Privacy policy
Version: 26 July 2026
1. Controller and contact
For data relating to website visits, registration, contracts, support and billing, the controller is the operator identified in the operator panel on this page. Pro-Tech IT Solutions is an operating division and brand of the operator, not a separate legal entity. Privacy requests may be sent to the privacy contact shown there. No data protection officer has been appointed unless stated otherwise in the future.
2. Roles when processing customer documents
The operator acts as controller for account, contract, technical, security and billing data. Where a customer uploads invoices or other documents containing personal data for extraction, review and conversion, the customer generally determines the purposes and essential means and acts as controller; the operator processes that data on the customer's behalf as processor under Article 28 of Regulation (EU) 2016/679. The data processing agreement forms part of the Terms of Service. Where an accountant or other professional uses the advisor workspace for clients, that professional remains responsible for holding the engagement and any required delegations, issuing lawful instructions and promptly revoking access that is no longer needed. The operator processes documents on the professional customer's behalf; the internal engagement confirmation does not replace an official delegation to the Agenzia delle Entrate.
3. Categories of data
- Registration and account data: business, name, email address, language, role, account status and password stored only as a hash.
- Business and tax data: legal name, address, VAT ID, fiscal code, PEC, recipient code, tax regime and numbering settings.
- Document and invoice data: uploaded invoices and images, supplier and customer details, amounts, tax rates, descriptions, document numbers and dates, generated XML and PDF files, file hashes and duplicate warnings.
- Contract and payment data: plan, allowance, billing period, subscription status, PayPal transaction references and invoices issued by the operator. The service does not receive complete payment instrument details.
- Technical and usage data: IP address and request data in server logs, sessions, access times, processing attempts and status, error messages and strictly necessary browser settings. With analytics consent, plan selection, checkout start, purchase, renewal and cancellation may also be measured with amount, currency and a pseudonymous technical reference; email addresses, PayPal identifiers, tax data and invoice content are not sent to Google.
- reCAPTCHA security data: when a protected action is submitted, the IP address, browser and device data, interaction signals, requested action, a short-lived security token and the risk score returned by Google are processed. Invoices and document content are not sent to reCAPTCHA.
- Communications and support: name, email address, subject and message submitted through the contact form, bug reports and a pseudonymous technical identifier derived from the IP address to limit abuse. Users should not include unnecessary invoice content in requests.
4. Purposes and legal bases
- Account creation and administration, document processing, delivery of results, support and subscription administration: performance of a contract or pre-contractual steps, Article 6(1)(b) GDPR.
- Issuing and retaining service invoices, tax compliance and responding to authorities: legal obligation, Article 6(1)(c) GDPR.
- Security, abuse and duplicate prevention, infrastructure protection, troubleshooting and legal defence: legitimate interests of the operator and users in a secure and auditable service, Article 6(1)(f) GDPR.
- Protection of public forms and sign-in through reCAPTCHA: legitimate interest in preventing bots, automated access attempts and abuse, Article 6(1)(f) GDPR. reCAPTCHA is a necessary security function and does not depend on optional analytics or marketing consent.
- Optional public-site analytics and marketing and conversion measurement in the customer portal: consent, Article 6(1)(a) GDPR. Consent is optional, may be refused and may be withdrawn at any time in cookie settings without affecting necessary functions.
- Handling contact-form requests: consent, Article 6(1)(a) GDPR; for pre-contractual or contractual enquiries, also Article 6(1)(b) GDPR. Automated abuse limiting relies on the legitimate interest in protecting the service, Article 6(1)(f) GDPR.
- Processing documents for the customer: documented customer instructions and the Article 28 GDPR agreement.
5. Sources and required information
Data comes from the user, uploaded documents, PayPal for payment and subscription status, the European Commission's VIES service for EU VAT validation and Banca d'Italia for official exchange rates. Required fields are necessary for the account, document generation or billing. The relevant function cannot be provided without them. Consent to optional analytics or marketing is not required to use the service.
6. Recipients and external services
Data may be accessed by authorised operator personnel and technical providers bound by confidentiality and, where required, an Article 28 GDPR agreement, particularly hosting, maintenance and email providers. PayPal processes data needed to activate, collect and reconcile subscriptions under its own privacy statement. Only the supplied country code and VAT number are sent to VIES to validate EU businesses. Only the currency and requested date are sent to Banca d'Italia for an official exchange rate; amounts, names and documents are not transmitted. When a protected action is submitted, Google reCAPTCHA receives the technical and interaction data required to assess abuse risk; it is loaded through recaptcha.net. Uploaded invoice content is not sent to PayPal, VIES, Banca d'Italia or reCAPTCHA. Authorities, tax or legal advisers and courts receive data only where required by law or necessary to establish, exercise or defend claims.
7. Automated analysis and artificial intelligence
Document extraction uses an analysis system configured by the operator. Results are technical suggestions and may contain errors. Before final generation, users can and must review and correct the essential data. The service does not make decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Customer documents are not used to train public models.
8. International transfers
Ordinary invoice-content processing takes place in the technical environment configured by the operator. PayPal may process payment and contract data outside the European Economic Area and states that it relies on adequacy decisions, binding corporate rules, EU standard contractual clauses or other GDPR safeguards. Google may process reCAPTCHA security data in third countries under its data protection terms and the safeguards described there. Optional Google analytics or marketing services load only after consent and may involve additional international transfers under Google's privacy policy. Information and available safeguards may be requested through the privacy address.
9. Retention
- Login sessions expire no later than 14 days and can be ended earlier by signing out.
- Cookie choices remain valid for the period stated in the Cookie Policy, currently 180 days.
- Account data, settings, uploaded documents, supplier records and generated files remain available for the contract term or until deletion provided in the application or requested by the user, subject to legal retention duties, restrictions and temporary technical copies.
- Deleting a generated document removes its output files. The archived original and data required for traceability may remain until account closure or a verified deletion request.
- Operator invoices, payment data and accounting records are retained for ten years or another mandatory statutory period.
- Security logs, reports and contract evidence are retained as long as needed to prevent abuse, handle the matter and establish, exercise or defend claims, then deleted or anonymised.
- Contact requests are retained for response and case handling and afterwards only as long as needed to document the communication or defend legal claims. The anti-spam identifier is evaluated only within the abuse-limiting time window.
- A reCAPTCHA token is valid for one verification and normally expires after two minutes. The service uses it only for immediate verification and does not store it permanently; any storage by Google is governed by its terms and privacy policy.
10. Security
Risk-appropriate technical and organisational measures are used, including logical tenant separation, access controls, password hashing, protected session cookies, HTTPS transport encryption in public operation, upload validation and necessary technical logging. No system can guarantee absolute security. Users must protect credentials and promptly report suspicious access.
11. Data subject rights
Where Articles 15-22 GDPR apply, data subjects may request access, correction, erasure, restriction, portability, objection to processing based on legitimate interests and withdrawal of consent for the future. Where the operator processes document data for a customer, requests should first be addressed to that customer as controller; the operator assists under the data processing agreement. Identity may be verified to prevent unauthorised disclosure.
A complaint may also be filed with the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or another competent supervisory authority under Article 77 GDPR.
12. Changes
This notice is updated when the service, providers or applicable law changes. Material changes will be announced in the service or by email before taking effect where required.