
3. Your card: what Stripe sees and what we see
When you pledge, you are redirected to Stripe's payment page, where you enter your card and complete 3D Secure verification with your bank. Full card details are collected and processed exclusively by Stripe and never pass through or get stored on our servers: we only receive the identifier codes needed to arrange the charge you authorised. Stripe processes your data under its own privacy policy, including as an independent data controller for fraud-prevention purposes.
4. Who your data may be shared with
- Stripe (Stripe Payments Europe, Ltd and its group companies), for payment processing.
- The hosting provider — Seeweb (Italy) — on whose servers the Site and the database are hosted.
- The email delivery service — Twilio SendGrid, Inc. (United States) — for service communications only.
- The Seller's accountant — Studio CMA (Italy) — who receives the invoicing data to process and issue the invoices through their cloud accounting software.
- The Italian Revenue Agency (Agenzia delle Entrate), via the Interchange System, to which electronic invoices are transmitted as required by law.
- Google: the Site's pages load their typefaces from Google Fonts; in doing so, your IP address is transmitted to Google's servers.
Beyond these parties, the data is not disclosed to anyone, except where required by public authorities or by law.
5. Transfers outside the European Union
The processing carried out by Stripe and Google may involve transfers of data to the United States. Such transfers take place on the basis of the safeguards provided for by the GDPR: adequacy decisions (EU-US Data Privacy Framework) or standard contractual clauses.
6. How long we keep it
- Completed purchase: contractual and accounting data is kept for 10 years, in compliance with civil-law and tax obligations.
- Declarations made when pledging (charge mandate and consent with loss of the right of withdrawal): for the ordinary limitation period of legal claims, normally 10 years.
- Invoicing data and issued invoices: 10 years from issue, in compliance with the obligation to retain accounting records; invoice requests not followed by an issued invoice are deleted together with the pledge data.
- Pledge with no charge (unsuccessful campaign or withdrawn pledge): the payment method is removed from Stripe and the pledge data is deleted or anonymised within [12 months] of the close of the campaign.
- Recovery and download tokens: until they expire and for as long as needed for support.
- Anti-abuse IP addresses: for [30 days].
7. Your rights
You may exercise at any time the rights set out in Articles 15–22 GDPR: access to your data, rectification, erasure, restriction of processing, objection (in particular to processing based on legitimate interest) and portability. Just write to luca@lucaercoli.it: we reply within one month. If you believe the processing infringes the law, you may lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it). Data included in invoices already issued cannot be freely deleted or amended during the mandatory retention period: any corrections are made using the instruments provided for by tax law (adjustment notes).
8. Cookies
The Site uses a single cookie, a technical session cookie, needed for the Site's forms — pledge and invoice request — to work (CSRF protection): it is deleted when you close your browser and requires no consent. We use no profiling or analytics cookies. The payment pages, hosted on Stripe's domain, use the cookies described in Stripe's own policy.
9. Provision of data
The email address and the declarations requested in the form are necessary to join the campaign: without them the pledge cannot be recorded. Invoicing data, on the other hand, is needed only if you request an invoice: without it the invoice cannot be issued. The Site is intended for adults only.
10. Changes
Any changes to this policy will be published on this page, with the date shown at the top updated accordingly.
Luca Ercoli (Sole Proprietorship) · VAT no. 03257590608 · Campaign Krynos · krynos · Document last updated 18 August 2026 · General terms and conditions of sale