skip to content

Privacy and cookie notice

No profiling cookies, no ads, aggregate statistics only: how cyber/verso processes your data.

Last updated: 15 September 2026

Who processes your data

cyber/verso is a personal and independent publication. The controller is Paolo De Rosa, acting as a natural person. For any question about this notice, or to exercise your rights, you can write to info@cyberverso.net.

In short

The site is designed to process as little as possible. I use no profiling cookies, I show no advertising, I do not sell your data and I do not disclose it to anyone for advertising or marketing purposes. The technical providers I rely on receive only the data needed to deliver the services described on this page.

I measure site traffic in aggregate form, without cookies and without linking visits to your subscription. Newsletter emails contain no tracking pixels and no tracked links: I do not record whether you open a message or which links you click.

The sections below describe the processing connected with your use of the site and of the newsletter.

Browsing the site

When you visit the site, your browser sends the hosting servers the technical information needed to deliver the pages: IP address, date and time of the request, page requested, browser and operating system, referring page.

The site is hosted on the Ghost(Pro) service of Ghost Foundation Ltd, which acts as processor on my behalf and whose servers are located in Amsterdam. Ghost in turn relies on its own authorised providers: Fastly for the delivery infrastructure, which is what serves the pages and image files to your browser, DigitalOcean for the infrastructure on which the service runs, and rsync.net for backups. Ghost also processes certain data relating to the operation of the service in its own right, as controller, under its own privacy policy.

This data is used to deliver the pages, protect the service and prevent abuse, on the basis of the legitimate interest in operating the site securely (Article 6(1)(f) GDPR). I do not use it to identify you.

Reading statistics

I measure which articles are read and where readers come from. The tool is built into the platform and uses no cookies and no form of storage in your browser.

For each page you open, a script sends to an address on my own domain: the page visited, the referring page, any campaign parameters present in the address, the browser and device information the browser itself transmits, the language set in it and the country estimated from the device's time zone. The service receiving this data computes a signature by combining your IP address, that browser information, the site identifier and a random value that changes daily. The signature groups visits coming from the same connection and the same browser within a single day, in order to estimate how many distinct visitors there were. It changes every day and is not used to link visits across different days. The IP address is used to compute that signature and is not retained in the statistics data. Events are then processed and stored on the analytics infrastructure of Tinybird, Inc., an authorised provider of Ghost, in a region located within the European Union.

The legal basis is the legitimate interest in understanding how the publication is doing and which content is read (Article 6(1)(f) GDPR). The measurement is aggregate, concerns this site alone and is not combined with other processing. I build no profiles, I do not follow you across other sites and I do not use this data for advertising.

The platform would also allow the identifier of your subscriber record to be sent to the statistics when you have reached the site from a link received by email. I have disabled that: the identifier is removed before the event is collected, including on the subscription confirmation page. The identifier of your record is therefore not transmitted to the statistics, and I do not associate this data with your subscription.

When you use the search function, your browser downloads the list of published articles. The request starts from an address on my own domain and is served by the infrastructure of the platform hosting the site. The matching against what you typed happens entirely in your browser: the search terms are sent neither to me nor to the platform.

Images hosted by third parties

Some cover images are still loaded from Unsplash servers (images.unsplash.com). To display them, your browser discloses your IP address and the technical request data to Unsplash, which processes that information as an independent controller under its own privacy notice. I am moving these images to the site's own servers.

Newsletter

Subscribing is optional and serves only to receive by email the content published on the site. Not subscribing does not limit your reading in any way: all articles are public.

How it works. When you enter your address, I process it in order to send you a confirmation email. Delivery of the newsletter begins only after you have opened the link in that email. If you do not open it, the request lapses and no subscription is created.

What data I process. Your email address, the date you subscribed, the status of your subscription and the newsletter you subscribed to, an internal technical identifier, and a record of confirmation and sign-in events. I also record the technical delivery outcomes reported by the sending service, namely successful delivery, failed delivery or a spam complaint. I do not ask for your name. I do not record whether you open emails or which links you click.

