Last updated: 2026-06-16

Privacy Policy

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Decree 101/2018, to users of the Bi-Rank platform (Piattaforma white-label di GEO (Generative Engine Optimization) per agenzie).

1. Data Controller

The Data Controller is BinaryCode srl, a company incorporated under Italian law, with registered office at Via S. Carlo 157, 81100 Caserta (CE), Italia.

For any data protection request, including exercising your rights under section 8, write to privacy@binary-code.it.

Il Titolare non ha nominato un Responsabile della Protezione dei Dati (DPO), non ricorrendone i presupposti di legge (art. 37 GDPR). Per ogni questione privacy è disponibile il contatto sopra indicato.

2. What data we process

Depending on how you use the platform, we process:

The platform is a professional tool for agencies and operators: it is not intended for minors and we do not knowingly collect data of minors.

3. Purposes and legal bases

Purpose Legal basis (Art. 6 GDPR)
Account creation and management, service delivery Performance of a contract (Art. 6.1.b)
Billing and tax/accounting obligations Legal obligation (Art. 6.1.c)
Payment processing Performance of a contract (Art. 6.1.b)
Security, abuse prevention, technical logs Legitimate interest (Art. 6.1.f)
Aggregated, anonymous usage statistics Legitimate interest (Art. 6.1.f)
Service communications (e.g. trial, renewal notices) Performance of a contract (Art. 6.1.b)

Providing account and billing data is necessary to use the service; failure to provide it prevents service delivery.

4. Processors and third parties

To deliver the service we rely on providers that process personal data on our behalf, appointed as Processors under Art. 28 GDPR:

Responsabile Finalità Dati Ubicazione
Axerve S.p.A. (Gruppo Banca Sella) — piattaforma Fabrick/Gestpay Elaborazione dei pagamenti con carta (gateway PCI-DSS). Dati di pagamento, identificativi transazione. Italia / UE
Fatture in Cloud S.p.A. (TeamSystem) Fatturazione elettronica e invio allo SDI. Dati di fatturazione (ragione sociale, P.IVA, indirizzo), importi. Italia / UE
OVHcloud (OVH SAS) Hosting dell'infrastruttura applicativa e dei database. Tutti i dati trattati dalla piattaforma (in qualità di host). Unione Europea (Francia)
Register S.p.A. (register.it) — SecureMail, relay SMTP authsmtp.securemail.pro Invio email transazionali (verifica, notifiche, trial). Indirizzo email, nome, contenuto della notifica. Italia / UE
OpenAI, L.L.C. / OpenAI Ireland Ltd — API ChatGPT Monitoraggio AI Visibility: interrogazione del modello con i prompt del cliente. Testo del prompt (query di settore, nome/dominio del brand). Nessun dato di pagamento. USA / UE — DPF + SCC
Google Ireland Ltd / Google LLC — API Gemini Monitoraggio AI Visibility: interrogazione del modello con i prompt del cliente. Testo del prompt (query di settore, nome/dominio del brand). USA / UE — DPF + SCC
Perplexity AI, Inc. — API Sonar Monitoraggio AI Visibility: interrogazione del modello con i prompt del cliente. Testo del prompt (query di settore, nome/dominio del brand). USA — SCC
Anthropic, PBC — API Claude (opzionale) Generazione assistita dei suggerimenti GEO (solo se selezionato l'engine Claude). Fatti estratti dalla pagina del cliente da ottimizzare. USA — DPF + SCC
DataForSEO OÜ — SERP API (AI Overview / AI Mode) — opzionale Monitoraggio della presenza del brand nelle AI Overview/AI Mode di Google Search. Query di settore, nome/dominio del brand monitorato. UE (Estonia) — DPA + SCC

Data may also be disclosed to public authorities where required by law, and to our advisors (e.g. accountant) for legal compliance.

5. Where we process data

Data is processed within the European Union / European Economic Area. Should a provider involve a transfer outside the EU, this will occur only with adequate safeguards under Art. 44 et seq. GDPR (e.g. standard contractual clauses).

6. How long we keep data

7. How we protect data

We adopt appropriate technical and organisational measures: encryption in transit (HTTPS), password hashing, encryption of payment tokens, role-based access controls, multi-tenant isolation, security event logging.

8. Your rights

As a data subject you may exercise, under Art. 15-22 GDPR, the rights of access, rectification, erasure ("right to be forgotten"), restriction, portability, and objection to processing based on legitimate interest, and withdraw consent where applicable without affecting prior processing.

To exercise them, write to privacy@binary-code.it. From your account area you can also, on your own, download your data (portability) and close your account (anonymising your personal data). Closing your account does not delete tax documents, which we are legally required to retain.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante, www.garanteprivacy.it) under Art. 77 GDPR.

9. Cookies

The site uses only technical storage and anonymous statistics without profiling cookies. See the Cookie Policy for details.

10. Changes

We may update this notice. The current version is always published on this page, with the date of last update.

Last updated: 2026-06-16.