This policy describes how the personal data of visitors to the nispo.it website are processed, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), Italian Legislative Decree 196/2003 (the "Privacy Code") and the Italian Data Protection Authority's Guidelines on cookies and other tracking tools (10 June 2021). This English version is a translation; the Italian version prevails.

The short version: without your consent the website only uses technical tools that it needs to work. Microsoft Clarity (statistics) and Google Ads (conversion measurement) are activated only if you accept them in the banner, and you can change your mind at any time from “Cookie preferences” at the bottom of every page. We do not sell personal data.

1. Data controller

The data controller is NisPo S.r.l. (VAT no. IT13164880968), Milan, Italy.
For any request concerning personal data you can write to info@nispo.it.

The website uses three categories of tools. Only the first is active without consent.

2.1 Technical tools (always active)

Information stored in your browser (localStorage and sessionStorage) to make the website work and remember your choices. It is not used to profile you, is not accessible to third parties and, under Article 122 of the Privacy Code, does not require consent.

NamePurposeDuration
nispo-consentRemembers your cookie choices6 months, then the banner is shown again
nispo-themeRemembers the light or dark theme you choseUntil deleted from the browser
nispo-langRemembers the language you chose, so the language notice is not shown againUntil deleted from the browser
nispo-seen:<page>Avoids replaying the opening animation of a page already viewedUntil the browser is closed

2.2 Statistics: Microsoft Clarity (only with consent)

With your consent to the “Statistics” category we use Microsoft Clarity, provided by Microsoft Ireland Operations Ltd., to understand how the website is used and improve it: heatmaps and recordings of browsing sessions (clicks, mouse movements, scrolling, pages viewed), together with information about your device and browser. Clarity assigns the browser a pseudonymous identifier through first-party cookies (_clck, _clsk) and Microsoft third-party cookies (CLID, MUID, ANONCHK, MR, SM). The Clarity script is not loaded until you consent; when you do, we pass your consent to Clarity through its consent API.

Provider information: Clarity cookies and Microsoft privacy statement.

Legal basis: consent (Art. 6(1)(a) GDPR and Art. 122 Privacy Code).

2.3 Marketing: Google Ads (only with consent)

With your consent to the “Marketing” category we use the Google Ads tag, provided by Google Ireland Ltd., to measure conversions: whether a demo request comes from one of our ads. The tag uses the first-party cookie _gcl_au (default duration 90 days) and Google cookies on Google's own domains. The tag is not loaded until you consent; we signal this to Google through Consent Mode (set to “denied” until you choose). We do not use the website for remarketing.

Provider information: cookies used by Google's advertising products and Google privacy policy.

Legal basis: consent (Art. 6(1)(a) GDPR and Art. 122 Privacy Code).

2.4 How to give, refuse and withdraw consent

  • On your first visit a banner asks what to activate: you can accept all, reject or choose by category. Closing the banner with the X means rejecting non-technical tools. Continuing to browse or scrolling does not count as consent.
  • You can change your choice at any time from the “Cookie preferences” link at the bottom of every page or from the button on this page. If you withdraw a consent, we delete the first-party cookies of the tools concerned and reload the page.
  • Your choice is remembered for 6 months; after that the banner is shown again.
  • Withdrawal does not affect the lawfulness of processing carried out before it. You can also block or delete cookies in your browser settings.

3. Browsing data

The website is a static site published through Cloudflare Pages (Cloudflare, Inc.). As with any website, the hosting infrastructure temporarily records in its technical logs some data implicitly transmitted by the browser (IP address, date and time of the request, requested page, user agent). These data are used exclusively to deliver the service and for security purposes (e.g. attack mitigation); Nispo does not use them to identify visitors and does not combine them with other data.

Legal basis: the controller's legitimate interest in the operation and security of the website (Art. 6(1)(f) GDPR).

4. Third-party fonts

The pages load their typefaces from the Google Fonts service (Google Ireland Ltd.). When the browser downloads the fonts, it transmits its IP address to Google. Google states that requests to its font servers are not associated with other Google account data and are not used for advertising, and that the service does not set cookies.

Legal basis: legitimate interest in a consistent and technically efficient presentation of the website (Art. 6(1)(f) GDPR).

5. Data you provide

Email. If you write to info@nispo.it, we process your address, the identification data you include and the content of your message, solely to reply to you and handle your request.

Demo booking. The “Book a demo” button opens, on top of the page, the booking calendar of the Cal service (Cal.com). To display it, the website loads a script from Cal's servers, which therefore receive your browser's IP address; the booking window may use Cal technical tools that it needs to work. The data you enter (name, email, chosen time slot, any notes) are processed by Nispo to organise and hold the demo; Cal operates under its own privacy policy. If you have consented to the “Marketing” category, when the booking is completed we send Google Ads a conversion event, which does not contain the data entered in the form.

Legal basis: performance of pre-contractual measures taken at your request (Art. 6(1)(b) GDPR); for loading the calendar, legitimate interest in offering online booking (Art. 6(1)(f) GDPR).

6. Recipients of the data

Data are not sold. They may be accessed, solely for their respective part and as independent controllers or processors, by the providers of the services described above: Cloudflare (hosting), Google (fonts and, with consent, Google Ads), Microsoft (with consent, Clarity), Cal.com (demo booking) and the email provider.

7. Transfers outside the EU

Some providers (Cloudflare, Google, Microsoft, Cal.com) belong to groups based in the United States. Where data are transferred outside the European Union, the transfer takes place on the basis of the EU-US Data Privacy Framework, for certified providers, or of the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR).

8. Retention periods

Your cookie choice is stored in your browser for 6 months. Clarity and Google Ads cookies have the durations stated by their providers (90 days for _gcl_au) and are deleted when you withdraw consent, for the part set on our domain. Hosting technical logs are kept by the provider only for as long as strictly necessary for security purposes. Email communications and booking data are kept for as long as needed to handle the request and, if a contractual relationship follows, for the applicable statutory periods.

9. Your rights

Under Articles 15-22 GDPR you have the right to:

  • access your personal data and obtain a copy;
  • request their rectification or erasure;
  • request restriction of processing or object to processing based on legitimate interest;
  • withdraw consent at any time, without affecting the lawfulness of prior processing;
  • receive your data in a structured format (portability), where applicable;
  • lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

To exercise your rights, write to info@nispo.it: we reply within the time limits set by Article 12 GDPR.

10. Minors

The Nispo website and services are aimed exclusively at companies and professionals and are not intended for anyone under 18.

11. Changes to this policy

If the website introduces new tools that process personal data, this policy and the banner are updated before they are activated and, for tools that require consent, consent is requested again. The date of the latest update is shown at the top of the page.