Privacy Policy

Last updated: 21 August 2026

1. Data controller

Digima di Bonomelli Francesco, sole proprietorship, Via Domenighini 8, 25043 Breno (BS), Italy. VAT IT03026150981 — Tax code BNMFNC70C10B149E.

Contact: customer@remoneo.com — PEC certificata@pec.digimaweb.it. No DPO has been appointed: the conditions of Art. 37 GDPR do not apply.

2. Dual role: controller and processor

We act as controller for registered users' data (professionals and firms): account, billing details, subscription data, technical logs and support.

We act as processor, on behalf of the customer firm, for the firm's own clients' data and the documents they upload through collection links. There the firm is the controller and determines purposes and means; the relationship is governed by the applicable data processing terms.

3. Categories of data

Registration and account data: email, name, firm name, password held in hashed form by the authentication system, optional TOTP second factor, language and notification preferences.

Tax and billing data provided at registration: business name, VAT number, tax code, address, country.

Subscription data: active plan, billing period, subscription status, renewal dates, Paddle identifiers (customer, subscription, transaction ids) and events received from Paddle. We do not receive or store full payment card details.

End-client records entered by the firm: name, email, phone, company.

Documents uploaded by the firm's clients and their metadata (file name, size, type, upload date, verification status).

External storage connection data: Google Drive OAuth tokens stored encrypted, needed to transfer files.

Technical and audit data: request events (creation, opening, upload, transfer, revocation), error logs, anti-abuse counters, AI usage logs (model, tokens, estimated cost, outcome — no document content).

Beta programme data, for participants only: the details of the participation request, the status and the activation and expiry dates of Beta access, information about actual use of the service (requests created, request events, files transferred or completed, features used, use of AI checks, dates and frequency of activity) and feedback submitted during or at the end of the Beta.

4. Purposes and legal bases

Providing the service, managing accounts and connected external storage — performance of the contract (Art. 6.1.b GDPR).

Managing subscriptions, renewals and payment status via Paddle — contract performance and legal obligations (Art. 6.1.b and 6.1.c).

Accounting and tax compliance — legal obligation (Art. 6.1.c).

Platform security, abuse prevention, audit trail and diagnostics — legitimate interest in a secure and reliable service (Art. 6.1.f).

Customer support and service communications (transactional email, reminders about document requests) — contract performance and legitimate interest.

Optional AI document checks — carried out on the firm's instruction, which can enable or disable them at any time; for the firm's own data the basis is contract performance.

Running the Beta programme, for participants only: handling the request and the participation, verifying actual use of the service, assessing the user experience, analysing feedback, improving and developing the service, and checking — under the conditions of the programme — whether the benefits reserved to participants have been earned — performance of the relationship with the participant and legitimate interest in developing and improving the service (Art. 6.1.b and 6.1.f).

We carry out no profiling and no automated decision-making producing legal effects. AI results are indicative only and remain under the professional's control. The assessment of Beta participation is likewise not automated decision-making: decisions about programme benefits are taken by people.

5. How data is processed

Processing is carried out electronically with appropriate technical and organisational measures: encryption in transit, access control through authentication and per-user isolation rules (row level security), encryption of storage connection tokens, optional two-factor authentication, and data minimisation in logs.

Uploaded documents pass through temporary storage and are deleted once the transfer to the firm's storage is confirmed. If a transfer fails, the file is kept for a limited period and then deleted automatically.

6. Recipients and providers

Supabase — database, authentication and temporary storage infrastructure (processor).

Cloudflare — application hosting and delivery (processor).

Paddle.com Market Limited — Merchant of Record for subscription sales: handles checkout, payments, invoicing, taxes, refunds and fraud prevention. For these activities Paddle acts as an independent controller of payment and billing data; see https://www.paddle.com/legal/privacy.

Google LLC / Google Ireland — Google Drive, when the firm connects its own storage: documents ultimately reside in the firm's Drive account.

Google LLC / Google Ireland — Google Ads: measurement of advertising campaign conversions (marketing consent); receives technical and browsing data, never email, names, VAT numbers or document contents.

Resend — transactional email delivery from notify.remoneo.com (processor).

Lovable AI Gateway and its model provider (Google Gemini) — only when AI checks are enabled, for analysing a single document; content is not used to train models.

Professional advisers (accounting, legal) and public authorities, within legal obligations.

We do not sell personal data and do not share it for third-party marketing.

7. International transfers

Some providers above may process data outside the EEA. Such transfers rely on the European Commission's Standard Contractual Clauses or adequacy decisions, with supplementary measures where needed. Write to customer@remoneo.com for details.

8. Retention

Account and firm data: for the duration of the relationship and until the account is deleted.

Uploaded documents: only as long as needed to transfer them to the firm's storage; deleted from temporary storage right after confirmation or, on persistent failure, within 48 hours of the last attempt.

Request metadata and audit events: until the request or the account is deleted.

Subscription data and accounting records: for the period required by applicable tax law (generally 10 years for accounting records).

Technical and AI usage logs: for a limited period needed for security, diagnostics and cost control.

On account deletion we remove remaining files from storage, revoke the external storage connection and delete the related encrypted key.

9. Your rights

You may exercise the rights under Arts. 15-22 GDPR: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, and withdrawal of consent where processing relies on it, without affecting prior lawfulness.

Send requests to customer@remoneo.com; we reply within one month, extendable in the cases allowed by the GDPR.

If your data was uploaded by a firm using Remoneo, that firm is the controller: address your request to it. We assist the firm as instructed.

You may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or your local supervisory authority.

10. Cookies and local storage

Remoneo uses strictly necessary cookies and local storage that are always active. With analytics consent we load PostHog for aggregate measurement of website and app usage; with marketing consent we load the Google Ads conversion tag to measure advertising campaign performance. See the Cookie Policy for details.

11. Updates

This notice may be updated as the service or its providers evolve. The last update date is shown at the top of the page; material changes are communicated to registered users.