Country. When the subscription is created, and on a sign-in through an emailed link if the information is missing, the platform discloses your IP address to the external GeoJS service in order to derive your approximate country, and stores only that item in the subscriber record, not the IP address. This function serves no purpose for a publication with no paid subscriptions and I am looking into how to remove it.

On what basis. Sending the newsletter relies on your consent (Article 6(1)(a) GDPR), which you give by opening the confirmation link and which you can withdraw at any time; withdrawal does not affect the lawfulness of earlier mailings. Honouring withdrawals, handling invalid addresses and keeping the service secure rely instead on the legitimate interest in not writing to people who do not wish to be contacted and in keeping the service working (Article 6(1)(f) GDPR).

How I document consent. Together with your subscription I keep the date and the confirmation event, and a reference to the version of this notice in force at that time, of which I hold a dated copy. When I delete your subscription I delete that documentation too, because keeping it any longer would itself require a legal basis and a time limit, and I have concluded that it is not necessary.

How you unsubscribe. Every email contains an unsubscribe link, which takes effect immediately and calls for no explanation. You can also write to info@cyberverso.net.

Recipients. Ghost Foundation Ltd operates the platform and the subscriber list as processor. For delivering the emails, Ghost relies on Mailgun Technologies, Inc., acting as its sub-processor.

Who it is for. I have chosen not to offer subscription to anyone under 14. This is not a threshold that applies everywhere: it is the limit set in Italy for a minor's own consent to information society services (Article 2-quinquies of the Italian Personal Data Protection Code), and I have adopted it as a rule of this service.

Cookies and browser storage

The site uses no profiling cookies and shows no consent banner. There are two reasons for this, and they should be kept apart.

The cookies and local storage listed in the table serve to complete the confirmation of your subscription, to handle the sign-in you requested and to remember your choice of theme: they are therefore necessary to provide functions you asked for, and fall within the exemption in Article 122 of the Italian Personal Data Protection Code. What matters is not that they are first-party, but that they are genuinely necessary for that function and for no other.

The traffic measurement described above is a different matter, and I do not treat it as a tool necessary to deliver the pages. It uses no cookies and no storage in your browser, concerns this site alone, produces aggregate results, is not combined with other processing and does not transmit the identifier of your subscription. It is on account of those characteristics, and not merely the absence of cookies, that I treat it as statistical measurement assimilable to technical tools.

Name Type When it is set Purpose Duration
ghost-members-ssr, ghost-members-ssr.sig first-party technical cookie when you open a confirmation or sign-in link received by email completing the confirmation of your subscription and handling the sign-in you requested removed immediately after confirmation; if removal fails, it expires within 184 days
ghost-access, ghost-access-hmac first-party technical cookie alongside the above, where set by the platform serving the correct version of the page one hour, or until the session is removed
cv-theme browser local storage only if you choose the light or dark theme remembering your preference until you clear the site's data from your browser

If you do not open a confirmation or sign-in link, the site sets no cookies at all. The site administration uses its own session cookie, which concerns only whoever manages the site.

Presence on the fediverse

Articles are also published on the fediverse through the ActivityPub protocol, under the account @social@cyberverso.net. If you follow the account, reply to, share or like a post from a fediverse account, the platform's ActivityPub service receives the public information of your profile, namely username, display name and image, and the content of the interaction. I do not receive this data from you but from the fediverse instance you come from, which is its source (Article 14 GDPR).

The processing relies on the legitimate interest in running the publication's presence on the fediverse and seeing reactions to its content (Article 6(1)(f) GDPR). I keep the data for as long as the interaction exists.

If you ask me to delete an interaction, I delete what is held for this publication and propagate the request as the protocol provides. By the nature of the fediverse, other instances hold independent copies of public content and apply their own rules: I cannot act on those copies, but this does not limit your rights over the data I process.

Webmentions

When another site cites an article and sends a webmention notification, the platform receives and stores the address of the citing page and the public metadata it contains, such as title, author and image. Here too I do not receive the data from you but from the public page citing the article, which is its source (Article 14 GDPR). I use it only to know who cites the content, on the basis of legitimate interest (Article 6(1)(f) GDPR), and I do not publish it on the site. I keep it for 24 months from receipt.

