Skip to content
MadTech

Privacy Policy and Cookie Policy

Last updated: 7 October 2026

1. Data controller

Data controller: MadTech, an engineering studio with operating bases in Rome and Catania.
Contact for anything concerning personal data: info@madtech.it.

2. Categories of data processed

  • Browsing data collected automatically through analytics cookies, only with prior consent (see section 4).
  • Data provided voluntarily by the user via email, WhatsApp or the site's contact form for enquiries or quotes (name, email address, message content, and IP address for security and anti-spam purposes).
  • For the free accessibility check, also the address of the site to be checked and any notes (see section 7).
  • For professional contacts that we initiate on LinkedIn, the public data described in section 8.

3. Purposes and legal basis

  • Anonymous statistical traffic analysis (Google Analytics 4) — legal basis: user consent, art. 6.1.a GDPR. No data is collected until the cookie banner is accepted.
  • Handling enquiries and quote requests (email, WhatsApp, contact form) — legal basis: pre-contractual measures at the data subject's request and legitimate interest in replying, art. 6.1.b and 6.1.f GDPR. To submit the form you confirm with a checkbox that you have read this policy: it is not a request for consent.
  • Collaboration proposals to other businesses (professional contacts on LinkedIn) — legal basis: legitimate interest, art. 6.1.f GDPR (details in section 8).

4. Cookies used

The site installs no analytics or profiling cookie until the user gives explicit consent through the banner. The choice is stored in the user's browser (not as a cookie but as a localStorage entry).

NameProviderPurposeDurationType
_gaGoogle Analytics 4Distinguishes users2 yearsAnalytics, with consent
_ga_RWTFJCJF3WGoogle Analytics 4Session state persistence2 yearsAnalytics, with consent
madtech_consent (localStorage)MadTechRemembers your cookie choiceUntil browsing data is clearedTechnical

5. Data recipients

Analytics data collected through Google Analytics 4 is processed by Google LLC (United States). The transfer is governed by the Standard Contractual Clauses (SCC) adopted by Google as data processor.

Data submitted through the contact form is processed by a self-hosted automation (n8n) on MadTech infrastructure and delivered to the MadTech mailbox through an email delivery service (Brevo, based in the EU) acting as data processor under art. 28 GDPR, limited to forwarding the message.

6. Data retention

  • Analytics data: retained in Google Analytics 4 for 14 months, the minimum retention setting recommended by the Italian data protection authority.
  • Contact data (email, WhatsApp, form): retained for as long as needed to handle the request, unless otherwise agreed with the data subject. The IP address collected by the form is used only to prevent abuse: the anti-abuse filter keeps it in memory for 1 hour, but the address also appears in the message that delivers the form to us and is kept as long as that message.
  • Free accessibility check: 12 months from the request (details in section 7).
  • Professional contacts we initiate: at most 12 months from the first contact if you do not reply (details in section 8).

7. Free accessibility check

On the web accessibility page you can request a free automated check of a website. This section describes how we process the data of the person who requests it; everything else is as described in the other sections.

  • Data processed: address of the site to be checked, name, email address, any notes and the IP address the request comes from, which the form adds to prevent abuse. The check visits only the public pages of the site and collects no data about its visitors.
  • Purpose: running the check and emailing you the report you asked for; if you reply, following up on your request. If your email address does not belong to the domain of the site, before sending the report we ask you to confirm the request by replying to an email, so that nobody can request it in someone else's name.
  • Legal basis: pre-contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR). Providing the data is optional, but without the site address and an email address we cannot send the report.
  • No newsletters or marketing: apart from the report and any confirmation request we will not write to you unless you reply. Using this data for promotional purposes would require separate consent, which the form does not ask for.
  • How the data travels, and recipients: the form sends the data to our automation (n8n), installed on a MadTech server; from there the message reaches the info@madtech.it mailbox through Brevo (France), which acts as a data processor for delivery only. The check runs on the same server and the report is sent from our own mail server, with a copy in the info@madtech.it mailbox. The server is provided by OVH (France), data processor for hosting, and is located in the European Union. Only the two people at MadTech who manage the mailbox read the data; we do not sell it or pass it on to third parties.
  • Transfers outside the European Union: none for this processing.
  • Retention: the request, the report and the log of handled requests are kept for 12 months from the request and then deleted. The technical log of the n8n automation deletes itself after 14 days, the anti-abuse counter after 1 hour. If the request turns into an engagement, the necessary data is kept for the duration of the relationship and for the legal obligations that follow from it.
  • Your rights: you can request access, rectification, erasure, restriction, portability or object at any time (Arts. 15-22 GDPR) by writing to info@madtech.it, and lodge a complaint with the Italian data protection authority (see section 9).

8. Professional contacts for collaboration proposals

This section concerns anyone who receives an invitation or a message from MadTech on LinkedIn without having written to us first. We point to it in the first message we send after the invitation has been accepted.

  • Data processed: first and last name, role, company, address of the public LinkedIn profile, published business contact details (for example the email address or phone number shown on the company website) and the results of an automated accessibility check of the public home page of the company website. The check reads only that public page and collects no data about its visitors.
  • Sources: the company website, the public LinkedIn profile and public chamber of commerce registers.
  • Purpose: proposing a professional service relevant to the company's business, for example an accessibility audit of its website. We write to people who hold a role in the company, about matters that concern the company: it is a business-to-business contact.
  • Legal basis: MadTech's legitimate interest in making its services known to other businesses (Art. 6(1)(f) GDPR). So that this interest does not weigh on you, we set ourselves limits: we use only business contact details; after the first message we send at most one follow-up, and if you do not reply we stop writing; we send no cold emails; we do not sell the data or pass it on to third parties.
  • How the data travels, and recipients: invitations and messages go through LinkedIn, which processes its members' data as an independent controller under its own privacy policy. The automated check runs on the MadTech server provided by OVH (France), in the European Union (see section 7). Only the people at MadTech who handle these contacts read the data.
  • Retention: if you do not reply, we keep the data for at most 12 months from the first contact and then delete it. If a relationship starts (a request, a quote, an engagement), we keep the necessary data for as long as the relationship requires and for the legal obligations that follow from it.
  • Your rights: you can object at any time, without giving reasons: just reply “no thanks” to the message or write to info@madtech.it. From then on we stop writing to you and delete your data, except your name and LinkedIn profile, which we keep on a do-not-contact list. You can also request access, rectification and erasure of the data (Arts. 15-17 GDPR) and lodge a complaint with the Italian data protection authority, the Garante per la Protezione dei Dati Personali (see section 9).
  • Data controller: as stated in section 1.

9. Your rights

You may at any time exercise the rights of access, rectification, erasure, restriction, objection and data portability (arts. 15-22 GDPR) by writing to info@madtech.it. You may also lodge a complaint with the Italian data protection authority (garanteprivacy.it).

10. Managing cookie preferences

You can change the choice made on the cookie banner at any time.

11. Changes to this policy

This policy may be updated to reflect regulatory changes or changes in the processing described. The last update date is shown at the top of the page.