Privacy

Privacy Policy

Last updated: 2026-07-13

This Privacy Policy explains how Chemotto S.r.l. (“ChemOtto”) processes personal data when you visit chemotto.com, use one of its regional versions, request a quotation or contact us. Our website is intended for business customers and their representatives: it has no user accounts, no behavioural advertising and no marketing profiles. This Policy should be read together with our Cookie Policy.

1. Data controller

The data controller is:

Chemotto S.r.l. Via Bocchetto 6, 20123 Milano, Italy VAT no. IT 14663780964 · REA MI-2799595 Email: info@chemotto.com · Telephone: +39 352 002 0128

ChemOtto has not appointed a Data Protection Officer. Questions and requests concerning personal data may be sent to the email address above.

2. Personal data we process

2.1 Website and technical data

When you access the website, our hosting, content-delivery and security infrastructure processes technical information necessary to deliver and protect it. Depending on the request, this may include your IP address; the date, time and URL of the request and the referring page; browser, device and user-agent information; browser language; an approximate country inferred by our content-delivery provider; HTTP headers and network or security signals; bot-detection information; and the regional-routing cookie described below.

Our own application is designed not to write IP addresses, email addresses or form contents to its logs. Your IP address is used transiently for exactly two application purposes: enforcing a submission rate limit (at most 5 submissions per minute per IP, held only for the rolling 60-second window) and Cloudflare Turnstile bot verification at form submission. This does not prevent our infrastructure providers from processing limited technical information in their own systems where necessary to deliver, secure and troubleshoot their services.

When you arrive at the main website address (chemotto.com/), an approximate country supplied by our content-delivery provider and your browser language are used to route you to a regional site version. A region cookie records the routing decision so later visits to the main address route the same way; it is set automatically during that redirect, holds nothing but a short region code, is renewed on each homepage visit for up to 12 months, and is read only server-side. Visitors who land directly on an inner page receive no cookie. Details are in the Cookie Policy.

2.2 Request-a-quote form

When you submit a quotation request, we process: your name; company name; business email address; telephone number, where provided; country; the products you are enquiring about (product names and CAS numbers, requested quantities and units, and grade, packaging and document information where provided — such as a technical data sheet, safety data sheet or certificate of analysis); your free-text message; the date and time of submission; and the version of this Privacy Policy presented with the form. A quotation request may contain up to 20 product line items.

2.3 Contact form

When you use the contact form, we process: your name; company name; business email address; telephone number, where provided; country; your message; the date and time of submission; and the version of this Privacy Policy presented with the form.

2.4 Internal request identifier

Our system assigns each quotation request an internal reference in the form REGION-LOCALE-DATE-SEQUENCE. It is used to organise and trace the request internally; because it is associated with your enquiry, we treat it as personal data for as long as that association exists. It is never shown to you, never placed in a URL or cookie, and is not used to track browsing activity. The daily counter behind it stores no personal data.

2.5 Information we do not request

We do not ask for special-category personal data (such as health, biometric or religious information). Please do not include such data, national identification numbers, payment-card details or unrelated personal information in free-text fields; if provided unrequested, it is not used beyond what the enquiry requires and is deleted or restricted where appropriate. Our services are directed at businesses and are not intended for children.

Responding to enquiries and quotation requests. We use form information to understand and answer your enquiry, prepare and send a quotation, discuss product, grade, packaging, logistics or availability requirements, supply requested technical or safety documents, and take other steps requested before a possible transaction. Where you are personally entering into a contract with ChemOtto — including as a sole trader — the legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to a contract). Where you contact us as an employee, director, agent or other representative of a company, the legal basis is Art. 6(1)(f) GDPR; our legitimate interests are responding to business enquiries, preparing commercial proposals and communicating with prospective and existing business customers through their representatives.

Operating, delivering and securing the website. Technical data is processed to deliver pages, route you to a regional site version, maintain availability, detect automated and abusive activity, enforce rate limits, verify Turnstile challenges and investigate incidents. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure, reliable business website.

Recording the privacy information presented with a form. We record the version of this Policy presented with the form and the server submission time, to demonstrate which privacy information was provided when the data was collected. Legal basis: Art. 6(1)(c) GDPR, in connection with our accountability and transparency obligations (Arts. 5(2), 12, 13, 24 GDPR). This record is not a consent and is not used as a marketing-consent record.

Website measurement. We use Cloudflare Web Analytics for aggregate information about site use and performance. As configured, it uses no cookies, no local storage and no fingerprinting; ChemOtto receives aggregate reports and cannot single you out in them. Cloudflare may process limited request and network information when generating and securing those reports. Legal basis: Art. 6(1)(f) GDPR.

Legal and regulatory compliance. Where an enquiry results in a transaction or business relationship, relevant information may be processed to comply with accounting, tax, customs, product-safety, sanctions or record-keeping obligations (Art. 6(1)(c) GDPR), and retained or used where necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR).

4. Required and optional information

Required form fields are identified in the form. They are needed to understand the enquiry, identify the relevant business customer and prepare a meaningful reply; without them we may be unable to respond. Telephone numbers and fields marked optional do not have to be provided.

5. Recipients and service providers

Within ChemOtto, access to personal data is limited to authorised personnel who need it for sales, sourcing, customer service, technical, administrative, legal or compliance purposes. Information may also be disclosed to professional advisers, auditors, insurers, banks, logistics providers or public authorities where necessary for a transaction, legal compliance or the protection of legal rights — limited to what the particular purpose requires.

