Privacy Policy
Information on the Processing of Personal Data (Privacy Policy)
Section titled “Information on the Processing of Personal Data (Privacy Policy)”Last updated: August 16, 2026
This policy describes how Fabrizio Terzi processes the personal data of users who consult the documentation and use the services provided through Factum Parse API (api.factum.pyragogy.org).
1. Data Controller
Section titled “1. Data Controller”- Controller: Fabrizio Terzi
- Address: Bergamo (BG), Italy
- VAT ID: IT04923300166
- Contact email:
info@pyragogy.org
2. Technical Architecture and Zero Data Retention (ZDR) Principle
Section titled “2. Technical Architecture and Zero Data Retention (ZDR) Principle”Factum Parse API is designed according to the principles of Privacy by Design and Privacy by Default (Art. 25 GDPR):
- Volatile In-RAM Processing: Documents (FatturaPA XML, PDF files, text strings) sent to the
/v1/parseendpoint are processed exclusively in the server’s volatile memory (RAM). - No Persistence: No document, extracted JSON payload, personal data or tax data is ever saved to disk, stored in relational databases, or recorded in application log files.
- Isolation from External AI Models: Personal and tax data are not used for training machine learning models nor forwarded to third-party AI providers without prior deterministic sanitization.
- Instant Deletion: Upon completion of the HTTP response (or in case of validation error), the memory occupied by the payload is immediately deallocated.
3. Types of Data Processed and Purposes
Section titled “3. Types of Data Processed and Purposes”A. Authentication and License Management Data
Section titled “A. Authentication and License Management Data”- Data processed: SHA-256 cryptographic hash of the API Key, Lemon Squeezy customer numeric identifier, email address associated with the subscription, subscription status (active, cancelled), service tier.
- Purpose: API call authentication, subscription validity verification, and service delivery.
- Legal basis: Performance of a contract to which the data subject is party (Art. 6.1.b GDPR).
B. Technical Connection Data and Rate Limiting
Section titled “B. Technical Connection Data and Rate Limiting”- Data processed: Caller IP address, request timestamp, invoked endpoint path, HTTP response code.
- Purpose: Protection against cyber attacks (DDoS, brute-force), abuse mitigation, and per-minute rate limiting enforcement.
- Legal basis: Legitimate interest of the Controller in the security and integrity of the infrastructure (Art. 6.1.f GDPR).
4. Payment Management and Merchant of Record
Section titled “4. Payment Management and Merchant of Record”Payments, customer invoicing and tax collection are entirely managed by:
- Lemon Squeezy, LLC (Merchant of Record)
- Address: 222 S. Main Street, Suite 500, Salt Lake City, UT 84101, USA.
All payment data (credit card numbers, billing addresses, purchaser tax information) are collected and processed directly by Lemon Squeezy as an independent Data Controller, compliant with PCI-DSS standards. The Controller neither accesses nor stores customers’ banking or payment details.
5. Data Recipients and Infrastructure Location
Section titled “5. Data Recipients and Infrastructure Location”The processing servers and authentication database are hosted exclusively within the European Economic Area (EEA) on dedicated servers protected by end-to-end encryption (TLS 1.3). No personal data is transferred to third countries not covered by adequacy decisions of the European Commission.
6. Data Retention Period
Section titled “6. Data Retention Period”- Payloads and files submitted for parsing: $0$ seconds (Zero Data Retention).
- API Key hashes and subscription status: Retained for the entire duration of the contractual relationship and deleted within 30 days of permanent account termination.
- Security logs (IP and rate limit): Retained for a maximum of 14 days for intrusion monitoring purposes and subsequently overwritten.
7. Data Subject Rights
Section titled “7. Data Subject Rights”Pursuant to Articles 15-22 of the GDPR, the user may at any time exercise their rights:
- Request access, rectification or erasure of their API Key and license data.
- Request restriction of processing or object to processing based on legitimate interest.
- Lodge a complaint with the national supervisory authority (Garante per la Protezione dei Dati Personali — garanteprivacy.it).
To exercise your rights, simply send a communication to: info@pyragogy.org.
