Skip to content
Fuer Partnerschaftsmoeglichkeiten Jetzt registrieren!

Privacy Policy

Privacy Policy

This Privacy Policy describes how personal data collected through the website tradenet.it is processed, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter "GDPR") and with Italian Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018 (Italian Privacy Code).

Last updated: 8 August 2026

1. Data Controller

The Data Controller (Titolare del trattamento) pursuant to Article 4(7) and Article 24 of the GDPR is:

  • Company name: Tradenet Services srl
  • Registered office: Via Marconi, 3, 36015 Schio (VI), Italy
  • VAT number / Tax code (P.IVA/C.F.): IT02860350244
  • Business Register (REA): VI-280734
  • Share capital: EUR 60,000.00 fully paid up
  • Email: services@tradenet.it
  • Contact email (from the website): marketing@tradenet-services.it
  • System email sender: noreply@notify.tradenet-services.it

The Data Controller has not appointed a Data Protection Officer (DPO), as the appointment is not mandatory under Article 37 of the GDPR. For any matter relating to the processing of personal data, you may contact the Data Controller at the addresses indicated above.

2. Categories of Personal Data Processed

Depending on how you interact with the website, the following categories of personal data may be processed for each processing activity:

2.1 User registration (double opt-in)

  • First name and last name;
  • Email address;
  • Telephone number;
  • Company name (optional);
  • Password (stored exclusively in hashed form using the bcrypt algorithm; the plaintext password is never stored).

Registration requires mandatory email verification and subsequent approval by an administrator.

2.2 Proof of consent ("clickwrap")

At the time of registration, in order to document the consent given, the following are recorded:

  • IP address;
  • User-agent (browser/device information);
  • Timestamp of the action;
  • A PDF audit record of the consent.

2.3 Affiliate programme

  • Referral code (ref-code);
  • Tracking of visits and conversions (by means of first-party affiliate tracking cookies);
  • Commissions accrued;
  • Internal wallet and cashout (withdrawal) requests.

2.4 Store, orders and payments

  • Order data and invoicing data (invoices with 22% VAT);
  • Product purchased;
  • Payments are processed through Stripe and PayPal: payment data (card details, account credentials) are handled directly by the payment providers and are not stored by the website.

2.5 Transactional emails

  • Email address and data necessary to send service messages (email verification, password reset, notifications), delivered via the Mailgun SMTP service.

2.6 Contact / request forms

  • Identification and contact data and the content of the message you send.

2.7 Navigation data

  • Data automatically transmitted by internet communication protocols during the use of the website (e.g. IP address, technical cookies as described in Section 9). Some resources are loaded from third-party CDNs (Google Fonts, Tailwind, jsDelivr, unpkg, Stripe.js) that may set technical cookies and/or log the IP address.

3. Purposes and Legal Bases of Processing (Art. 6 GDPR)

Your personal data is processed for the following purposes, each based on the corresponding legal basis under Article 6 of the GDPR:

  • Creation and management of the user account, email verification and administrative approval โ€” Legal basis: performance of a contract or of pre-contractual measures taken at your request (Art. 6(1)(b) GDPR).
  • Recording of proof of consent (IP address, user-agent, timestamp, audit PDF) โ€” Legal basis: compliance with a legal obligation to which the Controller is subject, namely the obligation to demonstrate that consent has been given (Art. 6(1)(c) GDPR, in conjunction with Art. 7(1) GDPR).
  • Management of the affiliate programme (ref-code, tracking of visits and conversions, commissions, wallet and cashout requests) โ€” Legal basis: performance of the affiliation contract (Art. 6(1)(b) GDPR).
  • Management of orders, payments and issuance of invoices โ€” Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations of an accounting and tax nature (Art. 6(1)(c) GDPR).
  • Sending of transactional/service emails (verification, password reset, notifications) โ€” Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Handling of requests submitted through the contact forms โ€” Legal basis: performance of pre-contractual measures or the legitimate interest of the Controller in responding to your requests (Art. 6(1)(b) and Art. 6(1)(f) GDPR).
  • Use of technical/necessary cookies โ€” Legal basis: legitimate interest of the Controller in ensuring the correct functioning and security of the website (Art. 6(1)(f) GDPR); technical cookies do not require consent pursuant to Art. 122 of Legislative Decree No. 196/2003.
  • Security of the platform, prevention of abuse and fraud โ€” Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).

Where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).

4. Methods of Processing and Security

Personal data is processed by electronic means and, where necessary, on paper, in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality set out in Article 5 of the GDPR.

The Controller adopts appropriate technical and organisational measures pursuant to Articles 25 and 32 of the GDPR to ensure a level of security appropriate to the risk, including:

  • Storage of passwords exclusively in hashed form using the bcrypt algorithm;
  • Encryption of communications in transit (HTTPS/TLS);
  • Access controls and restriction of processing to authorised persons;
  • Hosting infrastructure located within the European Union.

The website's application is developed in Go and hosted on servers provided by Hetzner within the European Union.

5. Recipients, External Processors and Non-EU Transfers

Your personal data may be made accessible to duly authorised persons who process data under the direct authority of the Controller, and may be communicated to third parties acting as Data Processors (responsabili del trattamento) appointed pursuant to Article 28 of the GDPR. The main Processors are:

  • Hetzner Online GmbH โ€” hosting and server infrastructure services (servers located within the European Union);
  • Mailgun (Sinch) โ€” transactional email delivery service (SMTP);
  • Stripe โ€” online payment processing service;
  • PayPal โ€” online payment processing service.

