1. Data controller
The data controller is Mighty Pixel SRL, with registered address at V.le G. da Cermenate 54, 20141 Milan (MI), Italy, VAT number 09278690962.
Privacy-related requests can be sent to info@mightypixel.it.
2. Types of data processed
The website does not provide user accounts, restricted areas, newsletters or profiling functions.
Browsing and technical data
Systems needed to publish and protect the website may acquire technical data generated while browsing, such as IP address, request date and time, requested URL, response code, user agent, and technical browser or device information.
This data depends on the hosting service and log configuration. The website code does not use it to profile users.
Data provided voluntarily
The contact form collects the request type, name, email address and message. Company and telephone number are optional. Users may voluntarily include other information in their message.
The form also uses a technical anti-spam field not intended for users and an indicator of the page language.
Privacy preference data
The browser stores the choice version, date, expiry and selected categories locally. No name, email address, IP address or other identifier is stored in the local preference record.
Analytics and tracking
As of the last-updated date, no analytics, advertising, profiling, session-recording or social-tracking tools were detected in the public website.
3. Purposes of processing
Data may be processed to make the website available and secure, diagnose faults and prevent abuse.
Data submitted through the form is used to receive, assess and answer the user’s enquiry and to manage subsequent communications requested by that person.
The privacy preference is stored so that the notice is not shown unnecessarily and the user’s choices can be applied.
4. Legal bases
Contact enquiries are handled to take pre-contractual steps at the data subject’s request or, for non-pre-contractual enquiries, on the legitimate interest in answering communications received.
Technical operation, security and abuse prevention may rely on the controller’s legitimate interest in maintaining a reliable and secure website.
Compliance with applicable legal obligations provides an additional legal basis where relevant.
Any future non-essential service requiring consent may be activated only after a positive, specific choice. No such optional service is active as of the date stated above.
5. Processing methods and security
Processing uses digital systems and technical and organisational measures appropriate to the risk, applying data minimisation, purpose limitation and need-to-know access.
The form sends data to the website server in a POST request and forwards it by SMTP to info@mightypixel.it. SMTP credentials are kept outside the public directory and are not included in the website.
No Internet transmission can be regarded as risk-free; the controller and relevant providers should review the measures applied periodically.
6. Retention
Contact enquiries are retained for as long as needed to handle the request and any resulting communications, plus any further period required by law or for the establishment, exercise or defence of legal claims. The exact operational period requires controller confirmation.
Technical-log retention depends on the hosting provider’s configuration and requires controller confirmation.
The privacy preference stored in the browser expires after six months, or sooner when the consent-model version changes.
7. Recipients and providers
Data may be processed by authorised personnel and providers supporting hosting, technical infrastructure and email, within the limits needed for their respective functions.
The repository does not identify the contracted hosting and email providers. Their identities and privacy roles require controller confirmation before final legal validation.
Data is not intended for public disclosure.
8. Transfers outside the EEA
The website code does not establish where hosting and email providers process data. Any transfer outside the European Economic Area must follow GDPR Chapter V and the applicable safeguards.
Providers, processing locations and safeguards require controller confirmation.
9. Data-subject rights
Where provided by the GDPR, data subjects may request access, rectification, erasure, restriction and portability, and may object to processing.
Where processing relies on consent, consent may be withdrawn at any time without affecting processing carried out lawfully before withdrawal.
Data subjects may lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority.
Italian Data Protection Authority10. Privacy contact
Requests concerning personal data or the exercise of rights can be sent to info@mightypixel.it. To support appropriate handling, the request should clearly describe the right being exercised and the relevant context.
11. Updates
This notice may be updated when the website, services, providers or applicable framework change. The date shown at the top identifies the latest published version.
A material change to the consent model will increment its version and trigger a new choice where required.