Our principal service providers, acting as processors, are:

ProviderRoleLocation of processing
Cloudflare, Inc.Content delivery, network and application security, Turnstile bot verification, rate limiting, cookieless analytics, object storage holding the website’s static content, and the serverless layer that processes form requestsGlobal network; the website’s static content is stored under Cloudflare R2’s European Union jurisdiction; technical and form-related information may be processed in the EEA and other countries, subject to the safeguards in Section 6
Amazon Web Services (Amazon SES)Transactional delivery of your form submission to our business mailbox as an emailEU — Frankfurt (eu-central-1); limited processing may be performed by authorised AWS group companies or subprocessors outside that region under the applicable data processing agreement
Google Cloud Italy S.r.l. (Google Workspace)Business email — the mailbox where your submission is received, stored and answered (info@chemotto.com)Google’s global infrastructure; Google and its approved subprocessors may process information in the EEA and other countries under the applicable contract and transfer safeguards

Your submission is converted into an email notification and delivered via Amazon SES (Frankfurt) to info@chemotto.com; the email is sent from a ChemOtto-controlled address, and the address you supplied appears only in the reply-to field so that authorised personnel can answer you directly. Subsequent correspondence is handled in the same mailbox.

Our processors are contractually required to process personal data only on documented instructions, to provide appropriate security measures and to assist with data-protection obligations. Certain providers may separately process limited account, billing or service-usage information for their own purposes as described in their own privacy documentation. We do not sell personal data and do not provide form information to third parties for their own advertising or marketing.

6. International transfers

Some service providers and their subprocessors operate outside the European Economic Area. Where personal data is transferred to a country covered by a European Commission adequacy decision, the transfer may rely on that decision — including transfers to US organisations participating in the EU–US Data Privacy Framework, where the specific recipient holds a valid certification. Where no adequacy decision applies, transfers are protected by European Commission Standard Contractual Clauses (Art. 46 GDPR), together with supplementary contractual, organisational or technical safeguards where required. A description or copy of the relevant safeguard may be requested at info@chemotto.com; commercially confidential information may be redacted.

7. Retention

We retain personal data only as long as necessary for the relevant purpose, then delete or anonymise it, unless a longer period is required by law or needed for legal claims.

DataRetention
Enquiries that do not lead to a business relationship (quote and contact submissions and related correspondence)24 months after the last substantive communication, enforced through a documented periodic mailbox review; they may be deleted earlier when clearly no longer needed
Enquiries that result in a transaction or business relationshipRelevant information becomes part of the contractual and accounting records, retained for 10 years under Italian law (Art. 2220 Codice Civile), or longer where tax, customs or other law, an audit, a dispute or a legal claim requires
Privacy-notice record (Policy version + server timestamp)Same period as the related enquiry or customer record
Rate-limiting and Turnstile verification dataOnly for the short period needed to perform the check (the rolling 60-second rate window; Turnstile tokens are single-use)
Application logs (designed to contain no IP addresses, email addresses or form contents)Up to 7 days (the log window of our current serverless platform plan)
Aggregate service telemetry (no personal data)Approximately 90 days
Aggregate web analyticsApproximately 21 days in our current configuration
The region routing cookie12 months, renewed on homepage visits; deletable in your browser at any time

Deletion from active systems may not immediately remove information from protected backups; backup data is isolated from ordinary use and overwritten in accordance with the applicable backup cycle. Where a legal dispute, official request or the protection of our legal rights requires it, relevant data may be retained for the applicable limitation periods, limited to that purpose.

8. Security

We use appropriate technical and organisational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the system, these include encrypted HTTPS transmission; access restricted to business need; multi-factor authentication for administrative and mailbox access; server-side form validation; bot detection and rate limiting; controlled application and infrastructure permissions; monitoring and incident-response procedures; contractual security requirements for processors; and retention and deletion procedures. No internet transmission or storage system can be guaranteed completely secure.

9. Your rights

Subject to the conditions and exceptions in applicable data-protection law, you may request access to personal data concerning you, correction of inaccurate or incomplete data, deletion, restriction of processing, data portability (where processing is automated, based on a contract, and the legal requirements are met), and information about applicable international-transfer safeguards.

You may also object at any time to processing based on Art. 6(1)(f) GDPR. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.

Our website-form processing does not rely on consent, so withdrawal of consent is not the applicable mechanism for stopping the processing described here. Rights are not absolute: information may have to be retained where required by law or needed for legal claims.

To exercise a right, write to info@chemotto.com and describe your request clearly; we may ask for reasonable information to verify your identity. We normally respond within one month; where permitted by law, this may be extended by up to two further months for complex or numerous requests, in which case we will inform you.

10. Complaints

You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU country where you live or work or where you believe an infringement occurred. ChemOtto’s Italian supervisory authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it). We encourage you to contact us first at info@chemotto.com so that we can address the concern.

11. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not use the forms or analytics to profile individuals. Automated spam, bot and security assessments performed by our infrastructure serve only to protect the website. Quotations and substantive replies are prepared by authorised personnel.

12. Third-party websites

The website may link to external websites or documents operated by third parties. Their processing is governed by their own privacy information; ChemOtto is not responsible for their independent practices.

13. Changes to this Policy

We may update this Policy to reflect legal, technical or operational changes. The current version and its effective date are published on this page; where a change is material, we may provide additional notice through the website or another appropriate channel. The forms always link to the version in force at the moment of your submission, and a change does not retrospectively alter the legal basis on which data was originally processed.