Privacy
Privacy policy
This page says what personal data this website processes, why, how long it is kept and who gets to see it. In plain language, which is what the GDPR itself asks for.
1Who we are
This website belongs to Diginesso di Beerendonk Wesley Johannes Wijnand, an Italian sole proprietorship (impresa individuale) run by Wesley Beerendonk. For the data this site processes, Diginesso is the controller.
- Legal name: Diginesso di Beerendonk Wesley Johannes Wijnand
- Legal form: Impresa individuale, registered with the Camera di Commercio Toscana Nord-Ovest
- Address: Piazza Guglielmo Marconi 6, 56046 Riparbella (PI), Italia
- REA number: PI-263609
- VAT number: IT02522840509
- Email: info@diginesso.com
- Certified Italian email (PEC): diginesso@pec.it
For anything to do with privacy, write to info@diginesso.com. It reaches me, Wesley Beerendonk, and I answer it myself. There is no data protection officer: a company this size is not required to appoint one. If that changes, it will say so here.
2In plain language
For anyone who would rather not read the whole page, in five lines.
- What I collect: what you type into the contact form, how you arrived (the page your visit started on and the site or ad that sent you), visit counts without cookies, and the ordinary log lines a server keeps.
- Why: to answer your question, and to keep the site working and safe.
- How long: your enquiry for 24 months after our last contact, log lines for 30 days at most.
- Who receives data: the suppliers and their regions are listed below. Digi may involve processing in the US. So may the conversion report to Google Ads, once that connection is active. I do not sell your data.
- How to get it removed: write to info@diginesso.com and ask me to delete it. You hear back within five working days.
3Two roles, strictly apart
On this website Diginesso is the controller. I decide what the site collects and what for, and this page is about that role, with one exception set out below.
In a client project Diginesso is the processor and the client is the controller. It is your data and your process, you decide what it is used for, and I do what the data processing agreement says. You sign that before a single record is touched, and the sub-processors are named in it.
If your company sits outside the EU and wants customers inside it, that split is the part you will be asked to show. The technical half is arranged: EU regions, a processing agreement with named sub-processors, and records you can hand to a supervisory authority. Appointing a representative in the EU under Article 27 is a legal appointment, so for that I point you to a party that takes the role on.
So this page does not cover the data I process for you inside a project. That sits in your own processing agreement, and how it is set up technically is on the Secure and European page.
The one exception is the Google user data section at the end of this page. Google requires it in this policy. It covers a Google Ads account you connect, in which I work on your behalf, and it applies inside a client project as well.
4The contact form
When you send the form, I store:
- your name and your email address
- your company name, if you fill it in
- your message
- the language you were reading in and the page you sent the form from
- how you arrived: the page your visit started on, the referring site and the campaign labels if you came through an ad or a newsletter, including the Google Ads click ID
- the moment you sent it
Your IP address is not stored with your enquiry. The form has one invisible field that only bots fill in. If that field is filled in, nothing is stored.
How you arrived is recorded on the first page you open, whichever page that is, and kept in your browser’s session storage for the length of your visit. That way it is still with the form if you look around first. It disappears when you close the tab. The cookie page names it and says what it is for.
Legal basis: taking steps towards an agreement at your own request, and my legitimate interest in being able to answer business enquiries and to know where they come from.
Where it sits: in my database at Supabase in Frankfurt. On top of that I get an email notification through Resend in Ireland, carrying the same details. Submissions do not belong in the server logs and are not written to them.
Retention: 24 months after our last contact, then the record goes. If you want it gone sooner, write to me and I delete it.
If you came in through a Google ad
Then the Google Ads click ID is stored with your enquiry. It is there so that I can measure my own advertising.
The Google Ads integration is being set up, and the conversion report described here is not switched on yet. Until it is, nothing from your enquiry goes to Google. Once the connection is active, my server will report such an enquiry as a conversion to Diginesso’s own Google Ads account, directly and without your browser taking part. Google will then receive the click ID from your first visit, which conversion the enquiry counts as, the time of that conversion, and a value if one has been set.
Nothing else from your enquiry will go along: not your name, email address, company, message or any intake conversation, and no hashed email address, phone number or IP address either. Whether and when an enquiry counts as a conversion depends on how far it got in my own follow-up. That follow-up stays with me. Google only sees the conversion that results from it.
