Legal · last updated 20 August 2026
This page explains what personal data timbaly.com collects, why, on what legal basis, how long it is kept and how to exercise your rights under the EU General Data Protection Regulation (Regulation 2016/679, “GDPR”).
The short version: this website collects what you send us through the contact form, plus first-party analytics about page visits. There are no advertising trackers, no data brokers and no third-party fonts.
Contents
The controller of the personal data processed through this website is Innovazione su Misura di Catana Petronela, registered office at Via Val Della Torre 81, 10149 Torino (TO), Italy, VAT number 12533670019.
Contact for any privacy matter: info@timbaly.com.
No Data Protection Officer has been appointed, as the processing carried out does not meet the criteria of art. 37 GDPR.
Through the contact form: your name, email address, optionally your business or website, the subject you select, and the content of your message. Also the fact and time of your consent to this policy, which we must be able to demonstrate.
If you write to us directly by email, we process the contents of that email and your address.
First-party analytics record page visits: the page URL, referrer, approximate date and time, browser and device type, language and, where a campaign link was used, the UTM parameters. Aggregate visit counting operates without cookies. Session-level information is held in your browser's sessionStorage under keys beginning aicms_ and disappears when you close the tab.
Your IP address is processed transiently by the web server to deliver the page and in security logs. It is not used to build a profile of you.
If the cookie banner is shown to you, your choice is stored in a cookie named aicms_cc for six months, so that you are not asked again on every page. The cookie policy lists it in full.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Replying to your enquiry | Form fields, message content | Art. 6(1)(a) — your consent, given with the checkbox |
| Proving consent was given | Consent flag, timestamp | Art. 6(1)(c) — legal obligation |
| Understanding how the site is used | Aggregate and session analytics | Art. 6(1)(f) — legitimate interest in improving the site |
| Keeping the site available and secure | Server and security logs, IP | Art. 6(1)(f) — legitimate interest in security |
| Remembering your cookie choice | aicms_cc cookie | Strictly necessary — and art. 6(1)(c) |
Providing the form data is voluntary, but without a name, an email address and a message we cannot reply to you.
We do not use your data for advertising, we do not sell or share it with data brokers, and we do not carry out automated decision-making or profiling that produces legal effects concerning you.
Only the people and providers who need to:
Fonts used on this site are downloaded and served from our own domain rather than loaded from Google Fonts, precisely so that no request — and therefore no IP address — reaches a third party while you read a page.
This section applies only if you hold a Timbaly account and choose to connect a Google account to it, so that the platform can create and read your Google Search Console property. Visiting this website does not involve any of it.
You start the connection, and Google shows you a consent screen listing exactly what is being asked. Timbaly requests three permissions:
webmasters — create the Search Console property for your domain, declare the sitemap, and read your search performance figures: clicks, impressions, CTR, average position, indexing state.siteverification — verify that the domain is yours, using the verification meta tag the platform writes into the head of your site.userinfo.email — read the email address of the connected account, so the panel can show you which one it is.What we store: the OAuth access and refresh tokens, encrypted at rest; the email address of the connected account; and the search performance figures the API returns, attached to your site.
What we do with it: we display it in your panel and use it to run the audit and the editorial plan for your own site. What we never do: we do not use Google user data to train AI models, we do not sell it, we do not use it for advertising, and we do not disclose it to anyone other than the infrastructure providers processing on our behalf under art. 28 GDPR.
Timbaly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long, and how to stop it: tokens are kept until you disconnect or revoke them; the search performance figures are kept while the site is active on the platform and are deleted with the site. You can disconnect at any time from Settings → Search visibility, which revokes the token and removes the verification tag, or revoke access directly at myaccount.google.com/permissions. The Search Console property itself stays in your Google account: it always was yours.
The legal basis is art. 6(1)(b) GDPR — the processing is necessary to provide the feature you asked for.
Processing takes place within the European Economic Area. Where a provider processes data outside the EEA, the transfer is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses under art. 46 GDPR, with supplementary measures where required.
Under arts. 15–22 GDPR you have the right to access your data, to have it rectified or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time — withdrawal does not affect the lawfulness of processing already carried out.
To exercise any of them, write to info@timbaly.com. We reply without undue delay and within one month, extendable by two further months for complex requests, in which case we will tell you.
You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it) — or with the authority of your habitual residence.
The site is served over HTTPS. Access to the administration area requires authentication, passwords are stored hashed, and credentials held on behalf of customers are encrypted at rest. Access to personal data is limited to those who need it. No measure makes a system perfectly secure, and we do not claim otherwise; if a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.
If this policy changes materially, the date at the top of the page changes with it and, where the change concerns processing based on your consent, we will ask for consent again. The current version is always the one published here.
This page was drafted from a fixed template rather than generated freely, deliberately: a retention period invented by a language model is not a policy, it is an exposure. It still needs one review by a qualified lawyer before you rely on it.