Last updated: [[1 September 2026]]
Effective date: [[1 September 2026]]
This Privacy Policy explains how AvvocatoVeloce (“Automight”, “we”, “us”) collects, uses, stores, shares and protects personal data when you visit avvocatoveloce.pro contact us, or use the automation systems and applications we operate (together, the “Services”).
1. Who we are
Data controller
Automight LLC
30 N Gould Street, Sheridan, WY 82801, United States
Email: [email protected]
Phone: +1 331-373-4112
For the personal data we process on behalf of our clients while building and running their automation systems, our client is the data controller and Automight acts as a data processor under a separate data processing agreement. This policy describes our own processing as a controller, and explains our practices generally so that end users understand how their data is handled.
2. What data we collect
2.1 Data you give us
- Contact and booking data: name, email address, phone number, company name, website, and anything you write in a form or in a strategy-session booking.
- Client and project data: billing details, contract information, technical documentation, credentials and access you grant us to build or maintain your systems.
- Correspondence: emails, messages and call recordings or notes, where you have been informed and, where required, have consented.
2.2 Data we collect automatically
- Technical data: IP address, browser type and version, device type, operating system, language, referring URL.
- Usage data: pages visited, time on page, clicks, and similar analytics events.
- Cookies and similar technologies: see our Cookie Policy for the full list and for how to change your choices.
2.3 Data we receive from third parties
We may receive data from advertising and analytics platforms, from tools our clients connect to their systems, and from Google APIs where you have explicitly authorised access (see section 3).
3. Google user data
Where our applications connect to Google services, they do so only after you have signed in with Google and granted permission on Google’s own consent screen. You control that permission and can withdraw it at any time.
3.1 Scopes we request and why
| Scope | What it allows | Why we need it |
|---|---|---|
userinfo.email / userinfo.profile / openid | Read your basic profile: name, email address, profile picture. | To identify your account, create your session and contact you about the service. |
[[gmail.readonly / gmail.send / gmail.modify]] | [[Read, send or organise messages in your Gmail mailbox.]] | [[To run the email automations you configure — for example reading incoming leads and sending the replies you have set up.]] |
[[calendar.events]] | [[Read and create events in your Google Calendar.]] | [[To book, reschedule and sync appointments generated by your funnel.]] |
[[spreadsheets / drive.file]] | [[Read and write the specific Google Sheets and Drive files you select.]] | [[To read and write the data your automations and reports depend on.]] |
We request the narrowest scopes that make the features you asked for work. We do not request scopes for features you have not enabled.
3.2 How we use, store and share Google user data
- We use Google user data only to provide and improve the user-facing features you have explicitly enabled.
- Data is transmitted over TLS and stored encrypted at rest on [[our servers hosted at provider / region]]. OAuth tokens are stored encrypted and are accessible only to the processes that need them.
- We do not sell Google user data, and we do not use it for advertising, profiling, credit assessment or any purpose unrelated to the feature you enabled.
- We do not transfer Google user data to third parties except: (a) sub-processors strictly necessary to operate the service, bound by equivalent obligations; (b) where you have given explicit consent; (c) where required by law.
- We do not allow humans to read your Google user data, except: with your explicit consent for specific messages or files; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data is aggregated and anonymised for internal operations.
- We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models. Where a feature you enabled sends content to an AI provider to produce your requested output, that content is processed only for that request and is not used by us or by the provider to train models.
3.3 Limited Use disclosure
Automight’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.4 Revoking access and deleting your data
You can revoke our access at any time from your Google Account at myaccount.google.com/permissions. Revoking access stops all further data retrieval immediately.
To have the Google user data we hold deleted, write to [[[email protected]]]. We delete it within 30 days of the request, and in any case within 30 days of your account being closed, except where retention is required by law.
