Skip to main content

Privacy and Cookie Policy of strobopost.com

General Information

This Privacy and Cookie Policy describes how STROBOPOST S.R.L. collects, uses, stores, and protects the personal data of users who visit the website strobopost.com, hereinafter also referred to as the “Website”.

This Policy is provided pursuant to Regulation (EU) 2016/679 (the General Data Protection Regulation, or “GDPR”), Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, and the applicable legislation concerning cookies and tracking technologies.

This Policy applies exclusively to this Website. It does not apply to any external websites, platforms, or services that may be accessed through links contained on the Website.

Data Controller

The Data Controller is:

STROBOPOST S.R.L.
Piazzale Italia, 279
55100 Lucca (LU), Italy
VAT Number and Tax Code: 02669370468
Email: info@strobopost.com
Phone: +39 349 758 1024

Requests concerning the protection of personal data or the exercise of data subject rights may be sent to the email address indicated above.

Types of Data Processed

Browsing Data

During normal operation of the Website, the IT systems and software procedures used may automatically collect certain information whose transmission is inherent in the use of Internet communication protocols.

Such information may include:

  • IP address;
  • date and time of the request;
  • address of the requested page;
  • method used to submit the request to the server;
  • server response code;
  • browser type and version;
  • operating system;
  • device used;
  • referring page;
  • technical information relating to the connection;
  • errors and diagnostic data.

This data is used to enable the operation of the Website, ensure its security, identify anomalies or attempted unauthorized access, and obtain technical statistical information.

Data Provided Through the Contact Form

When a user submits the form available on the Contact page, the following data may be collected:

  • first name;
  • last name;
  • VAT number;
  • company name;
  • telephone number;
  • email address;
  • type of request;
  • products of interest;
  • information entered in the description field;
  • any other information voluntarily provided by the user.

Users are requested not to include unnecessary information, personal data relating to third parties without authorization, or special categories of personal data, such as information concerning health, religious beliefs, political opinions, or sex life.

Data Provided by Email or Telephone

When users contact STROBOPOST directly by email or telephone, the contact details and information necessary to understand and handle the request are processed.

Data Relating to Security and Spam Prevention

The contact form is protected by Cloudflare Turnstile, a service used to distinguish requests submitted by genuine users from automated requests and to prevent spam, bots, and abusive use.

For verification purposes, Cloudflare Turnstile may process technical information relating to the browser, device, and connection, including the IP address, user agent, technical connection characteristics, information necessary to verify the browser, the originating domain, the widget identifier, and the result of the anti-spam verification.

Once the verification has been completed, a temporary token is generated and submitted together with the form. The token is then verified server-side by STROBOPOST through the Cloudflare Siteverify service.

The token is used exclusively to verify the legitimacy of the request and is not used by STROBOPOST for advertising, statistical analysis, or commercial profiling purposes.

Purposes and Legal Bases of Processing

Website Operation and Security

Browsing data is processed in order to:

  • display Website pages correctly;
  • ensure service stability;
  • prevent attacks, unauthorized access, and fraudulent activity;
  • detect technical errors;
  • perform maintenance and diagnostics;
  • protect IT systems and the rights of the Data Controller.

The legal basis for this processing is the Data Controller’s legitimate interest in ensuring the security and proper operation of the Website, pursuant to Article 6(1)(f) of the GDPR.

Handling Requests for Information, Support, Demos, and Quotations

Data provided through the form, by email, or by telephone is processed in order to:

  • respond to requests;
  • provide information about products;
  • arrange a demonstration;
  • prepare a quotation;
  • contact the user;
  • provide technical or commercial support;
  • understand the characteristics of the industrial application described.

The legal basis for this processing is the performance of pre-contractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR.

Where a request is submitted on behalf of a company or organization, the processing may also be based on the Data Controller’s legitimate interest in managing professional and commercial relationships.

