Privacy Policy and Personal Data Processing – EVOKA Website

Evoka, represented by Francesco Orlandi and Cristiano Ciuti as co-owners of the “Evoka” project, reachable at support@evoka.app, is committed to protecting the privacy of its users.

This document has been drafted pursuant to Article 13 of EU Regulation 2016/679 (hereinafter, the “Regulation” or “GDPR”) to inform you about how we process your personal data when using our website evoka.app (hereinafter, the “Site”).

The personal data you provide or otherwise collected during your use of the services offered (the “Services”) will be processed in compliance with the Regulation and applicable confidentiality obligations. The processing will be based on the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, data minimization, accuracy, integrity, and confidentiality.

Browsing Data

The IT systems and software procedures used to operate the Site collect, during normal use, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This information is not collected to be associated with identified users but, by its very nature, could allow users to be identified through processing and associations with data held by third parties. The data collected during navigation may include IP addresses, domain names of the devices used, URIs (Uniform Resource Identifiers) of requested resources, time of the request, method used to submit the request, size of the response file, server response code (e.g., success or error), and other parameters related to the user’s operating system and IT environment.

This data may be used to determine liability in the event of computer crimes against the Site or third parties. Otherwise, it is stored for no more than seven days.

Data Provided Voluntarily by the User

When using the Services, you may provide personal data of third parties. In such cases, you act as an independent data controller, assuming all legal obligations and responsibilities under applicable regulations.

You agree to indemnify the Data Controller from any dispute, claim, or demand for compensation arising from the unlawful processing of third-party data. If you provide or process personal data of third parties through the Site, you declare that you have obtained their prior consent, taking full responsibility for it.

Cookies

Information on cookies used by the Site is available in our Cookie Policy, accessible from the relevant section on the Site.

Purposes of Processing

Your personal data is processed for the following purposes:

  • to enable navigation of the Site;
  • to respond to specific requests submitted via the contact form;
  • to fulfill legal obligations under national or EU laws, or comply with requests from competent authorities.

Legal Basis for Processing

The legal basis for processing data for purposes (a) and (b) is Article 6(1)(b) of the GDPR, as the processing is necessary to provide the Services or respond to your requests. Providing data for these purposes is optional, but failure to provide such data may prevent the activation of the requested Services.

The legal basis for processing data for purpose (c) is Article 6(1)(c) of the GDPR, as the processing is necessary to comply with legal obligations.

Recipients of Personal Data

Your personal data may be shared, for the purposes described above, with:

  • parties involved in the delivery of Services (e.g., hosting providers or technical maintenance staff);
  • entities, authorities, or organizations that require data disclosure by law or by order of public authorities, acting as independent data controllers.

Data Transfers Outside the EEA

The Data Controller does not transfer your personal data outside the European Economic Area. If such transfer becomes necessary, it will be carried out in accordance with the safeguards set out in the GDPR.

Data Retention

Personal data will be retained only for as long as strictly necessary to achieve the purposes for which it was collected, in accordance with the principles of data minimization and storage limitation as per Article 5(1)(e) of the GDPR.

In any case, data may be retained for the time required to comply with contractual and legal obligations. For more information on the retention period and criteria used, you may contact the Data Controller using the contact details provided above.

Data Subject Rights

At any time, you have the right to:

  • access your personal data (Articles 15–22 of the GDPR),
  • request rectification or deletion of your data,
  • request restriction of processing in the cases provided for by Article 18 of the GDPR,
  • object to processing (Article 21),
  • withdraw consent (without affecting the lawfulness of processing based on consent before its withdrawal),
  • request data portability (Article 20),
  • lodge a complaint with the relevant Data Protection Authority pursuant to Article 77 of the GDPR (in Italy, the “Garante per la Protezione dei Dati Personali”).

All requests may be addressed to the Data Controller using the contact details listed above.

Changes to This Privacy Policy

The Data Controller reserves the right to modify or update this Privacy Policy, in whole or in part, due to changes in applicable law or for other reasons. Any changes will be promptly communicated and will become binding once published on the Site.

We recommend you regularly consult this section to view the most up-to-date version of our Privacy Policy.

Cookie Policy
evoka.app

Our website uses exclusively technical cookies, for the following purposes:

  • improving the user experience,
  • facilitating navigation,
  • managing authentication,
  • collecting statistical data (e.g., number of site visitors).

The use of these cookies is essential for the proper functioning of the service and does not require user consent.

What are cookies

A cookie is a small text file that is saved on the user's computer or device when they visit a website. Its purpose is to store useful information that will be read and updated each time the user returns to the same site. In practice, the cookie acts as a reminder of the user’s interactions with the site.

When a user visits a website, the web server sends the cookie to the browser (such as Chrome, Firefox, Safari, etc.), which stores it on the device. This allows the website to automatically adjust to the user during future visits—for example, by remembering browsing preferences.

While browsing, the user may also receive cookies from other websites (known as "third-party cookies"), which are set by entities other than the website being visited. These cookies are used for specific purposes defined by those third parties.


Technical cookies

Technical cookies are used to ensure the website functions correctly. They are used, for example, to:

  • authenticate the user,
  • maintain an active browsing session,
  • remember certain preferences (such as language settings).

User consent is not required for the use of technical cookies, as they are essential to providing the requested service.

Analytics cookies also fall under this category. These cookies collect anonymous, aggregated information about how users interact with the site (e.g., most visited pages, errors encountered, etc.). This data helps improve the quality and usability of the site.

Profiling cookies

Profiling cookies are used to collect information about the user’s browsing behavior, such as:

  • visited pages,
  • viewed or purchased products,
  • content consumed.

The goal is to create user profiles in order to display personalized advertising based on their interests.

The use of these cookies requires the user’s explicit and informed consent, in accordance with Article 7 of EU Regulation 2016/679 (GDPR) and applicable national laws.

Third-party cookies

Some web pages may contain elements from other websites (such as ads, videos, maps, or social media buttons). These elements may generate cookies managed by third parties, different from the owner of the visited site.

These third-party cookies are often used for profiling and marketing purposes, and they also require the user's prior and informed consent.