Privacy Policy
Last updated: 22 August 2026
This policy explains what we do with personal data on our public websites, our newsletter and the properties around them. It also sets out where the line runs between those and the ELECTE platform that customers log into: the two are governed differently, and a statement about one is not a statement about the other.
It is written to meet Articles 13 and 14 of the GDPR.
1. Who is responsible for your data
ELECTE S.R.L. is the controller of the personal data described in this policy.
Legal name — ELECTE S.R.L.
Registered office — Via Montenapoleone 8, 20121 Milano (MI), Italy
VAT number (P.IVA) — IT 12771670960
REA — MI-2682918
General contact — hello@electe.net
Editorial (The ELECTE Quarterly) — quarterly@electe.net
We are an Italian company and our servers are in the European Union. The controller is in Italy, the processing happens in Germany and Italy, and the only movements needing a safeguard under Chapter V of the GDPR are the ones going out to providers outside the EEA. Section 6 covers those.
Because we are established in the EU, we do not need a representative under Article 27. You deal with us directly.
Data-protection contact. Write to privacy@electe.net for anything in this policy: access, correction, deletion, objection, portability, or a question about how something works. That is the contact point required by Article 13(1)(b).
Data protection officer. We have not appointed one, and are not required to. Article 37 requires a DPO where an organisation is a public authority, where its core activity is large-scale regular and systematic monitoring of individuals, or where it processes special category data at scale. None applies to us.
2. The two systems this policy covers
The marketing estate. Our public websites and the properties around them: the newsletter, The ELECTE Quarterly, our radio and podcast output, and the media hub. ELECTE is the controller for everything here, and unless a section says otherwise, that is what this policy describes.
The platform. The product our customers log into. Two roles apply:
- For the content our customers put into the platform, ELECTE is a processor. We handle it on their instructions, for their purposes. If your data is in the platform because you are a customer's client, employee or contact, that customer is the controller and their privacy notice governs it. Send your request to them; if it reaches us first, we will pass it on.
- For account data — the identifiers, contact details and sign-in records needed to create, run and administer an account — ELECTE is the controller. Section 4 gives the lawful basis.
Every platform customer is covered by a data processing agreement. For self-serve customers it is incorporated by reference into the terms accepted at sign-up; enterprise customers can have it counter-signed as part of a master services agreement. Ask privacy@electe.net for a copy.
3. What we collect
3.1 On the marketing estate
What you give us.
- Contact details and messages when you write to us, fill in a form, ask a question about our work, or contact us as a journalist: your name, your email address, whatever else you put in the message, and our reply.
- Your newsletter subscription — the email address you give us. You can leave at any time using the link in every issue.
- Reviews, if you choose to leave one through an independent review platform.
The newsletter platform records whether an email was opened and which links were clicked. That is engagement data about you. It is listed in section 4 with its lawful basis, it is used to see which issues land and to stop sending to addresses that never open, and it is deleted within 30 days of your unsubscribing along with the rest of your subscriber record. Write to privacy@electe.net if you would rather we did not record it.
What is collected automatically.
- Traffic measurement. Our analytics runs on our own servers in Nuremberg. It is cookieless: it sets no identifier on your device and builds no profile of you, and the counts it produces do not leave our estate.
- Connection data at the edge. A CDN sits in front of every request for routing and DDoS protection, and necessarily handles connection data including your IP address.
- Site search. If you use the search box, your query goes to search software we run ourselves. Queries stay on our own servers.
- Cookies and similar technologies. See section 12.
3.2 On the platform
Account data, as described in section 2: what is needed to create an account, sign you in and administer it. Sign-in runs on software we host ourselves in Nuremberg.
Customer content is not described here, because it is not ours to describe. What it contains is decided by the customer who put it there.
4. Why we process it, and the lawful basis for each purpose
Article 6 of the GDPR requires a lawful basis for every purpose. Where we rely on legitimate interests, the interest itself is named.
Purpose — What is involved — Lawful basis (Art. 6)
Serving, running and defending the website — Page requests; connection data handled at the edge — 6(1)(f) legitimate interests — keeping the site available, fast and protected against attack
Measuring traffic with self-hosted, cookieless analytics — Aggregate page counts. No cookie, no identifier, no profile — 6(1)(f) legitimate interests — understanding which pages are read
Site search — The query you type — 6(1)(f) legitimate interests — returning results
Sending the newsletter — Your email address and engagement data — 6(1)(a) consent. You subscribe deliberately and can withdraw at any time
Answering enquiries and form submissions, including the confirmation email you get back — Your contact details and your message — 6(1)(b) where you are asking about working with us and the exchange is a step towards a contract; otherwise 6(1)(f) legitimate interests — replying to people who write to us
Managing business relationships and sales conversations in our CRM — Contact details, correspondence, notes on the relationship — 6(1)(f) legitimate interests — running a business relationship and keeping a record of it; 6(1)(b) where we are negotiating or performing a contract with you
Collecting reviews — Whatever you provide to the review platform — 6(1)(a) consent — leaving a review is your choice
Distributing podcast and audio episodes — Request data generated when you play an episode — 6(1)(f) legitimate interests — delivering the audio and knowing how often it is played
Translating and editing our own published content with AI assistance — Site and editorial content, not customer personal data — 6(1)(f) legitimate interests — publishing in every language we serve
Automating internal workflows — Data moving between our own tools — 6(1)(f) legitimate interests — running the company without manual re-keying
Advertising and campaign measurement — Data the pixel collects in your browser — 6(1)(a) consent — nothing loads until you accept in the consent banner
Creating and running platform accounts — Account data — 6(1)(b) performance of the contract with the account holder
Keeping records the law requires us to keep, and answering lawful requests from authorities — Whatever the obligation covers — 6(1)(c) compliance with a legal obligation
Establishing, exercising or defending legal claims — Whatever the claim concerns — 6(1)(f) legitimate interests — defending the company's position
Where the basis is legitimate interests, you can object — see section 9. Where the basis is consent, you can withdraw it at any time, and withdrawing does not affect what we did lawfully before you withdrew.
