u
Privacy Policy

Privacy Policy

Last updated: May 2026

1. Data Controller

kiricù, Milan. Email: hello@kiricu.com

For any questions regarding the processing of your personal data, you can write to the email address above.

A Data Protection Officer (DPO) has not been appointed, as the conditions set out in Article 37 of the GDPR are not met.

2. What data we collect

2.1 Data provided voluntarily through the contact form

We collect the data you provide by filling out the contact form on the website. In particular:

Name (mandatory)
Email address (mandatory)
Company or activity name (mandatory)
Website (optional)
Type of video requested (mandatory)
Indicative budget (mandatory)
Project timeline (optional)
Project description, free text (optional)

The provision of name, email address, company or activity name, video type, and indicative budget is necessary for us to reply to you: without these data, we will not be able to process your request. The other fields are optional and only serve to better frame the project.

We do not collect sensitive data (data related to health, political, religious, or sexual orientation).

2.2 Navigation data and technical logs

For reasons of security, abuse prevention, and the proper functioning of the site, our infrastructure provider (Cloudflare) automatically collects some technical data, including IP address, user agent, date and time of the request, and visited pages. These data are processed for security, anti-bot, anti-DDoS, and diagnostic purposes.

Legal basis: legitimate interest of the data controller to ensure the security and availability of the site (Art. 6, para. 1, let. f of the GDPR).

3. Why we collect your data (purposes and legal basis)

The data provided through the contact form are processed exclusively to respond to your request and evaluate a possible collaboration.

Legal basis: execution of pre-contractual measures adopted at the request of the data subject (Art. 6, para. 1, let. b of the GDPR).

Navigation data and technical logs are processed for IT security and site operation purposes, based on the legitimate interest of the data controller (Art. 6, para. 1, let. f of the GDPR).

We do not use your data for marketing, profiling, or newsletter purposes without your explicit consent.

4. How we use your data

We read your data to reply within 48 working hours
We do not sell your data to third parties
We do not transfer your data to third parties for commercial purposes
We do not use automated profiling or decision-making systems

5. Data processors (third-party providers)

For the proper functioning of the site, we rely on the following providers, who process your data on our behalf as data processors:

Formspree, Inc. Form management service provider. Headquarters: Austin, Texas, USA. Privacy Policy: formspree.io/legal/privacy-policy

Cloudflare, Inc. Hosting/CDN, DNS, security (anti-bot, anti-DDoS), and privacy-first analytics provider. Headquarters: San Francisco, California, USA. Privacy Policy: cloudflare.com/privacypolicy

Extra-EU Transfers

Both providers are located in the United States. Data transfer occurs based on the EU-US Data Privacy Framework (DPF) adequacy decision adopted by the European Commission on July 10, 2023, and, subordinately, based on the Standard Contractual Clauses (SCC) approved by the European Commission.

6. Cookies and tracking technologies

This site uses Cloudflare Web Analytics, a traffic analysis tool that does not use cookies and does not track individual users. No personal data is collected for analytical purposes.

The only cookie potentially set is the technical cookie __cf_bm by Cloudflare, used for Bot Management and security purposes, lasting 30 minutes. As a cookie strictly necessary for the functioning and security of the site, it does not require user consent under Art. 122 of the Privacy Code and the Guarantor's Guidelines on cookies.

We do not use Google Analytics, Meta Pixel, or other tracking tools based on profiling cookies. Therefore, a cookie banner is not required.

7. How long we keep your data

We keep the data collected through the contact form for the time strictly necessary to manage your request, and in any case no longer than 12 months from receipt of the form, unless a contractual relationship is established (in which case the legal terms for the retention of accounting and tax documents apply, generally 10 years).

Technical and security logs managed by Cloudflare are kept for the times indicated in the provider's privacy policy, generally no longer than necessary for security purposes.

You can request the deletion of your data at any time by writing to hello@kiricu.com.

8. Data security

We adopt appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 of the GDPR. In particular:

the site is served exclusively via HTTPS (TLS encrypted connection)
access to data collected via the form is limited to the data controller and those operating under their direct authority
the providers used (Formspree, Cloudflare) adopt internationally recognized security standards
no personal data beyond what is strictly necessary is stored locally on the site

9. Your rights

As a data subject, you have the right to:

Access — obtain confirmation of the processing and a copy of your data
Rectification — correct inaccurate or incomplete data
Erasure — obtain the removal of your data ("right to be forgotten")
Restriction — request the suspension of processing in certain cases
Portability — receive your data in a structured and machine-readable format
Objection — object to the processing at any time, in particular when based on legitimate interest
Withdrawal of consent — withdraw any given consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7, para. 3 of the GDPR)

To exercise these rights, write to: hello@kiricu.com

We will reply to your request within one month of receipt, optionally extendable by a further two months in case of particular complexity, giving you notice.

You also have the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).

10. Minors

The site is not intended for minors under 14, and we do not knowingly collect personal data from minors. If we become aware of having collected personal data from a minor without a valid legal basis, we will promptly delete it.

11. Changes to this policy

This Privacy Policy may be updated periodically. In case of substantial changes, we will update the date at the top of the document. We encourage you to review it periodically.

Kiricù is a video advertising studio based in Milan. This Privacy Policy is drafted pursuant to EU Regulation 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.