1. Data controller
Spazio Genesi ETS
Registered office: Via Francesco Caracciolo 14, 00167 Rome (RM), Italy
Operating office: Galleria Commerciale Via Roma 215, first floor — L'Aquila (AQ) 67100, Italy
Italian tax code: 96602450585
Email: [email protected] ·
Certified email (PEC): [email protected]
2. Founding principle: the work never leaves your device
The digital fingerprint (SHA-256) of the file is computed directly in your browser: the file of the work is never sent to, nor stored by, our servers, which only receive the fingerprint (a 64-character sequence from which the file cannot be reconstructed) and issue the certificate. Even if the file contained personal data (or special categories of data), those never reach the service. Historical note: until June 2026 the computation took place on our servers, with in-memory processing only and the file discarded immediately; today, not even that.
3. What data we process, why, and on what legal basis
3.1 Fingerprint, timestamp and signature
Your browser computes the SHA-256 fingerprint of the file and sends it to the service, which generates the date and time, the attestation string and a security signature (HMAC). These are technical data of the certificate.
3.2 Author-declared data (optional)
You may state a title, author, year and notes. These are optional: if you enter them, they appear on the certificate and are stored within the PDF certificate. The "author" field may contain a real name and therefore personal data. Such data are bound to the signature (they cannot be altered after issuance, for integrity).
3.3 IP address (anti-abuse and anti-bot)
The IP address is processed for rate-limiting (abuse prevention) and for the Cloudflare Turnstile anti-bot check when the attestation is issued. It is not used to profile you.
3.4 Visit statistics (Matomo)
We use Matomo, an analytics tool self-hosted on our own infrastructure, configured with an anonymised IP address and in cookie-less mode. It collects aggregate statistics only, which are not shared with third parties for commercial purposes. For this reason no consent is required and the service does not display a cookie banner.
3.5 Developer access: API key request
This subsection concerns exclusively those who request a self-service API key from
the page attestazione.spaziogenesi.org/developer/keys — not those who use the attestation
service from the website: for that use, as already described above, we do not process any identifying
personal data.
To issue the key we ask you to confirm your email address through Google, Microsoft or
LinkedIn ("one-shot" sign-in: we only read the email address verified by the provider, then we
discard the token — no session, no cookie, no ongoing access to your account). We process your
email address, the chosen provider and the date of the request, in order to issue the
key, to moderate its use (including any communication in case of revocation or suspected abuse) and to
keep an anti-abuse record. The key itself is never written into an HTML response: it travels only in
the URL fragment (#sgk=…), which the browser never sends to a server — not a
cosmetic improvement, but one less piece of data that could remain in a log.
Anyone holding an active key or a Professional subscription may also submit their application to the
public "Integrations" showcase (attestazione.spaziogenesi.org/integrazioni):
in that case the name of the application, its URL, description and any logo — data that
you choose to provide — become public, but only after a manual check by the service manager
(pre-moderation: nothing goes online without explicit approval). Your email address always remains
private and never appears in the showcase. You can amend or withdraw your submission at any time from
your profile (every amendment goes back into review); withdrawal immediately removes the entry from the
public page.
Legal basis: consent (art. 6.1.a) — the submission is a voluntary and revocable action.
Retention: for as long as the submission remains active, or until withdrawal; a request
to erase the key (§7) also anonymises the owner of the submission and removes it from the showcase.
3.6 Telegram channel (bot)
This subsection concerns exclusively those who use the Telegram bot @SGAttestBot — a convenience channel, distinct from the website: here the file you send passes through Telegram's servers and through our Worker, which computes its fingerprint in streaming and immediately discards the bytes — we never store it. The bot states this before downloading any file; if absolute privacy matters to you, the website remains the channel where the file never leaves your device.
We process your Telegram user id, whether you have accepted the warning about the file passing through, and daily usage counters (how many attestations/verifications you have requested), in order to apply quotas and prevent abuse. We do not process the username, name or any other data from your Telegram profile.
