imPC@ndo IT

Privacy

What this site knows about you, which is very little.

In short

This site has no sign-up, no comments, no contact form, no newsletter and uses no cookies. There is no analytics tool, no social button, no advertising and no profiling.

The only personal data of yours that passes through here is what any web server records in order to answer you: the IP address of the request. The rest of this page explains what happens to it.

Who processes the data

The data controller is Alessio Rosati, who runs impicciando.it in a personal capacity.

For anything concerning this page or your data: [email protected].

What the site collects

Technical logs. The site is hosted on Cloudflare Pages. Like any web server, the infrastructure records for each request the IP address, date and time, the page requested, the browser type and the referring page if present. They exist to deliver pages, to defend the site against attacks and to notice when something breaks.

CVE tracker search terms. When you use the search box, what you type travels in the page address (?q=…) and therefore ends up in the technical logs along with the rest of the request. It is not stored anywhere else, not tied to you and not used to build a profile. Still worth knowing: do not type into that box anything you would not put in a URL.

Nothing else. There are no accounts, no cart, no members' area. If you email me, I read it myself and it stays in my mailbox: it does not enter any contact management system.

Why I am allowed to

The legal basis for technical logs is legitimate interest (Art. 6(1)(f) GDPR) in delivering the service and protecting it from abuse. It is the bare minimum for a web page to reach you: without your IP the server would not know where to send the answer.

Who it is shared with

Cloudflare, Inc. — provides hosting and the delivery network, and acts as a data processor. Data may be processed outside the European Economic Area on the basis of the standard contractual clauses approved by the European Commission. Cloudflare's notice: cloudflare.com/privacypolicy.

Nobody else. Data is not sold, transferred or shared for commercial or advertising purposes, because this site has no commercial or advertising purposes.

For how long

Technical logs are retained by Cloudflare for the period set by its default configuration, in the order of a few days, then deleted. I keep no separate copies and build no archives from them.

The data published in the tracker is not personal data

The CVE tracker publishes information about software vulnerabilities, taken from NVD (NIST), CISA KEV and EPSS (FIRST). It concerns products and versions, not people. These are public, free sources, cited on every page.

Links to other sites

CVE pages link to vendor advisories and original sources, and the guides cite third-party documentation. Once you leave here, that site's notice applies, not this one: I have no way to control what they do, and I will not make declarations on their behalf.

Your rights

You may at any time request access to your data, its correction, its erasure, restriction of processing, object to processing, and receive it in a readable format (Arts. 15-22 GDPR). Write to [email protected].

An honest caveat: since I collect no identifiers beyond the technical ones, in most cases I cannot link a log entry to a person, and so I cannot satisfy an access request unless you give me further elements. This is not an excuse to ignore you: it is the reason there is little to hand back.

If you believe the processing infringes the GDPR you may contact the Italian Data Protection Authority or the supervisory authority of your country of residence.

Changes

If the site changes — say I one day add an analytics tool — this page will change first, not afterwards, and the date below will say so. Previous versions remain in the repository history.

Last updated: 14 August 2026 · Cookie policy