Privacy policy.
Overview
stormDMCA ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect through stormdmca.com (the "Site"), why we collect it, how we use it, who we share it with, and the rights you have over it. By using the Site you consent to the practices described below.
This policy is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Italian data-protection law (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018).
Who we are — data controller
For the purposes of GDPR and Italian data-protection law, the data controller of personal data collected through the Site is stormDMCA, contactable at privacy@stormdmca.com.
If you have any question about how we handle your data, please contact us at the address above. You also have the right to lodge a complaint with the Italian supervisory authority, Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority in your country of residence.
What we collect
We collect only the personal data we need to operate the Site and provide the services you request.
Information you provide directly
When you submit one of our forms, we collect the following:
Free copyright scan (/analysis):
- your name or alias (how you'd like us to address you);
- your email address (to send you the report);
- your stage name or username (the name we scan for);
- (optional) the platform(s) you publish on.
Engagement intake (homepage):
- your stage name or username;
- your contact email;
- the engagement tier you are considering;
- an optional brief description of your matter.
We never ask for personal data we don't need at the inquiry stage — no real name, no postal address, no financial information. Where a paid engagement requires payment, that information is collected and processed directly by our payment provider and does not pass through our servers.
Information collected automatically
When you visit the Site, our hosting provider may automatically collect standard server-log data, including:
- IP address;
- browser type and version;
- pages visited and referring URL;
- date and time of visit.
We do not currently run any analytics or behavioural-tracking tools that build a profile of you. Server logs are kept for security and operations only, and rotated automatically on a short cycle.
Why we collect it (legal basis)
Under GDPR Art. 6, we process your personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to deliver the analysis report or carry out a paid engagement you have requested;
- Consent (Art. 6(1)(a)) — for any optional communications such as service updates or newsletters; you may withdraw consent at any time without affecting prior lawful processing;
- Legitimate interest (Art. 6(1)(f)) — to operate, secure, and improve the Site and to communicate with you about your inquiry;
- Legal obligation (Art. 6(1)(c)) — where we are required to retain or disclose data to comply with applicable law.
How we use your information
We use your personal data only to:
- operate the Site and deliver the services you request;
- communicate with you about your inquiry, your engagement, and any matter you have entrusted to us;
- send you, where applicable and only with your consent, service updates or relevant news (you can opt out at any time);
- fulfil legal, accounting, and tax obligations applicable to us;
- protect the security and integrity of the Site and our systems.
Who we share it with
We do not sell, rent, or lease your personal data to third parties — ever.
We may share limited personal data with the following categories of recipient:
- Service providers acting on our behalf under a written data-processing agreement: our hosting provider (Vercel Inc.), our email-delivery provider (when configured), and any payment processor we engage for paid engagements. Each is contractually bound to use your data only as necessary to provide the relevant service and to maintain its confidentiality.
- Third parties acting at your direction — if you engage us for DMCA representation, we file notices with the platforms, hosts, registrars, and intermediaries hosting the infringing material. The minimum information necessary about you is included in those notices; in most cases this is our agent-of-record details rather than yours, in order to preserve your anonymity.
- Legal recipients — if required by law, court order, or in good faith to (a) comply with legal process, (b) protect and defend our legal rights or property, or (c) protect the personal safety of users of the Site or the public.
We do not transfer your unique personally identifiable information (email, name, username) to third-party advertisers or marketing partners.
International data transfers
Some of our service providers — including our hosting provider — may process data on servers located outside the European Economic Area (EEA), including in the United States. Where this is the case, we ensure that an adequate level of protection is in place through one of the safeguards approved under GDPR Art. 46:
- the EU-US Data Privacy Framework (where the recipient is certified);
- Standard Contractual Clauses approved by the European Commission;
- another mechanism approved under GDPR.
You may request a copy of the safeguard relevant to a specific transfer at the contact address below.
How long we keep it
We keep your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:
- Free-analysis inquiries: up to 12 months from your last interaction, then deleted unless you become a client;
- Engagement records (paid clients): for the duration of the engagement, and for up to 10 years after termination as required by Italian tax and accounting law;
- Server logs: rotated automatically, typically within 30–90 days;
- Withdrawn-consent records: a minimal record of your opt-out is kept indefinitely so that we can honour it.
Hosting & security
The Site is hosted on Vercel's edge infrastructure. Personal data submitted via forms is transmitted over TLS-encrypted connections (HTTPS) and processed by serverless functions in the same infrastructure. At this time, form submissions are not stored in any database operated by us; they are forwarded to our designated mailbox (or to an integrated email/CRM provider once configured).
We make commercially reasonable efforts to secure our systems against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure; you provide your information at your own risk and accept that we cannot guarantee absolute security.
Cookies
The Site does not currently set any cookies of its own. There is no analytics tracking, no advertising tracker, and no authentication cookie (the Site has no login).
If we add cookie-using tools in the future — for example a cookieless analytics provider, or a consent-based analytics tool — we will update this policy and, where the law requires, ask for your consent before any non-essential cookies are placed on your device.
You may set your browser to refuse cookies entirely. Currently, doing so will not affect any feature of this Site.
Your rights under GDPR
If you are in the EU/EEA, or your data is otherwise processed under EU/Italian law, you have the following rights with respect to your personal data:
- Access (Art. 15) — to know what data we hold about you and obtain a copy;
- Rectification (Art. 16) — to correct inaccurate or incomplete data;
- Erasure(Art. 17) — the "right to be forgotten" — to ask us to delete your data, subject to the retention obligations described above;
- Restriction of processing (Art. 18) — to limit how we use your data while a dispute is resolved;
- Data portability (Art. 20) — to receive your data in a structured, commonly used, machine-readable format;
- Object (Art. 21) — to object to processing based on our legitimate interest;
- Withdraw consent (Art. 7) — at any time, where processing is based on consent, without affecting prior lawful processing;
- Lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority in your country of residence.
To exercise any of these rights, contact us at privacy@stormdmca.com. We will respond within one (1) month, as required by GDPR. We may need to verify your identity before processing your request.
Automated decision-making
We do not make any decisions about you that are based solely on automated processing and that produce legal or similarly significant effects. Our free copyright scan uses AI tools to surface candidate URLs, but every notice we file is reviewed and signed by a human agent of record before dispatch.
Children's privacy
The Site and our services are intended for adults only. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us at privacy@stormdmca.com and we will delete it promptly.
External websites
The Site may contain links to third-party websites. This Privacy Policy applies only to the Site. We are not responsible for the privacy practices of any other website; please review their privacy policies before submitting any personal data.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be notified by a prominent notice on the Site, or — where we have your email — by email.
Contact
For any question about this Privacy Policy or about how we handle your personal data, contact us at: