Skip to content
CognitiveLogic
Framework Ecosystem AI Engine Demo
IT · EN
← Home
Legal document · GDPR

Privacy Policy

Last updated: July 2026 · Version 1.1

This notice describes how personal data of visitors to cognitivelogic.it is collected, used and protected, under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code) as amended by Legislative Decree 101/2018.

Data controller
Roberto Bob Malini — Cognitive Logic
Bologna (BO), Italy
Privacy contact
info@cognitivelogic.it
Applicable law
EU Reg. 2016/679 (GDPR) · Legislative Decree 196/2003 · Legislative Decree 101/2018

1. Data collected and purposes

1.1 Browsing data

The computer systems and software procedures used to operate this site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.

This category includes: IP addresses, browser type, operating system, provider domain name, request time, page visited. This data is kept in server logs for a maximum of 30 days and used exclusively to derive anonymous statistical information and to check that the site is working correctly.

1.2 Voluntarily provided data

If a user sends an email to the addresses shown on the site, the data necessary to respond to the request is collected (name, email address, message content). This data is not transferred to third parties and is kept for the time strictly necessary to handle the communication, in any case no longer than 24 months from the last contact.

1.3 Data sent to AI analysis tools

Some pages on the site (compliance auditor, prompt generator, QEN score widget, and the /agents/* endpoints that power them) allow free text or structured data to be submitted (e.g. the name of the entity being analysed, risk level, the content of a compliance request) in order to obtain an analysis generated by a third-party AI model (Anthropic Claude, Google Gemini or Mistral AI depending on the tool). This data is transmitted to the model provider to generate the response and is not used for purposes other than the one requested by the user. Some tools (qen-balneare-auditor.html, qen-horeca-auditor.html) instead compute the QEN score via a deterministic client-side formula, with no data sent to any AI model: in that case, the data sent to the server is only used to save the result in the project's public Knowledge Graph.

1.4 Cookies and tracking technologies

See the Cookie Policy for full details of the cookies used and consent options.

2. Legal basis for processing

Purpose Legal basis GDPR Art.
Delivery of the web service Legitimate interest of the controller Art. 6(1)(f)
Responding to email requests Performance of pre-contractual measures / legitimate interest Art. 6(1)(b)(f)
Sending data to AI analysis tools (agent endpoints) Explicit user consent, given by submitting the request Art. 6(1)(a)
Saving QEN results to the public Knowledge Graph Explicit user consent / performance of a pre-contractual request Art. 6(1)(a)(b)
Necessary technical cookies Legitimate interest / consent exemption Art. 6(1)(f) + Recital 47
Non-technical third-party cookies Explicit user consent Art. 6(1)(a)

3. Data recipients

Personal data is not sold or transferred to third parties for commercial purposes. It may be shared with:

  • Technical service providers (hosting, infrastructure) who process data as data processors under GDPR Art. 28
  • Google LLC — limited to a small number of internal/tool pages (alert-engine.html, qen-widget.html, qen-prompt-generator.html, mascot.html) that still load typefaces via Google Fonts (technical connection data); Google acts as an independent controller under its own privacy policy. The rest of the site hosts fonts directly on its own domain (self-hosted), with no third-party connections for typography
  • AI model providers — for pages that expose AI-based analysis tools (see Legal & IP for the list), content submitted by the user is transmitted to the relevant model provider (Anthropic, Google, Mistral AI depending on the tool) to generate the response
  • Competent authorities where required by law

4. Transfer to third countries

Technical connection data from the few pages that still load Google Fonts (see above) may be transferred to the USA. The same applies to data sent to analysis tools based on third-party AI models (Anthropic, Google, Mistral AI). Such transfers take place under the Standard Contractual Clauses (SCC) approved by the European Commission pursuant to GDPR Art. 46.

5. Data subject rights

Under GDPR Articles 15–22, users have the right to:

  • Access their personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Obtain erasure of data ("right to be forgotten", Art. 17)
  • Restrict processing (Art. 18)
  • Port data to another controller (Art. 20)
  • Object to processing (Art. 21)
  • Not be subject to automated decision-making (Art. 22)
  • Withdraw consent at any time, without prejudice to processing carried out before withdrawal (Art. 7(3))

To exercise these rights: info@cognitivelogic.it. The controller responds within 30 days of receipt.

Users also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or their own national supervisory authority.

6. Copyright and intellectual property

All content on cognitivelogic.it — texts, methodologies, algorithms, names (including "QEN", "Cognitive Logic", "Quantificazione Etica Naturale", "Quantification of Ethical Naturalness"), graphics and source code — is the exclusive property of Roberto Bob Malini and is protected by copyright law (Italian Law 633/1941 as amended, EU Directive 2019/790).

Reproduction, distribution, modification or commercial use without the written authorisation of the controller is prohibited. For licensing requests: info@cognitivelogic.it.

7. Data security

The site is served exclusively over HTTPS with a TLS certificate. Contact data received via email is stored on systems protected against unauthorised access. No payment data or special-category sensitive data is stored.

8. Changes to this notice

The controller reserves the right to modify this notice at any time, including in response to regulatory changes. Changes will be published on this page with an updated date at the top. Please check this page periodically.

Cognitive Logic
Quantificazione Etica Naturale — Knowledge Infrastructure.
© 2026 Roberto Bob Malini · cognitivelogic.it
LinkedInRoberto Malini LinkedInCognitive Logic SubstackFuori Menu Emailinfo@cognitivelogic.it
Home Privacy Policy Cookie Policy Accessibility