Privacy Notice on Personal Data Processing
(pursuant to Articles 13-14 of Regulation (EU) 2016/679 “GDPR” and Italian Legislative Decree 196/2003 as amended)
1) Data Controller
The Data Controller is: Alfonso Fiorentino
Email: [email protected]
DPO: not appointed (no requirement under Art. 37 GDPR).
2) Nature of the website
The Antenna Commander website is purely informational: it describes the project, its purposes and features. The site does not provide user registration, restricted areas, or direct sales.
2-bis) Specific context (IoT/ham radio) and strict separation
- The website is informational only and is separate from software/hardware installed locally by the user.
- The locally installed software does NOT send data to the Controller.
- No telemetry, cloud sync, accounts, or communications to Controller servers.
- Operational logs (e.g., pointing, bus errors, configurations) stay on the local device.
- No real geolocation data is transmitted to the Controller.
This notice applies ONLY to the informational website, not to the local operation of the open‑source software.
3) Categories of data
A) Browsing data (technical logs)
IP address, user‑agent, device/browser/OS type, date and time, requested resource (URL), request outcome, technical parameters for security and network management.
B) Data provided voluntarily
Data contained in communications sent to the Controller (e.g., email address, name if provided, message content and attachments).
C) Donations (if any)
If a donation is made via PayPal, the Controller may receive transaction information (transaction IDs, name, email, amount, reason) as provided by the service and necessary for compliance.
Special/judicial data
The site does not request nor intend to process special categories (Art. 9) or judicial data (Art. 10). If sent voluntarily by email, they are processed only if strictly necessary to handle the request.
4) Purposes and legal bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Technical operation, log management, security, abuse/fraud prevention, service continuity | Legitimate interest (Art. 6(1)(f)) |
| Reply to email requests | Pre‑contractual measures on request (Art. 6(1)(b)) and/or legitimate interest (Art. 6(1)(f)) |
| Usage/performance statistics | Legitimate interest (Art. 6(1)(f)) for cookieless stats; consent (Art. 6(1)(a)) where cookies/IDs or non‑technical tools are used |
| Accounting/tax obligations related to donations | Legal obligation (Art. 6(1)(c)) |
Balancing test (Art. 6(1)(f) GDPR)
- Legitimate interest: security, abuse prevention, service continuity.
- Necessity: logs are essential to detect anomalies (brute force/DDoS).
- Balancing: data minimization, short retention, reasonable expectations for a public site (Art. 5(1)(c)-(e)).
- Mitigations: limited log access, no profiling, no incompatible purposes.
Methodology inspired by WP29 Opinion 06/2014 and/or EDPB Guidelines 1/2024.
5) Data provision
- Browsing data are provided automatically and are necessary for site use and security.
- Email data are optional but necessary to receive a reply.
- Donations and downloads are optional.
6) Data recipients (Art. 13(1)(e))
Data may be processed by technical providers (hosting, security, analytics), appointed as processors where applicable, or as independent controllers for external services (PayPal, GitHub).
7) Transfers outside the EU (Chapter V GDPR)
Any transfers outside the EU occur under Arts. 44-49 GDPR through adequacy decisions (where applicable) and/or 2021 Standard Contractual Clauses (SCC), with supplementary measures if needed.
8) Cookies, tracking tools and statistics
8A) Cloudflare Web Analytics (cookieless)
- Cookieless: no cookies or client‑side storage.
- Data processed: IP, user‑agent, timestamp, requested URL and technical parameters; used for aggregated/pseudonymized metrics.
- Role: Cloudflare acts as Processor (DPA).
- Legal basis: legitimate interest (Art. 6(1)(f)).
- Transfers: Cloudflare, Inc. (USA) certified under EU–US Data Privacy Framework (status “Active”); alternatively SCC 2021 + supplementary measures.
- Right to object: Art. 21 GDPR via Controller email.
8B) Google Analytics (consent‑based)
- Google Analytics loads only after consent (Art. 6(1)(a)) under cookie rules.
- Consent is revocable at any time (Art. 7(3)).
- Minimization: IP anonymization where applicable, reduced data, limited retention, advertising features disabled.
9) Donations (PayPal)
The donation button/link redirects to PayPal, which acts as an independent controller. The Controller does not process payment data, but may receive transaction info necessary for administration/accounting.
10) Software downloads (GitHub)
- The Controller does NOT have access to download IPs or personal data of downloaders.
- GitHub may associate the action with the user account if logged in, per its policies.
- Any metrics visible to the Controller are only aggregated/public (e.g., total downloads), not individual.
11) Processing methods and security (Art. 32)
Processing is carried out with IT/telematic tools in compliance with lawfulness, fairness, transparency and minimization, adopting appropriate technical and organizational measures.
12) Data retention (Art. 5(1)(e))
- Web server logs (access/error): 7 days (automatic rotation).
- Security logs (WAF/fail2ban/firewall): 30 days.
- Incident response: until closure, max 6 months.
- Backups: logs are not included in long‑term backups (except temporary technical backups strictly necessary).
- Email/contacts: for the time needed to handle the request, then deletion/selective archiving.
- Donation/accounting data: per legal obligations.
13) Data subject rights (Arts. 15–22) and procedure
- Access (Art. 15): copy in machine‑readable format (JSON/CSV) within 30 days.
- Rectification (Art. 16) and erasure (Art. 17): applies to contact/email data; not to logs within security retention.
- Objection (Art. 21): to processing based on legitimate interest.
- Restriction (Art. 18) and portability (Art. 20) where applicable.
Procedure:
- Email [email protected] with subject “GDPR – request …”.
- Identity verification only if necessary and proportionate; documents used only for verification and then deleted.
- Acknowledgement within 72 hours.
Response time: within 1 month, extendable by 2 months if complex (Art. 12(3)). Complaints can be filed with the national DPA.
14) Automated decision‑making
No automated decision‑making or profiling (Art. 22).
15) Updates
This notice may be updated. The latest version will be published on this page.
Last update: 28 January 2026