Privacy policy
Last updated: 5 October 2026
This policy explains how personal data is processed when you visit onioncat.net or contact OnionCat, in accordance with Regulation (EU) 2016/679 (GDPR) and the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended).
1. Data controller
Riccardo Loti, self-employed professional trading as OnionCat (OnionCat di Riccardo Loti)
Corso Giulio Cesare 187, 10155 Torino (TO), Italy
VAT no. (P.IVA) 01234567890
Email: info@onioncat.net
2. What data is processed, why, and on what legal basis
Contact form and email
When you use the contact form or write to us, we process the data you provide: name, email address, phone number and company (optional), the type of request (private or business) and the content of your message. We use it only to reply to you and, where relevant, to prepare a quote or arrange a service visit.
Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). Providing this data is voluntary, but without it we cannot reply.
Phone and WhatsApp
If you call us or write to us on WhatsApp, we process your phone number and the content of the conversation for the same purposes and on the same legal basis as above. WhatsApp is a service of WhatsApp Ireland Ltd. (Meta group), which processes data under its own privacy policy.
Data seen during support work
While providing support, we may incidentally have access to data stored on your devices or systems. We process it only as far as strictly necessary to carry out the work you requested, without copying or keeping it, unless agreed otherwise in writing. For business clients who ask for it, we can sign a data processing agreement (art. 28 GDPR).
Technical data (server logs)
Like any website, our hosting provider automatically records technical data for each request, such as IP address, date and time, page requested and browser type. This data is used only to operate the site securely and to detect abuse.
Legal basis: legitimate interest in the security and correct operation of the website (Art. 6(1)(f) GDPR).
Website statistics
We use Plausible Analytics, a privacy-focused service based in the European Union, to count visits and see which pages are read. Plausible does not use cookies, does not collect personal data and does not track you across websites. All data is aggregated. Your IP address is used only momentarily to create a daily-rotating anonymous identifier and is not stored.
Legal basis: legitimate interest in understanding how the website is used (Art. 6(1)(f) GDPR).
3. Cookies and local storage
This website does not use cookies, either its own or third-party. If you choose a language with the language selector, your choice is saved in your browser's local storage so the site can remember it. This is strictly necessary to provide the function you requested and is never shared.
4. How long data is kept
- Enquiries and related correspondence: up to 24 months after the last contact, unless a contract follows. In that case, documents are kept as long as required by tax and accounting law (generally 10 years).
- Server logs: for the period set by the hosting provider for security purposes, normally a few weeks.
- Plausible statistics: aggregated and anonymous, so they contain no personal data.
5. Who processes the data
Data is processed by the controller and, on its behalf, by these service providers acting as data processors:
- GoDaddy, for website hosting and domain management;
- Microsoft, for business email (Microsoft 365);
- Plausible Insights OÜ (Estonia, EU), for anonymous website statistics;
- WhatsApp Ireland Ltd., if you choose to contact us on WhatsApp.
Data is not sold or shared with anyone for marketing purposes.
6. Transfers outside the European Union
Some providers, such as GoDaddy, Microsoft and Meta, are based in the United States or may process data there. Such transfers rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework or on the Standard Contractual Clauses approved by the European Commission.
7. Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to data portability (Articles 15–22 GDPR). To exercise these rights, write to info@onioncat.net.
You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
No automated decision-making or profiling takes place.
8. Changes to this policy
This policy may be updated from time to time. The date at the top shows the latest version.