Privacy Policy

What data we collect when you visit the site, use our services or contact us, why we use it and how you can exercise your rights.

Last updated: September 2, 2026

The commercial scope is B2B Italy only. Controlled payments are enabled for approved products, while anonymous public checkout, B2C, EU B2B and extra-EU B2B flows are not.

Controller and contact

The controller is MachineSignal. For privacy, support and operational requests, contact info@machinesignal.it.

Certified email: machinesignal@registerpec.it.

Who this policy covers

This policy applies to website visitors, B2B prospects, B2B customers, technical users of MachineSignal APIs and people who contact MachineSignal for support, billing or privacy requests.

MachineSignal Custom Services requests

When you submit the dedicated form, we process your company, contact name and role, business email, described need, desired outcome and, if provided, indicative volume, timing and budget range. We use this information to assess and respond to the free request on the basis of pre-contractual steps requested by the individual. The form does not automatically create an order, payment, invoice or contractual relationship.

At this stage we do not request files, credentials, special-category data or confidential documents. Requests that are not accepted or continued are retained for 90 days from receipt and then deleted. If the request becomes a project, the necessary data moves into the applicable pre-contractual and contractual records.

Data we may process

MachineSignal does not ask customers to send special-category data, health data, criminal offence data, data about minors, passwords, secret keys or full payment card data.

Purposes and legal bases

Purpose Legal basis
Provide the API service, manage accounts, packages and credits. Contract or pre-contractual steps.
Manage approved payments, invoices, credit notes and statutory records once those flows are enabled. Contract and legal obligation.
Security, anti-abuse controls, rate limits, fraud prevention and troubleshooting. Legitimate interest and security obligations.
Support, operational messages and privacy requests. Contract, pre-contractual steps, legal obligation or legitimate interest.
Reliability improvements using minimized technical logs. Legitimate interest, balanced against user rights.
Provide the free public-surface preview without creating an order, checkout, payment or commercial decision. Pre-contractual steps requested by the business user and legitimate interest, with transient domain processing and data minimization.
Understand aggregate machine demand and possible future B2B products using closed semantic fields held only in memory. These may include a self-declared coarse origin bucket (Italy, EU non-Italy, extra-EU or not declared), general business domain, action, object, desired output, current-product fit, urgency, recurrence and coarse budget band, including needs unrelated to current MachineSignal products. Foreign demand is research-only and does not enable commercial eligibility. No free text, buyer identity, fiscal/contact data, documents, payment data, raw payload or IP address is retained or used to infer geography for this purpose. Legitimate interest in improving and designing B2B services, with data minimization and no individual profiling.

Roles

MachineSignal is normally controller for account, billing, payment, security and service administration data. If a customer uses MachineSignal to process personal data on its own documented instructions, a separate data processing agreement may be required before that use case is enabled.

Service providers

MachineSignal may use providers for payment processing, billing, financial operations, hosting, API delivery, security, email, logging and AI/cloud processing. The operational stack includes Stripe for approved payment processing, Fatture in Cloud/TeamSystem for approved invoicing, Wise Business for financial operations, Register.it for domain/email services and DigitalOcean for hosting infrastructure. This disclosure does not enable anonymous public checkout, non-approved customer scopes or Wise payout by itself.

International transfers

If a provider processes data outside the European Economic Area, MachineSignal relies on the applicable transfer mechanism, such as an adequacy decision, Standard Contractual Clauses or another lawful safeguard.

Retention

Category Retention
Invoices, credit notes and accounting records. Legal accounting period, normally 10 years where applicable.
Orders, payments, credit ledger and billing reconciliation data. Legal accounting period or the period needed to protect legal rights.
Security, authentication and API metadata logs. Normally up to 12 months, unless a longer period is needed for security or legal reasons.
Raw debugging payloads. Normally 30 to 90 days, then deletion or minimization where possible.
DEC-250 and ACT-25 output files made available for customer download. 90 days after delivery, subject to a limited extension where needed for an open support request, dispute, security investigation or legal obligation.
Aggregate MCP demand counters, including bounded structured general-need signatures. In-memory only and reset on process restart; only closed categorical values are counted, general-need signatures are limited to 100 combinations per process, and raw requests are not retained.
Support communications. For the time needed to manage the request and protect legal rights.

Your rights

Subject to applicable law, individuals may request access, correction, deletion, restriction, objection and portability. Requests can be sent to info@machinesignal.it or, for certified communications, machinesignal@registerpec.it. Individuals may also lodge a complaint with the competent supervisory authority.

Automated decisions

MachineSignal produces B2B analytical outputs to support commercial prioritization. The outputs must not be used as the sole basis for decisions that produce legal or similarly significant effects on natural persons.

Security

MachineSignal applies proportionate security measures, including API key controls, idempotency, rate limits, provider separation, secret segregation, logging and abuse monitoring.

Updates

This policy may be updated when the service, providers, data flows, retention periods, countries served or commercial scope change.