Privacy Policy
Last updated: 2026-05-19 — GDPR Reg. UE 2016/679 + D.Lgs. 196/2003 e s.m.i.
Contents
1. Data Controller
The controller of personal data collected through this site is Leaf Games & Software S.r.l.s., Italian VAT ID 14669501000, tax code , with registered office at Circonvallazione Casilina 124, 00176 Rome (RM), Italy.
Controller contacts:
- Email: leaf.games.software@gmail.com
- Phone: +39 327 612 5471
- Certified email (PEC): dpo@leafgs.it (to be activated within 60 days after site go-live)
At publication date, the Controller has not appointed a Data Protection Officer (DPO) pursuant to art. 37 GDPR, as the processing activities do not fall within those requiring mandatory appointment. For any matter relating to data processing, the data subject may contact the Controller directly.
2. Types of data collected
Through this website we collect the following categories of personal data:
- Contact data voluntarily provided via form (first name, last name, email, optional phone, optional company, message content, service of interest);
- Application data for open positions (name, email, optional phone, optional LinkedIn URL, curriculum vitae in PDF/DOC, cover message);
- Technical and navigation data collected by our self-hosted analytics system (IP address anonymized on capture, user-agent, page visited, referrer, timestamp, browser language, viewport size). No profiling cookies, no third-party trackers;
- Security data (failed login logs, injection attempts, CSRF events) for site defence.
We do not collect special categories of data pursuant to art. 9 GDPR (health, religion, politics, biometrics), nor data of minors under 16.
3. Purposes of processing
- Response to contact requests and quotes voluntarily submitted by the user;
- Evaluation of applications for open positions or future archive (with explicit consent);
- Fulfilment of pre-contractual and contractual obligations should the contact evolve into a client/supplier relationship;
- Fulfilment of legal obligations (Italian electronic invoicing SDI, document retention for tax purposes, anti-money laundering);
- Aggregate anonymous statistics on site usage, aimed at continuous improvement of content;
- Legal defence and IT systems security (legitimate interest of the Controller).
4. Legal basis of processing
- Purposes 1, 2 — performance of pre-contractual measures upon request of the data subject (art. 6.1.b GDPR) + explicit consent at form submission (art. 6.1.a);
- Purpose 3 — performance of the contract (art. 6.1.b);
- Purpose 4 — legal obligation (art. 6.1.c);
- Purpose 5 — legitimate interest of the Controller in measuring website effectiveness in an aggregate and anonymous way (art. 6.1.f); the user can refuse opt-in consent via the cookie banner;
- Purpose 6 — legitimate interest of the Controller in systems security (art. 6.1.f).
5. Processing methods
Processing takes place by electronic means (hosting servers located in Italy, MySQL database with encryption at rest) and, where necessary, paper supports (signed contracts). Appropriate technical and organisational measures are adopted (Argon2id for passwords, mandatory HTTPS, prepared statements against SQL injection, CSRF tokens, anti-abuse rate limiting, strict Content Security Policy, access logs). Access to data is limited to authorised personnel bound by confidentiality.
6. Data retention
- Form contact data: 24 months from the date of last interaction, except for conversion into client (in that case the contract term + 10 years for tax obligations applies);
- Applications: 12 months from submission, except for explicit retention confirmation;
- Anonymous analytics logs: 14 months (aligned to GA4 standard);
- Security logs: 6 months, except for judicial needs.
7. Recipients and transfers
Data is not disclosed to third parties except:
- Hosting provider (Netsons S.r.l., Italy) — data processor pursuant to art. 28 GDPR, servers in EU;
- Transactional email provider (the same Netsons hosting via SMTP);
- Competent authorities upon legitimate request (judicial, tax, police).
No data transfer outside the European Economic Area.
8. Rights of the data subject
Pursuant to articles 15-22 GDPR, the data subject is entitled to:
- Access to their data (art. 15);
- Rectification of inaccurate data (art. 16);
- Erasure ("right to be forgotten", art. 17) except for legal retention obligations;
- Restriction of processing (art. 18);
- Portability of data in structured format (art. 20);
- Objection to processing based on legitimate interest (art. 21);
- Withdrawal of consent at any time (art. 7.3), without prejudice to previous processing.
To exercise these rights, write to leaf.games.software@gmail.com. We will reply within 30 days.
9. Cookies and similar technologies
For details on types and durations, see the dedicated Cookie Policy. The site uses only technical cookies (session, CSRF, language) and, subject to opt-in consent via banner, aggregate anonymous self-hosted statistics (no Google Analytics, no Meta Pixel, no advertising tracker).
10. Data security
We adopt appropriate security measures required by art. 32 GDPR: TLS encryption in transit (mandatory HTTPS), Argon2id password hashing, environment segregation, database access control, encrypted daily backups, monitoring logs, security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy). In the event of a data breach, we notify the competent authority within 72 hours pursuant to art. 33 GDPR, and the data subject when required by art. 34.
11. Complaint to supervisory authority
A data subject who believes that the processing of their personal data infringes the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it — Piazza Venezia 11, 00187 Rome, Italy).
12. Changes to this policy
This policy may be updated at any time. The current version is always available at this URL. In case of substantial changes (e.g. new purposes or new recipients), registered users will receive notification by email.