Privacy Policy
Last updated: September 4, 2026
Privacy Policy
1Data Controller
The Data Controller of personal data collected through the site and the Lunocode SaaS service (https://lunocode.eu/) is:
Moonify Srl
Via Carlo Imbonati 71, 20159 Milan (MI), Italy
VAT / Tax Code: 12697900962 — REA MI-2681207
PEC (Certified Email): moonify.srl@pec.it
Privacy Email: business@moonify.it
For any request regarding the processing of personal data, the data subject may contact the Controller at the contact details provided above.
2Scope of Application
This Privacy Policy governs the processing of personal data of users (hereinafter "Users" or "Data Subjects") who interact with Lunocode through the following touchpoints:
- Purchase and management of the SaaS subscription (account registration, billing, invoicing, payment gateway);
- "Request a Free Demo" form (commercial lead collection);
- Account management and system logs (authentication, IP address, usage telemetry, security).
This notice is provided pursuant to Articles 13–14 of Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Brazilian Lei Geral de Proteção de Dados ("LGPD"), and the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), where applicable based on the location of the Data Subject.
3Categories of Data Processed
| Category | Examples | Source |
|---|---|---|
| Identification and contact data | Name, surname, email, company name, billing address | Provided by the User during purchase or demo request |
| Company data (demo leads) | Company name, business email, role | Provided by the User via demo form |
| Payment data | Billing details, transaction ID (card data is processed directly by the Payment Processor) | Provided by the User / Payment Processor |
| Access credentials | Username, password (hashed), authentication token | Generated during registration |
| Usage and telemetry data | Access logs, IP address, user agent, application events, error diagnostics | Automatically collected by the system |
| Browsing and analytics data | Site interactions, traffic source, pages visited (see Cookie Policy) | Google Analytics 4, Google Search Console |
Lunocode does not request or intentionally process special categories of data (Art. 9 GDPR) or data relating to minors. Access to the service is reserved for adult users.
4Purposes and Legal Bases for Processing (Art. 6 GDPR)
| Purpose | Legal Basis |
|---|---|
| SaaS service delivery, account management, billing, and invoicing | Performance of a contract (Art. 6.1.b) |
| Tax, accounting, and administrative compliance | Legal obligation (Art. 6.1.c) |
| Management of demo requests and related commercial communications | Data subject's consent (Art. 6.1.a) |
| System security, fraud prevention, technical logs | Legitimate interest of the Controller (Art. 6.1.f) |
| Aggregated/anonymized statistical analysis on site usage | Legitimate interest of the Controller (Art. 6.1.f), subject to consent where required by applicable cookie regulations |
| Direct marketing and newsletter (opt-in) | Data subject's consent (Art. 6.1.a), revocable at any time |
The legitimate interest invoked for security and analytics purposes was evaluated by balancing the Controller's interest with the fundamental rights and freedoms of the Data Subjects; details of this balancing test are available upon request.
5Sub-processors
The Controller uses third-party providers that process data on its behalf as data processors pursuant to Art. 28 GDPR, bound by appropriate Data Processing Agreements (DPA):
- Cloud/Hosting Infrastructure: Hosting and data processing service providers for SaaS delivery;
- Payment Processors: Payment gateways for managing transactions and recurring billing;
- CRM for lead management: Platform used to manage contacts collected via the demo form;
- Google LLC: Provider of Google Analytics 4 and Google Search Console.
The updated list of sub-processors, including identity and specific purpose, is available upon written request to the Controller. The Controller reserves the right to update this list, notifying Users by publishing the updated version of this notice.
6Transfer of Data Outside the EU
Certain sub-processors may process data outside the European Economic Area, particularly in the United States. In such cases, Moonify Srl ensures an adequate level of protection through:
- Providers' adherence to the EU-US Data Privacy Framework (DPF), where applicable; or
- Execution of Standard Contractual Clauses (SCCs) approved by the European Commission via Implementing Decision (EU) 2021/914, supplemented by additional technical and organizational measures where necessary.
A copy of the documentation regarding the safeguards adopted is available upon request to the Controller.
7Data Retention Period
| Data Category | Retention Period |
|---|---|
| Accounting and tax data (invoices, transaction documents) | 10 years, as required by applicable Italian civil and tax law |
| Active account data | For the entire duration of the contractual relationship, plus the period necessary to manage potential disputes |
| Leads collected via demo form, without conversion or further interaction | 12–24 months from the last interaction, after which data is deleted or anonymized |
| Security logs and technical telemetry | 6–12 months, unless extended retention is required to establish or prevent unlawful acts |
| Data processed based on consent (marketing) | Until consent is withdrawn |
Upon expiry of the specified periods, data will be permanently deleted or irreversibly anonymized, unless otherwise required by law.
8Data Subject Rights (GDPR)
The Data Subject may exercise, within the limits and conditions laid down in Arts. 15–22 GDPR, the following rights:
- Access: Obtain confirmation of the existence of processing and access their personal data;
- Rectification: Obtain the correction of inaccurate data or the completion of incomplete data;
- Erasure ("right to be forgotten"): In cases provided for by law;
- Restriction of processing;
- Data Portability: Receive data provided to the Controller in a structured, machine-readable format;
- Objection: Object to processing based on legitimate interest or for direct marketing purposes;
- Withdrawal of Consent: Revoke consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal;
- Lodge a Complaint: Contact the competent Data Protection Authority (in Italy, the Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) or the supervisory authority of their state of residence.
Requests may be submitted to the Controller via PEC (moonify.srl@pec.it) or standard email (business@moonify.it). The Controller will respond within the terms provided by applicable law (normally 30 days, extendable by a further 60 days in cases of particular complexity).
9Notice for California Residents (CCPA/CPRA)
Pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents enjoy specific rights:
- Right to Know the categories and sources of personal data collected, the purposes of processing, and the categories of third parties to whom data is disclosed;
- Right to Delete personal data provided;
- Right to Correct inaccurate personal data;
- Right to Limit the use of sensitive personal information, strictly to purposes necessary for providing the requested service;
- Right to Non-Discrimination for exercising privacy rights.
"Do Not Sell or Share My Personal Information": Moonify Srl does not sell or share (as defined under the CPRA for cross-context behavioral advertising) Users' personal information with third parties. The use of Google Analytics 4 occurs for internal statistical purposes and does not constitute a "sale" or "sharing" under the CPRA.
California residents may exercise their rights by contacting the Controller at the details in Section 1, without needing to create an account.
10Notice for Residents of Brazil (LGPD) and Canada (PIPEDA)
- Users residing in Brazil may exercise rights provided under the Lei Geral de Proteção de Dados (Law 13.709/2018), similar to those in Section 8, by contacting the Controller as the "Controlador" of processing.
- Users residing in Canada may exercise rights under the Personal Information Protection and Electronic Documents Act, including access to and correction of their personal information, by contacting the Controller at the specified details.
11Data Security
The Controller adopts appropriate technical and organizational measures (encryption in transit and at rest, access control, logging, and monitoring) to protect personal data from unauthorized access, loss, destruction, or unlawful disclosure, in compliance with Art. 32 GDPR.
12Changes to this Privacy Policy
The Controller reserves the right to modify this notice at any time. Material changes will be communicated to registered Users, and the "Last updated" date will be updated accordingly.
