1. Data Controller
The Data Controller for the personal data collected through this website is:
2. Types of Data Collected and Processed
This website is designed with a privacy-by-default architecture and collects only strictly necessary technical navigation data:
- Technical navigation data and log files: Information automatically gathered by server systems during your visit (such as anonymized IP addresses, browser user agent, access timestamps). These logs are processed solely to verify correct site operations and protect server infrastructure from security threats.
- Data voluntarily provided by the user: Sending emails to our contact address results in the acquisition of your email address and any details included in the message, used solely to respond to your inquiry.
- Technical navigation preferences (localStorage): The browser locally saves a key named
enigmi_langto remember your preferred language choice (Italian or English). This value is kept locally on your device and never transmitted to third parties or used for profiling.
No profiling or tracking cookies: This website does not use account registrations, newsletter forms, Google Analytics, or advertising trackers (such as Meta Pixel). The interactive riddle quiz runs entirely client-side inside your browser without transmitting any answers to external servers.
3. Purpose and Legal Basis of Processing
Personal data is processed strictly for the following purposes:
- Website delivery and cyber security: Ensuring pages load properly and shielding systems from unauthorized activity. Legal basis: Legitimate interest of the Controller (Art. 6(1)(f) GDPR).
- Inquiry response: Handling and replying to messages sent voluntarily by users via email. Legal basis: Performance of pre-contractual or contractual measures upon user request (Art. 6(1)(b) GDPR).
4. Processing Methods and Data Retention
Data is processed using secure electronic tools in compliance with European security standards. Technical server logs are retained for a minimal duration required for security diagnostics (typically no longer than 30 days) and subsequently purged. Email correspondence is kept as needed to service requests and fulfill applicable statutory obligations.
5. Third-Party Sharing and Self-Hosting
Personal data is never sold, leased, or transferred to third parties for marketing purposes. Infrastructure partners (such as hosting and CDN providers) operate under Data Processing Agreements pursuant to Art. 28 GDPR.
All typographic fonts, imagery, and interactive assets are self-hosted directly on our servers, ensuring no background telemetry or IP forwarding occurs to third parties while browsing.
6. User Rights (Articles 15-22 GDPR)
Under the GDPR, you have the right to request access, rectification, erasure, restriction of processing, and data portability, or to object to processing. You may also lodge a complaint with the competent supervisory authority (in Italy: Garante per la Protezione dei Dati Personali - www.garanteprivacy.it).
To exercise your rights, please reach out directly to the Data Controller at: .