Contractual, Administrative, and Legal Obligations

If a commercial or contractual relationship results from a request, personal data may be used to:

  • prepare quotations and orders;
  • perform the contract;
  • arrange deliveries and support;
  • manage payments and invoicing;
  • comply with tax, accounting, and administrative obligations;
  • manage warranties, claims, and product-related liabilities.

The legal bases for such processing are the performance of a contract and compliance with legal obligations, pursuant to Article 6(1)(b) and (c) of the GDPR.

Prevention of Spam and Abusive Use

Technical data processed through Cloudflare Turnstile is used to protect the contact form, prevent automated submissions, and ensure the security of the Website.

The legal basis is the Data Controller’s legitimate interest in protecting its systems and preventing fraud and abuse, pursuant to Article 6(1)(f) of the GDPR.

Cloudflare Turnstile is classified within the Website’s preference management system as a Functional/necessary service because it is used exclusively for security and form protection purposes.

The service is therefore always active and is not subject to the user’s consent.

Preference Management and Documentation of Consent

The Website uses the Consent Manager integrated into YOOtheme Pro to allow users to manage their preferences concerning services and tools that are not strictly necessary.

Services may be classified under the following categories:

  • Functional;
  • Preferences;
  • Statistics;
  • Marketing.

Services classified as Functional are necessary for the proper operation or security of the Website and are therefore always active. Any services belonging to the other categories are activated only in accordance with the preferences expressed by the user.

Preferences are stored using a first-party technical mechanism in order to remember the user’s choice and avoid displaying the consent panel on every page visited.

STROBOPOST also uses an internal system to document the preferences expressed by users for accountability purposes and to provide evidence that consent has been properly obtained.

The register contains:

  • a pseudonymous identifier associated with the user’s choice;
  • date and time of the event;
  • categories or services accepted and rejected;
  • version of the applicable policy and/or consent banner;
  • any subsequent changes or withdrawals.

This information is used exclusively to document and manage privacy preferences and is not used for profiling, advertising, or analysis of user behavior.

The legal basis for this processing is compliance with accountability obligations under data protection legislation and the Data Controller’s legitimate interest in being able to demonstrate the proper management of the preferences expressed by users.

Establishment, Exercise, or Defense of Legal Claims

Personal data may be retained and used where necessary to establish, exercise, or defend the Data Controller’s rights in judicial or extrajudicial proceedings.

The legal basis for this processing is the Data Controller’s legitimate interest in protecting its rights.

Provision of Personal Data

The provision of browsing data is necessary in order to use the Website.

The provision of data marked as mandatory in the contact form is necessary in order to handle the request. Failure to provide such data may prevent the form from being submitted or make it impossible to provide an adequate response.

All other data is optional and may be provided freely by the user.

Acknowledging the Privacy Policy does not constitute consent to processing for promotional purposes. Processing required to respond to a request is based on the pre-contractual measures requested by the user.

The Website does not use data submitted through the form to automatically subscribe users to newsletters or recurring promotional communications.

Processing Methods and Security Measures

Personal data is processed using electronic tools and, where necessary, paper-based records.

The Data Controller adopts appropriate technical and organizational measures to reduce the risk of:

  • loss of data;
  • unauthorized access;
  • unlawful alteration or disclosure;
  • accidental destruction;
  • use incompatible with the stated purposes;
  • cyberattacks or abusive automated submissions.

Access to personal data is limited to authorized persons who require such access in order to perform their duties.

Data Retention Period

Personal data is retained only for as long as strictly necessary for the purposes for which it was collected.

In particular:

  • technical and security logs are normally retained for a limited period proportionate to security requirements, unless longer retention is necessary to investigate incidents, abuse, or attacks;
  • requests for information, quotations, or demos are retained for as long as necessary to manage the contact and, as a general rule, for no longer than 24 months after the last meaningful communication;
  • data relating to contractual relationships, orders, invoices, and administrative obligations is retained for the period required by applicable law, normally 10 years;
  • data required to manage claims or disputes may be retained until the relevant procedure has been completed and the applicable limitation periods have expired;
  • technical tokens generated by anti-spam systems are retained only for the time required to verify the request;
  • preferences relating to cookies and other services are retained for the period determined by the consent management system and may be updated or withdrawn by the user at any time;
  • server-side records relating to users’ expressed preferences are retained according to criteria proportionate to the need to document the validity of the choice, any subsequent changes or withdrawals, and compliance with accountability obligations. Records that are no longer necessary are periodically deleted.

