This document is drafted in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Italian regulations on the protection of personal data.
1.1 Data controller
The Data Controller is:
Nova Ecom Legacy LLC
Registered address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, USA
Commercial brand: Andy Max Tools
Contact email: info.andymaxtools@gmail.com
1.2 Categories of data collected
We collect and process the following categories of personal data:
Data voluntarily provided by the user
• First and last name
• Email address
• Password (stored in encrypted form)
• Billing data (company name, VAT number, tax code, address)
• Phone number (if provided)
• Payment data (handled via Stripe, not stored on our servers)
Data automatically collected
• IP address
• Browsing data (pages visited, time spent, referrer)
• Browser and device type
• Technical and third-party cookies (see Cookie Policy)
Data related to software use
• Operations performed with the software (type, date, time)
• VIN numbers of vehicles on which operations are performed
• Technical data of the electronic control units involved
• Credit balance and purchase history
• Unique license and installation identifiers
1.3 Purposes of processing
Personal data is processed for the following purposes:
• Performance of the contract: providing requested services, managing the user account, activating and maintaining software licenses, managing the credit system.
• Accounting and tax obligations: issuing invoices and managing accounting in compliance with applicable regulations.
• Service communications: sending communications related to the account, software updates, security notifications.
• Technical support: providing assistance in case of problems or requests.
• Security and fraud prevention: monitoring use of the software to detect anomalous behavior, license violation attempts, unauthorized use.
• Direct marketing: with prior consent, sending commercial communications about new products, offers and updates.
• Legal obligations: complying with legal obligations and cooperating with competent authorities if required.
1.4 Legal basis of processing
Data processing is based on:
• Performance of a contract to which the data subject is a party (Art. 6.1.b GDPR)
• Compliance with legal obligations (Art. 6.1.c GDPR)
• Legitimate interest of the Controller in system security and fraud prevention (Art. 6.1.f GDPR)
• Consent of the data subject for direct marketing purposes (Art. 6.1.a GDPR)
1.5 Methods of processing
Data is processed using IT and telematic tools, with organizational and logical methods strictly related to the indicated purposes. We adopt adequate technical and organizational security measures to protect data from unauthorized access, loss, modification or disclosure.
1.6 Parties having access to data
Personal data may be communicated to:
• Authorized internal staff trained in data protection
• Technical service providers (hosting, database, authentication)
• Stripe Inc. (payment processing)
• Supabase Inc. (database and authentication)
• Analytics and monitoring services (in aggregated and anonymized form)
• Legal, tax and accounting consultants (subject to professional secrecy)
• Competent authorities, upon legitimate request
Data is not transferred, sold or communicated to third parties for marketing purposes without the user's consent.
1.7 Extra-EU data transfer
Some of our providers (Stripe, Supabase) are based in the United States. Data transfers take place in compliance with GDPR provisions, with the application of Standard Contractual Clauses approved by the European Commission or on the basis of other adequate safeguards.
1.8 Retention period
Personal data is retained for the time necessary to achieve the purposes for which it was collected:
• Account data: for the entire duration of the contractual relationship and for 10 years after termination, for accounting and tax purposes
• Billing data: 10 years as required by tax regulations
• Software usage data: for the entire duration of the contractual relationship
• Marketing data: until consent is withdrawn
1.9 Rights of the data subject
In compliance with the GDPR, the user has the right to:
• Access their personal data (Art. 15 GDPR)
• Rectify inaccurate or incomplete data (Art. 16 GDPR)
• Obtain erasure of data (Art. 17 GDPR)
• Restrict processing (Art. 18 GDPR)
• Receive data in a structured format (portability, Art. 20 GDPR)
• Object to processing (Art. 21 GDPR)
• Withdraw consent at any time
• Lodge a complaint with the Data Protection Authority
To exercise their rights, the user may contact the Controller at: info.andymaxtools@gmail.com
1.10 Data security
We adopt technical and organizational measures to ensure data security, including password encryption, secure transmission protocols (HTTPS), controlled access, regular backups and system monitoring.
1.11 Changes to the Privacy Policy
We reserve the right to modify this Privacy Policy at any time. Changes will be published on this page and, if relevant, communicated by email to registered users. Users are advised to consult this page periodically.