Privacy Policy

privacy.last_updated:

1. Introduction

This website and service ("ScartoFlow" or the "Service") are operated by Fabio Camilli, a sole trader based in the United Kingdom, trading as "ScartoFlow" ("we," "our," or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

As a sole trader, I am the data controller responsible for your personal information. This means I determine how and why your personal data is processed.

By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Information You Provide to Us

We collect information that you provide directly to us when you:

  • Submit a request for waste management services through our wizard form
  • Contact us for support or inquiries
  • Register for or access our admin portal

This information may include:

  • Business Information: Business type, legal name, address, postal code (CAP), city, province, number of employees, opening days
  • Contact Information: Full name, email address, phone number
  • Waste Management Information: Types of waste, estimated volumes, pickup requirements, notes
  • Contract Information: Details about existing waste management contracts, current providers, costs, and pain points

2.2 Automatically Collected Information

When you access our Service, we automatically collect certain information, including:

  • Device Information: IP address, browser type and version, operating system
  • Usage Data: Pages visited, time spent on pages, click patterns, access times and dates
  • Cookies and Tracking Technologies: We use cookies to store your language preference (i18n_redirected) and improve your experience

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Provision: To process your requests, match you with appropriate waste management providers, and facilitate communication
  • Communication: To contact you regarding your requests, provide customer support, and send you relevant information about our services
  • Service Improvement: To analyze usage patterns, improve our matching algorithms, and enhance user experience
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes
  • Security: To protect against fraud, unauthorized access, and other security threats
  • Language Preferences: To remember and apply your language preference (Italian/English)

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal grounds:

  • Consent: When you voluntarily provide information through our forms
  • Contractual Necessity: To fulfill our obligations in providing the matching service
  • Legitimate Interests: To improve our services, prevent fraud, and ensure security
  • Legal Obligation: To comply with applicable laws and regulations

5. Data Sharing and Disclosure

5.1 Service Providers

We may share your information with third-party service providers who perform services on our behalf, including:

  • Hosting and Infrastructure: [Your hosting provider, e.g., Vercel, Netlify] for website hosting
  • Database Services: Neon (PostgreSQL) for data storage
  • Analytics Services: Google Analytics for website analytics and usage statistics
  • Font Services: Google Fonts for typography (may collect IP addresses)
  • AI Services: OpenAI (if applicable) for AI-powered features

5.2 Waste Management Providers

With your explicit consent, we may share your business and waste management information with qualified waste management providers to facilitate quote generation and service matching.

5.3 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, property, or safety.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Request data is retained for up to 3 years after your last interaction with our Service
  • Contact information is retained until you request deletion or withdraw consent
  • We may retain certain information for legal, accounting, or security purposes beyond the standard retention period

7. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

7.1 GDPR Rights (EEA/UK)

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

7.2 CCPA Rights (California)

  • Right to Know: Request information about categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
  • Right to Non-Discrimination: Exercise your rights without discrimination

7.3 Exercising Your Rights

To exercise any of these rights, please contact us at: info@scartoflow.it

We will respond to your request within 30 days (or as required by applicable law). We may require verification of your identity before processing your request.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for the Service to function (e.g., language preference cookie: i18n_redirected)
  • Analytics Cookies: We use Google Analytics to understand how users interact with our Service. Google Analytics uses cookies to collect information such as how often users visit our site, what pages they visit, and what other sites they used prior to coming to our site. We use this information to improve our Service. Google Analytics collects only the IP address assigned to you on the date you visit our site, rather than your name or other identifying information. Google's ability to use and share information collected by Google Analytics about your visits to our site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy. You can opt-out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our Service.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (HTTPS/TLS)
  • Secure database connections and access controls
  • Regular security assessments and updates
  • Limited access to personal data on a need-to-know basis

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

When we transfer personal data from the EEA to countries outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally recognized transfer mechanisms

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will take steps to delete such information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Service after changes become effective constitutes acceptance of those changes.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Fabio Camilli

Trading as: ScartoFlow

Sole Trader Registration: 4546979449

Business Address:

40 Croftongate Way
Brockley, London, SE4 2DL
UK

Email: info@scartoflow.it

Phone: +44 (0)798 5979 189

Note: As a sole trader, I do not have a separate Data Protection Officer. For all data protection inquiries, please contact me directly using the email address above.

14. Supervisory Authority

If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

United Kingdom: The Information Commissioner's Office (ICO) - ico.org.uk

Italy: Garante per la protezione dei dati personali - www.garanteprivacy.it

Other EU Countries: Please contact your local data protection authority. A list can be found at edpb.europa.eu