Privacy & Cookie Policy
Last updated: October 2026 · version 2026-10
1. Data collected via forms
When you submit a form we only collect the data you enter: Contact (name, email, optional company and message), Quote request (name, email, company, project type, budget, timeframe and message — all optional except name and email), Appointment booking (name, email, chosen service, date and time; phone and notes optional), Early access to a portfolio product (name, email, chosen product, optional company and plan). Submission is always conditional on your explicit acceptance of this Privacy Policy via a dedicated consent checkbox on every form (never pre-ticked). For security and abuse prevention we also record your IP address and browser type (user agent) at submission, and we keep the date, time and version of the notice you agreed to.
2. Browsing data and pseudonymous identifiers
Only if you accept analytics cookies from the banner, the site sends the Demonet Tracking Hub (an internal Demonet system, not a third-party service) page views and some discrete interaction events. This data is tied to a randomly generated session identifier (sessionId) stored only in the browser session memory (sessionStorage): it is not a persistent cookie, does not identify the person and is regenerated on each new visit. For each visit we record the page, the referring page, any campaign parameters, the browser type and the duration; the IP address is stored only in shortened form (for IPv4 the last part is zeroed, for IPv6 only the first 48 bits are kept) and cannot identify you. No tracking event is sent before consent.
3. Purposes of processing
Form data is processed to respond to requests, manage bookings and early-access, and deliver the requested services. Pseudonymous browsing data (when authorised) is used in aggregate form to understand which pages and products draw interest, with no individual or advertising profiling. Requests received through the forms may be classified automatically (priority, suspected spam, duplicates, type of service) with the support of AI systems: contact details are redacted before processing, the AI provider operates within the European Union, and no decision with legal effects is taken by automated means (see the AI transparency page).
4. Legal basis
Processing of form data is based on the consent given at submission (and on pre-contractual measures for quotes/bookings). Browsing and event tracking relies solely on analytics-cookie consent, which can be withdrawn at any time from the cookie preferences in the footer.
5. Cookies
We only use technical cookies/storage necessary for the site to work and, subject to consent, the pseudonymous session identifier described in point 2 for internal analytics. No third-party profiling or advertising cookies. You can change your mind at any time via the “Cookie preferences” button in the footer.
6. Sharing, processors and transfers
Data is processed by authorised Demonet staff and stored on the Demonet Tracking Hub systems. We do not sell or share your data for marketing. To deliver the service we may rely on suppliers acting as data processors (cloud hosting, email, push notifications, analytics, crash reporting); any transfers outside the EEA are covered by standard contractual clauses. Communications to the Tracking Hub always use HTTPS.
7. Retention and rights
Browsing and event data: 13 months, then deleted. IP address and browser type recorded with the forms: zeroed 30 days after submission. Contact data of requests that do not lead to a contract: deleted after 24 months; if the request leads to a contract, the data is kept for as long as needed to perform it and to meet legal obligations. The session identifier expires when the browser closes. Consent to the processing of form data is required to submit the form and can be withdrawn at any time. You have the right to access, rectify, request erasure, restriction, portability and to object to processing by writing to privacy@demonet.it; you may also lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali).
8. Demonet mobile apps
Demonet apps published on the stores may require account creation (email and credentials) and send push notifications, which can be disabled in settings. Device permissions (camera, files/storage, location) are requested only when the feature that needs them is used, with an explanation of the purpose, and can always be revoked from the operating-system settings.
9. Account and data deletion
You can delete your account and associated data from the app settings or by writing to privacy@demonet.it from the associated address: the request is fulfilled within 30 days. Profile, credentials, uploaded content, usage data and preferences are erased; only documents required by tax/legal obligations are retained. Full instructions are on the dedicated “Account deletion” page.
10. Minors
Demonet services and apps are not intended for children under 16. We do not knowingly collect data from minors; should we become aware of such processing, we will delete the data.
11. Security, controller and contacts
We adopt appropriate technical and organisational measures (HTTPS, authenticated back-office access, backups). Data controller: Demonet S.r.l., Via Staffette Partigiane 34, 41122 Modena (MO), Italy, VAT/Tax code 02671130363 — privacy@demonet.it. Google Play developer contact: info@demonet.it · www.demonet.it.