3.7 Email-domain agreements (academies, institutions, companies)
This subsection concerns exclusively those who attest a work under an agreement
between Spazio Genesi and an institution — an academy, a school, a company — (identified by the domain
of your institutional email address, e.g. @studenti.youracademy.it) — whether by requesting
an API key (§3.5) or through the "Attest with your email" access directly from the website. In both
cases we confirm your email address with the same "one-shot" Google, Microsoft or LinkedIn sign-in
described in §3.5: no password, no account with us. In the case of access from the website, the outcome
is a signed voucher that lives only in your browser (in sessionStorage; it
disappears when you close the tab or click "Sign out", with a maximum validity of 8 hours) — we create
neither cookies nor sessions on our server.
For attestations issued under an agreement only, we process your institutional email address, the sign-in provider and the association between your email address and the fingerprints of the works you attest. This log exists solely in order to: deliver the certificate custody guarantee provided for by the agreement, account for the monthly allowance shared with the institution, and produce an aggregate report for the institution (totals and number of members, never a nominal list of works) for invoicing and renewal purposes — unless otherwise agreed in writing with the institution. We do not process any additional data for those who use the service without an active agreement on their email domain.
Agreements may also cover companies and software houses whose application attests on behalf of their own users: in that case we process only the email address of the contact person holding the partner's API key (see §3.5) — the end users of the application remain anonymous to us: we process no data about them.
3.8 Professional subscription
This subsection concerns exclusively those who activate the paid annual subscription
from the page attestazione.spaziogenesi.org/profilo. As for §3.5 and §3.7, identity is
confirmed with the same "one-shot" Google, Microsoft or LinkedIn sign-in: no password, no account with
us, and the resulting voucher lives only in your browser (sessionStorage, never a cookie).
To activate and manage the subscription we process your email address, sign-in provider, subscription references (Stripe identifier, status, expiry date, amount) and the association between your email address and the fingerprints of the works you attest in this tier — the latter being what makes it possible to show you the archive of your certificates in the profile page and to honour the guarantee of retrieval for at least 5 years. The channel through which you produced each certificate (website, API, MCP, Telegram bot) is recorded in the same log, where it can be distinguished.
You may also tell us, optionally and with separate consent, your sector and your region (Professional profiling) or the application/operating system/development environment you use (Developer profiling, if you also hold an API key) — data that are never public and that we use only to offer you favourable terms or agreements when available. You can amend and erase them yourself at any time from the profile page, without writing to us.
Payments: payment processing takes place entirely on Stripe (the Checkout page and the management portal are hosted by Stripe): we never see nor store your card details. From Stripe we receive only the subscription identifiers needed to provide the service (not the payment details).
Reserved discount codes: if we agree a dedicated discount code with you (for example as part of an agreement or a personal promotion), we retain the email address to which the code is reserved, for the sole purpose of enforcing that reservation at the time of activation. The data is entered by us when the code is created — no action of yours on the website generates it — and it remains for the period of validity of the code; early erasure on request, as for the other data in this section (legal basis: pre-contractual measures requested by the data subject, art. 6.1.b, and legitimate interest in managing dedicated commercial terms, art. 6.1.f).
4. Retention and data residency
- File of the work: never sent, never stored — it stays on your device (see §2).
- PDF certificate + OpenTimestamps proof (.ots): archived to allow retrieval and verification over time. Retained indefinitely unless erasure is requested (see §7).
- Where: the certificate archive resides on Cloudflare R2 storage in the European Union jurisdiction (data residency in the EU). The processing engine (Cloudflare Workers) handles requests at the edge transiently.
- Developers' email addresses (§3.5): stored on Cloudflare D1 (the engine's database), which is separate from the R2 certificate archive and without R2's explicit EU jurisdiction constraint; covered by a Data Processing Agreement and Cloudflare's standard contractual clauses (see §6). This concerns only those who request an API key, not the users of the attestation service.
- Telegram bot data (§3.6): stored on a Cloudflare D1 database dedicated to the bot, separate both from the R2 archive and from the engine's database. Same contractual coverage from Cloudflare as described in the previous point.
- Agreement log (§3.7): stored on the same Cloudflare D1 as the engine, for the duration of the custody guarantee provided for by the agreement. It concerns only those who attest under an active agreement; the voucher issued for access from the website is never stored server-side (it lives only in your browser, see §3.7).
- Professional subscription data (§3.8): stored on the same Cloudflare D1 as the engine, for at least 5 years from the production of each certificate (retrieval guarantee). The actual payment data (card number, etc.) neither pass through nor are stored by us: they remain with Stripe, which is an independent controller of them (see §5).
