Who is responsible
The data controller is Sailfast Srls, VAT no. IT01383980321, Via Buie d’Istria 9, 34134 Trieste, Italy. For privacy questions or to exercise your rights, write to sailfast@sailfast.eu.
Data we process and why
When you visit the site, its hosting and security providers may process technical information such as your IP address, browser and device details, requested pages, timestamps, and security events. This is needed to deliver the site, maintain its security and diagnose faults. Sailfast relies on its legitimate interest in operating a secure website (GDPR Article 6(1)(f)).
When you email us, we receive your email address and any name, contact details, message or attachments you choose to send. We use these details to answer you and handle your request. If your enquiry concerns a possible service or contract, the legal basis is taking steps at your request before a contract or performing it (Article 6(1)(b)); for other enquiries, it is our legitimate interest in responding (Article 6(1)(f)). Information needed for invoices or other legal duties is processed under Article 6(1)(c). Emailing us is voluntary, but we cannot answer without a way to contact you.
The site itself has no contact form, newsletter, advertising pixels or analytics scripts. Its own code does not store information in your browser. See our cookie policy for the essential security cookie used by the hosting layer.
Who receives data
Authorised Sailfast personnel and service providers supporting website hosting, security, IT and email may access data as needed for these purposes. OpenAI hosts and operates this site on Sailfast’s behalf and uses sub-processors to provide that service. Data may also be disclosed where required by law or to protect legal rights. We do not sell visitor data.
International processing
Website hosting and security may involve processing outside the European Economic Area. Under the ChatGPT Sites data processing terms, transfers of EEA data by OpenAI Ireland to affiliates or third parties outside the EEA are supported by European Commission adequacy decisions or standard contractual clauses. For details or a copy of the relevant safeguards, contact us at the address above. Email service arrangements may also involve international processing; we will provide information about the safeguards applicable to a specific request on enquiry.
How long data is kept
We keep correspondence only while needed to answer the request, manage any ensuing relationship or claim, and meet applicable legal record-keeping duties; we then delete or anonymise it. In deciding the period, we consider the type of request, whether a contract follows, limitation periods and statutory obligations. Technical logs and security data are kept according to the limited operational and security retention settings of the relevant hosting provider. You may ask us for the period applicable to your data.
Your rights
Subject to the GDPR’s conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may contact us at sailfast@sailfast.eu to make a request. You can also lodge a complaint with the Garante per la protezione dei dati personali or another competent EU supervisory authority. The site does not make decisions about visitors solely by automated means that produce legal or similarly significant effects.
Other websites and updates
Brand links take you to third-party websites with their own privacy notices. We may update this policy if the site or its processing changes; the date above shows the latest revision.