Personal data may also be communicated to public authorities and supervisory bodies where required by law or to establish, exercise or defend a legal claim.

5.1 Transfers of data outside the European Union

Hosting and infrastructure are located within the European Union. However, some of the above-mentioned service providers (in particular Mailgun/Sinch and the payment providers Stripe and PayPal) and certain third-party CDNs may involve the transfer of personal data to countries outside the European Economic Area. Where such transfers take place, they are carried out in compliance with Chapter V of the GDPR (Articles 44 et seq.), on the basis of an adequacy decision of the European Commission or of appropriate safeguards, in particular the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR. You may request further information about such transfers and obtain a copy of the safeguards adopted by contacting the Controller at services@tradenet.it.

6. Retention Periods

Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, in accordance with the principle of storage limitation (Art. 5(1)(e) GDPR):

  • Account and registration data: for the entire duration of the contractual relationship (as long as the account remains active) and, thereafter, for the period necessary to comply with legal obligations or to defend a legal claim;
  • Proof of consent (IP address, user-agent, timestamp, audit PDF): retained for the entire duration of the relationship and for a subsequent period consistent with applicable limitation periods, in order to demonstrate that valid consent was given;
  • Affiliate programme data (ref-code, tracking, commissions, wallet, cashout): for the duration of participation in the programme and thereafter for the periods required by accounting and tax obligations;
  • Order, payment and invoicing data: retained for 10 years in accordance with accounting and tax obligations (Art. 2220 of the Italian Civil Code and applicable tax legislation);
  • Data contained in transactional emails and logs: for the time necessary for the service and platform security, and in any event no longer than required by law;
  • Contact form messages: for the time necessary to handle the request and, where relevant, for a subsequent period to manage any related requests.

Once the applicable retention periods have elapsed, personal data is deleted or irreversibly anonymised.

7. Data Subject Rights (Art. 15-22 GDPR)

As a data subject, you may exercise the following rights vis-ร -vis the Controller at any time:

  • Right of access (Art. 15 GDPR): to obtain confirmation as to whether or not your personal data is being processed and, if so, access to such data and to the related information;
  • Right to rectification (Art. 16 GDPR): to obtain the correction of inaccurate data and the completion of incomplete data;
  • Right to erasure ("right to be forgotten") (Art. 17 GDPR): to obtain the deletion of your data where one of the conditions provided by law applies;
  • Right to restriction of processing (Art. 18 GDPR): to obtain the restriction of processing in the cases provided for by law;
  • Right to data portability (Art. 20 GDPR): to receive your data in a structured, commonly used and machine-readable format and to transmit it to another controller;
  • Right to object (Art. 21 GDPR): to object, on grounds relating to your particular situation, to processing based on the legitimate interest of the Controller;
  • Right not to be subject to automated decision-making, including profiling (Art. 22 GDPR): the Controller does not carry out automated decision-making processes producing legal effects concerning you.

You also have the right to withdraw, at any time, any consent previously given (Art. 7(3) GDPR).

To exercise your rights, you may send a request to services@tradenet.it. The Controller will respond without undue delay and, in any event, within one month of receipt of the request, in accordance with Article 12 of the GDPR.

8. Right to Lodge a Complaint with the Supervisory Authority

Without prejudice to any other administrative or judicial remedy, if you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority pursuant to Article 77 of the GDPR. In Italy, the competent authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority), whose contact details are available at www.garanteprivacy.it.

9. Cookies

The website uses technical/necessary cookies only. It does not perform profiling and does not use third-party marketing cookies. The technical cookies used include:

  • Session cookies, necessary for authentication and navigation;
  • CSRF cookies, necessary for security (protection against cross-site request forgery);
  • Preference cookies (language and theme selection);
  • First-party affiliate tracking cookies, used to attribute visits and conversions within the affiliate programme.

Pursuant to Article 122 of Legislative Decree No. 196/2003 and to the Guidelines of the Garante on cookies of 10 June 2021, technical cookies do not require the user's prior consent.

The website also loads resources from certain third-party content delivery networks (CDNs) โ€” Google Fonts, Tailwind, jsDelivr, unpkg and Stripe.js โ€” which, for the purpose of delivering such resources, may set technical cookies and/or log your IP address. These resources are necessary for the correct display and functioning of the website. You can manage or disable cookies through your browser settings; disabling technical cookies may, however, prevent the website from functioning correctly.

10. Minors

The services offered through the website are intended for an adult audience and are not directed at minors. The Controller does not knowingly collect personal data from persons under the age of 18. Should the Controller become aware of having collected data from a minor without appropriate authorisation, it will take steps to delete such data as soon as possible. If you believe that a minor has provided personal data, please contact services@tradenet.it.

11. Changes to this Privacy Policy

The Controller reserves the right to amend or update this Privacy Policy at any time, in order to comply with applicable legislation or to reflect changes in the processing activities carried out. Any changes will be published on this page together with the relevant update date. You are therefore encouraged to consult this page regularly. The date shown at the top of this document indicates when it was last updated.