Google can connect the click ID to the ad click it came from, which is why the click ID counts as personal data. Google will use the conversions it receives as an independent controller, under the Google Ads Controller-Controller Data Protection Terms and Google’s own privacy policy (policies.google.com/privacy).
Legal basis: my legitimate interest in knowing which of my ads bring in enquiries (Article 6(1)(f) GDPR).
Your right to object: you can object to this report at any time, also before it is switched on, by writing to info@diginesso.com. From then on I do not report your enquiry to Google.
No cookie and no Google tag in your browser is involved. The click ID only sits in your browser’s session storage until you close the tab, as described above. The cookie page names that entry and the rules that apply to it. Google is an American company, and once the report is active, this data can be processed outside the EU. More on that under Transfers outside the EU.
5The intake with Digi
When Digi is available, you are talking to an AI. The first message says so. Wesley reads the conversation after you submit it and replies personally. Legal basis: taking steps towards an agreement at your request.
After four questions, your answers go through Vercel AI Gateway to Anthropic, PBC for a short summary. These US suppliers may process the text in the US. The name and email entered in the final step are not sent to the model. Personal information you include in an answer does travel with it.
Digi requests processing without model training and with zero data retention through the Gateway. If no eligible route is available, the request fails. Before enabling Digi, I check the processing agreements and safeguards for US transfers, including applicable standard contractual clauses and a transfer assessment.
Only when you submit the conversation with your contact details do I store the transcript with your enquiry in Supabase. Resend may send me a notification containing the transcript. Unfinished conversations are not stored in the database. The chat stays only in the memory of your open page.
Retention: the saved conversation and its enquiry are deleted 24 months after the last contact. The schedule that carries out this deletion automatically still has to be set up. I update the contact date after further correspondence. You can request earlier deletion.
6Email and booking a call
If you write to info@diginesso.com, your address and the contents of that mail sit in my mailbox, the way any business mailbox works.
Legal basis: preparing or performing an agreement, and my legitimate interest in being reachable for business.
Retention: business correspondence for 24 months after our last contact. Mail belonging to a signed assignment is kept for as long as the Italian bookkeeping obligation requires, which is ten years.
There is no booking tool on this site. A call is agreed by email, so no scheduling service gets to see anything of yours.
7Visit statistics
I measure with Plausible, a European service that works without cookies. Nothing is placed on your device and no profile is built. You cannot be recognised and you cannot be followed across sites.
What does get counted: which page was viewed, which site you came from, which country you are in, and what kind of device and browser you use. Your IP address is used to work out the country and is not stored afterwards.
I also count a few actions, such as a click on a contact button. Those counts hold no personal data.
Legal basis: legitimate interest, namely knowing whether the site does its job. No consent is needed, because nothing is stored on your device and the counts cannot be traced back to you. What does end up on your device is listed on the cookie page.
8Log files and security
The server keeps ordinary log lines: the time, the path requested, the status code, the kind of browser, and the IP address the request came from. That comes with running a website and it is what shows you faults and abuse.
Legal basis: legitimate interest, namely keeping the site up and safe.
Retention: no longer than 30 days.
Passwords and keys live in a sealed vault. They are not in code and not in a chat window. Everything travels over an encrypted connection. Production can be reached by me, with two-factor authentication, and by the systems that do the work. There is no team of onlookers behind me. Every time a person or a process reaches production, it is in the log.
9Suppliers
Digi additionally uses Vercel AI Gateway and Anthropic, PBC. They receive your intake answers for the summary. This processing may take place in the US, outside the EU regions used for hosting and storage. The intake section describes the conditions for activation.
These are all the parties that see any of the data on this website. The Secure and European page carries the same list for a client project, with more explanation. A privacy policy has to be complete on its own, so it is here as well.
