Privacy Notice — Statuo

Rev. 3 — Last updated: 9 July 2026

Courtesy translation. In case of any discrepancy, the Italian version prevails (statuo.io/termini, statuo.io/privacy).

1. Data controller

Apdsoftware of Carlo Zuffetti (apdsoftware.it), Via C. Colombo 15, 24047 Treviglio (BG), Italy, VAT IT03835250162, e-mail: privacy@statuo.io (the "Controller").

This notice covers data processed by the Controller in relation to the statuo.io website and the Statuo service (the "Service"). For data the Controller processes on behalf of its agency customers (e.g. end users' contact details added as notification channels), the Controller acts as processor: the DPA applies, not this notice.

2. Data processed, purposes and legal bases

Data Purpose Legal basis Retention
Account data: agency name, e-mail, password (hash) Provision of the Service, authentication Contract (art. 6.1.b GDPR) Contract duration + 30 days
Billing and payment data Subscription management Contract; legal obligations (6.1.c) Statutory terms (10 years for tax documents). Payment data is collected and processed by Paddle, not by the Controller
Panel usage data and technical logs (IP, user agent, timestamps) Security, abuse prevention, diagnostics Legitimate interest (6.1.f) Max 12 months
Monitoring configurations (URLs, the agency's notification channels) Provision of the Service Contract Contract duration + 30 days
E-mail for service communications (alerts, expirations, changes to the Terms) Performance of the contract Contract Contract duration
E-mail for product updates/marketing Informing about Service news Consent (6.1.a) or soft-spam for existing customers, with opt-out offered at collection and at every message, for similar services Until withdrawal/objection

Provision of contractual data is necessary: without it, the Service cannot be supplied. Data is collected directly from the data subject.

Data Protection Officer (DPO): not appointed, as the conditions of art. 37 GDPR are not met (no large-scale processing of special categories, no systematic monitoring of data subjects).

Automated decision-making: the Controller does not carry out processing under art. 22 GDPR (decisions based solely on automated processing producing legal or similarly significant effects).

3. Cookies and similar tools

The panel uses only technical storage (session token, language preference) necessary for its operation: it does not require consent. Public status pages use no cookies. The statuo.io website uses Umami, a self-hosted analytics tool running on the Controller's servers, which sets no cookies and does not track visitors across sites: data is aggregated and cannot be traced to individual visitors (legitimate interest, art. 6.1.f).

4. Recipients and sub-processors

Data may be processed, on the Controller's behalf, by providers appointed as processors under art. 28 GDPR:

Provider Service Location/data region
Hetzner Online GmbH Core/database infrastructure hosting EU (Falkenstein, Germany)
Google Cloud Continuous backup and disaster-recovery standby of the database; monitoring check (probe) infrastructure hosting EU (Belgium, Milan) + USA (Iowa; check execution in memory only, no data storage)
Paddle.com Market Ltd Payments (merchant of record — also acting as independent controller for the payment process) UK/EU
Resend Transactional e-mail delivery Ireland (EU)
Telegram FZ-LLC (only if the customer enables the channel; only the chat identifier is transferred) Notification delivery Non-EU

The up-to-date list is available on request at privacy@statuo.io. The Controller does not sell personal data nor share it for advertising purposes.

5. Transfers outside the EU

Where a provider entails transfers outside the European Economic Area (e.g. Telegram; execution of monitoring checks from Google Cloud's US location, without data storage), the transfer takes place on the basis of adequacy decisions (including the EU-US Data Privacy Framework, where applicable) or the European Commission's Standard Contractual Clauses (SCCs), with supplementary measures where necessary.

6. Data subject rights

Under arts. 15-22 GDPR you may exercise the rights of access, rectification, erasure, restriction, portability and objection — including objection to processing based on legitimate interest — by writing to privacy@statuo.io. The Controller responds within 30 days, extendable by two months in particularly complex cases with a reasoned notice. You may also lodge a complaint with the Italian supervisory authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).

7. Security

The Controller adopts appropriate technical and organizational measures, including: encryption in transit (TLS), passwords stored with robust hashing, per-customer data segregation (multi-tenancy), encrypted backups with restore testing, key-based and restricted infrastructure access. Following deletion, data may persist in backup copies until overwritten according to the rotation cycle, for a maximum of 30 days.

8. Minors

The Service is intended exclusively for professionals and businesses; it is not directed at persons under 18.

9. Changes

Any material changes to this notice will be communicated by e-mail and published on this page with the new update date.