This is a courtesy translation. In case of any discrepancy, the Italian version prevails. The Italian text is the legally binding one, and the references it makes — the Italian Data Protection Authority, its guidelines of 10 June 2021, the consumer's court of jurisdiction — are those of Italian law.
Privacy notice
How we process your data
Agenticodice is a free course. Most of the course can be read without registering; the account is used to save your progress, take the Diagnostic with memory, take the certification and receive the credential. This page sets out what data we process, why, for how long and with whom — describing the system as it is, not a template.
Version dated 15 August 2026 · Data controller: Giuseppe Citerna · giuseppe.citerna@gmail.com
1. Who the data controller is
The data controller is Giuseppe Citerna. For any request about your data, write to giuseppe.citerna@gmail.com. No data protection officer (DPO) has been designated: the point of contact for every request is the data controller.
2. What data we process
| Category | Data | When |
|---|---|---|
| Account | email, password (stored only as a hash), verification status, registration date, registration origin (e.g. from the course, from the Diagnostic), status of the full-access request (pending, approved, rejected) with date and any note from the data controller | when you create an account |
| Login sessions | for each login: session fingerprint, browser type (user agent) and a hashed fingerprint of the IP address — never the address in clear text — to recognize and revoke logins | at each login; deleted on expiry or with "Sign out" |
| Professional profile | first name, last name, professional area (primary and optional secondary), role, seniority, organization (optional), declared interest | you declare it when you register and can edit it in /my/profilo |
| Progress and certification | completed lessons, certification attempts with outcome, issued credentials (level, date, name on the credential) and, if you decide to turn it on, the public credential verification page | while you use the course and the certification |
| Diagnostic | the answers to the 12 questions and the resulting profile | if you take the Diagnostic; for unregistered users, the result is linked to a temporary identifier (see below) |
| Usage measurement | product events (e.g. lesson opened, module completed, Diagnostic started, certification attempt) with date, normalized page and a few technical properties; we do not record mouse movements, clicks, heat maps, scrolling or session replays | always; for unregistered users through the pseudonym ac_mid, for registered users through the internal account identifier |
| Technical signals | server errors and authentication friction (e.g. wrong password, unverified email), without the content of the credentials | when they occur; they stay only in our database and are never forwarded to third parties |
| Accountability logs | administrative actions on accounts (session revocation, deletion) with who performed them, on whom and when; accesses to the remote MCP service (date, tool, outcome, hashed fingerprint of the IP address) | when they occur |
| Consents | history of your choices (acceptance of the service, "email updates", "analytics"), with date, version of the privacy notice and origin | at registration and at every change |
We do not process special categories of data (Art. 9 GDPR) and we do not ask for payment details: the course is free.
3. Why we process it and on what lawful basis
- Providing the service you request (Art. 6(1)(b) GDPR): account, email verification, saving your progress, Diagnostic, certification, credential, service emails (verification, password reset, account notices).
- Legitimate interest (Art. 6(1)(f)): understanding where the course works and where it does not through internal, aggregate usage measurement; keeping the service secure (sessions, attempt limits, accountability logs); issuing credentials in the correct name; evaluating requests for access to the full course on the basis of the professional profile you declare. Internal measurement is pseudonymous for unregistered users and does not leave our systems.
- Consent (Art. 6(1)(a)), always optional, and you can withdraw it from
/my/profilo: "email updates" (news and learning paths, nothing else) and "analytics" (forwarding a copy of the usage measurement to the external tool described in section 5).
4. For how long
| Data | Retention |
|---|---|
| Account, profile, progress, credentials | as long as the account exists; you delete them yourself (see section 7) |
| Consent history | kept as evidence of your choices even after deletion, linked to the anonymous placeholder of the account (without email or name) |
| Login sessions | 30 days from login, then deleted; you can close them earlier with "Sign out" |
| Email verification and password reset tokens | a few hours, then deleted |
| Diagnostic of unregistered users | the result remains linkable to the temporary identifier for 7 days |
| Usage measurement events | 730 days, then they are deleted automatically |
| Remote MCP access log | 365 days, then deleted automatically |
| Administrative action log | 24 months, so that we can account for who revoked or deleted what; then deleted automatically. If an action is disputed, only the rows concerning it are kept until the dispute is closed |
| Aggregate analyses (periodic portal reports) | kept as statistics; they contain no data that could be linked to individuals |
5. Who we share data with
No data is sold or transferred for third-party purposes. To operate, the service relies on providers that process data on our behalf or as independent controllers:
- Application hosting and database: the portal runs on cloud infrastructure and the data is stored in a managed Postgres database. The providers see the data only as technical custodians.
- Email delivery: service emails (verification, password reset, notices) are sent through an outbound email provider, which receives the address, the name and the content of the message.