| Who | What for | Where the servers are | What they get to see |
|---|---|---|---|
| Vercel | Runs the site. | Frankfurt, with Amsterdam as fallback (fra1, ams1) | Traffic to and from the site, and whatever you type into a form at the moment you hit send. |
| Supabase | The database your enquiry lands in. | Frankfurt, Germany (eu-central-1) | Everything the form stores. This is where your enquiry actually lives. |
| Resend | Sends the notification of a new enquiry. | Ireland (eu-west-1) | The recipient address and the contents of that one email. Nothing beyond that. |
| Plausible | Counts how many people visit the site. | European Union, no cookies | Counts per page. No cookies, no profiles, no way to recognise a visitor. |
| Sanity | The system holding the text and images of the site. | European Union | The content of the site, no visitor data. Images come from a worldwide network, so the file you see may be served from a machine near you. |
| Google Ads, for my own advertising. Once the connection is active, my server will report an enquiry that came in through a Google ad there as a conversion. Google will use that report as an independent controller. | Google’s data centres, also outside the EU | Once the report is active: the click ID from your first visit, which conversion the enquiry counts as, the time of that conversion, and a value if one has been set. Nothing else from your enquiry, and until then nothing at all. |
Who is not on it: there is no advertising pixel on the site, no Meta pixel, no LinkedIn tag, no session recording and no heatmap. There is no Google tag on the site either. Once the conversion report is active, it goes straight from my server to Google Ads. The fonts ship with the site, so your browser fetches nothing from Google Fonts. If something is added, it appears here before it is switched on.
10Transfers outside the EU
Digi additionally uses Vercel AI Gateway and Anthropic, PBC. They receive your intake answers for the summary. This processing may take place in the US, outside the EU regions used for hosting and storage. The intake section describes the conditions for activation.
Vercel, Supabase and Resend are American companies. Hosting and storage use the EU regions above. Digi has the exception described above.
The same arrangement covers all three: a data processing agreement with the European Commission’s standard contractual clauses and the measures set out in them. For Sanity the content sits in the European environment, and where the supplier is established outside the EU the same clauses apply.
Google is an American company too. Once the conversion report described under the contact form is active, Google will receive that data, and it can then be processed outside the EU. It will fall under the Google Ads Controller-Controller Data Protection Terms, the data protection terms Google sets for Google Ads, which include the European Commission’s standard contractual clauses.
The honest part: whether a US authority can demand data from a European subsidiary is a question lawyers answer differently, and I am not going to pretend it is settled. For each supplier I have written down which data it touches and which measures stand against that. If you want to see that assessment, write to me.
If this is about a client project and that risk is too much for you, the EU-only option is on the Secure and European page.
11Retention periods
Per type of data, with a number.
| What | How long |
|---|---|
| Your enquiry from the form | 24 months after our last contact |
| Business email | 24 months after our last contact |
| Email belonging to a signed assignment | ten years, under the Italian bookkeeping obligation |
| Tokens and data of a Google Ads connection | while the connection is active, then deleted within 30 days |
| Send logs of the notification email | 30 days at most |
| Server log lines | 30 days at most |
| Database backups | 30 days, and the oldest is gone after 90 days at the latest |
| Visit statistics | kept as counts, with nothing in them that points back to you |
12Your rights
You have these rights, and you do not have to give a reason:
- access: ask which data I hold about you
- rectification: have something corrected that is wrong
- erasure: have your data deleted
- restriction: have the use put on hold while something is being sorted out
- objection: object to use based on legitimate interest
- portability: receive your data in a readable file
Write to info@diginesso.com. You hear back within five working days and I settle it within one month at the latest, as the GDPR requires. If it takes longer, you hear that before the month is out, with the reason.
If you are not happy with how I handle it, you can complain to a supervisory authority. Diginesso is established in Italy, so the lead authority is the Garante per la protezione dei dati personali in Rome (garanteprivacy.it). You can also complain to the authority in your own country, for example the Autoriteit Persoonsgegevens in the Netherlands or the competent state authority in Germany. That choice is yours, and a complaint in your own country counts just as much.
13Automated decisions
Nothing on this website makes a decision about you. There is no profiling, no score and no automatic rejection. I read your enquiry myself.
If you talk to Digi, that conversation assesses your process, not you.
14Children
This is a business service, aimed at company owners and not at children. I do not knowingly collect data from minors. If you think a child has sent me something anyway, write to me and I will remove it.
15Google user data
This section stands on its own and can be read on its own. It covers the Google Ads integration: the holder of a Google Ads account connects that account to Diginesso through Google’s own consent screen, and Diginesso then works in that account on the account holder’s behalf. It applies only if you connect a Google Ads account that way. If you do not, no Google user data of yours is involved.
Google requires the privacy policy itself to describe what happens to this data, so it is described here in full, even where the connection is part of a client project that has its own data processing agreement. What the integration does is described on the Google Ads integration page of this site. The integration is being set up, and no Google Ads account is connected to it yet.
