Platform Privacy Notice
Last Updated: May 1st, 2026.
This Platform Privacy Notice ("Notice") describes how Compiuta S.r.l. ("Compiuta", "we", "us", or "our") collects, uses, and protects personal data in its capacity as Data Controller in connection with the Connhex SaaS platform, available at dashboard.connhex.com.
This Notice applies to personal data collected directly from platform users - specifically, information required to create and manage an account, process billing, and operate the Service. It does not cover Customer Data that the Customer (as Data Controller) submits to the platform for their own purposes; that relationship is governed separately by the Data Processing Agreement.
For information about how Compiuta handles data on the Compiuta corporate website (compiuta.com), please refer to the Compiuta Privacy Policy.
Data Controller Identity
Compiuta S.r.l. Via T. Vecellio, 169 B 35132 Padova (PD), Italy VAT: IT 05375100285
Privacy contact and Data Protection Officer: info@compiuta.com
What We Collect and Why
The table below describes each category of personal data we process as Data Controller on the Connhex platform, including the legal basis and retention period for each.
| Data | How Collected | Purpose | Legal Basis (GDPR) | Retention |
|---|---|---|---|---|
| Email address | Account registration | Account management, transactional emails, service communications | Art. 6(1)(b) - performance of a contract | Duration of account, then 10 years (Italian fiscal law) |
| Billing name and address | Stripe checkout | Invoicing and tax compliance | Art. 6(1)(b) and Art. 6(1)(c) - contract and legal obligation | 10 years (Italian fiscal law) |
| Payment instrument details | Stripe - not stored by Compiuta | Payment processing | Art. 6(1)(b) - performance of a contract | Handled exclusively by Stripe |
| Anonymised platform usage events | Mixpanel (server-side) | Product improvement and feature development | Art. 6(1)(f) - legitimate interests | 12 months |
| Login and access logs | Platform infrastructure | Security, fraud prevention, and abuse detection | Art. 6(1)(f) - legitimate interests | 12 months |
| Support email content | Customer-initiated communication | Delivery of technical support | Art. 6(1)(b) - performance of a contract | 3 years |
Platform Analytics - Mixpanel
We use Mixpanel to understand how users interact with the Connhex platform interface, such as which features are accessed and navigation patterns. Data is transmitted server-side using only anonymised identifiers - no name, email address, or other directly identifying information is sent to Mixpanel. Mixpanel is configured to operate exclusively on its EU Data Residency infrastructure.
This processing is based on our legitimate interest in improving the product (GDPR Art. 6(1)(f)). You have the right to object to this processing at any time by contacting us at info@compiuta.com.
Payment Data - Stripe
Payment processing is handled by Stripe, Inc. Compiuta does not store card details or payment instrument data. Stripe acts as an independent data controller for payment data under its own privacy policy and PCI DSS compliance programme. Compiuta receives only a payment confirmation and a billing reference number.
Data Retention
We retain personal data only for as long as necessary for the purposes described above, or as required by applicable law. When you close your account, we will delete your personal data within thirty (30) days, except where longer retention is required by Italian fiscal law (typically 10 years for billing and invoice records) or where we have a legal obligation to retain records.
Free Plan inactivity: For Free Plan accounts, accounts inactive for twelve (12) consecutive months will be scheduled for deletion as described in our Terms of Service. We will email the registered address thirty (30) days before any deletion takes effect.
Data Transfers
All personal data we collect as Data Controller is stored on Hetzner Online GmbH infrastructure located within the European Economic Area (Germany and Finland). We do not transfer personal data outside the EEA, with the following limited exceptions:
- Mixpanel: Anonymised usage events are processed in Mixpanel's EU Data Residency infrastructure. No personal data is involved in this transfer.
- Stripe: Billing and payment data is processed by Stripe, which relies on the EU–US Data Privacy Framework for any transfers between the EU and the United States.
Subprocessors
We engage a small number of subprocessors to help us deliver the Service. The full list, including processing locations and purposes, is available at connhex.com/legal/subprocessors.
Your Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): You may request deletion of your personal data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18): You may request that we restrict processing of your personal data in certain circumstances.
- Right to data portability (Art. 20): You may request your personal data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): You may object at any time to processing based on our legitimate interests, including platform analytics.
To exercise any of these rights, contact us at info@compiuta.com. We will respond within thirty (30) days of receiving your request.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the competent supervisory authority. For Compiuta, the lead supervisory authority is:
Garante per la Protezione dei Dati Personali Piazza Venezia, 11 - 00187 Roma, Italy www.garanteprivacy.it
Changes to This Notice
We may update this Notice from time to time. Material changes will be communicated to registered account holders by email with at least thirty (30) days' advance notice. The date of the most recent update is shown at the top of this page.
Compiuta S.r.l. Via T. Vecellio, 169 B - 35132 Padova (PD) - Italy VAT: IT 05375100285
For questions regarding this Notice, contact: info@compiuta.com