Legal
Privacy policy
Last updated: 3 June 2026
This privacy policy describes how personal data is processed for users who visit the website, use the website builder platform («Builder»), and related services, in accordance with Regulation (EU) 2016/679 («GDPR») and Italian Legislative Decree 196/2003, as amended.
1. Data controller
The data controller is Martini Francesco (Sole proprietorship).
- Registered office: Via Fabio Fabiani 3, 59100 Prato (PO), Italy
- VAT No.: 02500080979
- Privacy enquiries: privacy@martinifrancesco.it
- Phone: +39 320 3209796
- Certified email (PEC): unitysite@pec.it
- Website: https://www.martinifrancesco.it
The controller is not required to appoint a Data Protection Officer (DPO); for any privacy-related matter you may write to the address above.
2. Scope
This privacy policy applies to the marketing website and the platform (registration, account area, Builder, website publishing and hosting, billing). For websites created and published by users through the Builder, the user is the data controller for their visitors' data; in that case we act as hosting provider and data processor (see section 9).
3. Categories of data processed
a) Registration and account data
- Email address, password (stored in encrypted form via hashing), first and last name.
- Optional profile data: phone number, contact email, company, role, city, country, address, website, biography, and profile picture.
b) Sign-in with Google (OAuth)
If you sign in with Google, we receive from your profile your Google identifier, email address (verified), and first/last name, in order to create or link your account. We do not store your Google password.
c) Account security data
- Security events (sign-in, sign-out, password change, account deletion) with IP address, user agent, and date/time, for security and abuse-prevention purposes.
d) Payment and billing data
- For paid subscriptions and packages we use Stripe: card data is processed directly by Stripe and does not pass through or get stored on our systems.
- We retain the Stripe customer ID, subscription status, amounts, and invoice references linked to your account.
e) Content created in the Builder
- Pages, text, design settings, components, variables, CMS data, and uploaded files (images, videos) in the media library.
- Such content may include third parties' personal data that the user chooses to enter: the user is responsible for the lawfulness of such entries.
f) Newsletter
- Email address and, optionally, name; technical data (IP, user agent, source URL) and confirmation/unsubscribe tokens, with a double opt-in mechanism.
g) Contact and consultation forms
- First name, last name, email, phone (optional), and message. These data are sent to us by email and are not stored in a dedicated database.
h) Browsing data and cookies
- Technical data collected automatically by our systems (IP address, browser/device type, pages visited, server logs) and cookies, as described in our Cookie policy.
4. Purposes and legal bases
- Account creation and management and provision of platform services — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Authentication and security (including Google sign-in and security logs) — legal basis: performance of a contract and legitimate interest (Art. 6(1)(b) and (f)).
- Publishing and hosting of websites created with the Builder — legal basis: performance of a contract.
- Payment, subscription, and billing management — legal basis: performance of a contract and legal obligation (Art. 6(1)(b) and (c)).
- Responding to requests submitted via contact/consultation forms — legal basis: pre-contractual measures and legitimate interest.
- Newsletter delivery — legal basis: consent, withdrawable at any time (Art. 6(1)(a)).
- Analytics and statistics / marketing via cookies — legal basis: consent, managed through the cookie banner.
- Legal compliance (accounting, tax, legal defence) — legal basis: legal obligation and legitimate interest.
5. Processing methods
Data are processed using IT and electronic means, with appropriate technical and organisational measures to ensure security, integrity, and confidentiality (e.g. encrypted connections, access controls, password hashing). Processing is carried out by the controller and by authorised persons and/or processors listed in section 7.
6. Data retention
- Account and content data: for the duration of the relationship and until account deletion, except where longer retention is required by law.
- Billing data: for the period required by tax law (generally 10 years).
- Contact data: until the request is handled and for any subsequent period required for compliance.
- Newsletter: until consent is withdrawn/unsubscription.
- Logs and security data: for as long as necessary for security purposes and within legal limits.
7. Recipients and external processors
Data may be processed, for the purposes stated above only, by providers acting as data processors, including:
- Aruba S.p.A. — hosting of the website and platform infrastructure;
- Stripe — payment and billing management;
- Google — OAuth authentication and, with consent, Google Tag Manager, Google Analytics, Google Ads, and Google Fonts;
- Microsoft — with consent, Microsoft Clarity (website behavioral analytics);
- Email providers (SMTP) — delivery of transactional emails and the newsletter.
Data are not disclosed or transferred to third parties for their own independent purposes.
8. Transfers outside the EU
Some providers (e.g. Stripe and Google) may process data outside the European Economic Area. In such cases, transfers take place in compliance with the GDPR, through adequacy decisions or standard contractual clauses approved by the European Commission.
9. User-published websites (hosting)
For websites that users create and publish through the Builder (on a subdomain or custom domain), the user is the data controller for their visitors' data, while the provider acts as data processor for hosting and technical transmission activities (for example forwarding form submissions by email). Users must provide their own privacy and cookie policies on their sites and collect the necessary consents. Visitor data from published sites are not used by the provider for its own purposes.
10. Data subject rights
You may exercise the rights provided under Articles 15–22 of the GDPR at any time:
- access, rectification, and erasure of data;
- restriction of processing and objection to processing;
- data portability;
- withdrawal of consent, without affecting the lawfulness of processing based on consent before its withdrawal;
- complaint to the Italian Data Protection Authority (garanteprivacy.it).
To exercise your rights, write to privacy@martinifrancesco.it. You may also delete your account from your account settings.
11. Nature of data provision
Providing data necessary for registration, service delivery, and billing is mandatory in order to use the platform: without it, we cannot create an account or provide the service. Providing data for the newsletter and for analytics/marketing cookies is optional and based on consent: refusal does not prevent use of the website, but disables the related features (e.g. newsletter delivery, analytics).
12. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects or similarly significantly affects data subjects under Art. 22 GDPR.
13. Minors
The services are not directed at children under 16. We do not knowingly collect data from minors without parental or guardian consent.
14. Cookies
The website uses technical cookies and, with consent, analytics and marketing cookies. For details and to manage your preferences, see our Cookie policy.
15. Changes to this policy
This privacy policy may be updated from time to time. Changes will be published on this page with the date of the last update.