Which Google user data I access
The integration asks Google for one permission, the OAuth scope https://www.googleapis.com/auth/adwords, and for nothing else. That is the scope of the Google Ads API. With it, in the Google Ads account you connect, the integration can reach:
- the account’s customer ID and its descriptive name
- the account’s currency and time zone
- how campaigns, ad groups, keywords and ads fit together in the account
- campaigns and their settings
- ad groups
- keywords, negative keywords included
- ads
- budgets
- performance figures: cost, clicks and impressions
- conversion actions, conversion counts and conversion values
- keyword ideas with their search volumes and bid ranges from Keyword Planner, in the account’s currency. That is Google’s aggregate data about searches, fetched through your connection, and not data about you.
What the integration does not access:
- Gmail
- Google Drive
- Google Calendar
- Google Contacts
- your Google Account profile, meaning your name, email address and photo. There is no “Sign in with Google”.
- any other Google service or data outside Google Ads
Those permissions are not requested, so the integration cannot reach that data.
What I use it for
Only for these features, and only in the account you connect:
- Reporting: reading how your campaigns perform, meaning cost, clicks, impressions and conversions, and showing that to you.
- Campaign management: creating and changing campaigns, budgets, ad groups, keywords and ads.
- Keyword research: keyword ideas from Google’s Keyword Planner, with search volumes and bid ranges, for the campaigns you want to run.
Changes happen only on your instruction: nothing in your account is created or changed unless you asked for that change.
There is no other use of your Google user data.
The same scope has one more use, which does not touch your account: reporting enquiries to this website that came in through a Google ad as conversions in Diginesso’s own Google Ads account. That concerns visitors of this website, Diginesso is the controller for it, and it is described above under the contact form.
Who I share it with
With nobody, other than the suppliers needed to run the integration: Vercel runs the application and Supabase holds the database. Both are in the supplier list above, with their region. If a report reaches you by email, that email goes through Resend.
Beyond that, only where the law obliges me to, or if Diginesso is ever merged or sold, and then only with your explicit consent beforehand. No selling, no reselling, no ad networks and no data brokers.
How I protect it
The access tokens Google issues are stored encrypted at rest. The keys live in a sealed vault, not in code and not in a chat window. Production can be reached by me, with two-factor authentication, and by the systems that do the work. In transit everything goes over an encrypted connection, and every time a person or a process reaches production, it is in the log.
Retention, and how you end the connection
The tokens, and the Google Ads data stored for your connection, are kept for as long as the connection is active.
You can end the connection at any time:
- in your Google Account, at https://myaccount.google.com/linkedapps, where the apps with access to your account are listed. The tokens stop working at once.
- by writing to info@diginesso.com. I then revoke the access at Google myself.
The connection also ends when our work together ends, and in that case too I revoke the access at Google myself. However it ends, I delete what I still hold, the tokens and the Google Ads data stored for the connection, within 30 days.
Copies in database backups disappear as those backups are replaced, on the schedule in the retention table above.
Limited Use
Diginesso’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
In concrete terms:
- Google user data is used only to provide the features listed above, the ones you use.
- It goes to others only where that is needed to provide those features, to comply with the law, or in a merger, acquisition or sale of Diginesso, and in that last case only with your explicit consent beforehand.
- No person reads it, except with your explicit consent for specific data, for example when you ask me to look at a campaign, for security purposes such as investigating abuse, to comply with applicable law, or in aggregated and anonymised form for internal operations.
- It is not used to serve or target advertising, for Diginesso or for anyone else, including remarketing and interest-based advertising. The only ads it touches are the campaigns in your own account, changed on your instruction.
- It is not sold and not resold.
- It is not used to develop, train or improve generalised AI or machine learning models.
16Changes and versions
If the setup changes, this page changes before that change goes in. That is the same promise as on the Secure and European page.
| Version | Date | What changed |
|---|---|---|
| 1.2 | 24 September 2026 | Google user data rewritten for the Google Ads integration, on one scope. Sign in with Google (openid, email, profile) dropped. Tokens are now deleted within 30 days after the connection ends, where 1.1 deleted them straight away. New: a planned server-side report to Google Ads of enquiries that came in through a Google ad, not switched on yet; Google added to the suppliers and to transfers outside the EU. The contact-form list now also names the page your visit started on. |
| 1.1 | 22 September 2026 | Digi through Vercel AI Gateway and Anthropic; retention and US transfers. |
| 1.0 | 21 September 2026 | First version. |