Last updated: September 2, 2026
Controller and contact
The controller is MachineSignal. For privacy, support and operational requests, contact info@machinesignal.it.
Certified email: machinesignal@registerpec.it.
Who this policy covers
This policy applies to website visitors, B2B prospects, B2B customers, technical users of MachineSignal APIs and people who contact MachineSignal for support, billing or privacy requests.
MachineSignal Custom Services requests
When you submit the dedicated form, we process your company, contact name and role, business email, described need, desired outcome and, if provided, indicative volume, timing and budget range. We use this information to assess and respond to the free request on the basis of pre-contractual steps requested by the individual. The form does not automatically create an order, payment, invoice or contractual relationship.
At this stage we do not request files, credentials, special-category data or confidential documents. Requests that are not accepted or continued are retained for 90 days from receipt and then deleted. If the request becomes a project, the necessary data moves into the applicable pre-contractual and contractual records.
Data we may process
- Business contact and account data, such as company name, business email and billing identifiers.
- Order and payment metadata, such as product code, amount, currency, payment status and Stripe event ids, for approved checkout and payment flows.
- Billing data required for invoices, credit notes, reconciliation and statutory records.
- Continuation metadata for MS-ACT-25, such as hashed buyer identifier, source order and delivery references, entitlement id and the hash of the 25-record set.
- API metadata, such as endpoint, timestamp, request id, idempotency key, API key id, product code, credit balance and error state.
- Input and output data needed to provide the service, such as domains, company names, sector hints, scores and generated reports.
- For the free public-surface preview, one to three public company domains are processed transiently to inspect observable website signals. The preview service does not persist those submitted domains or include them in application logs.
- Security data, such as IP address, user agent, rate-limit events, authentication attempts and abuse signals.
- Support communications, including emails and operational messages.
MachineSignal does not ask customers to send special-category data, health data, criminal offence data, data about minors, passwords, secret keys or full payment card data.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide the API service, manage accounts, packages and credits. | Contract or pre-contractual steps. |
| Manage approved payments, invoices, credit notes and statutory records once those flows are enabled. | Contract and legal obligation. |
| Security, anti-abuse controls, rate limits, fraud prevention and troubleshooting. | Legitimate interest and security obligations. |
| Support, operational messages and privacy requests. | Contract, pre-contractual steps, legal obligation or legitimate interest. |
| Reliability improvements using minimized technical logs. | Legitimate interest, balanced against user rights. |
| Provide the free public-surface preview without creating an order, checkout, payment or commercial decision. | Pre-contractual steps requested by the business user and legitimate interest, with transient domain processing and data minimization. |
| Understand aggregate machine demand and possible future B2B products using closed semantic fields held only in memory. These may include a self-declared coarse origin bucket (Italy, EU non-Italy, extra-EU or not declared), general business domain, action, object, desired output, current-product fit, urgency, recurrence and coarse budget band, including needs unrelated to current MachineSignal products. Foreign demand is research-only and does not enable commercial eligibility. No free text, buyer identity, fiscal/contact data, documents, payment data, raw payload or IP address is retained or used to infer geography for this purpose. | Legitimate interest in improving and designing B2B services, with data minimization and no individual profiling. |
Roles
MachineSignal is normally controller for account, billing, payment, security and service administration data. If a customer uses MachineSignal to process personal data on its own documented instructions, a separate data processing agreement may be required before that use case is enabled.
Service providers
MachineSignal may use providers for payment processing, billing, financial operations, hosting, API delivery, security, email, logging and AI/cloud processing. The operational stack includes Stripe for approved payment processing, Fatture in Cloud/TeamSystem for approved invoicing, Wise Business for financial operations, Register.it for domain/email services and DigitalOcean for hosting infrastructure. This disclosure does not enable anonymous public checkout, non-approved customer scopes or Wise payout by itself.
International transfers
If a provider processes data outside the European Economic Area, MachineSignal relies on the applicable transfer mechanism, such as an adequacy decision, Standard Contractual Clauses or another lawful safeguard.
Retention
| Category | Retention |
|---|---|
| Invoices, credit notes and accounting records. | Legal accounting period, normally 10 years where applicable. |
| Orders, payments, credit ledger and billing reconciliation data. | Legal accounting period or the period needed to protect legal rights. |
| Security, authentication and API metadata logs. | Normally up to 12 months, unless a longer period is needed for security or legal reasons. |
| Raw debugging payloads. | Normally 30 to 90 days, then deletion or minimization where possible. |
| DEC-250 and ACT-25 output files made available for customer download. | 90 days after delivery, subject to a limited extension where needed for an open support request, dispute, security investigation or legal obligation. |
| Aggregate MCP demand counters, including bounded structured general-need signatures. | In-memory only and reset on process restart; only closed categorical values are counted, general-need signatures are limited to 100 combinations per process, and raw requests are not retained. |
| Support communications. | For the time needed to manage the request and protect legal rights. |
Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, objection and portability. Requests can be sent to info@machinesignal.it or, for certified communications, machinesignal@registerpec.it. Individuals may also lodge a complaint with the competent supervisory authority.
Automated decisions
MachineSignal produces B2B analytical outputs to support commercial prioritization. The outputs must not be used as the sole basis for decisions that produce legal or similarly significant effects on natural persons.
Security
MachineSignal applies proportionate security measures, including API key controls, idempotency, rate limits, provider separation, secret segregation, logging and abuse monitoring.
Updates
This policy may be updated when the service, providers, data flows, retention periods, countries served or commercial scope change.