At the end of the applicable retention periods, personal data is deleted, anonymized, or retained only where required by law.

Recipients of Personal Data

Personal data may be disclosed, where necessary, to:

  • STROBOPOST employees, collaborators, and authorized personnel;
  • hosting and IT infrastructure providers;
  • email service providers;
  • parties responsible for Website maintenance;
  • system administrators;
  • security and spam-prevention service providers;
  • administrative, tax, legal, and technical advisers;
  • carriers, distributors, or commercial partners where necessary to handle a specific request;
  • public authorities, judicial authorities, or law enforcement agencies where required by law.

Where required, providers processing personal data on behalf of the Data Controller are appointed as data processors pursuant to Article 28 of the GDPR.

Personal data is not sold.

Transfers to Countries Outside the European Economic Area

Certain technology providers, including Cloudflare, may operate through internationally distributed infrastructure.

Where personal data is transferred to countries outside the European Economic Area, such transfers take place in accordance with Chapter V of the GDPR, on the basis of an adequacy decision or appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission and any applicable supplementary measures.

Cloudflare Turnstile

The Website uses Cloudflare Turnstile, provided by Cloudflare, Inc., to protect the contact form against spam, bots, and automated requests.

Turnstile performs technical checks on the browser, device, and connection and generates a temporary token associated with the verification.

The token is transmitted to the STROBOPOST server together with the request and validated through the Cloudflare Siteverify service. The Secret Key used for verification is stored exclusively server-side and is never transmitted to the user’s browser.

Turnstile is used exclusively for security and abuse-prevention purposes and is not used by STROBOPOST for advertising, remarketing, statistical analysis, or commercial profiling.

Within the Website’s Consent Manager, Cloudflare Turnstile is classified as a Functional service required for form security and is therefore always active.

Further information concerning Cloudflare’s processing activities is available in Cloudflare’s documentation and Privacy Policy.

Cookies and Other Tracking Technologies

What Are Cookies?

Cookies are small pieces of data that a website may store in a user’s browser while they are browsing.

Other technologies, such as local identifiers, scripts, pixels, tokens, and browser storage mechanisms, may perform similar functions. Where appropriate, these technologies are collectively referred to in this Policy as “Tracking Technologies”.

Technical Cookies

The Website may use cookies or other technical tools that are strictly necessary to:

  • enable navigation;
  • ensure security;
  • prevent spam and abuse;
  • store privacy preferences;
  • maintain the proper operation of pages and forms.

These tools are not used for profiling or behavioral advertising and do not require prior consent, without prejudice to the obligation to provide users with appropriate information.

List of Cookies and Technologies Used

Cloudflare Turnstile

Provider: Cloudflare, Inc.
Purpose: form security, bot detection, and spam prevention.
Data processed: IP address, user agent, TLS fingerprint, technical browser and connection information, originating domain, and verification result.
Category: necessary/security.
Legal basis: legitimate interest in ensuring Website security.

In its standard configuration, Turnstile may use tokens and other temporary technical mechanisms necessary to complete the verification process.

Cookie Used to Store Privacy Preferences

Name: yootheme_consent
Provider: STROBOPOST / YOOtheme Pro
Domain: strobopost.com
Purpose: to store the preferences expressed by the user through the Consent Manager, restore the selected preferences during subsequent visits, and manage any later changes.
Category: technical / Functional / necessary.
Duration: 30 days.

This cookie is strictly necessary for managing privacy preferences and is not used for advertising, profiling, or analysis of user behavior.