Emails you send me

If you write to info@cyberverso.net, I process your address and the content of your message in order to reply, on the basis of the legitimate interest in handling correspondence (Article 6(1)(f) GDPR). I keep messages for 36 months from the last exchange. The mailbox is operated by Google Ireland Limited as part of the Google Workspace services, acting as processor under its own data processing terms. Messages are stored and processed within the European Union. Google may rely on its own providers outside the European Economic Area, on the basis of the standard contractual clauses adopted by the European Commission.

How long I keep data

Data Criterion
Newsletter subscription for as long as you remain subscribed; deleted within 45 days of withdrawal of the last subscription
Consent documentation deleted together with the subscription
Suppressed addresses only the data needed not to write to you again, with periodic review of that need; withdrawals are kept separate from temporary delivery failures
Webmentions 24 months from receipt
Correspondence 36 months from the last exchange

Data processed by the infrastructure hosting the site, such as technical logs, reading statistics events and email delivery outcomes, is retained by the providers as part of their own security measures and is not used by me beyond the purposes described on this page. I have asked Ghost for the exact periods and will state them here as soon as they are available.

Transfers outside the European Union

The servers hosting the site are located in the Netherlands, and the service that processes reading statistics operates within the European Union. Some providers on which Ghost relies do, however, process data outside the European Economic Area, in particular in the United States: this is the case for the delivery infrastructure, for part of the file storage and for the email delivery service. The same applies to the geolocation service mentioned above.

For those transfers, the processing agreement with Ghost provides for the standard contractual clauses adopted by the European Commission, and requires Ghost to impose equivalent obligations on its own providers. You can obtain information about the safeguards applicable to these transfers, and a copy of them, by writing to info@cyberverso.net; the copy may contain the redactions necessary to protect confidential information.

Recipients

To summarise who may receive your data.

Ghost Foundation Ltd hosts the site and operates the newsletter as processor. In the path taken by reader data, Ghost relies on the following authorised providers: Fastly, for delivery infrastructure, in the United States; DigitalOcean, in the European Union, for the infrastructure on which the service runs, and rsync.net, in the United States, for backups; Tinybird, Inc., in the European Union, for the analytics infrastructure underlying the reading statistics; and Mailgun, in the United States, for delivering the newsletter emails. Ghost also relies on further providers that concern the management of its relationship with me as a customer rather than the readers of the publication.

In addition: GeoJS, which receives the IP address in the case described in the newsletter section; Google Ireland Limited for the mailbox; and Unsplash, as an independent controller, for as long as the images mentioned above remain.

Beyond what is described on this page I do not disclose your data to anyone, unless necessary to comply with a legal obligation. Each of the parties named may in turn rely on its own providers, within the limits set by the respective agreements. This list is updated whenever the provider chain changes.

My relationship with Ghost is governed by a processing agreement under Article 28 GDPR, the text of which is public at ghost.org/dpa. The current list of Ghost's authorised providers, with the purpose and country of each, is set out in Annex A to that agreement and can be requested from Ghost. If you wish to check the provider chain yourself, these are the documents to start from.

Your rights

You can ask me to give you access to your data, to rectify or erase it and to restrict its processing (Articles 15, 16, 17 and 18 GDPR). Where processing relies on consent or on a contract and is carried out by automated means, as with the newsletter subscription, you can ask to receive it in a structured, machine-readable format (Article 20 GDPR).

You can object at any time to the processing based on legitimate interest described on this page (Article 21 GDPR). If you do, I stop the processing unless I demonstrate compelling legitimate grounds that override your interests and rights.

You can withdraw your consent to the newsletter at any time, through the link in every email or by writing to me.

To exercise these rights, write to info@cyberverso.net. I reply within one month; if the request is particularly complex I may extend that period by two further months, informing you of the reasons within the first month.

If you consider that the processing infringes the law, you can lodge a complaint with a supervisory authority, in particular in the Member State where you habitually reside, where you work, or where the alleged infringement took place. In Italy the authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

I carry out no profiling and take no automated decisions producing legal effects concerning you or similarly significantly affecting you.

Changes

Any changes to this notice are published on this page, with the new update date. If a change materially affects the newsletter, I will inform subscribers.