Privacy Policy

Last updated: 17 June 2026

1. Who is responsible (controller)

The controller for the processing of personal data on this website is:

Cinque Monti Ltd.
[Registered office address]
Email: fabio@5monti.com

2. Our approach to your data

Privacy is built into how this product works, not added on afterwards. We practice data minimization, we do not sell your data, and we do not use third-party advertising or cross-site tracking. Wherever possible, processing happens locally and stays within our own infrastructure.

3. Visiting this website (server logs)

When you visit our website, our hosting provider automatically records technical access data (such as the requested page, date and time, referrer, and a shortened/anonymized IP address) in server log files. This is necessary to deliver the site, ensure stability, and protect against attacks.

Legal basis: our legitimate interest in a secure and functional website (Art. 6(1)(f) GDPR).

4. Cookies

Our public website does not use tracking or advertising cookies, and therefore does not display a cookie-consent banner. Where you log into the product, a strictly necessary session mechanism may be used to keep you signed in; this is not used for tracking.

5. Analytics (cookieless, self-hosted)

We measure aggregate website usage with Umami, a privacy-friendly analytics tool that we host ourselves on our own server. It is cookieless and sets no identifiers on your device. It does not store personal data: IP addresses are anonymized via a daily-rotating hash and are not retained, and no profiles are built across websites.

We use this only to understand aggregate trends (e.g. page views, referrers, country, device type). Retention is limited (up to 12 months). Because no personal data is stored and nothing is read from or written to your device, this processing does not require consent and is based on our legitimate interest in understanding and improving our site (Art. 6(1)(f) GDPR).

6. Registration and use of the product

If you create an account or activate a license, we process the data you provide (such as your email address and account credentials) to operate the service, manage your license, and communicate with you about it. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

The GCTRL product is designed to run on your own infrastructure with local inference. Knowledge you process in the product, and conversational sessions in the chat features, are handled under our GDPR-by-design model and are not stored by us for our own purposes.

7. Contacting us

If you contact us by email, we process your message and contact details to handle your request. Legal basis: our legitimate interest in responding to enquiries, or pre-contractual/contractual measures where applicable (Art. 6(1)(f) / (b) GDPR).

8. Hosting

This website and its analytics are hosted on our own virtual server provided by Hostinger, located in [data-centre region, e.g. EU]. Our hosting provider processes data strictly on our behalf as a processor under a data-processing agreement.

9. Data retention

We keep personal data only as long as necessary for the purposes described above or as required by law. Server logs and anonymized analytics are kept for a limited period and then deleted or aggregated. Account data is kept for the duration of your account relationship.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17);
  • restrict processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, contact us at fabio@5monti.com. You also have the right to lodge a complaint with the competent data-protection supervisory authority in your country.

11. Data security

We use appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access, including encrypted transport (HTTPS) and access controls.

12. Changes to this policy

We may update this policy to reflect changes to our service or legal requirements. The current version is always available on this page, with the “last updated” date shown above.

See also our Legal Notice.