Documenti legali
Informativa privacy
Sito web e candidature. Ultimo aggiornamento: 5 ottobre 2026. English version
Titolare del trattamento
Il titolare del trattamento è Ognjen Elia Dolić, founder del progetto Exploit2Impact, che agisce come persona fisica in attesa della costituzione della società. Quando la società sarà costituita, questa informativa verrà aggiornata con i nuovi dati del titolare.
Per qualsiasi richiesta sulla privacy: exploit2impactcareers@gmail.com
A chi si rivolge questa informativa
Questa informativa riguarda chi visita il sito exploit2impactcareers.site e chi invia una candidatura per collaborare al progetto Exploit2Impact. È resa ai sensi degli artt. 13 e 14 del Regolamento (UE) 2016/679 (GDPR) e del D.Lgs. 196/2003 (Codice privacy).
Quali dati trattiamo
Dati di navigazione
Quando visiti il sito, Cloudflare, che lo ospita e lo protegge, tratta automaticamente alcune informazioni tecniche: indirizzo IP, data e ora della richiesta, pagina richiesta, tipo di browser e sistema operativo, codice di risposta del server. Servono a far funzionare il sito e a proteggerlo da abusi. Non li usiamo per identificarti o profilarti, salvo il caso di accertamento di reati su richiesta delle autorità.
Dati della candidatura
Nome e cognome, email, città e paese, ruolo e tipo di collaborazione di interesse, link a LinkedIn o portfolio, testo del messaggio ed eventuali allegati che scegli di inviare.
Quando invii il form, i dati viaggiano su una connessione cifrata fino al server del sito, che li inoltra via email al titolare senza conservarli. Se l'invio diretto non è disponibile, il form prepara invece un'email nel tuo programma di posta, che decidi tu se inviare.
Dati per prevenire abusi del form
Per bloccare invii automatici e ripetuti, il server usa il tuo indirizzo IP per contare quante candidature arrivano in un minuto. Il conteggio non viene salvato e si azzera da solo. Non viene usato per altri scopi.
Dati che ci invii spontaneamente
Se ci scrivi direttamente via email, trattiamo i dati contenuti nel messaggio per risponderti.
Cookie e archiviazione locale
Il sito non usa cookie propri né di profilazione. Salva solo due impostazioni tecniche nel tuo browser (lingua e animazione d'apertura) e Cloudflare può usare cookie tecnici di sicurezza. I dettagli sono nella cookie policy.
Finalità, basi giuridiche e conservazione
| Finalità | Base giuridica | Conservazione |
|---|---|---|
| Far funzionare il sito e proteggerlo da attacchi e abusi | Legittimo interesse del titolare (art. 6.1.f GDPR) | Secondo i tempi tecnici del fornitore di hosting |
| Impedire invii automatici o ripetuti del form | Legittimo interesse del titolare (art. 6.1.f GDPR) | Circa un minuto, senza salvataggio |
| Valutare la candidatura e contattarti durante la selezione | Misure precontrattuali richieste da te (art. 6.1.b) e consenso (art. 6.1.a) | Al massimo 12 mesi dalla ricezione |
| Rispondere a richieste inviate via email | Misure precontrattuali o legittimo interesse (art. 6.1.b e 6.1.f) | Il tempo necessario a gestire la richiesta, al massimo 12 mesi |
| Gestire la collaborazione, se inizia | Contratto (art. 6.1.b) e obblighi di legge (art. 6.1.c) | Per la durata del rapporto e i termini previsti dalla legge |
| Difendere un diritto in sede giudiziaria | Legittimo interesse (art. 6.1.f) | Per il tempo necessario alla tutela del diritto |
Alla scadenza dei termini i dati vengono cancellati.
Dati obbligatori e facoltativi
Nome, email, ruolo, tipo di collaborazione e messaggio sono necessari per valutare la candidatura: senza questi dati non possiamo prenderla in considerazione. Città e link al profilo sono facoltativi.
Come proteggiamo i dati
Il sito usa solo connessioni cifrate (HTTPS) e non carica script, font o servizi da siti esterni. Non usa strumenti di analisi, pubblicità o tracciamento. Il server inoltra le candidature senza salvarle. I dati delle candidature sono conservati in una casella email accessibile solo al titolare, con misure tecniche e organizzative adeguate al rischio.
Chi può ricevere i dati
I dati non vengono venduti né diffusi. Possono accedervi:
- il titolare e, se presenti, i co-founder o membri del team coinvolti nella selezione, vincolati alla riservatezza;
- Cloudflare, che ospita il sito, lo protegge dagli attacchi e inoltra le candidature via email;
- il fornitore del servizio di posta elettronica (Google, servizio Gmail), per le email ricevute;
- le autorità competenti, solo se richiesto dalla legge.
I fornitori trattano i dati per conto del titolare o come autonomi titolari secondo le proprie condizioni di servizio.
Trasferimenti fuori dall'Unione europea
Cloudflare e Google sono società con sede negli Stati Uniti, quindi alcuni dati possono essere trattati fuori dallo Spazio economico europeo. In questi casi il trasferimento avviene con le garanzie previste dagli artt. 45 e 46 GDPR: la decisione di adeguatezza della Commissione europea sul Data Privacy Framework UE-USA (Decisione (UE) 2023/1795) per le società aderenti, oppure le clausole contrattuali tipo approvate dalla Commissione.
Decisioni automatizzate
Non prendiamo decisioni basate unicamente su trattamenti automatizzati, profilazione compresa. Ogni candidatura viene letta e valutata da una persona.
