Privacy policy
Information about personal-data processing on the SiteSpark website.
This policy explains what data we collect, why we process it, how long it may be retained and what rights apply to people contacting SiteSpark.
1. Data controller
The controller is SiteSpark Maciej Maslanka. Contact us at kontakt@sitespark.it about personal-data processing.
2. Data we process
We process information submitted voluntarily through forms and enquiries, including name, company, email address, telephone number, message and project details.
When a form is submitted, we also record its time, page path, a safely limited page and referrer URL, UTM campaign parameters and — after analytics consent — random session and visitor IDs. An IP address may be used transiently by the server or hosting provider to prevent abuse, but SiteSpark does not persist raw IP addresses or full User-Agent strings in its lead and analytics stores.
3. Purposes and legal basis
Data is used to answer enquiries, prepare proposals or audits, protect the website from abuse and establish or defend legal claims where necessary.
The basis is taking steps at the request of the data subject and, where applicable, the controller’s legitimate interest.
Optional SiteSpark analytics, Google Analytics 4 and Microsoft Clarity start only after consent, which can later be withdrawn.
4. Technical analytics
After consent, we may measure page views, sessions, general device category, country supplied by the infrastructure, traffic source, UTM campaign, CTA clicks, form stages, scroll depth and aggregated performance metrics. Form-field values are not written to analytics events and device fingerprinting is not used.
5. Recipients and retention
Data may be shared with providers supporting hosting, email, forms, communication automation or technical analytics, only to the extent required for those purposes.
We retain data for the enquiry and communication period and for a justified period needed to preserve agreements, settlements or potential claims.
Events in the first-party analytics store have a configurable retention period, set to 90 days by default. New form submissions and CRM changes are held in an encrypted journal; historical entries created before encryption may remain in a legacy store until a controlled migration is completed.
6. Your rights
You may request access, correction, deletion, restriction, object to processing and lodge a complaint with the competent supervisory authority.
7. Contact
For privacy and personal-data matters, contact kontakt@sitespark.it.