Last updated: 18 July 2026
FillWright is operated by Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — VAT IT15237911001, REA RM-1576999, PEC [email protected] ("Redbit", "we", "us", "our"). Given the size of our organisation we are not required to appoint, and have not appointed, a Data Protection Officer under Article 37 GDPR. For any privacy matter contact [email protected] or use our contact form.
This policy explains how we handle personal data when you visit fillwright.com and use the FillWright application. It should be read together with our Terms of Service and, for business customers, our Data Processing Agreement (DPA).
We do not intentionally collect special-category (sensitive) personal data about you.
Directly from you (registration, forms, uploads) and automatically from your use of the service (logs and security events).
We do not rely on consent for cookies because we set no tracking cookies (Section 11).
We do not sell or rent your personal data. We may disclose data to public authorities where legally required, and to professional advisers or a successor entity under confidentiality.
Our infrastructure and databases are hosted in the European Union (Germany). Payment processing is provided within the EEA by Revolut (Revolut Bank UAB, Lithuania), so no transfer outside the EEA is involved for payments. Some sub-processors (Anthropic) are located in the United States; those transfers are covered by the European Commission's Standard Contractual Clauses and, for UK personal data, the UK International Data Transfer Addendum, together with supplementary measures. A copy of the relevant safeguards is available on request via [email protected].
We do not carry out automated decision-making that produces legal or similarly significant effects on you (Art. 22 GDPR). AI is used only to suggest how your CSV columns map to a form's fields; you review and control every mapping and every submission.
FillWright uses no analytics, advertising, profiling, or tracking cookies, and therefore shows no cookie banner. The public website sets no cookies at all. Once you sign in, the application sets a single strictly-necessary session cookie solely to keep you authenticated for the duration of your session; under the ePrivacy Directive this cookie is exempt from consent. Logging out or clearing your browser removes it. We use no third-party trackers, pixels, or device fingerprinting.
You have the right to access, rectification, erasure, restriction, data portability, and objection, and — where processing is based on consent — the right to withdraw it. To exercise any right, contact [email protected] or use our contact form. We may need to verify your identity. We respond within one month (extendable by two further months for complex requests). You may lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or, for UK data subjects, the ICO (ico.org.uk).
For the CSV lead data you upload and submit, you are the controller and we process it only on your instructions and for the sole purpose of performing the submissions you configure, under our DPA. We do not use it for our own purposes, do not sell or share it, and delete it as described in Section 9. Data-subject requests about that data should be directed to you as controller; we will assist you in responding.
If you are a California resident, this section applies to personal information we handle as a business.
Where other data-protection laws apply to you (for example Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, or similar), we honor the equivalent rights those laws grant. Contact [email protected] and we will handle your request under the applicable law.
FillWright is a business service and is not directed to children. Users must be at least 18 years old. We do not knowingly collect personal data from anyone under 16; if you believe a child's data reached us, contact [email protected] and we will delete it.
We protect data with encryption in transit (TLS), hashed passwords (Argon2id), mandatory two-factor authentication for financial actions, rate limiting and login lockout, strict per-target authorization, SSRF protections on outbound requests, audit logging, and least-privilege access. No system is perfectly secure; we will notify you and the competent supervisory authority of a personal-data breach where and as legally required.
We may update this policy. Material changes will be notified by email and by in-app notice before they take effect. The "Last updated" date above shows the current version.
Privacy questions and data-subject requests: [email protected] or our contact form. Postal: Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy.