Privacy policy
Last updated: 3 August 2026
This policy explains which personal data Reneva
(the application served at my.reneva.app) processes, for which
purposes, on which legal bases and for how long, pursuant to Articles 13 and 14 of
Regulation (EU) 2016/679 (GDPR).
The service is a management tool for renewals, jobs, documents and time tracking, aimed at freelancers and agencies. Part of the data concerns who uses the service; another, much larger part concerns the user's own clients, which the user enters and remains the controller of. That distinction is in section 2 and it matters, because it changes who answers for what.
1. Data controller
The controller is Green Marketing Agency, registered office at Via Louis Pasteur 2, 67100 L’Aquila (AQ), Italy — VAT no. IT02106940667.
For any request concerning personal data, including the exercise of the rights in section 5, the contact is info@greenmarketing.agency. No Data Protection Officer has been appointed: none of the mandatory cases under Article 37 GDPR applies.
2. Data processed, purposes and legal bases
a) Account data
Name, email address, password and personal settings (language, notification preferences, dashboard layout). If you enable two-step verification or a passkey, we also process the technical data that mechanism requires.
Passwords are never stored in clear text: the system only keeps an
Argon2id hash, from which the original password cannot be recovered.
The two-step verification secret and the recovery codes are encrypted at rest.
Purpose: creating and managing your access, providing the service, supporting you. Legal basis: performance of the contract (Art. 6.1.b GDPR); for technical security logs, legitimate interest (Art. 6.1.f) in protecting the service against abuse.
b) Data you enter into the tool — you are the controller of this
Records of your clients, documents, recurring fees, jobs, hours, expenses, notes and attachments. This is data you upload and of which you are the controller: whoever operates the service acts as a processor under Article 28 GDPR, that is, processes it only to run the tool for you, on your instructions.
Concretely: this data is not used for the service's own purposes — no profiling, no selling, no training of artificial intelligence models, no aggregation with other users' data. Access by whoever runs the infrastructure only happens for maintenance, security, or support you have asked for.
Every installation is isolated: one user's data is never visible to other users of the service.
c) Usage data
Inside the application the service uses Google Analytics 4 and Microsoft Clarity to understand which features are used and where the interface creates friction. Clarity also records interaction with the pages (pointer movement, clicks, scrolling).
These tools are part of how the service works: by creating an account you accept that your use of the application is measured with them, as set out in the Terms of Service you accept at registration. On the public website (outside the application) analytics tools are governed by the website's own consent banner.
Two minimisation measures are already written into the code, not merely promised:
-
on pages that contain a name (client, job, document) the page title is
not transmitted: the section of the app is sent instead (for
example
clients), because the title would contain a person's name; - the query string is never transmitted: it may contain what you typed into the search box.
Legal basis: performance of the contract (Art. 6.1.b GDPR), as product analytics is part of the service accepted at registration.
d) Feedback and support
The service includes a feedback chat: the messages you send, with their date and the user who wrote them, are kept for 180 days and then deleted automatically (not a manual promise: deletion is a scheduled routine).
Purpose: replying to you and improving the product. Legal basis: performance of the contract and legitimate interest in improving the service.
e) Service email
Transactional email (address verification, password reset, due-date reminders, sending documents) is delivered through Brevo, acting as a sub-processor.
If you configure your own SMTP server to send documents to your clients, those messages leave your infrastructure and do not pass through our providers.
f) Artificial-intelligence assistant features
The service offers optional assistant features (suggestions, summaries, answers about what you have on file). When you use them, only the content needed to answer is sent to the model provider — Anthropic — through infrastructure operated by the service provider, acting as a technical relay.
What is worth knowing, put plainly:
- the transfer happens only when you use an assistant feature, never in the background;
- no anonymisation: names travel in clear. For the dashboard suggestions what leaves is aggregate figures (subscriptions, deadlines, money in, expenses, hours) and, when the analysis needs them, your company's name, the names of at most three clients and three price list items, and the most frequent archiving reasons. Email addresses, phone numbers, VAT numbers, IBANs, addresses and document text are never sent;
- from the feedback bubble what leaves is instead whatever you write: it is the one place where you decide the content, so do not use it for your clients' sensitive data;
- the content sent is not used to train the provider's models;
- alternatively you can configure your own key with a provider of your choice: in that case the relationship with that provider is directly yours;
- the capabilities that would widen this list — extended reading of your financial data, writes from connected assistants and assisted bank reconciliation — are off and stay off until you turn them on yourself, one by one, in Settings › AI;
- if you do not use these features, no content from your archive ever reaches an artificial-intelligence provider.
Legal basis: performance of the contract, limited to the feature you chose to use.
g) Backups
Database and attachment backups are stored on Cloudflare R2 with
client-side encryption (restic): data is encrypted
before it leaves the server, so the storage provider is not able to read it.
Legal basis: legitimate interest in service continuity and protection against data loss (Art. 32 GDPR, security measures).
3. Where data is processed
The application and its database run on dedicated servers located in Contabo GmbH, data centres in Germany (European Union).
Some providers are based or run infrastructure outside the European Union: Anthropic (AI assistant), Microsoft (Clarity), Google (Analytics), Cloudflare (backup storage). Transfers rely on the safeguards of Chapter V GDPR — standard contractual clauses (SCC) and, where applicable, the provider's certification under the EU-U.S. Data Privacy Framework. For backups there is an additional technical safeguard: as stated in section 2.g, data reaches the provider already encrypted.
4. How long data is kept
- Account and tool data: for as long as the account is active. On closure it is deleted, except what must be retained by law.
- Documents with tax relevance: 10 years, as required by Italian civil and tax law (Art. 2220 of the Civil Code and VAT legislation). This period prevails over a deletion request.
- Feedback and support messages: 180 days.
- Backups: kept on rotation, with automatic removal of the oldest copies; a requested deletion propagates to backups within the rotation cycle.
- Technical and security logs: as long as needed to detect and reconstruct abuse, and in any case no longer than 12 months.
5. Your rights
You may exercise the rights under Articles 15-22 GDPR at any time:
- access to your data and to information about the processing (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure, within the limits of retention obligations (Art. 17);
- restriction of processing (Art. 18);
- portability (Art. 20): the service provides CSV export of the main lists, which you can use on your own at any time;
- objection to processing based on legitimate interest (Art. 21).
Requests go to the address in section 1 and are answered within one month. If you believe the processing infringes the law, you may lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or bring the matter before a court.
6. Cookies and similar technologies
The service uses the minimum number of cookies needed to work, plus the analytics ones described in section 2.c, active inside the application as part of the service. No advertising cookies, no sharing with ad networks.
| Cookie | Type | What it does | Duration |
|---|---|---|---|
reneva_session |
Technical | Keeps you signed in: without it every page would ask you to log in again. | Session |
XSRF-TOKEN |
Technical | Protects forms against requests forged by other sites (CSRF). | Session |
_ga, _ga_* (Google Analytics 4) |
Analytics | Measures visits and features used, with the minimisation described in section 2.c. | Up to 2 years |
_clck, _clsk (Microsoft Clarity) |
Analytics | Records interaction with pages to find friction points in the interface. | Up to 1 year |
Technical cookies do not require consent (Art. 122 of the Italian Privacy Code): the service cannot work without them. Analytics cookies are part of how the application works, as described in section 2.c; on the public website they are governed by the website's own consent banner.
7. Changes to this policy
If the processing changes — a new provider, a new purpose — this page is updated and the date at the top changes.