Privacy Policy
Full GDPR & CCPA compliant privacy policy.
1. Data Controller
The data controller for this website is: Lead Machine Open Source Project c/o Lead Machine Contributors Via Privacy 1, 20121 Milano MI — Italy VAT ID (P.IVA): IT00000000000 Email: axsen_kurtoski@financier.com For matters relating to this Privacy Policy, you may contact the Controller at any time at the email above.
2. Categories of Data Collected
Lead Machine collects the absolute minimum of personal data. In practice, only the following: a) Contact form data: if you voluntarily fill in a contact form (demo request, partnership, bug report, waitlist), we collect the name and email address you provide. Processing is based solely on your explicit, opt-in consent. b) Server logs: our web hosts (Vercel, GitHub Pages) may retain transient IP-based connection logs for up to 7 days for pure security/anti-abuse purposes. We do not have access to these logs unless a legal request compels the host to provide them. c) We explicitly do NOT collect: — Third-party analytics (no Google Analytics, no GA4, no Matomo, no Plausible) — Advertising or marketing tracking cookies (no Meta Pixel, no LinkedIn Insight, no Twitter/X Ads) — User behavioral profiling of any kind — Cross-device tracking — Financial data (we don't process payments)
3. Purposes of Processing
The Data Controller processes personal data solely for the following purposes: — Responding to contact requests: when you email us or submit a form, we use your data to reply. Period. — Security & anti-abuse: transient IP logs processed by our hosting providers solely to prevent DDoS, brute-force attacks and spam. — Compliance with a legal obligation: where we are compelled by binding EU or national law to produce records.
4. Legal Basis for Processing
Processing is based on one or more of the following, as applicable under Art. 6 GDPR: (a) Explicit, specific, revocable consent (Art. 6(1)(a)) — for contact form submissions and waitlist signups. You may withdraw consent at any time by emailing axsen_kurtoski@financier.com. (b) Compliance with a legal obligation (Art. 6(1)(c)) — e.g., tax record retention. (c) Legitimate interests (Art. 6(1)(f)) — only in the narrow case of server-level anti-abuse/security logs. We balance these interests against your rights and find the impact to be minimal (transient, unprofiled, never used for marketing).
5. Data Retention
Data categories are retained for the following maximum periods: — Contact form submissions (name + email): 36 months from the last interaction with you. This allows us to recognize returning conversations. After 36 months, we permanently delete. — Transient host-level security logs: up to 7 days (outside our control). — Financial/customer records relating to consulting or custom builds: 10 years per Italian civil & tax law (Art. 2220 c.c., Art. 3 D.P.R. 600/1973).
6. Your Rights (GDPR Articles 15–22)
Under the EU General Data Protection Regulation (and comparable laws like the CCPA), you have the following rights, free of charge: — Right of access (Art. 15): you may request confirmation of whether we process your data and obtain a copy. — Right to rectification (Art. 16): correct inaccurate or incomplete data. — Right to erasure (“right to be forgotten”, Art. 17): request deletion, subject to legal retention exceptions. — Right to restriction (Art. 18): suspend processing in certain cases. — Right to data portability (Art. 20): receive your data in a machine-readable format. — Right to object (Art. 21): object to processing based on legitimate interests. — Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal. — Right to lodge a complaint with a supervisory authority. How to exercise: email axsen_kurtoski@financier.com with the subject “GDPR Request”. We respond within 30 calendar days.
7. Cookies
A dedicated Cookie Policy exists at /cookies. We set 3 (three) first-party strictly-necessary cookies only. No tracking cookies, no marketing cookies, no third-party cookies of any kind are set by this website.
8. International Transfers (Extra-EU)
To the extent that any processing involves a transfer of personal data outside the European Economic Area, we rely exclusively on one of the following: (a) Standard Contractual Clauses (SCCs / Standardvertragsklauseln) as adopted by the European Commission (Decision 2021/914 and subsequent); (b) Adequacy decisions (e.g., UK IDTA, Switzerland FAIA, Japan APPI); (c) Explicit, informed, opt-in consent (Art. 49(1)(a) GDPR) after you have been specifically informed of the risks. We never transfer personal data to the United States without SCCs + documented supplementary technical measures (end-to-end encryption at rest and in transit).
9. Supervisory Authority
The lead supervisory authority for Lead Machine is the Italian Data Protection Authority (Garante per la protezione dei dati personali — www.garanteprivacy.it). You may lodge a complaint at any time, in any EU language, with the Garante or with the DPA of your habitual residence, place of work, or place of the alleged infringement.
10. Changes to this Policy
We reserve the right to modify this Privacy Policy at any time. Material changes will be flagged with a banner on the homepage for 30 days after publication, and the “Last updated” date at the top of this page will be incremented. Continued use of the site after changes constitutes acceptance.