Pursuant to Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
Last updated: 23 aprile 2026 · Titolare: Sinibaldi Jordan
The data controller is: Sinibaldi Jordan web portal: https://aitailormade.it For any request regarding data processing, please contact the controller through the official channels indicated on the portal.
The portal may process the following categories of data: a) Technical browsing data: IP address, user agent, pages visited, access timestamps, HTTP referrer. Collected automatically by servers for security and monitoring. b) User preferences: selected language, cookie banner choice. Stored locally in the browser (localStorage/cookies). c) Voluntarily submitted content: texts, queries, images and files uploaded by the user in portal modules (BeGreen, BeTransfer, BeElectric, BEIT, BePDF). Processed solely to deliver the requested service. d) AI module interaction data: prompts and generated responses. Potentially transmitted to third-party AI providers (see art. 6). e) Donation data: donation transactions are managed directly by PayPal; the portal does not receive or retain payment data.
Data is processed for the following purposes: 1. Service delivery: execution of portal module functions at the user's request. Legal basis: performance of a contract or pre-contractual measures (Art. 6.1.b GDPR). 2. IT security: preventing unauthorized access, fraud, abuse and attacks. Legal basis: legitimate interest of the controller (Art. 6.1.f GDPR). 3. Legal obligations: compliance with regulatory requirements. Legal basis: legal obligation (Art. 6.1.c GDPR). 4. Service improvement: aggregated and anonymized analysis of portal usage. Legal basis: legitimate interest. 5. Cookie consent management: where required by applicable regulations. Legal basis: consent (Art. 6.1.a GDPR).
Data is retained for the time strictly necessary for the stated purposes: - Technical security logs: up to 90 days, unless retention is required for ongoing investigations. - Files uploaded via BeTransfer: deleted at the user-configured expiry date, or in any case within 30 days of upload. - Images analyzed by BeGreen: stored in server cache to improve response speed; periodically deleted. - Browser preferences (language, cookie consent): stored locally until deleted by the user. - Session data: deleted upon session closure or token expiry.
Under Arts. 15-22 GDPR, data subjects have the right to: - Access (Art. 15): obtain confirmation of processing and a copy of their personal data. - Rectification (Art. 16): request correction of inaccurate or incomplete data. - Erasure (Art. 17 — "right to be forgotten"): obtain deletion of their data, subject to legal obligations. - Restriction of processing (Art. 18): request restriction of processing in certain cases. - Data portability (Art. 20): receive data in a structured, machine-readable format, where applicable. - Objection (Art. 21): object to processing based on legitimate interest. - Withdrawal of consent (Art. 7.3): withdraw consent at any time without affecting the lawfulness of prior processing. - Complaint to the supervisory authority: lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it). Requests must be submitted via the official portal contact channels.
Data is not sold or transferred to third parties for their own commercial purposes. It may be disclosed to the following parties, only to the extent strictly necessary to provide the service: - Hosting provider (OVH SAS, France, EU): for server infrastructure. Adequacy ensured by EU headquarters. - AI provider (e.g. GitHub Models / Microsoft Azure OpenAI): for processing prompts sent to AI modules. Prompts may contain text entered by the user. Adequacy ensured by Standard Contractual Clauses (SCCs) or EU Commission adequacy decision. - PayPal (Europe) S.a.r.l. et Cie, S.C.A.: exclusively for donation transactions. Governed by its own privacy policy. For any transfer outside the EEA, the controller ensures that adequate safeguards exist pursuant to Arts. 44-46 GDPR.
The AITailorMade portal is not intended for users under 14 years of age. The controller does not knowingly collect personal data from children under 14. If a parent or guardian discovers that a minor has provided personal data without authorization, they are invited to contact the controller for deletion.
This notice may be updated to reflect legal changes, technical evolutions of the portal or new module integrations. Material changes will be communicated with a prominent notice on the site. The date of the last update is shown at the top of this page.