Privacy policy

Last updated: 3 August 2026

This policy explains which personal data Reneva (the application served at my.reneva.app) processes, for which purposes, on which legal bases and for how long, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

The service is a management tool for renewals, jobs, documents and time tracking, aimed at freelancers and agencies. Part of the data concerns who uses the service; another, much larger part concerns the user's own clients, which the user enters and remains the controller of. That distinction is in section 2 and it matters, because it changes who answers for what.

1. Data controller

The controller is Green Marketing Agency, registered office at Via Louis Pasteur 2, 67100 L’Aquila (AQ), Italy — VAT no. IT02106940667.

For any request concerning personal data, including the exercise of the rights in section 5, the contact is info@greenmarketing.agency. No Data Protection Officer has been appointed: none of the mandatory cases under Article 37 GDPR applies.

2. Data processed, purposes and legal bases

a) Account data

Name, email address, password and personal settings (language, notification preferences, dashboard layout). If you enable two-step verification or a passkey, we also process the technical data that mechanism requires.

Passwords are never stored in clear text: the system only keeps an Argon2id hash, from which the original password cannot be recovered. The two-step verification secret and the recovery codes are encrypted at rest.

Purpose: creating and managing your access, providing the service, supporting you. Legal basis: performance of the contract (Art. 6.1.b GDPR); for technical security logs, legitimate interest (Art. 6.1.f) in protecting the service against abuse.

b) Data you enter into the tool — you are the controller of this

Records of your clients, documents, recurring fees, jobs, hours, expenses, notes and attachments. This is data you upload and of which you are the controller: whoever operates the service acts as a processor under Article 28 GDPR, that is, processes it only to run the tool for you, on your instructions.

Concretely: this data is not used for the service's own purposes — no profiling, no selling, no training of artificial intelligence models, no aggregation with other users' data. Access by whoever runs the infrastructure only happens for maintenance, security, or support you have asked for.

Every installation is isolated: one user's data is never visible to other users of the service.

c) Usage data

Inside the application the service uses Google Analytics 4 and Microsoft Clarity to understand which features are used and where the interface creates friction. Clarity also records interaction with the pages (pointer movement, clicks, scrolling).

These tools are part of how the service works: by creating an account you accept that your use of the application is measured with them, as set out in the Terms of Service you accept at registration. On the public website (outside the application) analytics tools are governed by the website's own consent banner.

Two minimisation measures are already written into the code, not merely promised:

Legal basis: performance of the contract (Art. 6.1.b GDPR), as product analytics is part of the service accepted at registration.

d) Feedback and support

The service includes a feedback chat: the messages you send, with their date and the user who wrote them, are kept for 180 days and then deleted automatically (not a manual promise: deletion is a scheduled routine).

Purpose: replying to you and improving the product. Legal basis: performance of the contract and legitimate interest in improving the service.

e) Service email

Transactional email (address verification, password reset, due-date reminders, sending documents) is delivered through Brevo, acting as a sub-processor.

If you configure your own SMTP server to send documents to your clients, those messages leave your infrastructure and do not pass through our providers.

f) Artificial-intelligence assistant features

The service offers optional assistant features (suggestions, summaries, answers about what you have on file). When you use them, only the content needed to answer is sent to the model provider — Anthropic — through infrastructure operated by the service provider, acting as a technical relay.

What is worth knowing, put plainly:

Legal basis: performance of the contract, limited to the feature you chose to use.

g) Backups

Database and attachment backups are stored on Cloudflare R2 with client-side encryption (restic): data is encrypted before it leaves the server, so the storage provider is not able to read it.

Legal basis: legitimate interest in service continuity and protection against data loss (Art. 32 GDPR, security measures).

3. Where data is processed

The application and its database run on dedicated servers located in Contabo GmbH, data centres in Germany (European Union).

Some providers are based or run infrastructure outside the European Union: Anthropic (AI assistant), Microsoft (Clarity), Google (Analytics), Cloudflare (backup storage). Transfers rely on the safeguards of Chapter V GDPR — standard contractual clauses (SCC) and, where applicable, the provider's certification under the EU-U.S. Data Privacy Framework. For backups there is an additional technical safeguard: as stated in section 2.g, data reaches the provider already encrypted.

4. How long data is kept

5. Your rights

You may exercise the rights under Articles 15-22 GDPR at any time:

Requests go to the address in section 1 and are answered within one month. If you believe the processing infringes the law, you may lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or bring the matter before a court.

6. Cookies and similar technologies

The service uses the minimum number of cookies needed to work, plus the analytics ones described in section 2.c, active inside the application as part of the service. No advertising cookies, no sharing with ad networks.

Cookie Type What it does Duration
reneva_session Technical Keeps you signed in: without it every page would ask you to log in again. Session
XSRF-TOKEN Technical Protects forms against requests forged by other sites (CSRF). Session
_ga, _ga_* (Google Analytics 4) Analytics Measures visits and features used, with the minimisation described in section 2.c. Up to 2 years
_clck, _clsk (Microsoft Clarity) Analytics Records interaction with pages to find friction points in the interface. Up to 1 year

Technical cookies do not require consent (Art. 122 of the Italian Privacy Code): the service cannot work without them. Analytics cookies are part of how the application works, as described in section 2.c; on the public website they are governed by the website's own consent banner.

7. Changes to this policy

If the processing changes — a new provider, a new purpose — this page is updated and the date at the top changes.