Privacy policy

This page explains which personal data we process, why we do it and how long we keep it. It covers people who visit this site, people who join the waiting list and CookieMi customers.

1. Who processes your data

The data controller is:

  • Web Solution Group Srl
  • Via Monte Sabotino, 2
  • VAT number 04598080168
  • Email: mail@cookiemi.com

2. What data we process, and why

Who you are What we process Why For how long
You visit this site The technical data of the request that the server records: IP address, page requested, date and time, browser To run the site and protect it from abuse At most 12 months in the server logs
You join the waiting list Email address, language, date and time; your IP address as a non-reversible code, and the kind of browser you use To write to you when CookieMi launches and to stop automated signups The email address until that message is sent; the IP code and the browser for 90 days
You open an account Email address, language, sign-in dates, non-reversible code of the IP address you signed up from, one-time sign-in codes (stored only in encrypted form) To let you into the panel and keep your account safe For as long as you keep the account, then deleted
You subscribe Subscription and payment data (amount, dates, status) and the copy of the event Stripe sends us for every payment, which contains the billing details you gave Stripe: name, email and address. We never see your card details: only Stripe handles them To handle the payment and meet tax obligations Accounting records for 10 years, as the law requires; if you delete your account we immediately strip name, email and address from those copies and only amounts, dates and identifiers remain
We write to you Log of the service emails sent: recipient, subject, result. Never the content of the codes To know whether a message arrived and to be able to send it again 90 days

We do no profiling, we make no automated decisions about you and we do not sell your data to anyone.

3. On what basis we do it

  • For your account and your subscription: the contract we have with you (GDPR art. 6.1.b).
  • For the waiting list: the consent you gave us when you joined, which you can withdraw at any time (art. 6.1.a).
  • For the security of the service and protection from abuse: our legitimate interest in keeping a working service running (art. 6.1.f).
  • For invoices and accounting records: a legal obligation (art. 6.1.c).

4. Who helps us run the service

To run CookieMi we rely on a few companies, which process the data on our behalf, each in the role stated below, under a contract that places on them the same obligations we have. They are:

Who What they do for us In what role Where
AWS Hosting of the application and the database Data processor (sub-processor under GDPR art. 28(4)) Germania
Stripe Payments Europe, Ltd. Payment collection and subscription billing Data processor for carrying out the payment; independent controller for the anti-fraud and regulatory obligations set out in payment services law Ireland (European Union)
mail@cookiemi.com Sending of the service emails (sign-in codes, subscription notices) Data processor (sub-processor under GDPR art. 28(4)) to be completed: country

Beyond these, we disclose data only to those legally entitled to it — for example our accountant, or an authority making a formal request.

5. Where the data is

CookieMi's data is kept in Unione Europea.

We do not transfer data outside the European Economic Area, unless the supplier named above does so on the basis of an adequacy decision of the European Commission or of the standard contractual clauses, with the additional measures required.

6. The data of people who visit our customers' sites

The banner installed on a customer's site records the consent choices of the people who visit it. The controller of that data is the customer, not us: we process it on their behalf, as data processor, under the agreement required by GDPR art. 28 that every customer finds in their own panel.

There too, IP addresses are not kept in the clear: only a non-reversible code goes into the log. If you have visited the site of one of our customers and want to exercise your rights, contact that site: they are the controller. We help them answer you.

7. Your rights

You can ask us at any time to see the data that concerns you, to correct it, to delete it, to restrict its use, to receive it in a readable format so you can take it elsewhere, and you can object to processing based on our legitimate interest (GDPR arts. 15-22). If you have given us consent, you can withdraw it whenever you want: what was done before stays valid.

Just write to mail@cookiemi.com. We answer within a month.

If you think we are getting something wrong, you can contact the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garante@gpdp.it) or the authority of the country where you live.

8. The cookies on this site

On cookiemi.com we use our own banner: you can see the full list of cookies and change your mind whenever you want.

Read the cookie policy · Change your cookie preferences

9. How we keep the data safe

  • The site and the panel travel encrypted (HTTPS).
  • Sign-in codes are stored only in encrypted form and expire within minutes.
  • IP addresses go into the logs only as a non-reversible code.
  • Every customer sees only their own data.
  • Card details never pass through our servers.

10. If we change this policy

When we update it we change the date at the top of the page. If a change affects you closely, we write to you by email.

This policy covers the data we process ourselves. For data collected on the site of one of our customers, the controller is that site.