Last updated: 14 August 2026
Privacy notice
This notice explains how personal data is processed when you browse Creaitivo, use the contact form, or request a reading through the AI audit. It is written in line with Regulation (EU) 2016/679 (GDPR) and applicable Italian privacy rules.
[ In short ]
- The data controller is Dussin Nicola, operating the Creaitivo project.
- The site does not use marketing cookies, advertising profiling or newsletters. Google Analytics is activated only after an explicit choice.
- The contact form sends an email to the controller: no account is created and the data is not used for newsletters or marketing.
- The audit requires email verification. Email, URL, status, and result are recorded to provide one preview per address and prevent abuse.
Notice contents
Data controller
The data controller is Dussin Nicola, with registered office at Via Lattuada Serviliano 26, 20135 Milan, Italy, Italian Tax Code DSSNCL76P10A471G and VAT number 13922200962, represented by Dussin Nicola, operating the Creaitivo project.
For privacy requests, you can write directly to the email address below. A Data Protection Officer (DPO) has not been appointed because the current processing activities of the site do not require one.
- Privacy email: nicola.creaitivo@gmail.com
- Registered office: Via Lattuada Serviliano 26, 20135 Milan, Italy
- Relevant websites: creaitivo.com, www.creaitivo.com and domains connected to the Creaitivo project
Data processed
The site is designed to collect only the data needed to respond to requests, run the audit, and keep the service secure.
- Navigation and technical data: IP address, user agent, requested URLs, request time, technical logs and information needed for operation, security and abuse prevention.
- Contact form data: name, email, optional website and free-text message.
- AI audit data: verified email address, submitted URL or domain, selected language, request status, public content retrieved from the indicated website, technical evidence and qualitative reading produced, date, and pseudonymized technical identifiers used to prevent abuse.
- Language preference: the technical cookie creaitivo_lang, used to remember the selected language.
- Analytics preference: creaitivo_analytics_consent, stored in the browser for six months to remember whether measurement was accepted or declined.
- Analytics data, only after consent: pages visited, anonymous funnel events (audit code request and verification, preview completion, CTA clicks, and successful form submission), device information, and approximate visit origin collected through Google Analytics 4. Email addresses, entered URLs, names, and messages are not sent to Analytics.
Purposes and legal bases
Data is processed for specific purposes and with legal bases aligned with the GDPR.
- Replying to requests sent through the form or by email and evaluating a possible professional relationship: pre-contractual or contractual measures requested by the data subject, Article 6(1)(b) GDPR.
- Verifying the email address, providing the requested preview, and recording its result: pre-contractual measures requested by the data subject, Article 6(1)(b) GDPR.
- Limiting the preview to one use per email, preventing abuse, protecting the site, and containing improper use of external services: legitimate interest of the controller, Article 6(1)(f) GDPR.
- Keeping communications when needed for tax, accounting, legal obligations or the protection of rights: legal obligation or legitimate interest, Articles 6(1)(c) and 6(1)(f) GDPR.
- Remembering the selected language and keeping navigation consistent between Italian and English: technical functionality and legitimate interest in improving the site experience.
- Measuring aggregate use of pages through Google Analytics 4: user consent, Article 6(1)(a) GDPR. Consent may be declined or withdrawn at any time without affecting navigation.
How the contact form works
When you submit the form, your name, email, optional website, and message are transmitted through Resend and delivered to the personal Gmail account nicola.creaitivo@gmail.com. No account is created, no automated newsletter is activated, and the contact is not sold or shared with third parties for marketing.
The message field is free text: avoid entering sensitive data, third-party data, or confidential information that is not needed to receive an initial reply.
How the AI audit works
Before the audit, Resend sends a one-time code valid for 10 minutes to the submitted address. After verification, the user may start one preview within 20 minutes. The code and access token are stored only in cryptographically derived form and cannot be recovered in plain text.
When you submit a URL to the audit, the server normalizes the address, verifies that it is public, and reads the page and sitemap where possible. The preview reports technical evidence as found, not found, or needing review; it does not measure visibility in AI engines. The system blocks local, private, or unsafe URLs.
If the AI function is active, the domain and a sample of the retrieved public content may be sent to Perplexity Sonar for a qualitative reading and limited web search. The preview may show one demonstration question, its answer, and the sources associated with that single run; it does not measure citation share or the brand's overall presence in AI engines. The audit does not make automated decisions with legal or similarly significant effects on a person: it only produces a diagnostic preview.
Email, URL, preview status, and result are recorded in Convex to prevent repeated use, document service delivery, and allow the controller to handle access or erasure requests. These data are not used for newsletters or promotional communications without a separate request.
Providers and recipients
Data may be processed by technical providers that help deliver the site, receive email or generate the AI reading. They are involved only to the extent necessary for the requested service.
Provider
Role
Vercel
Hosting, content delivery, and server functions for the site.
Convex
Database and backend functions used for email verification, the one-preview-per-address limit, and storage of the audit URL, status, and result.
Resend
Sends one-time audit codes and delivers contact-form messages to the controller's Gmail account. It processes the addresses, metadata, and content needed to deliver transactional emails.
Perplexity Sonar API
Possible qualitative reading of public content and limited web search to produce one demonstration answer with its associated sources.
Google / Gmail
Receipt and management of emails sent to the controller's personal Gmail account.
Google Analytics 4
Aggregate measurement of site use, activated only after consent; advertising signals and Google Signals disabled in the tag.
Transfers outside the European Economic Area
Some providers may process data outside the European Economic Area. Where this happens, processing must rely on the applicable GDPR safeguards, such as adequacy decisions, Standard Contractual Clauses, data processing addenda or other measures provided by law.
Retention
Data is kept only for as long as necessary for the purposes for which it was collected.
- Emails and contact requests: for the time needed to reply and manage the relationship, unless legal obligations or rights protection require longer retention.
- Automatic audit: email, URL, status, result, and pseudonymized technical identifiers are retained for 12 months from the latest activity, unless erased earlier where the legal conditions apply or needed to protect legal rights. They are then removed automatically; only a non-reversible, pseudonymized cryptographic email fingerprint remains, used solely while the one-use-per-address limit remains active.
- Language cookie: up to 12 months.
- Analytics preference: 6 months, after which a new choice is requested.
- Google Analytics cookies (_ga and _ga_<container-id>): according to the duration configured in Google Analytics, only if accepted; the site removes them when consent is withdrawn.
- Technical logs and data handled by providers: according to the technical and security retention periods applied by the respective services.
Data subject rights
You may exercise the rights set out in Articles 15-22 of the GDPR by writing to nicola.creaitivo@gmail.com. A reply is normally provided within one month, unless an extension applies in complex cases as provided by law.
- Access to personal data.
- Rectification or update.
- Erasure, where the conditions apply.
- Restriction of processing.
- Portability, where applicable.
- Objection to processing based on legitimate interest.
- Withdrawal of consent, if any future processing is based on consent.
- Complaint to the Italian Data Protection Authority.
Sensitive data and minors
The site is not directed to minors and does not request special categories of personal data. Do not enter health information, political opinions, racial or ethnic origin, religious beliefs, biometric data, judicial data or other unnecessary sensitive information in the form.
Changes to this notice
This notice may be updated if services, providers, analytics tools, contact methods or legal obligations change. The date at the top indicates the latest published version.
For privacy information or requests, write to nicola.creaitivo@gmail.com. If you believe the processing breaches privacy law, you may lodge a complaint with the Italian Data Protection Authority. Italian Data Protection Authority
Back home