Privacy notice
Last updated: 30 September 2026.
Who processes your data
The data controller is Safira Intelligence di Giacomo Balossi, registered office Via Montebello 70, Lecco (LC), Italia, VAT number pending assignment. For any question about your data, write to giacomo@safiraintel.com.
What data we collect and why
When you create the account we collect the company name, your full name, your email and your password, which we keep only as an encrypted fingerprint. They are used to verify the email address, create your workspace, let you sign in and send you your account emails (codes, request confirmation and activation). When you choose a plan, name, email and company name go to the subscription system to activate it. Your workspace keeps the data you enter.
Who receives the data
To make Safira work, some data passes to these providers, each only for its own task:
- Resend (United States): sending the account emails (access codes, request confirmation, activation): email address, your workspace address and message text
- Cloudflare (United States): Safira's subscription system: name, email and company name when you ask for a plan, usage counts; and the secure connection between the Internet and the server
- DeepInfra (Deep Infra Inc.) (United States): the artificial intelligence model: texts of the emails and messages you have analysed, web pages read with names and contact details of people
- TypeSafe (TypeSafe AI Inc.) (United States): a second artificial intelligence model: texts of the pages read, with the names of company owners
- SearchApi (SearchApi LLC) (United States): web searches: the search queries, which may contain names of companies and people
- Serper (country to be confirmed): web searches: the search queries, which may contain names of companies and people
- Brave Search (United States): web searches: the search queries, which may contain names of companies and people
- Kaspr (France): professional contact details: name and LinkedIn profile of the decision maker whose email or phone you request
- Openapi (Italy): Italian business register data: the VAT numbers of the companies searched
- Telegram (country to be confirmed): notices to the founder about how the service is running: the name of the company requesting access or a plan, and technical alarms
- Esri (United States): the meeting maps: the network address of whoever uses it and the areas shown on the map
How long we keep sign-up data
An account request that is not confirmed within 24 hours, or is not approved, keeps company, name and email for 30 days after it is closed; after that it remains only as a record with no personal data. An approved request is kept for as long as the company has its workspace. For the codes sent by email we keep only an encrypted fingerprint of the address, deleted after 2 days. When the server backups are active, they also contain this data and are kept for 12 to 24 months, then deleted. When you ask for a plan, Safira's subscription system receives your name, email and company name: if you do not become a customer, after 12 months only the dates and technical data with no name, email, company or workspace address remain.
Your rights
You can ask to see your data, correct it, delete it, restrict its use, receive it in a readable format or object to its use by writing to giacomo@safiraintel.com. You can also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
Why we use the data and on what legal basis
Below you will find, purpose by purpose, the legal basis under Article 6 of Regulation (EU) 2016/679 (the “GDPR”) for the data described on this page.
Creating the account and letting you sign in. Verifying your email with the code, preparing your workspace, letting you sign in and, when you ask, helping you with “Sign in” and “Forgot your password”. Legal basis: the performance of the contract or of pre-contractual steps you request (Art. 6(1)(b)), when you are the contracting party, for example as a professional or the owner of a sole proprietorship. When the contracting party is the company you act for, the basis is our legitimate interest in managing the relationship with that company through the people who represent it (Art. 6(1)(f)).
Sending you service emails. The verification codes and, where provided, the notices about the status of your request or your account. These are service-only emails: they contain no advertising, no links to open and no tools that record when you open them. Legal basis: the same as in the previous point.
Activating the account and the plan. Reviewing the request, activating the account and the chosen plan, managing the free trial, measuring the use of the features included in the plan, issuing invoices and recording payments. For this, the subscription system receives your name, email and company name, the business profile you give during setup (type of business, countries, offering, customers, size and requested plan), the invoicing details and usage counts. The approval of the account is decided by a person. Legal basis: Art. 6(1)(b) or, for those acting on behalf of a company, Art. 6(1)(f), as above.
Complying with legal obligations. Keeping invoices and accounting records and answering requests from the authorities. Legal basis: compliance with a legal obligation (Art. 6(1)(c)). Invoices and accounting records are kept for ten years (Article 2220 of the Italian Civil Code).
Protecting the service and preventing abuse and fraud. Limiting attempts per network and per email address, checking with the anti-bot service that whoever fills in the forms that trigger an email is not an automated program, keeping technical logs of how the service runs and reporting anomalies to the people who run the service. Legal basis: our legitimate interest in the security of networks and services and in fraud prevention (Art. 6(1)(f), and Recitals 47 and 49 GDPR). The per-network counts stay only in the program's memory, not in an archive; for the email limits we keep an encrypted fingerprint of the address, not the address; the Portineria log contains neither your IP address nor your email.
Answering your requests and protecting our rights. Handling requests about your data, complaints and any disputes. Legal basis: the legal obligation for requests about data (Art. 6(1)(c) and Arts. 12-22 GDPR) and our legitimate interest in defending our rights (Art. 6(1)(f)).
