Privacy Notice — Statuo
Rev. 3 — Last updated: 9 July 2026
Courtesy translation. In case of any discrepancy, the Italian version prevails (statuo.io/termini, statuo.io/privacy).
1. Data controller
Apdsoftware of Carlo Zuffetti (apdsoftware.it), Via C. Colombo 15, 24047 Treviglio (BG), Italy, VAT IT03835250162, e-mail: privacy@statuo.io (the "Controller").
This notice covers data processed by the Controller in relation to the statuo.io website and the Statuo service (the "Service"). For data the Controller processes on behalf of its agency customers (e.g. end users' contact details added as notification channels), the Controller acts as processor: the DPA applies, not this notice.
2. Data processed, purposes and legal bases
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data: agency name, e-mail, password (hash) | Provision of the Service, authentication | Contract (art. 6.1.b GDPR) | Contract duration + 30 days |
| Billing and payment data | Subscription management | Contract; legal obligations (6.1.c) | Statutory terms (10 years for tax documents). Payment data is collected and processed by Paddle, not by the Controller |
| Panel usage data and technical logs (IP, user agent, timestamps) | Security, abuse prevention, diagnostics | Legitimate interest (6.1.f) | Max 12 months |
| Monitoring configurations (URLs, the agency's notification channels) | Provision of the Service | Contract | Contract duration + 30 days |
| E-mail for service communications (alerts, expirations, changes to the Terms) | Performance of the contract | Contract | Contract duration |
| E-mail for product updates/marketing | Informing about Service news | Consent (6.1.a) or soft-spam for existing customers, with opt-out offered at collection and at every message, for similar services | Until withdrawal/objection |
Provision of contractual data is necessary: without it, the Service cannot be supplied. Data is collected directly from the data subject.
Data Protection Officer (DPO): not appointed, as the conditions of art. 37 GDPR are not met (no large-scale processing of special categories, no systematic monitoring of data subjects).
Automated decision-making: the Controller does not carry out processing under art. 22 GDPR (decisions based solely on automated processing producing legal or similarly significant effects).
3. Cookies and similar tools
The panel uses only technical storage (session token, language preference) necessary for its operation: it does not require consent. Public status pages use no cookies. The statuo.io website uses Umami, a self-hosted analytics tool running on the Controller's servers, which sets no cookies and does not track visitors across sites: data is aggregated and cannot be traced to individual visitors (legitimate interest, art. 6.1.f).
4. Recipients and sub-processors
Data may be processed, on the Controller's behalf, by providers appointed as processors under art. 28 GDPR:
| Provider | Service | Location/data region |
|---|---|---|
| Hetzner Online GmbH | Core/database infrastructure hosting | EU (Falkenstein, Germany) |
| Google Cloud | Continuous backup and disaster-recovery standby of the database; monitoring check (probe) infrastructure hosting | EU (Belgium, Milan) + USA (Iowa; check execution in memory only, no data storage) |
| Paddle.com Market Ltd | Payments (merchant of record — also acting as independent controller for the payment process) | UK/EU |
| Resend | Transactional e-mail delivery | Ireland (EU) |
| Telegram FZ-LLC (only if the customer enables the channel; only the chat identifier is transferred) | Notification delivery | Non-EU |
The up-to-date list is available on request at privacy@statuo.io. The Controller does not sell personal data nor share it for advertising purposes.
5. Transfers outside the EU
Where a provider entails transfers outside the European Economic Area (e.g. Telegram; execution of monitoring checks from Google Cloud's US location, without data storage), the transfer takes place on the basis of adequacy decisions (including the EU-US Data Privacy Framework, where applicable) or the European Commission's Standard Contractual Clauses (SCCs), with supplementary measures where necessary.
6. Data subject rights
Under arts. 15-22 GDPR you may exercise the rights of access, rectification, erasure, restriction, portability and objection — including objection to processing based on legitimate interest — by writing to privacy@statuo.io. The Controller responds within 30 days, extendable by two months in particularly complex cases with a reasoned notice. You may also lodge a complaint with the Italian supervisory authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).
7. Security
The Controller adopts appropriate technical and organizational measures, including: encryption in transit (TLS), passwords stored with robust hashing, per-customer data segregation (multi-tenancy), encrypted backups with restore testing, key-based and restricted infrastructure access. Following deletion, data may persist in backup copies until overwritten according to the rotation cycle, for a maximum of 30 days.
8. Minors
The Service is intended exclusively for professionals and businesses; it is not directed at persons under 18.
9. Changes
Any material changes to this notice will be communicated by e-mail and published on this page with the new update date.