- Google Fonts: the pages of the account area load fonts from Google's servers; your browser sends the request to Google with your IP address. No cookies are set.
PostHog (PostHog Inc., European instance eu.i.posthog.com): receives a copy of the usage events only of registered users who have turned on the "analytics" consent in their profile. It does not receive name, email or professional profile: it receives the internal account identifier, the event name and a few technical properties (e.g. module, lesson, outcome). No PostHog script is loaded in your browser: the data is sent from our servers. Without consent, PostHog receives nothing and the measurement stays only in our database.
Anthropic (Anthropic PBC): the analysis engine of the portal sends the model
claude-opus-5 only aggregate statistics (completion counts, rates, trends) and receives natural-language interpretations intended for the portal administrators. No emails, names, profiles, individual answers or any data that could be traced back to a person are sent.
Some of these providers are based in the United States or may also process data outside the European Union. In those cases we rely on the safeguards provided for in Chapter V of the GDPR: an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, for the providers that participate in it) or the standard contractual clauses. The up-to-date list of providers, with location and applicable safeguard, is available by writing to the data controller.
6. What we do not do
- No profiling for advertising purposes, no advertising, no third-party trackers in the browser.
- Access to the full course is granted by the data controller, a person, who reads the declared professional profile and decides — normally within 2 business days, with an email giving the outcome. It is not an automated decision and AI plays no part in it.
- No profiling of individuals. Certification grading is automatic but not opaque: it applies rules declared before the test, the same for everyone, with no AI models; you can retry without limit and, if you believe an outcome is wrong, ask the data controller for a human review.
- AI models never see your personal data: they receive only aggregate statistics.
- The directory of registered users is visible only to the portal administrators, never to external tools.
- The service is intended for adults, in the course of their careers: it is not designed for minors.
6-bis. Use of artificial intelligence systems
Agenticodice uses an artificial intelligence system in one place only, and for one purpose only:
interpreting aggregate statistics on the use of the course (completion rates, trends, friction) and proposing a natural-language reading to the portal administrators. The language model is claude-opus-5, developed by Anthropic; the system that queries it is ours, built for this internal use only, and is not offered to third parties.
- No decisions about you. AI plays no part in assessing the Diagnostic or the certification attempts, nor in issuing credentials: these are declared rules, the same for everyone, verified by tests. It does not profile, classify or rank people.
- No personal data. It receives only aggregate numbers; segments too small to be anonymous are suppressed before they even reach it.
- No interaction with you. There are no AI-based assistants or chats in the course: if one day there were, it would be stated clearly that you are talking to an automated system.
- Marked provenance. Every text produced by the system carries with it, in machine-readable form, an indication that it was generated by a model (with provider and model) or by deterministic rules; the indication stays attached to the text wherever it is shown or transmitted.
In our assessment, with respect to Regulation (EU) 2024/1689 (the AI Act): the system is not high-risk; it does not interact with people (Art. 50(1)) and does not produce texts published to inform the public (Art. 50(4)); since it generates text, we mark its outputs as AI-generated with the metadata described above: this is our technical solution for the marking obligation (Art. 50(2)), which we consider adequate for purely internal use, also in light of the European Commission's guidelines on Art. 50, adopted on 20 July 2026 (the obligations apply from 2 August 2026). There is also a voluntary Code of Conduct on the transparency of AI-generated content: we use it as a reference against which to periodically compare our solution, without presenting any of this as a certification of compliance. Should the picture change — for example with an AI assistant inside the course — this notice will be updated before, not after.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection (Arts. 15–22 GDPR), and the right to withdraw your consents at any time without affecting previous processing.
- Rectification: you edit your profile from
/my/profilo. The name on a credential already issued remains the one at the time of issue. - Withdrawal of consent: the "email updates" and "analytics" switches in
/my/profilo. - Erasure: from
/my/profilo, "Delete account" section. The profile, login methods, sessions, tokens, Diagnostic results and credentials are deleted; the account remains as an anonymous placeholder (without email or password) and the usage measurement events remain but no longer lead back to anyone. The administrative action log keeps the email as it was at the time of the action, as accountability evidence. - Access, portability, objection: write to giuseppe.citerna@gmail.com; we reply within one month.
- You can lodge a complaint with the Garante per la protezione dei dati personali (the Italian Data Protection Authority, garanteprivacy.it).
8. Security
Passwords are stored only as hashes (scrypt); session cookies are HttpOnly, SameSite and Secure; the database stores only a fingerprint of each session; writes accept requests from the site's origin only; the remote MCP service is protected by tokens, origin checks and rate limits, and exposes only aggregate statistics.
9. Changes
If this notice changes, the new version will have a new date and you will find it at this address. Substantial changes will be flagged to you in your account area. The version accepted by each person is recorded together with their consents.
See also the cookie policy and the terms of service.