Skip to content

Privacy notice

What happens to personal data when you browse 1801.it, send the contact form, or send a data protection request. Written to be checked against the site, not to reassure: every field listed below is a field that actually exists in the database.

Last updated: 1 September 2026

Who the controller is

The controller for the personal data described here — the person who decides why and how it is processed — is:

Operator of this website
Alessio Tortolini
Sole trader registered in the Czech Republic (zahraniční fyzická osoba, legal form 424), trading as 1801.
Registered office
Mečislavova 181/9
Praha 4 – Nusle
140 00 Praha 4
Czech Republic
Registration numbers
IČO (company ID): 23162236
DIČ (VAT ID): CZ687759303
Business activity registered since 7 April 2025
How to reach the operator
For data protection requests use the data protection request form, which is handled separately from sales enquiries. For anything else, the contact form or written post to the address above.

No data protection officer has been appointed: the processing described here does not meet the conditions in Article 37 GDPR that would require one. Requests are handled by the controller directly.

Scope

This notice covers the public pages of 1801.it, the contact form that appears on them, and the data protection request form. It does not describe customer projects, systems we run on a client's behalf, or internal environments: there the client is normally the controller and we process data on their instructions under the relevant agreement.

What is collected

Nothing is collected while you simply read a page, beyond the strictly necessary cookie and the server-side request logs described further down. Data is stored when you submit a form.

From the contact form, stored as a record in the contacts table:

  • first name and last name
  • e-mail address
  • company name, if you fill it in
  • phone number, if you fill it in
  • the message you write
  • the request context and the topic — which form on which page the request came from
  • the source URL: the address of the page the form was submitted from

Alongside it, in a meta field:

  • your IP address
  • your browser user agent string
  • UTM and referral parameters carried in the link you arrived through, if any
  • the timeline and budget indications, where the form asks for them

From the data protection request form: your e-mail address, the type of request, your message, and the same technical metadata. That form deliberately does not ask for your name, company or phone number.

Both forms include a hidden honeypot field and a simple arithmetic captcha, and are rate limited per IP address. If the honeypot is filled in, the submission is discarded without being stored.

Filling in either form is voluntary. There is no statutory or contractual obligation to provide anything — but without an e-mail address there is no way to reply, so the consequence of not providing it is simply that the request cannot be handled.

Why, and on what legal basis

Each purpose has its own legal basis under Article 6(1) GDPR. They are listed separately because they are separate, and because they expire at different times.

Replying to what you sent, and discussing whether the work is a fit

Legal basis: steps taken at your request prior to entering into a contract — Article 6(1)(b) GDPR. You contacted us about possible work; reading the message, replying to it, and keeping the exchange while the conversation is open is the pre-contractual step you asked for.

Keeping the site available and blocking abuse of the forms

Legal basis: legitimate interests — Article 6(1)(f) GDPR. This covers the IP address and user agent stored with a submission, the per-IP rate limit, the captcha and the honeypot, and the request logs of the server and the protection layer in front of it. The interest is keeping a public form usable without it becoming a spam relay; the data used for it is limited to what the request itself carries, and it is the first thing to be removed (see retention).

Invoicing and accounting, if the conversation becomes an engagement

Legal basis: compliance with a legal obligation — Article 6(1)(c) GDPR. Once there is a commercial relationship, Czech accounting and tax law requires invoices and the records supporting them to be kept for their own statutory periods, which are longer than the retention periods below and are not something we can shorten on request.

No marketing e-mails are sent from the data collected on this website, and there is no newsletter. No automated decision-making or profiling in the sense of Article 22 GDPR is carried out: a person reads every message.

How long it is kept

Two periods, both enforced by a scheduled job rather than by intention:

  • 24 months for a contact record that did not become a client, counted from when it was created. After that the record is deleted, message included. Records belonging to an engagement that went ahead are kept for as long as the relationship and the accounting obligations above require.
  • 12 months for the technical metadata: IP address, user agent, UTM and referral parameters. These are emptied from the record after twelve months while the rest of it is left intact, because the security purpose they were collected for no longer applies.

Server and protection-layer request logs follow their own shorter rotation on the infrastructure that produces them, and are not merged into the contact records.

Who else processes it

The record itself is readable only by the operator, through an authenticated administration area. Contact data is not sold, rented or shared for anyone else's marketing. Beyond that, three categories of provider are involved because the site has to run somewhere:

  • Hosting. The site and its database run on a server we administer ourselves, located in Germany, rented from Hetzner.
  • CDN, DNS and protection. Traffic reaches the server through Cloudflare, which terminates the connection, filters abusive requests and therefore processes connection data including your IP address. Cloudflare acts as a processor under its own Data Processing Addendum, which is incorporated by reference into the subscription agreement and applies without a separate signature. Where that connection data leaves the EEA, Cloudflare states that it relies on the EU Standard Contractual Clauses and, for transfers to the United States, on its certification under the EU–U.S. Data Privacy Framework. Both documents are published at cloudflare.com/cloudflare-customer-dpa.
  • Outbound e-mail. A mail service delivers the internal notification that a new message has arrived, and any reply we send you. It is not named here because naming a provider we have not verified in this document would be worse than naming a category; ask through the request form and you will be told which one it is.

Data is also disclosed where a law or a lawful order requires it.

Your rights

Under the GDPR you can ask for access to your data, rectification of it, erasure, restriction of processing, and portability of what you provided. Where processing rests on legitimate interests you can object to it, and where it rests on the pre-contractual basis you can ask us to stop and delete the record. Exercising any of these costs nothing.

Use the data protection request form. It is separate from the sales form on purpose: it asks for an e-mail address, the type of request and a message, and nothing else. Requests are answered within the period set by Article 12(3) GDPR. If we cannot tell from the request which record is yours, we will ask for the minimum needed to identify it rather than for identity documents.

Complaining to a supervisory authority

If you think this processing breaches data protection law, you can lodge a complaint with a supervisory authority, and you can do so without contacting us first.

The controller is established in the Czech Republic, so the competent authority is the Czech data protection authority: Úřad pro ochranu osobních údajů (ÚOOÚ), uoou.gov.cz.

You may also complain to the supervisory authority of the EU member state where you live or work, or where the alleged breach took place — a complainant in Italy, for example, can go to the Garante per la protezione dei dati personali. That does not change which authority is the lead one for this controller: the ÚOOÚ is.

Changes to this notice

The date at the top is the date of the current version. If what the site does changes — a new provider, a new field on a form, an analytics tool — this page is meant to be updated before that change goes live, not after.