Compliance and Transparency

Privacy Policy.

We process your personal data following a radical approach based on encryption and structural minimization. No profiling, no tracking cookies, and impossible access to your plain text data.

GDPR Compliant Zero Profiling Cookies Privacy by Design Updated: March 2026
Document summary
1
Data Controller
GDPR Art. 13.1.a

Artur Arkadiusz Woszczyk
Milan (MI)
privacy@calculegal.it — contact for all privacy-related requests.

Data Protection Officer (DPO) CalcuLegal has assessed the obligation to appoint a DPO under Art. 37 GDPR. Due to the nature of the processing — no sensitive data in plain text, no systematic profiling, consent-based and occasional processing — the appointment is not mandatory. However, the Controller remains available for any requests at the email address indicated above.
2
Processing principles
GDPR Art. 5

CalcuLegal processes personal data in compliance with the principles set out in Art. 5 GDPR. In particular:

Lawfulness, fairness, and transparency. Every processing operation is based on an explicit legal basis. The user is informed clearly and understandably before the processing begins.
Purpose limitation. The collected data is used exclusively for the stated purposes. It is not transferred to third parties for marketing, profiling, or behavioral analysis.
Minimization. Only data strictly necessary for the purpose is processed. The simulation phase neither requires nor collects identifying data.
Accuracy. The user is solely responsible for the truthfulness of the data entered. The Controller has no way to verify its accuracy.
Storage limitation. Data is not kept longer than necessary for the purpose for which it was collected.
Integrity and confidentiality. AES-GCM 256 bit + RSA-OAEP 4096 bit encryption. Exclusive access to the recipient via MFA. Not even the Controller can access the plain text data.
3
Data processed, purposes, and legal bases
GDPR Art. 13.1.c–d

Simulation phase — no personal data

During the completion of the calculators and the viewing of the estimate report, the Service does not collect or process identifying data. The entered parameters (type of injury, degree of disability, expenses, impact on work) are treated as anonymous input for a mathematical calculation and are not associated with any identity.

Structural anonymity — There is no personal data to protect in the simulation phase because no personal data enters the system. This is not a contractual commitment — it is a technical property of the architecture.

Legal orientation phase — upon explicit consent

If the user chooses to request contact with a Partner Firm, the following data is processed:

Data collected: first name, last name, email address, phone number, brief description of the situation.
Purpose: encrypted transmission of the file to the Partner Firm designated by the user; monitoring of SLA response times.
Legal basis: explicit user consent (Art. 6.1.a GDPR), granted via double opt-in with integrated privacy notice at the end of the simulation.
Retention: encrypted data is kept for the time necessary to manage the file and for a maximum of 90 days from closure. The plain text content is never accessible to the Controller.

Technical navigation data

The computer systems and software procedures of the Service acquire, during normal operation, some technical data whose transmission is implicit in the use of internet communication protocols: IP address, browser type, operating system, visited pages, time of request.

This data is processed exclusively for technical security purposes (detection of attacks, system anomalies) and is not used to identify the user or produce behavioral profiles. It is kept for a maximum of 30 days and then automatically deleted.

Legal Basis — Technical Data Legitimate interest of the Controller in system security (Art. 6.1.f GDPR), balanced with the user's rights due to the brevity of retention and the absence of any profiling purpose.
4
Communication to third parties
GDPR Art. 13.1.e

The user's personal data is not assigned, sold, or communicated to third parties for marketing, profiling, behavioral analysis, or any other purpose other than those stated in this Policy.

Partner Firm. Receives the encrypted file exclusively upon the explicit request of the user. Acts as an independent data controller for activities subsequent to the first contact.
Technical suppliers. Entities managing the server infrastructure operate as data processors (Art. 28 GDPR) and are contractually bound to the same confidentiality standards as the Controller.
No assignment to advertising platforms, social networks, data brokers, or market analysts.
No data transfer to third countries outside the European Economic Area, except for legal obligations.
5
User rights
GDPR Arts. 15–22

The user can exercise the following rights at any time by sending a request to privacy@calculegal.it. The Controller will respond within 30 days of receipt.

Article Right Description
ART. 15 GDPR Access Obtain confirmation of processing and a copy of the personal data processed.
ART. 16 GDPR Rectification Correct inaccurate or incomplete data.
ART. 17 GDPR Erasure Request data deletion ("right to be forgotten"), within the technical limits of encryption.
ART. 18 GDPR Restriction Obtain restriction of processing in certain cases provided by law.
ART. 20 GDPR Portability Receive one's data in a structured, machine-readable format.
ART. 21 GDPR Objection Object to processing based on legitimate interest, including for technical security purposes.
ART. 7.3 GDPR Withdrawal of consent Withdraw the given consent at any time, without prejudice to the lawfulness of the previous processing.
ART. 77 GDPR Complaint Lodge a complaint with the Data Protection Authority (garanteprivacy.it).
Architectural technical limit — Due to the encryption architecture, the Controller does not have access to the plain text content of the files transmitted to Partner Firms. The exercise of the rights of access, rectification, and erasure on that data must be addressed directly to the receiving Partner Firm, which acts as an independent data controller for activities following the first contact.
7
Security measures
GDPR Art. 32

The Controller has adopted adequate technical and organizational measures to ensure a level of security appropriate to the risk, pursuant to Art. 32 GDPR. Full technical details are available in our Technical Compliance document.

AES-GCM 256 bit encryption for data at rest — banking and military standard.
RSA-OAEP 4096 bit encryption for the symmetric key — exclusive access to the recipient.
Mandatory MFA authentication to access the file vault.
Transmission over HTTPS + TLS 1.3 with 12-month HSTS.
Zero-knowledge architecture: the Controller does not possess the decryption keys and cannot access the plain text data.
8
Changes to the Privacy Policy
GDPR Art. 13.2

This Policy may be updated to reflect regulatory changes, service modifications, or improvements in informational transparency. The date of the last update is always indicated at the bottom of the document.

In the event of substantial changes to the processing — particularly those requiring new consent — the user will be informed at least 30 days in advance via a prominent notice on the home page and, if available, via email.

Version 1.0 — Effective date: March 2026 — Last updated: March 2026
Artur Arkadiusz Woszczyk — VAT 05247450967
Related links: Terms and ConditionsDeontological complianceTechnical compliance