Privacy Policy
1. Controller
Lorenzo Rubino
Via Domenico Zampieri 23, 40033 Bologna, Italy
VAT number (Partita IVA): 04085421206
Privacy contact: [email protected]
2. Scope of this policy
This policy applies to the Lap Analysis Launcher public product page at /lap-analysis-launcher/, the trial request form, the reports web app, the downloadable desktop app when it uses online account, license, update, or report features, and related support, setup, and account administration.
When the desktop app is used only for local report generation without signing in or uploading files, source data and generated reports remain on the user's device unless the user chooses to upload, sync, store, or send them through an online feature or support channel.
3. Personal data processed
- Contact and trial data, including name, email address, team or business name, role, expected report volume, vehicle or workflow details, data source details, PDF customization options, and message content, if provided.
- Account data, including username, display name, account or team membership, user role, account status, authentication status, password reset or recovery metadata, and recovery-code lifecycle metadata. Recovery codes are intended to be stored as hashes, not as readable codes.
- License and entitlement data, including license key, permitted source entitlements, enabled features, report allowance, activation status, hardware or device identifiers used for activation, app session identifiers, app version, operating system, and offline grace or validation status.
- Report workflow metadata, including report type, input type, selected source entitlement, racetrack, driver name, reference name, session name, car number, report layout, report configuration, processing status, error messages, timestamps, deletion status, and usage counters.
- Uploaded or stored report material when online report processing or cloud PDF storage is used, including CSV, VBOX, AiM, image, logo, track, reference, or PDF files, related file names, object keys, content types, file sizes, and generated PDF output details.
- Local desktop data, such as locally generated reports, local report files, cached account state, cached logos, and pending offline usage sync records. These remain on the user's device unless an online feature or support workflow sends them to the service.
- Technical and security data, including IP address or IP hash, user agent, request logs, session identifiers, audit events, abuse-prevention signals, and diagnostic information needed to operate and secure the service.
- Cloudflare Turnstile challenge data used to verify that trial request submissions are not automated abuse.
- Technical connection data generated when the browser requests Google Fonts from Google servers.
The service is not designed to collect special categories of personal data. Users should avoid uploading personal data that is not needed for report generation, account administration, or support.
4. Purposes and legal bases
- To respond to enquiries, trial requests, and requested follow-up about the product or related services. Legal basis: pre-contractual measures at the data subject's request and, where applicable, legitimate interest.
- To create, administer, authenticate, secure, and support user accounts and team workspaces. Legal basis: contract or pre-contractual measures and legitimate interest.
- To issue, validate, enforce, and support licenses, entitlements, usage limits, vehicle access, offline grace periods, and software downloads or updates. Legal basis: contract or pre-contractual measures and legitimate interest.
- To process uploaded telemetry or report source files, generate reports, store PDFs when cloud storage is enabled, and make report history available to the account. Legal basis: contract or pre-contractual measures.
- To provide team setup, custom logo, custom PDF layout, track, vehicle, and support services requested by the user or customer. Legal basis: contract or pre-contractual measures.
- To maintain security, prevent abuse, debug failures, audit account activity, and protect the service. Legal basis: legitimate interest.
- To comply with accounting, tax, legal, and dispute-management obligations where a paid agreement or private payment flow is used. Legal basis: legal obligation, contract, and legitimate interest, depending on the record.
- To operate and secure trial requests, including Turnstile verification and repeat-request blocking. Legal basis: legitimate interest.
- To deliver the page correctly, including remote font loading. Legal basis: legitimate interest.
5. Whether providing the data is mandatory
Name, email address, and vehicle or workflow details are necessary to send and handle a trial request. Account credentials, license data, entitlement data, and technical session data are necessary to provide online account and license features. Report source files and report metadata are necessary only when the user chooses an online report-processing or PDF-storage workflow. Other setup details are optional but may be needed to provide custom configuration or support.
6. Recipients and service providers
- Cloudflare, for website hosting, Pages Functions, Turnstile verification, API delivery, security controls, and download or update delivery infrastructure.
- Supabase, for account, license, entitlement, report metadata, storage, and database infrastructure used by online account and report features.
- Reports API and processing infrastructure used to receive report jobs, process uploaded files, generate PDFs, and return report output.
- Resend, for email delivery of contact, trial, account, support, and fulfillment-related messages.
- Google, for remote loading of Google Fonts.
- Payment or invoicing providers used only for separately arranged private commercial flows, where applicable.
This public launcher page does not currently use analytics or marketing trackers based on the site code inspected for this service page.
7. International transfers
Some providers used to operate the website, account system, report processing, email delivery, payment, or support workflows may process data outside the European Economic Area. Where that happens, processing is expected to rely on adequacy decisions, Standard Contractual Clauses, or other contractual or legal transfer mechanisms made available by those providers.
8. Retention
Contact and trial submissions are kept for the time necessary to handle the request and related follow-up. Account, license, entitlement, and usage records are kept while the account or license remains active and afterwards for the time needed to support the service, resolve disputes, preserve evidence, or comply with legal obligations.
Uploaded source files used for online report generation are kept for the time needed to process the report, manage temporary upload cache, retry failures, or provide the requested report workflow. Stored PDFs remain available until deleted by the user or account administrator, replaced by retention limits, or removed during support or account closure. Report metadata, quota records, audit events, and deletion records may be kept longer than the files themselves where needed for usage accounting, security, support, or legal reasons.
Local desktop files and local caches remain under the user's device control unless sent through an online feature. Accounting, tax, and payment records are retained for the legally required period where a paid agreement exists.
9. Cookies and tracking
As currently configured, the public launcher page does not use analytics or marketing cookies and does not run analytics or advertising trackers in its page code. Online account features may use authentication, session, security, and local storage mechanisms that are necessary to keep users signed in, validate licenses, prevent abuse, or remember service state. If analytics, advertising, or other non-essential tracking is added, this policy and the consent setup should be updated before that tracking is enabled.
10. Local desktop storage
The packaged desktop app may store account sessions, tokens, validation cache, configuration, logos, report history references, and pending offline usage records on the user's device. The desktop app is designed to use operating-system secure storage for sensitive session data where available. Local report files are controlled by the user and are not uploaded unless the user chooses an online report, PDF storage, sync, or support workflow.
11. Automated checks
The service may automatically check license validity, account status, report allowance, permitted source entitlements, upload state, and processing status. These checks are used to operate the service and enforce access rules. The service does not use solely automated decision-making within the meaning of GDPR Article 22 for decisions producing legal or similarly significant effects.
12. Data subject rights
Subject to the conditions and limits of applicable law, data subjects may request access, rectification, erasure, restriction of processing, objection, and data portability where applicable.
13. Complaint right
If you believe your personal data has been processed unlawfully, you may lodge a complaint with the competent supervisory authority. In Italy, this is the Garante per la protezione dei dati personali.
14. Contact
Privacy requests or questions may be sent to [email protected].