5. Who we share it with
5.1 What does not leave our own servers
Analytics, site search, the automation of residency-sensitive flows, our structured operational data and identity all run on infrastructure we operate ourselves in Nuremberg, Germany. No third-party service receives your page views, your search queries or that data.
Residency-sensitive data stays inside that estate end to end. The external automation platform we use for other work carries only non-sensitive flows and has no path into the self-hosted database. That split is a design rule, not a preference.
5.2 Where the data physically sits
Purpose — Location
Application and database hosting — Nuremberg, Germany
Object storage for media — EU-scoped storage, served from our own domain
CDN, DDoS protection and edge — Global edge network, EU origin
Off-site backups — Milan, Italy
5.3 Categories of processor
We use service providers in the categories below. The current list, naming each provider and what it does, is available on request to privacy@electe.net.
- Hosting for the application and its database
- Object storage and content delivery
- Newsletter delivery
- Transactional email
- Customer relationship management
- Review collection
- Podcast hosting
- AI processing of our own published content, for translation and editorial work
- Automation of non-sensitive workflows
5.4 Other recipients
- Professional advisers — lawyers, accountants, auditors and insurers, in the course of advising us.
- Authorities, where the law obliges us to respond.
- A buyer or successor, if the business or part of it is ever sold, merged or transferred. We would tell you if this changed who controls your data.
We do not sell personal data for money. Where an advertising pixel is enabled and you have accepted marketing, some US state laws would treat the resulting data flow as "sharing" for targeted advertising; declining it in the consent banner prevents it.
6. Sending data outside the EEA
Personal data on this estate starts inside the EU — in Nuremberg, with backups in Milan — and stays there for hosting, analytics, search, automation, structured data and identity. The question arises only for the processor categories in section 5.3 whose providers operate outside the EEA, principally in the United States.
Where a recipient is established outside the EEA, the transfer runs on the European Commission's standard contractual clauses — Module 2 where we transfer as controller, Module 3 where we transfer as processor — with the UK Addendum for transfers out of the United Kingdom and the Swiss amendments for transfers out of Switzerland. Where the recipient is certified under the EU–US Data Privacy Framework, we rely on that certification in addition to the clauses rather than instead of them.
We hold the safeguards on file and will send you a copy of the ones covering a particular recipient if you ask at privacy@electe.net.
7. How long we keep it
Category — How long we keep it
Newsletter subscription — email address and engagement data — Purged within 30 days of unsubscribing. One thing is kept indefinitely: a hash of your email address on a suppression list, which is what stops a later import from mailing you again. It is not readable as an address and is used for nothing else.
Contact and enquiry form submissions, and the correspondence that follows — 24 months from our last contact with you.
CRM contact records — 24 months from the last engagement, then deleted or anonymised. Where the contact became a customer, the record is kept for the life of the contract and then follows the account-closure rule below.
Platform account data — A 30 to 90 day reactivation grace period after closure, then deleted.
Platform customer content — A 30-day export window after the contract ends, then deletion from live systems within 90 days. The same figures are in the DPA.
Analytics counts — 24 months, aggregate only. There is no identifier in it to attach to you.
Off-site backups — A 30-day rolling rotation. When we delete something it is gone from the live system straight away, but persists in a backup for up to 30 more days before the rotation overwrites it. During that time it is not used for anything. Read every "we delete it" above with those 30 days after it.
Invoices and tax records — 10 years. Italian law requires it — Codice Civile art. 2220 — and it overrides the deletion rules above for financial records. Closing an account does not delete an invoice.
The consent layer keeps no server-side record of your cookie choice: it is stored in your own browser, so there is nothing on our side to retain or delete.
8. Do you have to give us your data?
Mostly no. You can read the site without giving us anything. You need to give us an email address to receive the newsletter, and contact details to get a reply to an enquiry. For platform accounts, the account data is needed to provide the service under the contract; without it there is no account.
9. Your rights
Under the GDPR you can ask us to:
- Give you access to the personal data we hold about you, and tell you how we use it (Art. 15).
- Correct it if it is wrong or incomplete (Art. 16).