Its use does not require separate consent because it is necessary to remember and document the privacy choice made by the user.

WordPress Administration Area Cookies

The Website’s administration area, which is reserved exclusively for authorized users, may use WordPress cookies required to verify cookie support, authenticate administrators, and protect login sessions.

These may include:

Name: wordpress_test_cookie
Purpose: to verify whether the browser accepts cookies.
Category: technical.
Duration: session.
Recipients: exclusively users who access the WordPress login page.

These cookies are not normally installed when users simply browse the public pages of the Website.

Analytics, Advertising, and Profiling Cookies

As of the last update of this Policy, the Website does not use:

  • Google Analytics;
  • Google Tag Manager for tracking purposes;
  • Meta Pixel;
  • LinkedIn Insight Tag;
  • advertising cookies;
  • remarketing systems;
  • behavioral profiling tools.

If any such services are introduced in the future, this Policy will be updated and any tools that are not strictly necessary will remain blocked until the user has provided the required consent.

Links to YouTube and Social Networks

The Website may contain links to YouTube, Facebook, Instagram, LinkedIn, or other external websites.

Where such services are provided exclusively as links, no content or cookies from the external platform are loaded merely as a result of browsing the Website.

If the user selects one of these links, they leave strobopost.com and access the external platform. From that point onwards, personal data is processed by the relevant provider in accordance with its own privacy and cookie policies.

Managing and Changing Preferences

Users may change their previously expressed preferences at any time by selecting the “Cookie Settings” link available in the Website footer.

Changes to preferences take effect for subsequent loading of the relevant services.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Managing Cookies Through the Browser

Users may view, delete, or block cookies through their browser settings.

Disabling technical cookies or security tools may prevent certain Website features from operating correctly, including submission of the contact form.

Cookie management procedures vary depending on the browser used. Relevant instructions are normally available in the privacy or security sections of Google Chrome, Mozilla Firefox, Apple Safari, Microsoft Edge, Brave, and Opera.

Automated Decision-Making and Profiling

STROBOPOST does not use personal data collected through the Website to make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject.

No commercial profiling of Website users is carried out.

Automated checks performed by Cloudflare Turnstile are used exclusively for security purposes and to identify automated or potentially abusive requests.

Data Subject Rights

Where provided for by the GDPR, data subjects may exercise the following rights:

  • obtain confirmation as to whether personal data concerning them is being processed;
  • obtain access to their personal data;
  • request correction of inaccurate data;
  • request completion of incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive personal data in a structured, commonly used, and machine-readable format, where applicable;
  • request transmission of personal data to another controller, where technically feasible;
  • withdraw consent at any time in relation to processing activities based on consent;
  • not be subject to decisions based solely on automated processing in the circumstances provided for by law;
  • lodge a complaint with the competent supervisory authority.

Requests to exercise these rights may be sent to:

info@strobopost.com

The Data Controller may request information that is strictly necessary to verify the identity of the person submitting the request.

Complaint to the Supervisory Authority

A data subject who believes that the processing of their personal data infringes applicable data protection legislation may lodge a complaint with the:

Italian Data Protection Authority
(Garante per la protezione dei dati personali)

This is without prejudice to the data subject’s right to seek judicial remedies before the competent courts.

Data Relating to Minors

The Website and the products presented are primarily intended for businesses, professionals, and industrial operators.

The Data Controller does not intend to knowingly collect personal data relating to minors through the Website. If a minor has provided personal data without the authorization of a person exercising parental responsibility, a request for deletion may be submitted by contacting the Data Controller.

Changes to This Policy

The Data Controller may update this Privacy and Cookie Policy in order to reflect:

  • changes in applicable legislation;
  • decisions or guidance issued by supervisory authorities;
  • changes to the services used;
  • the introduction of new features;
  • changes to processing activities.

The updated version will be published on this page and will indicate the date of the latest revision.

Last updated: 18 September 2026.

© STROBOPOST S.R.L. All rights reserved.

VAT number: 02669370468