Notice under Art. 13 GDPR · Cookie policy
Privacy & Cookies
No accounts, no cookies, no profiles. This site processes only two families of data: the technical minimum needed to run securely, and whatever you choose to send us when you write.
Last updated: 17 September 2026
Data controller
The data controller is the company below. For anything concerning your data, write to info@nok.business or via certified email (PEC).
No Data Protection Officer has been appointed: the appointment is not mandatory for the processing described on this page (Art. 37 GDPR). Your point of contact is info@nok.business.
What we process, why, and on which legal basis
- Browsing data — the hosting infrastructure's technical logs (IP address, request timestamp, user agent), needed to serve the site and keep it secure. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: the hosting provider's technical windows.
- Usage statistics, without cookies and without third parties — the counting is ours and stays on our own systems: no external analytics script is loaded by the site. The same counting applies to all our properties — this site, the design system at nok.business/design, the internal control room at nok.business/analytics and the group site at group.nok.business — and each property's numbers stay SEPARATE from the others: they can be read together, but they are never mixed. We measure page views, visits (pages opened in the same tab count as a single visit: that, and nothing else, is what the "nok-visita" entry described in the cookie policy is for), country, language, referring site, device type (phone or computer), how long a visit lasts and how far the page is scrolled, including time spent in each section of the story, which sections are reached and in which section the reading stops: we use this to understand which parts of the site work and which do not. We also record your device's LOCAL HOUR and DAY OF THE WEEK at the time of the visit — two whole numbers (0-23 and 0-6), not your time zone and not a precise time — so we know when the site is being read. We also measure the page's TECHNICAL PERFORMANCE on your device — loading times and responsiveness, the visual stability of what you read while it loads, scrolling fluidity (frames per second): these are durations of the machine, not of you, and they exist to keep the site usable on phones and slow connections. Finally we count the ACTIONS taken on the site, and only these four: the email address copied, writing started from the first screen, a project card opened (how many times, not which project) and a frequently asked question opened. For each one we keep how many times it happened, in how many visits it happened at least once, and in which section of the story it happened. They are overall totals ("project cards were opened 118 times"), never one person's sequence of gestures. These measure the CONTENT, not a person's behaviour: no individual journey is reconstructed or stored. To estimate how many distinct people visit us we use a statistical structure (HyperLogLog) that does NOT retain what it is given: your IP address only enters a temporary calculation, which changes daily, and is never written anywhere. No persistent identifiers; "Do Not Track" is honoured. These numbers describe no individual and cannot be traced back to anyone, not even by us. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: 100 days, after which counters delete themselves.
- Contact — if you write to info@nok.business we process your address, what you tell us and what is needed to reply. Legal basis: responding to your request and pre-contractual steps (Art. 6(1)(b) GDPR). Retention: up to 24 months after our last reply; if a contract follows, contractual records are kept for 10 years (Art. 2220 of the Italian Civil Code).
Providing data is optional: the site works without giving us anything. Without an address, we simply cannot reply.
Artificial intelligence: the transparency we practise
Artificial intelligence is our trade, and we use it ourselves first. This website was designed and developed with the aid of AI tools, under human direction, review and responsibility. We state this as a transparency choice, consistent with the principles of Regulation (EU) 2024/1689 (AI Act) and of Italian Law no. 132 of 23 September 2025.
When you contact us, the Company may process your data with the aid of AI systems, including AI agents: for instance to read and organise requests, draft replies, or analyse the needs you describe.
- Every decision affecting you remains human: no decision based solely on automated processing produces legal effects or similarly significant effects on you (Art. 22 GDPR).
- AI providers process data as processors (Art. 28 GDPR) or under contractual terms that exclude the use of your data for model training.
- AI systems receive only what each task requires (data minimisation, Art. 5(1)(c) GDPR).
There are no chatbots on this site, nor any system that interacts with you directly. If one day there are, you will be told there, before you use them, as required by Art. 50 of the AI Act.
Recipients and transfers outside the EU
Data may be processed on the Company's behalf by technical service providers: the hosting, delivery and counter-storage infrastructure (Vercel), email providers and providers of artificial-intelligence systems. They act as processors under Art. 28 GDPR or, within their own technical remit, as independent controllers. No dissemination, no sale to third parties for marketing.
Some providers are established in third countries, notably the United States: transfers rely on Arts. 44 et seq. GDPR — the European Commission adequacy decision of 10 July 2023 (EU-U.S. Data Privacy Framework) for certified providers, or standard contractual clauses under Art. 46 GDPR.
Your rights
You may at any time exercise the rights under Arts. 15-21 GDPR: access, rectification, erasure, restriction, portability, objection. Write to info@nok.business: we reply within one month (Art. 12(3) GDPR).
If you believe a processing operation infringes the law, you may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), under Art. 77 GDPR, or apply to the courts.
Updates to this notice
Any substantial change will be published on this page, with the update date at the top. The version you are reading is the one in force.