Metrika Research / Legal information

Privacy notice

How we handle information when you visit this site or send an enquiry. Last updated: 26 September 2026.

Who is responsible for your data

The data controller is METRIKA RESEARCH DI ALBERTO ANDOLFATTO (sole trader), whose registered office is at Via San Nicola 5, 36022 Cassola (VI), Italia, VAT number 04604740243. For privacy questions or to exercise your rights, email info@metrikaresearch.com.

This notice covers this Metrika Research website and its contact form. A subsequent professional engagement may require separate information about the processing needed to provide that service.

Information we receive

When you use the form, we receive your full name, email address, selected topic and enquiry text. Your company is optional. The system associates the page language, receipt date and time, and a unique reference with your enquiry.

The server also stores a cryptographic digest of the submitted fields to recognise a retry of the same enquiry. This checks for duplicates; it is not a device fingerprint and is not used to track browsing.

The form does not accept attachments. Include only information relevant to your enquiry. Do not send passwords, access credentials, health information, payment-card details or confidential information about other people.

Connecting to the site involves technical data processed by the hosting infrastructure, such as your IP address and web-request information. Providers may process logs, device information and security events to operate and protect the service. Our application does not store IP addresses, user agents or browsing history in the enquiries database, and does not write message contents to its application logs.

Why we use it and our legal bases

We use your information to read your enquiry, understand its context and contact you. Where you request steps before entering a contract to which you would be a party, the necessary processing is based on Article 6(1)(b) GDPR. For general enquiries and communications with people acting for a company, we rely on our legitimate interest in handling professional communications and the enquiries we receive, under Article 6(1)(f).

Field validation, duplicate recognition and limits on repeated submissions help keep the form reliable and prevent abuse. We rely on our legitimate interest in the security and continuity of the service, under Article 6(1)(f). Application limits use the email address and submission time without building an advertising profile.

Submitting the form does not subscribe you to a newsletter or promotional campaign. We do not use it for commercial profiling, automated lead scoring or decisions with legal or similarly significant effects. The form does not send your enquiry to AI models to generate a response or score it.

What you need to provide

Contacting us is your choice. Your name, email and message are needed to receive and handle an enquiry through the form; submission cannot be completed without them. The topic provides context. You may leave the company field blank.

The reference shown after a successful submission confirms that the enquiry was recorded. The internal Microsoft 365 notification is a subsequent operational step and may be retried after an error; the confirmation does not mean the enquiry has already been read or that a contract has been agreed.

Who can access the information

Enquiries are intended for people authorised by the controller to handle them. They are not published on the site, and no public message list is available. We use Cloudflare Workers and Cloudflare D1 directly to deliver the website and store enquiries.

Cloudflare processes information hosted on our behalf under the applicable service agreements and its Data Processing Addendum. The suppliers involved are identified in Cloudflare's sub-processor list. Data may also be disclosed to authorities where a legal obligation requires it.

After the enquiry is recorded in the database, the system sends an operational notification to info@metrikaresearch.com through Microsoft 365 and Microsoft Graph. The notification contains the enquiry information needed to handle it and allows a reply to the email address supplied in the form. Microsoft processes this information within Microsoft 365 under the applicable agreements and the Microsoft Products and Services Data Protection Addendum. If the email service does not accept the notification, the enquiry remains stored in D1 and the system retries delivery; the confirmation displayed on the site confirms storage, not that we have read the enquiry.

Hosting and international transfers

Cloudflare uses international infrastructure to deliver and protect its services. A database's location does not imply that every processing activity involving connections, support or security takes place in the same territory. We do not present this site as a service with all processing confined to Italy or the European Union.

Transfers outside the European Economic Area are subject to the safeguards in the applicable agreements, including adequacy decisions and standard contractual clauses where relevant. Hosting terms are described in Cloudflare's DPA; Microsoft 365 notification processing is covered by the Microsoft DPA. You may contact us for information about applicable safeguards and how to obtain a copy.

How long we keep it

Enquiries are retained in the operational database for 12 months from submission. Scheduled periodic operations remove expired records even when nobody visits the website. Errors or a backlog can delay completion, and these operations require monitoring. Expired enquiries are not reused for new contact.

If an engagement follows, information needed for that relationship may be retained separately for its purposes and applicable obligations. Retention necessary for a specific legal duty is based on Article 6(1)(c); retention necessary to establish, exercise or defend a legal claim is based on the legitimate interest in protecting that right, under Article 6(1)(f). It is limited to relevant information and the period needed.

Infrastructure logs and any backup copies follow the provider's retention periods and procedures. These are distinct from the retention period for enquiries in the operational database. Contact us at the address above for clarification about these categories.

Your rights

Where the GDPR provides, you may request access, correction, deletion or restriction of your personal data. You may object to processing based on legitimate interests for reasons relating to your situation. Data portability applies under its legal conditions, in particular to data you provide that is processed by automated means on the basis of consent or a contract.

Send your request to info@metrikaresearch.com. Where needed, we may ask for only the information necessary to verify your identity. We respond without undue delay and normally within one month; we will explain any extension permitted by law and its reasons.

You may complain to the Italian Garante per la protezione dei dati personali or another competent supervisory authority. The General Data Protection Regulation explains these rights and their conditions.

Cookies and updates

Our cookie notice explains the technologies used while browsing. Our application does not use advertising cookies or behavioural analytics services.

We update this notice when the processing described changes. The date above identifies the published version. Before using data for another purpose, we will provide the information required by law.