Privacy Policy
This privacy notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") to all individuals interacting with the website neednerd.dev (the "Site").
1. Data controller
The data controller is Filippo De Pretto, self-employed professional with Italian VAT number IT04778630980, ordinary Italian tax regime.
For any request regarding personal data processing, you can contact the controller at ciao@neednerd.dev.
No Data Protection Officer (DPO) has been appointed, as the conditions set out in Article 37 GDPR do not apply.
2. Personal data processed
The Site processes the following categories of data:
- Browsing data automatically collected by the hosting provider (Cloudflare): IP address, user agent, request timestamps, requested URL, HTTP status codes. Processed exclusively in aggregate form and only for the time strictly necessary for the security and proper functioning of the Site.
- Booking data: if you book a call through the embedded Cal.com calendar, Cal.com collects your name, email address and time availability. This data is processed directly by Cal.com Inc. as a data processor (see section 5). Cal.com may also set technical cookies on its own domain for the widget to function — see Cookie Policy.
- Email contact data: if you send an email directly to ciao@neednerd.dev, the message content and your contact details will be processed in order to reply and handle the request.
The Site does not use any analytics, profiling, advertising or third-party tracking tools.
3. Purposes and legal bases of processing
| Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|
| Site delivery and security | Legitimate interest (Art. 6.1.f) — Cloudflare technical logs | Up to 30 days in hosting logs |
| Call booking via Cal.com | Pre-contractual measures at the data subject's request (Art. 6.1.b) | Per Cal.com policy (see section 5) |
| Handling email enquiries | Pre-contractual measures (Art. 6.1.b) | Until end of conversation + tax obligations (10 years) |
4. Provision of data
Providing data for the above purposes is optional. Refusing to provide booking data means you cannot book a call through the inline calendar, but the direct email channel at ciao@neednerd.dev remains always available.
5. Data recipients and non-EU transfers
Data may be shared with the following parties:
5.1 Cloudflare, Inc. (hosting)
The Site is hosted on Cloudflare Pages (Cloudflare, Inc., based in the United States). Cloudflare acts as data processor solely for the technical delivery of the Site (access logs, CDN, DDoS protection). Non-EU data transfers are governed by the Standard Contractual Clauses (SCCs) approved by the European Commission. More info: cloudflare.com/privacypolicy.
5.2 Cal.com, Inc. (booking calendar)
When you activate the inline calendar (functional cookies with consent), booking data (name, email, time slot) is processed by Cal.com, Inc. (based in the United States) as a data processor. Cal.com adheres to the SCCs and to the EU-U.S. Data Privacy Framework. More info: cal.com/privacy.
5.3 Fontsource (self-hosted fonts)
Site fonts (Manrope, Inter, JetBrains Mono) are self-hosted on the neednerd.dev domain via the open-source Fontsource library. No user data is transferred to Google Fonts or other external font services.
5.4 Public bodies and tax authorities
For tax, accounting and anti-money-laundering obligations, billing data is transmitted to the tax advisor, to the Italian Revenue Agency (Sistema di Interscambio for electronic invoicing) and to other legally competent bodies.
6. Your rights
You have the right to exercise at any time the rights set out in Articles 15-22 GDPR, in particular:
- Access to your data (Art. 15)
- Rectification (Art. 16)
- Erasure / "right to be forgotten" (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
- Withdrawal of consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
To exercise these rights, simply send a request to ciao@neednerd.dev.
7. Lodging a complaint with the supervisory authority
You have the right to lodge a complaint with the competent authority, i.e. the Italian Data Protection Authority (Garante per la protezione dei dati personali) — garanteprivacy.it.
8. Data security
The Site adopts adequate technical and organisational measures to protect the personal data processed: mandatory HTTPS connection (HSTS), HTTP security headers (CSP, X-Frame-Options, etc.), continuous updating of software dependencies, and the principle of data minimisation.
9. Changes to this notice
The controller reserves the right to update this notice in case of regulatory changes or evolution of the Site. The current version is always available on this page, with the date of the last update at the top.
In short: the Site does not track, profile or sell data. The only third-party integration is the Cal.com widget for booking calls (technical cookies on their domain). For anything, write to ciao@neednerd.dev.