Privacy Policy
Information pursuant to art. 13 GDPR and the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018).
Controller
Gruber Evi, Via Gaudententurm 12, 39020 Parcines (BZ), Italy
VAT ID IT03066110218 · info@smartcms.ai
No data protection officer has been appointed; appointment is not mandatory for this processing.
What we process, and why
- Contact and access enquiries — name, email address and message. We store access requests and their review, invitation and activation history in SmartCMS. Authorized platform administrators use these details to review access. We send notifications and invitations through Resend. The form itself does not create an account or subscribe you to marketing emails. Your organization and first space are created when you accept an approved invitation and complete setup. Declined or revoked requests are deleted after 90 days, unanswered requests after 12 months; activated requests are retained, but their message is erased after 30 days.
- Account data — email address, name, password hash, verification status. To create and operate your account. Art. 6(1)(b) GDPR (performance of a contract).
- Content you create — entries, media, schemas and everything else you store in a space. To provide the service. Art. 6(1)(b).
- Billing data — plan, subscription status, Stripe customer and subscription identifiers. Card details are handled by Stripe and never reach our servers. Art. 6(1)(b) and 6(1)(c) (statutory retention).
- Server and audit logs — IP address, timestamp, request path, and an audit trail of changes made in the CMS. To operate the service securely and to reconstruct who changed what. Art. 6(1)(f) (legitimate interest in security and traceability).
- Usage statistics — aggregate page views and aggregate interaction events (for example, clicking the product demo or the access request form) via our self-hosted Umami instance, without cookies and without personal data or cross-site tracking. Art. 6(1)(f).
Recipients
We use the following processors. Those outside the EU receive data on the basis of the European Commission’s standard contractual clauses.
| Recipient | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server, database, cache | Falkenstein, Germany |
| Microsoft (Azure Blob Storage) | Media and file storage | Germany West Central |
| BunnyWay d.o.o. (bunny.net) | CDN delivery, image optimisation | Slovenia; global edge cache |
| Fly.io | Runtime for generated app previews | Frankfurt (fra) |
| Stripe Payments Europe, Ltd. | Payment processing, invoicing | Ireland; onward transfer to Stripe, Inc. (USA) ⚠ |
| Resend | Transactional email (verification, password reset, access enquiries) | USA ⚠ |
| Together AI | AI text, image description and image generation — through smartcms's account (included allowance) or your own key | USA ⚠ |
| Anthropic | AI text generation and App Builder — through smartcms's account (App Builder allowance) or your own key | USA ⚠ |
| OpenAI | AI text generation, only with your own key | USA ⚠ |
| AI text and image generation, only with your own key | USA ⚠ |
Error monitoring (Sentry) and usage statistics (Umami) run on our own infrastructure and are not third-party recipients.
AI features and your content
When you use an AI feature, the content you submit for that operation is sent to the AI provider selected for your space (see the table above). Those providers are located in the United States. AI features are optional: if you do not use them, no content is sent to them.
If your space has no own key for the selected provider, smartcms sends the content of that operation to Together AI (CMS AI features) or Anthropic (App Builder) under smartcms’s own provider account, as our processor. We record usage metadata (feature, model, token counts, cost) per space to enforce the allowance; the content itself is not stored for this purpose.
Retention
Account and content data are kept for as long as your account exists and are deleted when you delete your organisation. Billing records are kept for the statutory retention period under Italian law. Server logs are kept for a short operational period; audit records are kept for the lifetime of the space they belong to.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection under art. 15–21 GDPR, and the right to withdraw consent at any time. Write to info@smartcms.ai. You may also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.