5. Recipients (processors and other parties involved)
Data are neither transferred nor sold. To provide the service we rely on:
| Party | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. | Engine (Workers), archive (R2 — EU), anti-bot (Turnstile) | Fingerprint, certificate, IP address |
| Microsoft Azure | Cryptographic signer of the PDF; host of the Matomo analytics | PDF certificate (during signing) |
| GitHub, Inc. (Microsoft) | Hosting of the interface (GitHub Pages) | Technical browsing data |
| DigiCert, Inc. | Time-stamping authority (RFC 3161) | Only the hash/signature to be time-stamped — no personal data |
| OpenTimestamps (public calendars) | Anchoring in the Bitcoin blockchain | Only a hash sha256(fingerprint‖nonce) — no personal data |
| Stripe, Inc. | Payment processing for the Professional subscription (§3.8) | Payment data (never seen by us), email address for invoicing |
In addition, public authorities in the cases provided for by law only.
Note on the developer sign-in (§3.5) and on agreements (§3.7): Google, Microsoft and LinkedIn do not act as our processors, but as independent controllers in their role as the identity provider chosen by whoever requests the key or signs in from the website — they process the authentication according to their own privacy notices. We receive only the verified email address, not the access token.
Note on the Telegram bot (§3.6): Telegram FZ-LLC does not act as our processor, but as an independent controller in its role as transport provider — the file and the messages pass through its infrastructure according to its own privacy notice, before reaching our Worker.
Note on Professional subscription payments (§3.8): Stripe, Inc. does not act as our processor, but as an independent controller in its role as payment service provider — it processes your card data according to its own privacy notice; we receive only the subscription identifiers, never the payment data.
6. Transfers outside the EU
Cloudflare, Microsoft, GitHub, LinkedIn and DigiCert are based in the United States. Any transfers take place in compliance with GDPR safeguards (standard contractual clauses / adequacy decisions). The certificate archive is kept in the EU jurisdiction; edge processing is transient and does not entail storage outside the EU.
7. Immutability, blockchain and the right to erasure
- Only a hash (
sha256(fingerprint‖nonce)) is recorded in the Bitcoin blockchain: it is not personal data, it is irreversible, and it cannot and must not be erased (it contains no personal information). - The archived PDF certificate, by contrast, may contain personal data (author, file name): at your request we erase it from our archive (right to erasure, art. 17). The signature binds the data for integrity, but does not prevent removal of the archived copy.
- If you have requested a self-service API key (§3.5), you can ask for the early erasure of your email address at any time (without waiting for the 180 days), by writing to [email protected]: the key is revoked and the email address anonymised immediately, instead of at the end of the retention period.
- If you have used the Telegram bot (§3.6), you can ask for the early erasure of your user id and usage counters at any time, by writing to [email protected] — there is no need to wait for the 90 days.
- If you have attested under an agreement with an educational institution (§3.7), you can ask at any time for your email address to be removed from the log, by writing to [email protected]: the log remains in pseudonymous form (the works are still counted for the purposes of the guarantee and of the report to the institution, but with your email address no longer associated with them).
- If you have a Professional subscription (§3.8), you can ask at any time for your email address to be removed from the log, by writing to [email protected]: unlike the other sections, this entails the loss of access to your browsable archive from the profile page (certificates remain valid and retrievable by fingerprint, as for anyone). Upon explicit request we can also delete the copies of the PDFs still archived, where they are not shared with other attestations.
8. Your rights (artt. 15–22 GDPR)
You have the right of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, and — where applicable — withdrawal of consent. To exercise them, write to [email protected] (stating, if possible, the SHA-256 fingerprint of the certificate concerned). You may lodge a complaint with the Garante per la protezione dei dati personali (the Italian data protection authority).
9. User responsibility
By choosing a file for attestation you declare that you are entitled to it and that you have the right to process its content. If you enter third parties' personal data in the declared fields, you are responsible for the lawfulness of doing so. The service does not verify title to the work: it provides a cryptographic attestation of existence, not legal proof of ownership.
10. Minors
The service is not directed at children under 14 and does not knowingly collect their data.
11. Changes
This notice may be updated; the "Last updated" date indicates the version in force.