This page is not final: the entity details in square brackets are still to be filled in.
Legal
Privacy policy
What we collect, why, where it sits, and how to get it back or get rid of it. This site collects very little, so this page is short.
Last updated: 21 July 2026
Who is responsible
The data controller is [RAGIONE SOCIALE], VAT number [P.IVA], registered at [INDIRIZZO].
For anything on this page — a question, a request, a complaint — write to [EMAIL PRIVACY]. A person reads it.
We have not appointed a data protection officer. We are not required to, and pretending otherwise would only add a mailbox nobody answers.
What this page covers
This page covers the public eutetic site and the demo behind the login. It does not cover a box installed in a workshop: what a box reads from your machines is governed by the contract signed with your company, not by this page.
The contact form
The form at the bottom of the home page asks for four things: your name, your company, your email address, and your message. Name, email and message are required; company is not.
We use them for one purpose: to read what you wrote and answer you. Nothing goes into a mailing list, and we do not write to you again about something else.
The legal basis is Article 6(1)(b) GDPR — steps taken at your request before entering into a contract — and, where your message is not about a possible contract, our legitimate interest under Article 6(1)(f) in replying to people who write to us. You choose what to put in the message field, so please keep it to what is needed to answer; do not send health data, ID documents, or anyone else's personal data.
The form is delivered by FormSubmit, a third-party form relay, which passes the message on to our mailbox. It is a processor for that step. We have not been able to confirm where FormSubmit operates its servers, so we cannot rule out that your message is handled outside the European Economic Area. If that matters to you, write to us directly at the address above instead of using the form.
The form has a hidden field that automated senders fill in and people do not. If it comes back filled, the message is dropped and nothing is sent anywhere. That field collects nothing about you.
We keep the resulting email for as long as the conversation is live, and then for up to 24 months, so that we can pick up a thread you started. After that it is deleted.
Accounts and login
You can create an account directly or receive one from an administrator. Before signing in, you must verify your email address. We hold your name, email address, password stored as a hash — never in readable form — role, and a record of your sessions.
We use it to let you in, to keep you logged in, and to know who did what if something needs to be looked into. The legal basis is Article 6(1)(b): performance of the arrangement under which you were given access.
Account and profile data lives in a Supabase Postgres database in region eu-west-1, inside the European Union. Supabase also provides the authentication service. Transactional authentication emails are delivered by Resend, which receives the destination address and the message needed for that delivery.
We keep it while the account is open. Close the account and we delete it, along with the sessions, within 30 days.
What you load into the demo
If you import a dataset into the demo, that file stays in your browser. It is held in your browser's own storage on your own machine and is never uploaded to us. We cannot see it, and clearing your browser storage removes it for good.
Hosting and server logs
The application is deployed through Coolify on Eutetic's server hosted by Seeweb in Italy. Like any hosting provider, Seeweb and our server can record requests as they arrive — IP address, time, page requested, and browser string. Those logs exist to serve pages and detect abuse, on the legitimate-interest basis of Article 6(1)(f), and are kept only as long as operationally necessary.
Cloudflare provides DNS, HTTPS proxying and Turnstile abuse protection. Requests therefore pass through Cloudflare, and Turnstile evaluates browser and interaction signals on login, signup and password-recovery forms. Where a provider processes data outside the European Economic Area, the transfer is governed by the safeguards in that provider's data-processing terms.
What we do not do
It is worth being specific about the things this site does not do:
- There is no analytics of any kind. No page-view counter, no heatmaps, no session recording.
- There are no profiling or advertising cookies. Strictly necessary session and Turnstile security technology is described on the cookie page.
- There is no advertising, no ad network, no tracking pixel.
- The video on the home page is served from our own site, not embedded from a video service, so watching it tells nobody anything.
- We do not sell, rent or trade personal data. There is no scenario in which we would.
- There is no automated decision-making and no profiling under Article 22 GDPR. Nothing here decides anything about you on its own.
Who else sees the data
The processors used for these functions are Seeweb for server hosting, Cloudflare for network and abuse protection, Supabase for authentication and database services, Resend for authentication email, and FormSubmit for delivering the public contact form. Beyond them, we disclose personal data only if a court or competent authority requires it.
Your rights
Under Articles 15 to 22 GDPR you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask us to limit what we do with it, ask for it in a portable form, and object to processing we base on legitimate interest. Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not undo what was lawful before.
Write to [EMAIL PRIVACY]. We answer within one month. If we need longer we will tell you why, before the month is up.
Giving us your data is never compulsory. The consequence of not giving it is simply that we cannot do the thing it was for: no email address, no reply.
If you think we have handled your data badly, you can complain to the Garante per la protezione dei dati personali (garanteprivacy.it), or to the supervisory authority where you live or work. You can go to court as well. We would rather you told us first, but that is your call, not ours.
Changes to this page
If we start doing something new with personal data, this page changes before the new thing starts, not after. The date at the top is the date of the last change.