- Delete it where there is no good reason for us to keep processing it (Art. 17).
- Restrict what we do with it — for example while we check whether it is accurate (Art. 18).
- Port it: receive it in a structured, machine-readable format, or have us send it to someone else where that is technically feasible (Art. 20).
- Object to processing based on our legitimate interests (Art. 21). Where you object to direct marketing, we stop.
- Withdraw consent at any time, where consent is the basis (Art. 7(3)). This does not make the earlier processing unlawful.
How to exercise them. Write to privacy@electe.net. We will answer within one month, as Article 12(3) requires, and will tell you if we need to extend that and why. It is free. We may ask you for enough information to be sure it is really you, and no more.
Some things need no request. Every newsletter has an unsubscribe link. You can reopen the consent banner to change your cookie choices; clearing your browser's site data also resets them, since that is the only place the choice is stored.
If your data is on the platform because of a customer relationship with someone else, we are the processor and the customer is the controller. Send your request to them. If it reaches us first, we will pass it on rather than acting on it ourselves.
10. Complaining to a supervisory authority
If you are not satisfied with how we have handled your data or your request, you can complain to a data protection supervisory authority. These are independent public authorities: they supervise how organisations apply data protection law, investigate complaints, and can order a company to change what it does or fine it.
Ours is the Garante per la protezione dei dati personali, the Italian supervisory authority, at garanteprivacy.it, because ELECTE is established in Italy. You can also complain to the authority in the EU country where you live or work, or where you think the problem happened. Complaining to an authority does not stop you raising it with us directly.
11. Automated decisions and profiling
We do not make automated decisions about you that produce legal effects or anything similarly significant, in the sense of Article 22. We do not score visitors or rank them, and no automated system decides what you may or may not have. Our platform reads business data and produces forecasts and decision support for the people using it; a person decides what to do with the output.
Where an advertising pixel is enabled and you have accepted marketing, that pixel's operator may profile you for advertising on its own platforms. That is profiling, though not an Article 22 decision, and declining marketing in the consent banner is how you avoid it.
12. Cookies and similar technologies
The full list is in our Cookie Notice. What matters here is how the consent layer behaves.
- Three categories: Essential, Analytics and Marketing. Marketing exists because one advertising tool is configured; remove it and the banner drops to two.
- The consent layer runs offline. It makes no call to a consent backend when you load a page. Your choice is stored in your browser and nowhere else, so we hold no server-side consent record about you.
- Analytics runs outside consent. Our own analytics is self-hosted on our own domain, sets no cookie and stores no identifier on your device. There is nothing on your device to ask permission for and no third party receives the data, so we treat it as essential and say so.
- "Accept essentials only." The button most sites label "Reject All" is labelled "Accept essentials only" here, in every language we publish in, because that is what it does.
- Google Analytics 4 runs in advanced consent mode: it fires with every consent signal denied and sends cookieless pings until you accept the Analytics category.
- Live today: Google Analytics 4 and Microsoft Clarity in Analytics, and one website visitor tracker in Marketing. Every other pixel our consent layer can carry is switched on individually by configuration, and none of the others is set.
13. Security
Everything we run is hosted in the EU, in Nuremberg, with off-site backups in Milan. Analytics, search, automation, structured data and identity are self-hosted rather than handed to vendors. Internal tools sit behind an access gateway that authenticates every request. We maintain sixteen written security policies.
Certifications. We hold none today. Our status is SOC 2 Type II (audit in progress).
Physical security. We operate no offices housing production infrastructure and no self-managed physical servers. Physical access control, environmental controls and secure hardware disposal at the data centres are inherited from our providers.
No system is perfectly secure, and we do not promise that ours is.
14. Children
Our sites, newsletter and publications are made for a professional audience and are not directed at children. We do not knowingly collect personal data from children, and we run no feature designed to attract them. If you believe a child has given us personal data, write to us and we will delete it.
15. If you are outside the EU
This policy applies to everyone who uses our sites, wherever you are. We handle a request to access, correct or delete data the same way regardless of where the person making it lives — see section 9.
US state privacy laws such as the CCPA apply only to companies that meet their thresholds, and turn largely on selling and sharing personal information. We do not sell personal data for money. Where advertising pixels are enabled and you have accepted marketing, some of those laws would treat the resulting flow as "sharing" for targeted advertising, and declining it in the consent banner is the control. We do not operate a separate US rights process, because the process in section 9 is open to you already.
16. Changes to this policy
When we change this policy we update the date at the top and publish the new version on this page.
If a change materially affects how we use data you have already given us — a new purpose, a new category of recipient, a new transfer — we will say so prominently on the page, and where we hold your contact details and the change affects you, we will tell you by email before it takes effect. We will not treat your continued use of the site as agreement to a materially different use of data you gave us under the old policy.
17. How to contact us
Data-protection requests and questions about this policy — privacy@electe.net
General enquiries — hello@electe.net
Editorial (The ELECTE Quarterly) — quarterly@electe.net
Press and media — press@electe.net
Post — ELECTE S.R.L., Via Montenapoleone 8, 20121 Milano (MI), Italy