← FillWright

Privacy Policy

Last updated: 18 July 2026

1. Who we are (data controller)

FillWright is operated by Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — VAT IT15237911001, REA RM-1576999, PEC [email protected] ("Redbit", "we", "us", "our"). Given the size of our organisation we are not required to appoint, and have not appointed, a Data Protection Officer under Article 37 GDPR. For any privacy matter contact [email protected] or use our contact form.

2. Scope

This policy explains how we handle personal data when you visit fillwright.com and use the FillWright application. It should be read together with our Terms of Service and, for business customers, our Data Processing Agreement (DPA).

3. Our two roles

  • Controller — for the personal data of your account, billing, and use of the service.
  • Processor — for the "lead" data you upload (CSV) and submit through the service, you are the controller and we act only on your documented instructions under a Data Processing Agreement (DPA). Section 13 applies to that data.

4. Personal data we process (as controller)

  • Identity & account: name, username, email, hashed password, two-factor status, role, locale.
  • Billing: company details, VAT/tax identifiers, address, wallet and transaction records. Card data is handled directly by Revolut and is never stored by us.
  • Authorization evidence: domain-ownership proofs, uploaded permission documents, and attestations you provide.
  • Technical & usage: IP address, timestamps, request metadata, audit logs, and security events.

We do not intentionally collect special-category (sensitive) personal data about you.

5. Where the data comes from

Directly from you (registration, forms, uploads) and automatically from your use of the service (logs and security events).

6. Purposes & legal bases (GDPR / UK GDPR)

  • Operating the service, accounts, and authorized submissions — performance of a contract (Art. 6(1)(b)).
  • Billing, invoicing, accounting and tax — legal obligation (Art. 6(1)(c)) and contract.
  • Security, fraud and abuse prevention, rate limiting, and audit logging — legitimate interests (Art. 6(1)(f)).
  • Service communications (invitations, notices) — contract and legitimate interests.
  • Handling abuse reports and lawful requests — legal obligation and legitimate interests.
  • Improving the service using aggregated data (no profiling of you) — legitimate interests.

We do not rely on consent for cookies because we set no tracking cookies (Section 11).

7. Sub-processors & recipients

  • Revolut (Revolut Bank UAB) — payment processing (European Union — Lithuania).
  • Anthropic — optional AI assistance for form-field mapping only (United States). No submission is ever auto-executed by AI.
  • LangChain (LangSmith) — LLM observability for the AI mapping feature: token usage, cost, and latency only. Prompt and response content is redacted and never sent (EU region).
  • Smartproxy / Decodo — regional network egress, only when you enable it for an authorized target.
  • IONOS — hosting infrastructure (European Union, Germany).
  • Redbit's self-managed transactional email system (mail.redbitapp.com) — sending service emails.

We do not sell or rent your personal data. We may disclose data to public authorities where legally required, and to professional advisers or a successor entity under confidentiality.

8. International transfers

Our infrastructure and databases are hosted in the European Union (Germany). Payment processing is provided within the EEA by Revolut (Revolut Bank UAB, Lithuania), so no transfer outside the EEA is involved for payments. Some sub-processors (Anthropic) are located in the United States; those transfers are covered by the European Commission's Standard Contractual Clauses and, for UK personal data, the UK International Data Transfer Addendum, together with supplementary measures. A copy of the relevant safeguards is available on request via [email protected].

9. Retention

  • Account data: deleted within 30 days after you close your account (or on a verified erasure request), unless longer retention is legally required.
  • Billing & invoicing records: retained for 10 years, as required by Italian tax law.
  • Operational and security logs: up to 12 months.
  • Uploaded lead data and derived records (rows, runs, submissions): deletable by you at any time and purged on account closure. Residual copies in encrypted backups are overwritten within 30 days.

10. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects on you (Art. 22 GDPR). AI is used only to suggest how your CSV columns map to a form's fields; you review and control every mapping and every submission.

11. Cookies & tracking

FillWright uses no analytics, advertising, profiling, or tracking cookies, and therefore shows no cookie banner. The public website sets no cookies at all. Once you sign in, the application sets a single strictly-necessary session cookie solely to keep you authenticated for the duration of your session; under the ePrivacy Directive this cookie is exempt from consent. Logging out or clearing your browser removes it. We use no third-party trackers, pixels, or device fingerprinting.

12. Your rights (GDPR / UK GDPR)

You have the right to access, rectification, erasure, restriction, data portability, and objection, and — where processing is based on consent — the right to withdraw it. To exercise any right, contact [email protected] or use our contact form. We may need to verify your identity. We respond within one month (extendable by two further months for complex requests). You may lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or, for UK data subjects, the ICO (ico.org.uk).

13. Lead data you upload (our processor role)

For the CSV lead data you upload and submit, you are the controller and we process it only on your instructions and for the sole purpose of performing the submissions you configure, under our DPA. We do not use it for our own purposes, do not sell or share it, and delete it as described in Section 9. Data-subject requests about that data should be directed to you as controller; we will assist you in responding.

14. California privacy rights (CCPA / CPRA)

If you are a California resident, this section applies to personal information we handle as a business.

  • Categories collected: identifiers (name, email, username, IP), commercial information (billing and transactions), and internet/network activity (logs). Within the lead data you upload as controller, the categories are those you determine.
  • Purposes: the business purposes described in Section 6.
  • No sale or sharing: we do not sell your personal information and do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. Because we do not engage in those activities, no "Do Not Sell or Share My Personal Information" mechanism is required.
  • Sensitive personal information: we do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use.
  • Your rights: to know/access, delete, correct, and to non-discrimination for exercising them. Submit a request via [email protected] or the contact form; an authorized agent may act for you with proof of authorization. We verify identity before responding.
  • Service-provider role: for the lead data you upload, we act as your service provider and process it only on your behalf under our DPA.

15. Other jurisdictions

Where other data-protection laws apply to you (for example Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, or similar), we honor the equivalent rights those laws grant. Contact [email protected] and we will handle your request under the applicable law.

16. Children

FillWright is a business service and is not directed to children. Users must be at least 18 years old. We do not knowingly collect personal data from anyone under 16; if you believe a child's data reached us, contact [email protected] and we will delete it.

17. Security

We protect data with encryption in transit (TLS), hashed passwords (Argon2id), mandatory two-factor authentication for financial actions, rate limiting and login lockout, strict per-target authorization, SSRF protections on outbound requests, audit logging, and least-privilege access. No system is perfectly secure; we will notify you and the competent supervisory authority of a personal-data breach where and as legally required.

18. Changes to this policy

We may update this policy. Material changes will be notified by email and by in-app notice before they take effect. The "Last updated" date above shows the current version.

19. Contact

Privacy questions and data-subject requests: [email protected] or our contact form. Postal: Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy.