Canonical public document
Owevaro Privacy Notice
> Published English translation confirmed by the owner on 17 August 2026. The Italian source remains canonical and prevails in the event of a discrepancy. The underlying document retains status in_review and effective_from: null.
Draft intended for professional review. The processing of real documents is not authorised. Email and calendar integrations are available only in an allowlisted private test operated by the controller; they are not open to the public.
Identity and contact details
Alin Daniel Epure, Italian VAT number 17835711007, Via Antonio Banfi 10, 00166 Rome, Italy. Current contact: info@lentita.com; certified email (PEC): a.epure@pec.it. Whether to introduce a dedicated Owevaro address remains an open decision; a non-existent contact address is not published.
Roles by purpose
Owevaro acts as an independent controller for registration, authentication, account and workspace management, security, logging, abuse prevention, support, complaints, privacy requests, legal obligations, establishment, exercise or defence of legal claims, operational communications and future billing.
Owevaro normally acts as a processor when a professional customer or organisation determines the purposes of the workspace and entrusts personal data on the basis of documented instructions and a final DPA. That business flow is closed.
In the consumer flow, the user is not assumed to be the controller for every item of counterparty data. The legal basis, necessity and Article 14 obligations concerning counterparties, representatives, signatories, collaborators and other named persons are still under assessment: real consumer documents remain prohibited.
Data, data subjects and sources
The Agency Summary aggregates amounts already recorded by customer and by an optional organisational group; Owevaro does not receive, hold or transfer funds.
Account and session data, declared capacity, notice/acceptance events, technical logs, workspace records and synthetic files. In the private integration test, following separate authorisations by the controller, Owevaro processes account/provider details, scopes, encrypted tokens and — for no more than 25 recent emails — the technical identifier, subject line, sender and date received. Message bodies, previews and attachments are neither requested nor retained. Only messages containing an explicit date in the subject generate a proposal. Potential data subjects in future real documents include users, creators, counterparties, representatives, signatories, collaborators and named persons. Data comes from the user, authorised members and, only after the relevant gates have been opened, uploaded documents.
Special categories of personal data, data relating to criminal convictions and offences, and minors' data are permanently excluded from the service. No plan or exemption permits their upload, storage or analysis. A user declaration, generic consent or DPA does not make their processing admissible within Owevaro.
Purposes and candidate legal bases
| Purpose | Role | Operational basis | Status |
|---|---|---|---|
| Account, access and requested functions | controller | Article 6(1)(b), limited to the contracting user | in_review |
| Security, abuse prevention and defence of claims | controller | Article 6(1)(f), with necessity/balancing test still to be completed | in_review |
| Tax obligations and lawful requests | controller | Article 6(1)(c), where applicable | future |
| Business customer content | processor | instructions and legal basis of the customer acting as controller | CLOSED |
| Third-party data in the consumer flow | possible controller | legal basis and Article 14 position not final | BLOCKED |
| Email and calendar in the allowlisted private test | controller | Article 6(1)(b) for the function requested by the controller; separate and revocable OAuth authorisation | PRIVATE_TEST_ONLY |
| Future payments through Stripe Managed Payments | controller for the account/user relationship; Stripe roles by purpose to be validated | contract and legal obligations, only after the gate is opened | PREPARED_CLOSED |
| Email and calendar for public users, external AI and Usage Watch | to be classified by purpose | no current authorisation | CLOSED |
OAuth authorisation is a technical permission and is not the same as a GDPR legal basis. Google uses the restricted gmail.metadata scope; Microsoft uses the delegated Mail.ReadBasic permission. Both exclude message bodies, previews and attachments from the requested scope. Calendar scopes technically permit event management, but Owevaro uses only the creation of an event selected and confirmed by the user; it does not import the calendar and does not create events automatically.
Cookies, local storage and PWA
No advertising cookies, profiling, fingerprinting or optional analytics are active on the Owevaro domain. The browser stores only necessary technical items: the preference recording dismissal of the notice, the Supabase session after login, a temporary timestamp used to recover from loading errors, and static PWA resources through the Service Worker and Cache Storage. The PWA cache is not designed to store contracts or workspace records. The inventory, keys and durations are described in COOKIE-STORAGE-POLICY.md.
If the user chooses Google, Microsoft or Apple, the provider's external pages may use their own technologies under their respective notices. Server and provider logs, which may include IP address, user agent, time, route and response code, are distinct from data stored in the browser. The Owevaro notice is informational and closing it does not express consent.
Optional service feedback
The user may voluntarily submit a category and text to help improve Owevaro. These are associated with the account identifier and date. The purpose is service improvement, with a candidate basis under Article 6(1)(f) GDPR and a balancing test still in_review. The interface warns users not to enter contracts, customer data, special-category data or other third-party personal data. The proposed maximum retention period is 12 months; the data is also deleted with the account.
Providers and locations
The repository documents Supabase Free for identity/database/storage in eu-west-2 (London), with DPA Version 1 and Supabase Pte. Ltd., and two Hostinger KVM 4 VPSs in Frankfurt for frontend, API, file controls and technical logs, covered by the DPA for VPS Services. Vercel is not part of the current production flow and is retained temporarily only as an inactive rollback. Google, Apple and Microsoft may take part in login where configured; Gmail, Google Calendar, Outlook and Microsoft Calendar take part only in the authorised private test. Stripe live and Managed Payments are prepared, but SALES_ENABLED=false prevents all checkout activity; for future enabled transactions, Stripe states that it acts as merchant of record and processes the data needed for orders, payments, taxes, receipts, refunds, disputes and fraud prevention under its terms. Vertex AI and Resend remain blocked or future. Subprocessor lists and SCCs are documented; onward access, an updated Supabase TIA and Hostinger's geographical matrix remain subject to provider responses and professional review before real data is processed.
The United Kingdom is covered by the current EU adequacy decision identified in LEGAL-SOURCES.md. Any other transfers require an applicable safeguard, verification of actual access and supplementary measures. A primary region does not prove the absence of access from outside that region.
Retention, deletion and restoration
Periods are defined by system in RETENTION-POLICY.md. In the prepared local flow, the uploaded original remains in quarantine only for antivirus scanning, reconstruction, OCR and extraction, and is deleted on completion; it is not promoted to durable document storage or included in the self-managed backup. Minimized upload metadata, evidence of the policy applied, structured data and user-confirmed citations remain. Active deletion does not amount to a general promise concerning providers' internal backups, which remains subject to professional review. Real documents remain blocked until the gate is opened.
Rights and complaints
Requests may be sent to the contact details above. Where applicable, Owevaro handles access, rectification, erasure, restriction, portability and objection. The standard GDPR time limit is one month and may be extended in the circumstances provided by law, subject to informing the data subject. Verification of the requester's identity, scope, system searches, response and evidence are governed by DSAR-PROCEDURE.md. A complaint may be lodged with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
Security, breaches, automation and minors
The code contains controls for TLS, RLS, private buckets, quarantine and file analysis; their effectiveness in external environments remains at the evidentiary level stated in the evidence register. The personal data breach runbook is documented but not operational. No solely automated decisions producing legal or similarly significant effects are envisaged. The service is restricted to adults; the age declaration is not strong identity or age verification.