Privacy policy
Last updated: 14 August 2026
This notice describes how personal data of users of www.mandalo.it (the “Service”) is processed under Regulation (EU) 2016/679 (“GDPR”) and applicable Italian law.
1. Data controller
The data controller is Franco Ramonda, tax code RMNFNC76T14D205F, sole proprietor of FR Italy, with registered address at Via Bruno Caccia 9, 12100 Cuneo (CN), Italy, VAT 02976040044. Website: www.fr-italy.com. Email: privacy@fr-italy.com · info@mandalo.it.
2. Types of data processed
Depending on use, we may process: account data (email, password hash, name, plan, email verification); Google OAuth data; transfer data (sender, recipients, title, message, file metadata, protection password hash, dates, guest-limit IP); temporarily stored uploaded files; payment/subscription data (PayPal/Pagami references, amounts, status); advertising data if you request a campaign; technical logs and cookies as described below.
3. Mandalo.it add-in for Microsoft Outlook
The add-in lets you select and upload files to Mandalo.it and insert the related download link into the message. It may process the Mandalo account token, files selected by the user, and metadata needed for the transfer. It does not read unrelated messages and does not send email on its own. Data is processed according to the methods and retention periods described in this notice.
4. Purposes and legal basis
Service delivery (upload, download, link email, account): contract performance (GDPR Art. 6(1)(b)). Security, abuse prevention, quotas: legitimate interest and legal obligations. Payments and subscriptions: contract performance. Google login: contract and, where required, consent to Google permissions. Tax compliance: legal obligation. Technical cookies: technical necessity. Analytics cookies (Google Analytics 4) and marketing/campaign measurement cookies (Google Ads): user consent via the cookie banner and Consent Mode.
5. Nature of provision
Data required to send a transfer or create an account is mandatory to provide the Service. Without it, those features cannot be used. Google Login is optional.
6. Processing and security
Data is processed with appropriate technical and organizational measures: HTTPS transmission; at-rest file encryption (XChaCha20-Poly1305) on non-public storage; passwords stored only as hashes; token links and expiries; secure sessions and security HTTP headers.
The controller is Italian and applies GDPR. Application servers and file storage are hosted on OVHcloud infrastructure in the European Union (Germany — Limburg). Data at rest on the server is encrypted. Administrative access to the servers is not publicly exposed: it requires security keys and two-factor authentication (2FA). We do not sell file contents for advertising. You remain responsible for credentials, links, and passwords shared with recipients.
7. Retention
Service data (accounts, transfers, files and technical logs) is stored on OVH servers located in the European Union. Files and transfers: until set expiry, then deleted or unavailable (except Pro recovery if active). Account: for the relationship duration and longer for legal obligations. Technical logs: usually no more than 12 months unless security requires longer.
8. Recipients
For hosting and storage we use OVHcloud (EU). Where necessary we may also involve: Aruba (SMTP), Google (OAuth, Analytics, Ads — analytics/marketing cookies only with consent), PayPal, Pagami, Cloudflare (anti-spam where enabled), and professionals for legal compliance. Transfer recipients receive only what is needed to download (link and, if provided by the sender, password).
9. Storage location and transfers
Service data (database, uploaded files and operational backups) is stored on OVH servers in the European Union and is not transferred outside the EU for hosting or storage. Using optional third-party features (e.g. Google login, Analytics/Ads with consent, PayPal payments) may involve limited processing by those providers under their notices and GDPR safeguards.
10. Cookies
The site uses essential technical cookies and, only with your consent, analytics cookies (Google Analytics 4) and marketing/conversion cookies (Google Ads). Full details (list, purposes, retention, how to withdraw consent) are in the dedicated Cookie policy.
11. Data subject rights
You may exercise access, rectification, erasure, restriction, portability, objection, and consent withdrawal by writing to privacy@fr-italy.com. Complaint to the Italian DPA: www.garanteprivacy.it.
12. Minors and changes
The Service is not intended for under-14s. This notice may be updated; the current version is on this page with the update date.
For details on technical, analytics and marketing cookies see the Cookie policy.