Human review intake
Privacy Notice
1. Controller
Name: Matteo Bortolu
Address: via Sassari 73, Stintino (SS)
Email: cce@bortolu.com
2. Data collected
The intake collects your name, email, professional role, optional organisation, review scope, competence statement, conflict or limitation statement, ratings, findings, disposition and optional notes. It also records submission timestamps, review status, the accepted Terms version and the acknowledged Privacy Notice version. The application does not intentionally store IP addresses.
3. Purposes
Data is used to receive and authenticate human reviews, assess reviewer competence and independence, evaluate and disposition findings, maintain the publication-assurance record, contact reviewers about clarification, protect the intake and preserve publication traceability.
4. Lawful basis
Article 6(1)(f) GDPR – legitimate interests. The controller has a legitimate interest in obtaining independent, competent human review of the AI-assisted book in order to complete Gate 6 (publication assurance), verify quality, clarity, proportionality of claims and accountability of the published work.
Legitimate interests, where applicable: Legitimate interests: obtaining traceable, independent human review findings necessary to close Gate 6 and support a credible publication record for Capability-Centric Engineering. Balancing test: processing is limited to data voluntarily submitted by the reviewer for the explicitly stated purpose; it is not intrusive, is not used for marketing or other purposes, and the reviewer is informed that the review is used only for publication assurance. The controller’s interest does not override the rights and freedoms of the data subject.
Accepting the submission terms and acknowledging this notice are recorded as evidence of the transaction and transparency. A privacy acknowledgement is not treated as consent unless the lawful-basis field above expressly states that consent is used for a specific purpose.
5. Required information
Fields marked with an asterisk are required to assess whether a review is admissible. Without them, the review cannot be submitted through the form. Organisation and additional notes are optional.
6. Recipients and processors
Hosting and infrastructure provider (Aruba S.p.A., Italy); database and application hosting services operated by or on behalf of the controller; email delivery services used to receive or acknowledge submissions; professional advisers (legal counsel or compliance consultants) only when strictly necessary for the purposes of the processing or to respond to data-subject requests.
Review content is not made public automatically. Accepted findings may enter controlled publication-assurance records. Reviewer identity or review text is published only with separate permission or where required by law.
7. International transfers
No transfers outside the EEA. Personal data is processed and stored within the European Economic Area (primarily Italy) by the controller and its EEA-based service providers.
8. Retention
Rejected submissions: retained for up to 12 months after the assessment decision (or until Gate 6 is closed, whichever is earlier) for accountability and possible clarification. Accepted submissions and Gate 6 records: retained for the commercial life of the edition plus 5 years, or longer if needed to demonstrate the independent-review process. Security and access logs: retained in accordance with the hosting provider’s standard retention (typically 12–24 months) or as required for security and legal compliance.
Data is deleted or anonymised when it is no longer necessary, subject to legal obligations, dispute preservation and the integrity of an accepted assurance record.
9. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, portability or objection. Where processing relies on consent, you may withdraw consent without affecting earlier lawful processing. Send requests to cce@bortolu.com. Identity verification may be required before a request is fulfilled.
10. Complaint
You may complain to the competent supervisory authority: Garante per la protezione dei dati personali (Italian Data Protection Authority), https://www.garanteprivacy.it/. You may also contact the controller first so the concern can be addressed directly.
11. Automated decisions and AI assistance
No solely automated decision produces legal or similarly significant effects for reviewers. AI-assisted tools may support bounded security, formatting, duplicate detection or analysis, but a human owner decides whether a review is accepted into the publication-assurance record. Do not submit confidential, special-category or unnecessary third-party personal data.
12. Security
The intake uses HTTPS, server-side validation, same-origin and CSRF controls, parameterised database operations, protected administrative access, restricted exports and data-minimising logs. Security controls reduce risk but cannot guarantee absolute protection.
13. Changes
Material changes create a new notice version. The form records the version acknowledged at submission. The current version remains available at this URL.