Privacy Policy
Last updated: 2026-04-15
This Privacy Policy explains how Qode S.r.l.(the “Company”, “we”, “our”) collects, uses, and protects personal data of visitors to infrar.io (the “Site”). It is prepared in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
1. Data Controller
The data controller is Qode S.r.l., registered office at [Registered office address], VAT number [VAT number]. For any privacy related request you can contact us at privacy@infrar.io.
2. What data we collect
The Site is a marketing website. We collect only the minimum data required to operate it safely and to respond to your requests.
2.1 Server logs
Our hosting infrastructure automatically records technical information when you visit the Site, including IP address, user agent, requested URL, referrer, and timestamp. These logs are used exclusively to ensure availability, diagnose technical issues, and detect abuse.
2.2 Waitlist
If you voluntarily submit your email address to join the waitlist, we store that email and the submission timestamp in order to notify you when early access opens. We do not use this address for marketing beyond that purpose.
2.3 Direct contact
If you email us at the addresses published on the Site, we will process your message and any personal data it contains solely to reply to your request.
We do not use analytics, advertising pixels, or third party tracking on the Site. We do not profile visitors.
3. Legal basis for processing
- Server logs: legitimate interest (Art. 6(1)(f) GDPR) in operating a secure and reliable website.
- Waitlist submissions: consent (Art. 6(1)(a) GDPR), given by you when submitting your email.
- Direct contact: performance of pre contractual measures at your request (Art. 6(1)(b) GDPR).
4. Retention
- Server logs: retained for up to 30 days, then deleted or anonymised.
- Waitlist emails: retained until early access is granted or until you request deletion, whichever comes first.
- Email correspondence: retained for the time necessary to handle the request and up to 12 months thereafter for auditability.
5. Recipients and processors
We do not sell or share your personal data. We rely on a limited set of service providers acting as data processors under Art. 28 GDPR:
- Hosting and infrastructure: Scaleway S.A.S. (France, European Union), which hosts the Site and processes technical logs.
All processing takes place within the European Economic Area. We do not transfer personal data outside the EEA.
6. Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy;
- rectify inaccurate or incomplete data;
- request erasure (“right to be forgotten”);
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, garanteprivacy.it).
To exercise your rights, write to privacy@infrar.io. We will respond within one month.
7. Cookies
The Site uses only strictly necessary cookies, as described in our Cookie Policy. No tracking or profiling cookies are set.
8. Security
We apply reasonable technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls, and routine log rotation. No system is perfectly secure; if you become aware of a vulnerability please contact us at privacy@infrar.io.
9. Changes to this policy
We may update this Privacy Policy to reflect changes to the Site or to legal requirements. Material changes will be highlighted on this page and, where appropriate, communicated by email. The effective date at the top of this page indicates the latest revision.
