Privacy Policy
Last updated: 6 October 2026
1. Data Controller
The Data Controller is Matteo Sacco, email: mailalertsaas+privacy@gmail.com (hereinafter, “Controller” or “we”).
2. Categories of Personal Data Collected
In connection with the use of the Nexalarm service, we collect the following categories of data:
- Registration and account data: full name, email address, company name. Authentication is managed by Supabase Auth: passwords never transit through our application servers.
- Service configuration data: IMAP credentials of the monitoring email account (stored encrypted using hybrid RSA-4096 + AES-256-GCM encryption), polling intervals, email filters.
- Managed client data: client name, client code, address, phone numbers, email, subscription dates entered by the user into the platform.
- Alarm data: content of alarm emails received from the security system, alarm type, date and time, sender.
- Technical and browsing data: IP address, browser type, operating system, access logs, session tokens.
3. Purposes and Legal Basis for Processing
a) Service delivery and contract performance
Managing user accounts, authentication, platform operation, alarm email monitoring, notifications.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
b) Security and fraud prevention
Protecting the platform from unauthorized access, retaining access logs for security audits.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
c) Legal obligations
Compliance with applicable tax, accounting, and legal obligations.
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
4. Processing Methods and Security
Processing is carried out using electronic and automated tools. We implement appropriate technical and organizational measures to ensure data security, including:
- Authentication and session management delegated to Supabase Auth (OAuth2, signed JWTs, secure client-side storage)
- IMAP credentials encryption with hybrid RSA-4096 + AES-256-GCM (private key stored exclusively on the worker server, never exposed to the web application)
- Encrypted communications via HTTPS/TLS
- Role-based access control (OWNER / ADMIN / OPERATOR)
- Row-Level Security (RLS) enabled on all database tables
5. Data Retention Periods
- Account data: for the duration of the contract and for 10 years following termination (fiscal and accounting obligations).
- Alarm data and email logs: for 12 months from the event, unless otherwise configured or required by law.
- Access and security logs: for 12 months from recording.
- Managed client data: for the duration of the contract; deleted within 30 days of termination upon request.
6. Recipients and International Transfers
Personal data may be disclosed, to the extent strictly necessary, to:
- Cloud infrastructure, hosting, database and email providers (Supabase for database and authentication, Netlify for hosting the website and the application, Resend for service emails) acting as Data Processors under Art. 28 GDPR, with appropriate contractual safeguards.
- Competent authorities, where required by law.
Data may be transferred outside the EU/EEA only in the presence of appropriate safeguards (European Commission adequacy decision, standard contractual clauses, or other GDPR-compliant mechanism).
7. Data Subject Rights (Arts. 15–22 GDPR)
Users have the right to:
- Access their personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (“right to be forgotten”, Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
- Withdrawal of consent, where applicable, without affecting the lawfulness of prior processing
To exercise these rights, contact the Controller at the email address in § 1. Users also have the right to lodge a complaint with the competent supervisory authority.
8. Cookies
This site uses strictly necessary technical cookies for the operation of the service. For detailed information, please consult our Cookie Policy.
9. Changes to This Policy
The Controller reserves the right to modify this policy at any time. Changes will be communicated by updating the date below and, where deemed necessary, by direct notification to users.