4. Why we process your data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Replying to enquiries and preparing proposals | Steps taken at your request prior to entering a contract |
| Delivering the Services and supporting your systems | Performance of a contract |
| Invoicing, accounting, tax and legal records | Legal obligation |
| Security, fraud prevention and service improvement | Legitimate interests |
| Non-essential cookies, analytics and marketing communications | Consent |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
5. Who we share data with
We do not sell personal data. We share it only with service providers that help us run the business, each bound by contract to process it solely on our instructions:
- Hosting and infrastructure providers [[e.g. Hetzner, Cloudflare]]
- Automation and workflow platforms [[n8n (self-hosted), Make.com, Zapier]]
- CRM and communication tools [[GoHighLevel, Google Workspace]]
- Analytics and advertising platforms [[GetInsights, Google Analytics, Meta]]
- Payment and invoicing providers [[Stripe, …]]
- Professional advisers, and public authorities where the law requires it
6. International transfers
Automight is established in the United States and operates from [[Malta]]. Personal data originating in the European Economic Area may therefore be transferred outside it. Where that happens, we rely on the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, together with appropriate technical and organisational safeguards.
7. How long we keep data
- Enquiries that do not become projects: 24 months from the last contact.
- Client and contract data: for the duration of the relationship plus 10 years, for accounting and legal purposes.
- Google user data and OAuth tokens: for as long as your integration is active; deleted within 30 days of revocation, account closure or a deletion request.
- Analytics data: [[14 months]].
8. How we protect data
We use TLS in transit, encryption at rest, role-based access control, least-privilege credentials, multi-factor authentication on administrative accounts, logging, and regular backups. No system is perfectly secure, but we keep these measures under review and will notify you and the competent supervisory authority of a personal data breach where the law requires it.
9. Your rights
Depending on where you live, you may have the right to: access your data; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and opt out of the sale or sharing of personal data (we do not sell it). To exercise any of these, write to [[[email protected]]] We reply within 30 days.
If you are in the EEA and believe we have handled your data unlawfully, you may lodge a complaint with your national data protection authority.
10. Children
The Services are for businesses and are not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Cookies
We use technical cookies and, with your consent, analytics and marketing cookies. Full details and controls are in our Cookie Policy.
12. Changes to this policy
We may update this policy. The current version is always at automight.io/privacy-policy, with the revision date at the top. Where changes are significant, we will notify you by email or a notice on the site before they take effect.
13. Contact
Automight LLC — 30 N Gould Street, Sheridan, WY 82801, United States
[[[email protected]]]
14. Utilizzo di ZOOM
2. Dati Raccolti tramite Zoom (Integrazione Video)
AvvocatoVeloce permette agli utenti con ruolo avvocato di collegare il proprio account Zoom tramite protocollo OAuth per generare automaticamente i link per le videocall quando un cliente prenota un appuntamento.
2.1 Dati raccolti e Autorizzazioni
Durante il processo di collegamento, l’applicazione richiede le autorizzazioni necessarie per leggere il profilo di base e creare riunioni pianificate. (Le etichette esatte degli scope sono configurate nel portale Zoom dal titolare).
- ID Utente Zoom e ID Account: necessari per associare in modo univoco il tuo account Zoom al tuo account AvvocatoVeloce.
- Nome, Cognome e Indirizzo Email: utilizzati esclusivamente per visualizzare nel pannello di controllo quale account Zoom hai collegato, rassicurandoti sulla corretta associazione.
- Access & Refresh Token (OAuth): indispensabili per comunicare con le API di Zoom per tuo conto.
- Metadati delle riunioni create: quando viene confermato un appuntamento, AvvocatoVeloce crea una riunione su Zoom e salva localmente l’ID della riunione (Meeting ID) e il link di partecipazione (Join URL) associandoli all’appuntamento. Trasmettiamo a Zoom il titolo, la data/ora di inizio, la durata e il fuso orario, impostando la sala d’attesa attiva. Non effettuiamo letture, aggiornamenti o cancellazioni delle riunioni preesistenti o create.
2.2 Finalità del trattamento
Questi dati vengono utilizzati esclusivamente per:
- Creare le riunioni virtuali su richiesta (quando un appuntamento viene fissato nel calendario di AvvocatoVeloce).
- Restituire il link della riunione in modo da poterlo inviare al cliente e al legale.
