Privacy notice
Version 5 — 4 September 2026
This is the English version. Versione italiana — the two are equivalent; in relationships governed by Italian law the Italian text prevails.
This page explains what happens to the email address you leave in order to open the preview of the map of authorized BESS projects. It is provided pursuant to art. 13 of Regulation (EU) 2016/679 (GDPR).
Who processes your data
The data controller is PLUTEO S.r.l., Via A. De Gasperi 82, 62010 Mogliano (MC), Italy, tax code and VAT no. 02109050431. MACSE.IT is a Pluteo brand. To exercise your rights, or for any request, write to privacy@pluteo.io. We have not appointed a Data Protection Officer.
How the preview works
The preview opens once only per email address and stays accessible for 30 minutes. It is there to show what the data looks like. Once the window closes, the preview does not reopen with the same address.
Some people reach the map instead through a direct invitation link we send them. In that case no email address is involved at any point: the link itself carries the authorization, and we ask you for nothing.
What data we process
We process your email address and the choice you make on the updates checkbox. We do not ask for your name, company or anything else, and we use no analytics or profiling tools.
Our hosting and email delivery providers may process the technical connection data strictly necessary to deliver and protect the service — including the IP address — according to their respective configurations.
To keep the preview from being abused we also keep, on our own infrastructure, a cryptographic fingerprint of the IP address the request comes from, together with the hour in which it was made. We do not keep the IP address itself in clear. The fingerprint is computed one-way with a separate key and is used for one thing only: capping how many previews can be opened from the same connection within one hour. It is a pseudonymised identifier, not an anonymous one — within the retention window it lets us recognise the same connection, and nothing else. You can object to this processing at any time by writing to privacy@pluteo.io; we will stop unless there are compelling legitimate grounds, which is the case for requests that are themselves abusive.
For what purposes, and on what legal basis
- To open the preview for you. Legal basis: the performance of measures taken at your request (art. 6.1.b GDPR). Providing the address is mandatory: without it we cannot open the preview.
- To enforce the limit of one preview per address. Legal basis: our legitimate interest in distributing in a controlled way content we offer as a trial (art. 6.1.f GDPR). How we do this is explained below.
- To prevent automated abuse and protect fair availability of the preview and of the service. In practice: stopping a single connection from using up other people’s addresses in bulk. Legal basis: our legitimate interest (art. 6.1.f GDPR). You may object at any time.
- To send you updates and communications about our services. Legal basis: your consent (arts. 6.1.a and 7 GDPR; art. 130 of the Italian Privacy Code). Providing it is optional: if you do not tick the box the preview opens anyway and your address is not recorded in any list.
How the one-preview limit works
To know whether an address has already used its preview we do not keep the address: we keep a cryptographic fingerprint of it, that is, a string computed one-way, from which the original address cannot be recovered and no readable address can be derived. The fingerprint only serves to answer the question “has this address already been through?”. It cannot be used to write to you, it is not linked to any other data and it is not disclosed to anyone.
Since the limit is permanent, the fingerprint is kept for an indefinite period. If you would rather have it removed you can ask us at privacy@pluteo.io; you may also object at any time to this processing, which is based on a legitimate interest.
The one cookie
When the preview opens we write a single cookie, first-party, called bm. It
contains the moment at which access expires and a signature that lets us verify it has not been
altered. It contains neither your email address nor a reusable identifier, and it is not
used for analytics, profiling or marketing.
It is a technical cookie, necessary to deliver the service you expressly requested: for this reason it is not subject to consent (art. 122 of the Italian Privacy Code) and you will not find a banner. It expires automatically after 30 minutes — or after 8 hours if you reached the map through an invitation link, so that a working session need not be reopened; in that case too it holds no identifier. You can delete it at any time from your browser settings: you will only lose the session in progress. We use no other cookies.
Who we share the data with
We do not sell and do not transfer your address. It may be processed on our behalf, by processors appointed pursuant to art. 28 GDPR, by parties in the following categories:
- the site’s hosting and delivery provider (currently Netlify);
- the email delivery platform provider (currently Brevo), to whom your address is disclosed only if you have ticked the updates box.
Some providers may process data outside the European Economic Area. In that case the transfer takes place on the basis of the mechanism applicable from time to time — an adequacy decision or the European Commission’s Standard Contractual Clauses, with any supplementary measures. You can ask us for the up-to-date list of providers and a copy of the safeguards applied by writing to privacy@pluteo.io.
How long we keep it
- If you did not tick the box: your address is not recorded in any list. Only the fingerprint described above remains.
- If you did tick the box: we keep the address for 24 months from consent. At expiry we delete it, or we ask you for fresh consent before continuing.
- IP fingerprints for the hourly cap: kept in hourly buckets and erased by an hourly clean-up, so two hours at most. They are not linked to your address or to any other data, and are never used for anything but the cap.
- Proof of consent and deletion requests: kept separately and with restricted access for as long as necessary to demonstrate that we acted correctly and not to contact you again; they are not used for marketing purposes.
Your rights
In the cases provided for by arts. 15-22 GDPR you can ask us to access your data, to correct it, to erase it, to restrict its processing, to receive it in a machine-readable format and to object to the processing. Write to privacy@pluteo.io: we reply within one month.
On marketing you always have the last word: you can withdraw your consent at any time, free of charge and without formalities, using the unsubscribe link at the bottom of each of our messages. Withdrawal does not affect the lawfulness of previous sendings.
If you believe the processing of your data infringes the law you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (garanteprivacy.it), Piazza Venezia 11, 00187 Rome, Italy.
Automated decision-making
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not carry out profiling.