This notice explains how personal data collected through the Human Time Ledger website, the case submission form, email communications and the page used to support the project is processed.
1. Data controller
The data controller is Fernando Carta, the person responsible for the Human Time Ledger project.
For privacy-related requests or to exercise your rights, write to contatti@humantimeledger.com .
2. Data processed
Navigation and security data
The systems hosting the website and APIs may process the IP address, date and time of the request, requested URL, browser and device information, request outcome, technical logs, errors and data required to prevent abuse and unauthorised access.
Case submissions
When a case is submitted, the information collected includes full name, email address, role, organisation, descriptions of the process and solution, measurement data, data source and any additional information entered voluntarily in the form.
Financial contributions
To manage a contribution, the project may process the name and email address when provided, Stripe session and transaction identifiers, amount, currency, payment status, date and the information needed to manage receipts, refunds and disputes. Human Time Ledger does not receive or store complete card details.
Communications
When an email is sent, the email address, message content, any attachments and the information needed to respond to and manage the request are processed.
3. Purposes and legal bases
- receiving, checking and assessing submitted cases, on the basis of steps requested by the data subject and the legitimate interest in operating the ledger;
- contacting the submitter, verifying the email address, requesting clarification and communicating the outcome of the review;
- publishing an approved case and the information agreed with the submitter, on the basis of the authorisation obtained during the editorial process;
- managing contributions, receipts, refunds, disputes and administrative or legal obligations;
- responding to requests received by email;
- protecting the website and preventing abuse, fraud and unlawful automated use, on the basis of the legitimate interest in maintaining service security;
- complying with legal obligations or requests from competent authorities.
4. Required and optional data
Fields marked as required in the submission form are necessary to assess and verify the case. Without them, the proposal cannot be submitted.
On the Support page, the name and email entered before checkout are optional; Stripe may still request the information required to process the payment and send a receipt.
5. Publication of cases
The submitter's contact details are not published automatically. Before publication, the content undergoes editorial review and confirmations or amendments may be requested.
The public ledger may include information about the organisation, project, results and sources agreed with the submitter. Personal data that is not necessary is excluded or minimised.
6. Recipients and service providers
Data may be processed by technical providers used to operate the service, within the limits required for their respective functions:
- Vercel, for frontend hosting;
- Render, for API hosting and application logs;
- Neon, for the PostgreSQL database;
- Resend, for transactional email delivery;
- Upstash, for abuse prevention and request rate limiting;
- Stripe, for checkout, payments, receipts and refunds.
Providers operate under their respective privacy roles and contractual terms. Some processing may involve transfers of data outside the European Economic Area; where this occurs, the mechanisms and safeguards required by applicable law are used.
7. Retention
- unpublished submissions and related contact details are retained for as long as necessary for assessment and, as a rule, no longer than 24 months from the last interaction, unless a dispute or legal obligation requires otherwise;
- information about published cases is retained for the lifetime of the ledger and while it remains relevant for editorial, historical and verification purposes;
- contribution data is retained for the period required to manage the payment and for the periods required by administrative, tax and civil law;
- communications are retained for the time needed to manage the request and any subsequent activities;
- technical logs and security data are retained for limited periods compatible with problem diagnosis, security and abuse prevention.
8. Security
Technical and organisational measures proportionate to the risk are used, including encrypted HTTPS connections, separation of credentials, access controls, webhook signature verification, request rate limiting and software component updates.
No system can guarantee absolute security. In the event of an incident, the procedures required by applicable law will be followed.
9. Data subject rights
Where provided for by the General Data Protection Regulation, you may request access, rectification, erasure, restriction, portability, object to processing and withdraw consent, without affecting the lawfulness of processing carried out before withdrawal.
Requests may be sent to contatti@humantimeledger.com . You may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
10. Cookies and tracking technologies
As of the last update, the website does not use profiling, advertising or analytics cookies and does not use browser tracking technologies. Further information is available in the Cookie Policy.
11. Changes to this notice
This notice may be updated following changes to the website, service providers or applicable law. The version published on this page always shows the date of the latest update.
This notice describes the project's current configuration. Before the services used are changed or new processing purposes are introduced, the content must be reviewed and updated.