Privacy Policy

Last Updated: August 2026

Reference Language and Translations: This Privacy Policy is available in multiple languages for the convenience and transparency of our global users. Translated versions are provided to facilitate understanding; however, in the event of conflicts, interpretative discrepancies, or inconsistencies between the translations and the original texts, the Italian and English versions (the official project management languages) shall prevail and serve as the primary basis for the legal interpretation of these terms, to the maximum extent permitted by local consumer protection laws.

1. Data Controller and Contact Information

The Data Controller for the personal data collected through this website (mybusinesscard.digital) is Pellegrini Marco, residing in Bergamo, Italy. This website is an independent and personal project currently offered entirely free of charge. For any inquiries regarding data protection, erasure, or to exercise your rights, you can contact the Data Controller directly at the dedicated email address: privacy(at)mybusinesscard(dot)digital (replace (at) with @ and (dot) with .).

2. Data Collected, Legal Basis, and Public Nature of Content

We only collect essential information voluntarily provided during registration and personalization of your digital business card. This includes: your registration email address and, for your digital card (only if you choose to include them): first and last name, headings/titles, professional role, physical address, website links, custom links, personal descriptions, embedded YouTube video links, profile picture, cover images, gallery images, phone numbers, and social media links.

  • Legal Basis for Processing and Explicit Free Service: The processing of personal data provided during the registration phase is based on the performance of a contract or pre-contractual measures (Art. 6, para. 1, b of the GDPR). Transparency note for the user: the creation, management, and hosting of your business card are services provided completely free of charge. The term "contract" or "contractual relationship" is used solely for terminology compliance with the GDPR, which classifies the provision of zero-cost web services under contractual agreements.
  • Security and System Logs: The storage of server log files and IP addresses is based on the legitimate interest of the Data Controller (Art. 6, para. 1, f of the GDPR) to ensure the security, integrity, and proper functioning of the platform (prevention of fraud, spam, and cyberattacks). These logs are retained for a maximum period of 12 months and are kept strictly separate from your user profile.
  • Public Nature of the Data: By personalizing your digital business card, you acknowledge and agree that all information entered into the profile fields is, by definition, public and accessible to anyone who visits your unique URL or scans the generated QR code. The platform is not responsible for any third-party use of information that you have voluntarily disclosed to the public.

3. Data Retention, Hosting, and International Data Transfers

All alphanumeric data (texts, credentials, and emails) are securely stored on physical servers located within the European Union, hosted by the provider Netsons S.r.l. in Italy.

To ensure high performance and fast loading times globally, media files (photos and images) are distributed and cached through the Cloudflare R2 Object Storage infrastructure. Media files may transit through or be temporarily cached in Cloudflare data centers located outside the European Union. Such transfers are carried out in full compliance with the GDPR (Chapter V), as Cloudflare guarantees equivalent protection standards through the adoption of Standard Contractual Clauses (SCCs) approved by the European Commission and its adherence to the EU-U.S. Data Privacy Framework where applicable.

4. Extraordinary Corporate Actions and Business Transfer (Assignment or Sale)

Users' personal data is never sold, rented, or disclosed to third-party marketing agencies for commercial or external advertising purposes.

The user acknowledges and expressly agrees that, in the event of extraordinary corporate or project transactions — such as, but not limited to, a merger, acquisition, sale of business, reorganization, or full sale of the platform and business branch (including source code, trademark, domain, and full technological infrastructure) — the database containing the data and profiles of registered users may be transferred to the third-party buyer or successor. Such transfer will occur exclusively to ensure the operational continuity of the service or for the legitimate monetization of the project. The new buyer will be legally bound to process the data in compliance with this privacy policy and applicable data protection laws (GDPR). In any case, if the user does not wish for their data to be transferred to the new operator, they retain the right to exercise their right to immediate deletion and free withdrawal at any time via the dedicated functions within the platform, before the transfer becomes effective.

5. User Rights, Deletion Procedure, and Guest Data

  • User Rights (EU and Non-EU): For users residing within the European Union, the rights set forth in Articles 15-22 of the GDPR are fully guaranteed (access, rectification, restriction, objection, data portability, and erasure). For users accessing the service from territories outside the European Union, the Administrator extends the same high standards of protection and recognizes the exercise of fundamental privacy rights in accordance with applicable local regulations.
  • Right to Lodge a Complaint (EU Users): European users have the right to lodge a formal complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali - www.garanteprivacy.it) or with the supervisory authority of the EU Member State where they habitually reside.
  • Guest Data: If you use the dashboard as a guest without registering, all entered data is temporary and is automatically and irreversibly deleted from the server every 24 hours via an automated process (cronjob).
  • Secure Deletion Procedure: Registered users can independently delete their account at any time. To complete the operation, the user must follow the guided procedure within the control dashboard. Upon completion of the verification required by the system, the public profile, credentials, and all associated media files will be permanently and irreversibly removed from live production systems. Alternatively, the user can request permanent deletion by writing directly to: privacy(at)mybusinesscard(dot)digital. In this case, the Data Controller will proceed with the manual removal of data within the necessary technical timeframes and, in any event, within the deadlines prescribed by the GDPR.