- Gestire la revoca dell’accesso quando decidi di scollegare l’account.
AvvocatoVeloce NON registra, NON trascrive, né archivia l’audio o il video delle riunioni. Non effettuiamo letture delle riunioni preesistenti nel tuo account Zoom.
2.3 Conservazione e Sicurezza dei Dati (Storage e Protezione)
I token OAuth (Access Token e Refresh Token) sono salvati nei nostri database.
- Crittografia at rest: I token sono crittografati a riposo (at rest) utilizzando l’algoritmo AES-256-GCM.
- Nessuna esposizione: Nessun token (o segreto API) viene mai esposto, trasmesso o memorizzato nel browser del client. L’aggiornamento dei token avviene interamente lato server su canali HTTPS.
I dati del profilo Zoom e i token associati vengono mantenuti finché l’account Zoom risulta collegato ad AvvocatoVeloce. In caso di disconnessione dall’app o rimozione dal Marketplace Zoom, i token locali e la riga del profilo vengono eliminati. La rimozione dal Marketplace viene comunicata tramite un webhook Zoom di deautorizzazione, accettato solo dopo la verifica crittografica della firma e della validità temporale dell’evento. Tuttavia, gli ID e i link delle riunioni (Meeting ID / Join URL) associati agli appuntamenti restano nei record degli appuntamenti. L’eliminazione dello storico account deve essere richiesta al supporto; il titolare deve verificare e documentare prima dell’invio gli eventuali obblighi di conservazione applicabili.
2.4 Condivisione dei Dati
I dati raccolti tramite l’integrazione Zoom non vengono venduti, affittati o condivisi con terze parti per scopi di marketing o pubblicitari. Sono comunicati a Zoom per autorizzare l’account e creare le riunioni richieste; possono inoltre essere trattati dai fornitori infrastrutturali che ospitano l’applicazione e il database, nei limiti necessari all’erogazione e alla protezione del servizio.
Zoom e i fornitori infrastrutturali possono trattare dati fuori dallo Spazio Economico Europeo. Prima della pubblicazione, il titolare deve verificare ruoli privacy, localizzazione dei dati, basi giuridiche e garanzie applicabili ai trasferimenti internazionali.
2.5 Revoca, Disconnessione e Cancellazione
Puoi revocare l’accesso in qualsiasi momento direttamente dall’interfaccia di AvvocatoVeloce (alla voce Impostazioni > Riunioni Zoom).
- Quando esegui la disconnessione, AvvocatoVeloce invia una richiesta alle API di Zoom per revocare i token.
- Subito dopo, il record locale contenente i tuoi dati utente Zoom e i token cifrati viene eliminato dai nostri server, indipendentemente dal successo della chiamata di revoca remota.
- Se rimuovi AvvocatoVeloce dal Marketplace Zoom, Zoom invia un evento di deautorizzazione firmato. Dopo averne verificato autenticità e data, AvvocatoVeloce elimina automaticamente lo stesso record locale; eventuali consegne duplicate non producono errori né conservano copie aggiuntive.
- Nota bene: AvvocatoVeloce non aggiorna né elimina le riunioni precedentemente create nel tuo account Zoom. Per gestire o rimuovere quelle riunioni, o revocare l’accesso lato Zoom, puoi visitare il Zoom App Marketplace (Installed Apps).
3. I tuoi Diritti
Ai sensi della normativa vigente, hai il diritto di richiedere l’accesso, la rettifica, l’aggiornamento o la cancellazione permanente dei tuoi dati personali (inclusi i dati acquisiti tramite Zoom). Puoi consultare la documentazione nella nostra Guida Zoom o inviare una richiesta formale di cancellazione dei dati (Data Deletion Request) a [email protected]
Avviso sui requisiti di conformità
I controlli tecnici descritti includono crittografia AES-256-GCM at-rest per i token OAuth e comunicazioni verso Zoom via HTTPS. Non rivendichiamo certificazioni formali SOC 2, ISO 27001, test di penetrazione esterni indipendenti, DAST, SAST o SSDLC.