Privacy Policy
Last updated: September 2026
On this page
1. Data Controller
This Privacy Policy (hereinafter, the "Policy") describes how we collect, use, store, and protect the personal data of users (hereinafter, the "Users" or the "User") who access and use the Oltre.ai platform and related services (hereinafter, the "Service").
The Data Controller for the processing of personal data is:
Oltre.ai Srl Viale dell'Industria 10, 67039 Sulmona (AQ), Italy Tax Code and VAT No.: 02226290662 REA AQ-220661 Email: info@oltre.ai Certified email (PEC): oltre.ai@pec.it
This Policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") and Italian data protection legislation.
2. Categories of Personal Data Collected
2.1 Data provided directly by the User
During registration and use of the Service, we collect the following categories of personal data voluntarily provided by the User:
a) Identification data: first name, last name;
b) Contact data: email address, telephone number;
c) Professional data: company name.
2.2 Data collected automatically
During use of the Service, we automatically collect certain technical and usage information:
a) Browsing data: IP address, browser type, operating system, pages visited, session duration;
b) Platform usage data: search queries performed, tests executed, reports generated, interactions with Service features;
c) Data collected through cookies and similar technologies, as described in the dedicated section.
2.3 Payment data
Payments are processed exclusively through the Stripe platform. The Data Controller does not collect or store payment card data or other financial instruments of the User. For information on how payment data is processed, please refer to Stripe's privacy policy, available on their website.
3. Purposes and Legal Basis for Processing
Users' personal data is processed for the following purposes:
| Purpose | Description | Legal basis |
|---|---|---|
| Service provision | DescriptionAccount registration, authentication, subscription management, provision of Platform features | Legal basisPerformance of contract (Art. 6.1.b GDPR) |
| Service communications | DescriptionSending technical communications, updates, notifications relating to the Service and account | Legal basisPerformance of contract (Art. 6.1.b GDPR) |
| Direct marketing | DescriptionSending promotional communications, newsletters, commercial offers relating to the Data Controller's services | Legal basisUser consent (Art. 6.1.a GDPR) |
| Analysis and improvement | DescriptionAnalysis of Service usage, aggregate statistics, improvement of features and user experience | Legal basisLegitimate interest (Art. 6.1.f GDPR) |
| Legal compliance | DescriptionCompliance with obligations under law, regulations or EU legislation, requests from judicial authorities | Legal basisLegal obligation (Art. 6.1.c GDPR) |
4. Cookies and Tracking Technologies
The Platform uses cookies and similar technologies to ensure the proper functioning of the Service, analyse User behaviour, and personalise the browsing experience.
4.1 Types of cookies used
Technical cookies: essential for the functioning of the Platform, enabling navigation and use of main features. These do not require User consent.
Analytics cookies: used to collect aggregate information on Service usage to improve performance and usability. The Platform uses Mixpanel for aggregate analysis of feature usage.
Marketing cookies: used to track User preferences and provide personalised advertising content. These cookies are only installed with User consent.
4.2 Preference management
The User can manage their cookie preferences through the consent banner displayed on the Platform upon first access, or subsequently through their browser settings. Disabling certain cookies may limit Service functionality.
5. Data Recipients
Users' personal data may be disclosed to the following categories of recipients:
5.1 Service providers
Hosting provider: Contabo GmbH, for hosting the Platform's technological infrastructure, with servers located within the European Union;
Payment processing: Stripe, Inc., for payment management;
Artificial intelligence platforms: OpenAI (ChatGPT), Anthropic (Claude), Perplexity AI, and other platforms integrated into the Service, limited to data necessary for executing queries and analyses requested by the User;
Analytics tools: Mixpanel, for aggregate Platform usage analysis;
CRM: Customer Relationship Management systems for managing User relations.
5.2 Other recipients
Data may also be disclosed to judicial or administrative authorities where required by law or by orders from competent authorities.
The service providers listed above act as Data Processors pursuant to Article 28 GDPR, based on specific contractual agreements ensuring adequate security and data protection measures.
6. Data Transfers
The Platform's servers are located within the European Union. The Data Controller does not transfer Users' personal data outside the European Economic Area.
Should it become necessary in the future to transfer data to third countries, the Data Controller will ensure that such transfers comply with the safeguards provided by the GDPR, including Standard Contractual Clauses approved by the European Commission or other appropriate legal bases.
7. Data Retention
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected:
Account data: retained for the duration of the contractual relationship and for sixty (60) days following account deletion, to allow for possible restoration and for administrative purposes;
Usage and analytics data: analysis results are retained in anonymised and aggregated form, so as not to allow User identification;
Data for marketing purposes: retained until consent is withdrawn by the User;
Data for legal compliance: retained for the period required by applicable legislation.
8. Security Measures
The Data Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
a) encryption of data in transit using TLS 1.3 protocol;
b) encryption of data at rest using AES-256 algorithm;
c) pseudonymisation and anonymisation techniques where applicable;
d) role-based access controls and secure authentication;
e) regular backups and disaster recovery procedures;
f) continuous infrastructure monitoring for anomaly and threat detection.
9. Data Subject Rights
Pursuant to Articles 15-22 of the GDPR, the User has the right to:
Access: obtain confirmation of the existence of processing of their personal data and access to such data;
Rectification: obtain correction of inaccurate data or completion of incomplete data;
Erasure: obtain erasure of their personal data in cases provided by law;
Restriction: obtain restriction of processing in cases provided by law;
Portability: receive their data in a structured, commonly used, and machine-readable format;
Objection: object to the processing of their data on legitimate grounds, including processing for direct marketing purposes;
Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise their rights, the User may send a request to the email address info@oltre.ai or to the certified email address oltre.ai@pec.it. The Data Controller will respond within thirty (30) days of receiving the request.
The User also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali - www.garanteprivacy.it) if they believe that the processing of their data violates applicable legislation.
10. Minors
The Service is intended for Users who are at least sixteen (16) years of age. For Users between the ages of sixteen and eighteen, the processing of personal data is subject to the consent of a parent or legal guardian, in accordance with Article 8 of the GDPR and Italian implementing legislation.
11. Amendments to this Policy
The Data Controller reserves the right to amend this Policy at any time. Amendments will be published on the Platform and, where significant, communicated to the User by email. Continued use of the Service following publication of amendments shall constitute acknowledgement thereof.
The User is invited to periodically review this Policy to check for any updates.
12. Contact
For any information regarding the processing of personal data or to exercise their rights, the User may contact the Data Controller at the following addresses:
Email: info@oltre.ai Certified email (PEC): oltre.ai@pec.it Registered office: Viale dell'Industria 10, 67039 Sulmona (AQ), Italy
Oltre.ai Srl — Viale dell'Industria 10, Sulmona (AQ) — VAT No. 02226290662
© 2026 Oltre.ai - All rights reserved