Organising the service. Internal notices to the people who run Safira, for example that a company has requested access or a plan, with only the company name, and technical alarms. Legal basis: our legitimate interest in organising the service (Art. 6(1)(f)).
Consent. Today we do not ask for any consent, because none of these purposes requires it. We do not use your data for advertising, to profile you or to sell it to third parties. If one day we wanted to use it for a purpose that requires consent, for example promotional communications, we will ask you first and you will be able to withdraw it at any time, without affecting what was done before the withdrawal (Art. 7 GDPR).
Objection. When the legal basis is legitimate interest, you can object at any time on grounds relating to your particular situation (Art. 21 GDPR) by writing to the privacy address given above. We stop, unless we demonstrate compelling legitimate grounds or the data is needed to defend a right. On request, we explain how we balanced our interest against your rights.
If you do not give us the data
The company name, your full name, your email and a password are necessary to create the account: without them, sign-up cannot be completed. Without the technical cookies described below, the sign-up and sign-in pages do not work. To move to a paid plan, the invoicing details are also needed. What you enter in your workspace is up to you.
Other people's data in your workspace
In your workspace you can keep data about other people: the contacts and decision makers of the companies you follow, the emails and messages you connect or have analysed, meeting notes. For this data the controller is your company, which decides why and how to use it; we process it on its behalf, as processor (Art. 28 GDPR), under the data processing agreement that is part of the terms of the service. It is up to your company to give these people its own privacy notice and to answer their requests; to do so, the workspace offers “Delete forever”, the “Do not contact” list and “Download all my data”.
Some features are active only if they are included in your company's plan and if you use them: the search for companies and decision makers from public sources and specialised providers, analyses and drafts written with artificial intelligence, professional contact details, the read-only connection to your Outlook mailbox, the satellite maps. The providers each one involves are in the list “Who receives the data”. Safira prepares email drafts but does not send them: the person using the workspace decides whether to send them and sends them from their own email program.
If you ask to join your company's workspace, your name, your email and a description of the device (for example “Windows · Chrome”) reach the owner of the workspace and, when the workspace is connected to the subscription system, also the people who run Safira, who can approve or reject the request just like the owner. We send you the code to confirm your email.
Transfers outside the European Union
The server hosting the workspaces and their archives belongs to Hetzner Online GmbH and is located in Germany. Some other providers in the list “Who receives the data” are based in the United States or may process data outside the European Economic Area. For each of them, here is the safeguard under Chapter V GDPR on which the transfer is based.
Cloudflare, Inc. (United States), for the secure connection between the Internet and the server, the anti-bot check and the subscription system; Resend (Plus Five Five, Inc., United States), for sending emails; Esri (Environmental Systems Research Institute, Inc., United States), for the satellite map images: they are certified under the EU-U.S. Data Privacy Framework, which the European Commission found adequate in Implementing Decision (EU) 2023/1795 of 10 July 2023. The data processing agreements of Cloudflare and Resend also include the European Commission's standard contractual clauses. Resend keeps our account data, including the sending logs, in the United States even when the email is sent from Europe.
TypeSafe (TypeSafe AI, Inc., United States) and SearchApi (SearchApi, LLC, United States) are not certified under the Data Privacy Framework: their data processing agreements, which are part of their terms of service, include the standard contractual clauses approved by the European Commission (Art. 46 GDPR).
DeepInfra (Deep Infra Inc., United States), Serper and Brave Search (Brave Software, Inc., United States) do not appear to be certified under the Data Privacy Framework; for them, the safeguard required by Art. 46 GDPR is being defined. You can ask us at any time how far we have got.
KASPR SAS is based in France and states that it processes data, as far as possible, in the United Kingdom and the European Economic Area, with standard contractual clauses for any transfers. Openapi S.p.A. is based in Italy and states that, as a rule, data does not leave the European Economic Area. Telegram, which we use only for internal notices, states that it stores the data of users in the European Economic Area in data centres in the Netherlands and uses standard contractual clauses for transfers to the companies of its group.
If you connect your Outlook mailbox, data passes between our server and Microsoft, your company's provider; Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework.
You can request a copy of the safeguards adopted by writing to the privacy address. Whether a company is certified under the Data Privacy Framework can be checked on the official list: www.dataprivacyframework.gov/list.
Cookies and similar technologies
The pages of the safiraintel.com website set no cookies, store nothing in your browser, load no resources from other sites and use no analytics tools.
The pages for signing up and signing in (accedi.safiraintel.com) use only technical cookies, which travel only over an encrypted connection and cannot be read by the pages' scripts: “__Host-portineria_iscrizione” links your browser to the account request, to show you its status, and lasts 30 days; “__Host-portineria_verifica” links the browser to the code requested with “Sign in” or “Forgot your password” and lasts 20 minutes; “__Host-portineria_lingua” remembers the language chosen with the Italiano/English selector, lasts one year and is set only if you choose the language.
