CercaPosta

Privacy Policy

Version: 11 September 2026

This policy covers cercaposta.it, the app.cercaposta.it cloud service, desktop and mobile clients, and managed CercaPosta installations.

1. Roles and contact details

WpWeb S.r.l., via Livorno 60, 10144 Turin, Italy, tax and VAT ID 07292240012, certified email info@pec.wpweb.com, is controller for the website, sales enquiries, accounts, service security, subscriptions, payments, receipts and support. Contact privacy@wpweb.com. No DPO has been appointed.

For email and attachments archived by a customer organisation, that organisation will normally be controller and WpWeb acts as processor under Article 28 GDPR for the managed cloud service. Organisation administrators can see members, plans and aggregate usage, but cannot read members' email content. The sole exception is an individual AI answer that a user expressly chooses to report for review: it may contain text derived from emails and is visible only in the protected superadmin queue. In an on-premises installation WpWeb processes data only when support or another agreed service requires it.

2. Data we process

We do not request special-category data, but email content uploaded by a customer may contain it. The controller is responsible for the appropriate legal basis, proportionality and permissions.

3. Purposes and legal bases

Purpose Legal basis
Registration, verification, access, organisations and service delivery contract or pre-contractual steps
Payments, receipts, tax and accounting contract and legal obligation
Security, fraud and abuse prevention, audit and continuity legitimate interest and security duties
Answering sales and support requests pre-contractual steps or contract
Marketing communications consent, withdrawable at any time
Umami website analytics consent, changeable through “Cookie preferences”
Archive, search, OCR, AI and follow-up customer controller instructions and service delivery
Review of a voluntarily reported AI answer user request and legitimate interest in service safety and quality

We do not make solely automated decisions producing legal or similarly significant effects. AI output may be inaccurate and must be checked against the displayed sources.

4. Registration, identity and Google user data

You may use email and password with a time-limited verification link, Google OpenID Connect or Sign in with Apple. We receive a stable provider identifier, name when available, email and its verification; Apple may supply a Private Relay address if you select Hide My Email. We do not receive the Google/Apple password. Signing in or registering with Google alone does not authorize Gmail access, and we do not access iCloud. We do not automatically link an external identity to an existing account with the same email without an authenticated check. Apple refresh tokens are encrypted and used only to verify consent status and revoke the connection.

Gmail source: Google data we process

Adding Gmail is optional and requires a separate Google consent. CercaPosta requests only the read-only gmail.readonly permission; it does not receive your Google password or access Google Contacts, Google Calendar or Google Drive. The service may access the mailbox's primary address, labels and synchronization identifiers, message metadata and headers, email bodies, and attachments included in the folders and filters selected by the user.

We use this data only to associate the source with the correct account and provide the features the user requests: background synchronization and copying selected emails into the archive, deduplication, organisation, indexing, search, attachment OCR and, only when the user invokes the relevant feature, AI or follow-up results based on relevant content. The permission does not allow CercaPosta to send, modify or delete messages in Gmail.

Archived copies, related metadata, indexes and any embeddings are stored according to the archive mode selected by the user; the refresh token required for synchronization is encrypted. Data is transmitted over encrypted connections and protected through access controls and user separation. We do not sell or rent Google user data, use it for advertising or commercial profiling, or use it to train general-purpose artificial intelligence or machine-learning models. We transfer it only to providers necessary to deliver the service and, for user-requested AI features, to the endpoint configured for the installation and only to the extent relevant to the request. Human access is limited to support requested and authorised by the user, security incident handling or legal duties.

You can stop access by deleting the source in CercaPosta or revoking CercaPosta in your Google Account settings; the token is revoked or deleted and no new synchronization occurs. Content already copied remains in the archive until the user or organisation deletes it or the retention periods in section 8 apply, including ordinary backup rotation.

CercaPosta's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We use rate limits, a honeypot, disposable-email checks and, when enabled, Cloudflare Turnstile. The minimum age for self-service registration is 18.

5. Payments

Stripe or PayPal process the payment data they require as independent controllers under their own policies. CercaPosta stores transaction identifiers, outcome, amount, currency, VAT, billing details and receipt, but not full card data. Bank transfer and other manual payments require administrator verification before activation.

6. Archive, AI and encryption

Content remains isolated by user and is allocated to the correct commercial workspace. Shared company allowances do not make messages shared. When enabled, AI processes the content required for the chosen feature through endpoints configured for the installation. Sources are shown where supported. During registration you may choose an archive protected by a personal key, for which you must retain the recovery kit, or a standard archive without a personal key, with full administrator-assisted recovery and continuous synchronisation. Even in encrypted mode, the search index and embeddings required for search and AI contain derived plaintext protected through infrastructure safeguards. You may change mode later. During conversion the service temporarily suspends archive use, transforms and verifies stored data, revokes cryptographic credentials that are no longer compatible, and removes previously generated exports and previews. Before starting, it explains the effects on the Recovery Key, trusted devices and shares.

Below each saved AI answer you can choose Report answer. Before submission, the service identifies the data that will be shared: only that answer, the selected reason and any optional comment. Your question, the full conversation, cited emails and attachments are not submitted. The reported answer may nevertheless reproduce parts of emails used by the AI. Report content is encrypted with the installation key and can be viewed only by the superadmin responsible for review; access and status changes are recorded in the audit log.

7. Recipients and international transfers

Authorised staff and necessary suppliers may process data: hosting and transactional email, Cloudflare Turnstile, optional Google or Apple login, Google for an authorized Gmail source, Stripe or PayPal, and configured AI endpoints. Umami is self-hosted in the EU. We favour EEA infrastructure; any transfer outside the EEA relies on a GDPR transfer mechanism and applicable safeguards. Request the current processor list from privacy@wpweb.com.

8. Retention

Exceeding an allowance never triggers automatic deletion. A 30-day grace period applies after a downgrade; new ingestion may then be paused while existing content is preserved.

9. Your rights

Contact privacy@wpweb.com to request access, correction, erasure, restriction, portability, objection or consent withdrawal. For organisation-controlled content, contact the organisation first; WpWeb assists it when acting as processor. You may complain to the Italian Data Protection Authority or the authority in your country.

10. Cookies and changes

See the Cookie Policy. Analytics choices can be changed from the footer. Material policy changes will be notified in the service and identified by a new version.