I tuoi diritti
In qualsiasi momento puoi chiedere di:
- accedere ai tuoi dati e riceverne una copia (art. 15);
- correggerli o completarli (art. 16);
- cancellarli (art. 17);
- limitarne il trattamento (art. 18);
- riceverli in un formato strutturato o trasferirli a un altro titolare (art. 20);
- opporti al trattamento basato sul legittimo interesse (art. 21);
- revocare il consenso, senza effetti sui trattamenti già svolti (art. 7.3).
Scrivi a exploit2impactcareers@gmail.com. Rispondiamo entro un mese dalla richiesta, come previsto dall'art. 12 GDPR.
Se ritieni che il trattamento violi la normativa, puoi presentare reclamo al Garante per la protezione dei dati personali o all'autorità del paese in cui vivi o lavori.
Modifiche a questa informativa
Potremo aggiornare questa informativa, per esempio quando la società sarà costituita o se cambieranno i servizi usati dal sito. La versione in vigore è sempre pubblicata su questa pagina.
Privacy notice
Website and applications. Last updated: 5 October 2026.
Data controller
The data controller is Ognjen Elia Dolić, founder of the Exploit2Impact project, acting as an individual until the company is incorporated. Once it is, this notice will be updated with the new controller details.
For any privacy request: exploit2impactcareers@gmail.com
Who this notice is for
This notice covers visitors to exploit2impactcareers.site and anyone who applies to work on the Exploit2Impact project. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the Italian Privacy Code (Legislative Decree 196/2003).
What data we process
Browsing data
When you visit the site, Cloudflare, which hosts and protects it, automatically processes technical information: IP address, date and time of the request, requested page, browser and operating system, server response code. This keeps the site running and protects it from abuse. We do not use it to identify or profile you, except to investigate crimes at the request of the authorities.
Application data
Full name, email, city and country, role and type of collaboration of interest, LinkedIn or portfolio link, message text and any attachments you choose to send.
When you submit the form, the data travels over an encrypted connection to the site's server, which forwards it by email to the controller without storing it. If direct sending is unavailable, the form instead prepares an email in your mail app, which you decide whether to send.
Data used to prevent form abuse
To block automated and repeated submissions, the server uses your IP address to count how many applications arrive within a minute. The count is not stored and resets automatically. It is not used for any other purpose.
Data you send us directly
If you email us directly, we process the data in your message to reply.
Cookies and local storage
The site uses no cookies of its own and no profiling cookies. It only stores two technical settings in your browser (language and opening animation), and Cloudflare may use technical security cookies. Details are in the cookie policy.
Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Running the site and protecting it from attacks and abuse | Controller's legitimate interest (Art. 6(1)(f) GDPR) | According to the hosting provider's technical retention |
| Preventing automated or repeated form submissions | Controller's legitimate interest (Art. 6(1)(f) GDPR) | About one minute, not stored |
| Assessing your application and contacting you during selection | Pre-contractual steps at your request (Art. 6(1)(b)) and consent (Art. 6(1)(a)) | Up to 12 months from receipt |
| Replying to requests sent by email | Pre-contractual steps or legitimate interest (Art. 6(1)(b) and (f)) | As long as needed to handle the request, up to 12 months |
| Managing the collaboration, if it begins | Contract (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c)) | For the duration of the relationship and the periods required by law |
| Establishing or defending legal claims | Legitimate interest (Art. 6(1)(f)) | As long as needed to protect the right |
Once these periods end, the data is deleted.
Required and optional data
Name, email, role, type of collaboration and message are required to assess an application: without them we cannot consider it. City and profile link are optional.
How we protect data
The site only uses encrypted connections (HTTPS) and loads no scripts, fonts or services from external sites. It uses no analytics, advertising or tracking tools. The server forwards applications without saving them. Application data is kept in a mailbox only the controller can access, with technical and organisational measures appropriate to the risk.
Who may receive the data
Data is never sold or disclosed publicly. It may be accessed by:
- the controller and, where applicable, co-founders or team members involved in selection, bound by confidentiality;
- Cloudflare, which hosts the site, protects it from attacks and forwards applications by email;
- the email provider (Google, Gmail service), for emails received;
- competent authorities, only where required by law.
Providers process data on the controller's behalf or as independent controllers under their own terms of service.
Transfers outside the European Union
Cloudflare and Google are based in the United States, so some data may be processed outside the European Economic Area. In those cases transfers rely on the safeguards in Articles 45 and 46 GDPR: the European Commission's adequacy decision on the EU-US Data Privacy Framework (Decision (EU) 2023/1795) for participating companies, or the Commission's standard contractual clauses.
Automated decisions
We do not make decisions based solely on automated processing, including profiling. Every application is read and assessed by a person.
Your rights
At any time you can ask to:
- access your data and receive a copy (Art. 15);
- correct or complete it (Art. 16);
- erase it (Art. 17);
- restrict its processing (Art. 18);
- receive it in a structured format or transfer it to another controller (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent, without affecting processing already carried out (Art. 7(3)).
Write to exploit2impactcareers@gmail.com. We reply within one month of your request, as required by Article 12 GDPR.
If you believe the processing breaches the law, you can lodge a complaint with the Italian Data Protection Authority (Garante) or with the authority in the country where you live or work.
Changes to this notice
We may update this notice, for example when the company is incorporated or if the services used by the site change. The current version is always published on this page.