In your workspace, the technical cookie “__Host-safira_sessione” keeps you signed in: it lasts 30 days, and the session expires in any case after 30 days without use or 90 days after signing in. The application also stores in the browser's memory some interface preferences, such as the language, the filters and the state of the menu, and drafts not yet saved: they stay in your browser.
On the forms that trigger an email (sign-up, new code, “Sign in”, “Forgot your password”) the page loads Cloudflare's Turnstile anti-bot check from challenges.cloudflare.com: Cloudflare receives your IP address, some technical characteristics of the browser and of the connection and the site the request comes from, and may use in the browser technical tools strictly necessary for the check. According to its Turnstile privacy notice, Cloudflare uses these signals to provide the check to us and also, as an independent controller, to improve its own anti-bot system. In your workspace, when you open a satellite map (for example the meeting map or the Search map), the browser downloads the images from Esri's servers, which receive your IP address and the areas shown.
We use no profiling, advertising or analytics cookies, neither ours nor anyone else's. For technical tools that are strictly necessary for a service you have requested, the law does not require consent (Article 122 of the Italian Personal Data Protection Code; the Italian Data Protection Authority's cookie guidelines of 10 June 2021): this is why we do not show you a banner. You can delete cookies in your browser settings, but the sign-in pages and the workspace will not work until you accept them again.
Automated decisions
We do not take decisions about people who sign up for or use Safira based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them (Art. 22 GDPR): the approval of the account is decided by a person.
Some rules apply automatically, equally for everyone and without assessing personal aspects: the limits on attempts, the anti-bot check, the expiry of requests not confirmed within 24 hours, the order of arrival when the places for new workspaces are full, the end of the free trial on its date, the plan limits and the suspension of paid features, with the workspace in read-only mode, when an invoice remains unpaid beyond the deadlines. If you think one of these rules has affected you by mistake, write to us: a person will check it.
In your workspace, the artificial intelligence features propose scores, summaries and drafts about companies and contacts: they are suggestions for the people using the workspace, who decide what to do with them.
Minors
Safira is a service for businesses and professionals and is not aimed at minors under 18. We do not knowingly collect data about minors; if we find out that we have received any, we delete it.
Security
We protect data with technical and organisational measures appropriate to the risk (Art. 32 GDPR). For example: passwords are kept only as a cryptographic fingerprint and verification codes only as a fingerprint, valid for 10 minutes and with at most 5 attempts; pages travel over an encrypted connection (HTTPS); the sign-in cookies travel only over an encrypted connection and cannot be read by the pages' scripts; each customer has a separate workspace, with its own archive; access to the servers is restricted to authorised people.
No system is invulnerable. If a personal data breach is likely to result in a high risk to you, we will tell you without undue delay, as required by Art. 34 GDPR. To report a security issue or a suspicious email in the name of Safira, use the address shown at the bottom of every page.
Other retention periods
In addition to the periods given above: the account and workspace data are kept for as long as the account is active. If the account is closed, the workspace is switched off and the owner can reopen it in read-only mode to download the data; 30 days after closure the workspace is deleted with all its data. The owner can ask us to delete it earlier, after receiving the data if they want it.
In the subscription system, the detail of individual uses is deleted after 13 months; the totals needed for invoicing remain. Invoices and accounting records are kept for ten years. After the relationship ends, we keep the other account data only for as long as necessary for accounting and tax obligations and to protect our rights, then we delete it or make it anonymous.
A workspace that was prepared but never activated is paused after 14 days, with its data kept; if the request is not activated, we may delete it together with the data entered. The server's technical logs have a maximum size and overwrite themselves.
How to exercise your rights and complaints to the Garante
To exercise the rights described above, write to the privacy address; we have not appointed a data protection officer. We reply without undue delay and at the latest within one month, which may be extended by two further months if the request is complex or requests are numerous; in that case we let you know within the first month (Art. 12 GDPR). The reply is free of charge, except for manifestly unfounded or excessive requests. We may ask you to confirm your identity, for example by writing to us from the account's email address.
If you believe that the processing of your data infringes the GDPR, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (Art. 77 GDPR; www.garanteprivacy.it): by certified email (PEC) to protocollo@pec.gpdp.it, by registered letter with return receipt to Piazza Venezia 11, 00187 Rome, Italy, or by delivering it by hand to the same address. You can also contact the supervisory authority of the European Union country where you live or work, or the courts (Art. 79 GDPR).
Changes to this notice
We may update this notice when the service, the providers or the rules change. This version is dated 30 September 2026. If a change significantly affects the use of your data, we will tell you before it applies, by email or in your workspace. Previous versions can be requested from the privacy address.