Skip to content
CargoNode
  • The warehouse
  • Modules
    • Sales
    • Accounting
    • Analytics
    • Third-party logistics
    • See all
  • Who it is for
    • E-commerce
    • Import/export
    • Third-party logistics
    • Manufacturing
    • See all
  • Compliance
  • Integrations
  • Pricing
ITTalk to us
  • The warehouse
  • Modules
    • Sales
    • Accounting
    • Analytics
    • Third-party logistics
  • Who it is for
    • E-commerce
    • Import/export
    • Third-party logistics
    • Manufacturing
  • Compliance
  • Integrations
  • Pricing
  • Sign in
Talk to us
  1. Home/
  2. Privacy

Privacy Policy

Last updated: 8 September 2026

This policy explains which personal data IVEmind processes through the cargonode.app website and through the CargoNode service, for what purposes, for how long and with whom it shares them. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003. Version 1.0. This English text is provided for convenience only: in case of any discrepancy, the Italian version prevails.

On this page

  1. Who processes your data
  2. What this policy covers
  3. The data we collect from the website
  4. Why we process them, and on what legal basis
  5. What actually happens to a message sent from the form
  6. How long we keep the data
  7. Who we share the data with
  8. Transfers outside the European Union
  9. The CargoNode service: who decides and who executes
  10. The providers involved in the service
  11. How we protect the data
  12. Your rights
  13. Minors
  14. Updates to this policy
  15. Contact
  1. Who processes your data

    The data controller is IVEMIND Società Cooperativa Sociale, registered office at Via Werner von Siemens 23, 39100 Bolzano (BZ), Italy. Tax code and VAT number IT03138990217, company register REA BZ-235349, certified email ivemindscs@pec.it.

    For anything concerning personal data, including exercising your rights, write to privacy@ivemind.com. Commercial enquiries go to sales@ivemind.com.

    The controller has not appointed a Data Protection Officer, as the mandatory conditions of Article 37 GDPR do not apply; a privacy contact is available at the address above.

  2. What this policy covers

    Two separate things, with two separate roles. The first is the public cargonode.app website you are reading, where IVEmind is the data controller. The site is a showcase — you cannot create an account, buy anything or pay for anything — and the only place where you can leave us data is the contact form.

    The second is the CargoNode service, the application reserved for customers under contract. For the data a customer enters into its own space — records of its customers and suppliers, orders, documents — IVEmind acts as data processor under Article 28 GDPR, and the customer company remains the controller. A section further down sets out how the roles are divided.

  3. The data we collect from the website

    From the contact form: full name, email address, message and — if you choose to fill them in — company and phone number. Along with the message we record the language of the page you wrote from and the IP address the request came from.

    Technical connection data: to deliver the pages, the infrastructure processes the IP address, the browser and device type, the date and time and the address of the requested page. These are the data without which no web page can reach anyone.

    We collect nothing else. The site has no statistics tools, hosts no third-party pixels, profiles no one and writes no cookies: the only information that may stay in your browser is your light or dark theme preference, and only if you press the toggle yourself. The details are in the Cookie Policy (https://cargonode.app/en/cookie-policy/).

  4. Why we process them, and on what legal basis

    To answer your enquiry and handle the exchange that follows: steps taken at your request prior to entering into a contract (Article 6.1.b GDPR) and, where the enquiry comes from a business, our legitimate interest in responding to a commercial contact (Article 6.1.f).

    To protect the form from automated abuse: a hidden field a visitor never sees or fills in, a check on how long the form took to complete, and a cap on submissions from a single IP address. Legitimate interest in keeping the channel usable by people who genuinely write to us (Article 6.1.f).

    To run the site securely and keep the technical records needed to diagnose faults and abuse: legitimate interest (Article 6.1.f). To meet legal, accounting and tax obligations where the contact turns into a business relationship: legal obligation (Article 6.1.c).

    There is no consent-based marketing processing, because there is no marketing: the address you leave us is used to reply to you and never enters a list, a newsletter or any third-party tool.

  5. What actually happens to a message sent from the form

    It is worth spelling out, because it is simpler than people expect. The form writes to no database: the content is composed into an email and delivered to sales@ivemind.com through the Amazon Web Services email service. Your address goes into the “Reply to” field, so whoever reads it answers you directly.

    The internal notification also carries the IP address of the connection the submission came from: it is what lets us recognise automated submissions and stop abuse. The same information stays in the technical logs of the function that receives the form.

    The message is not used to profile you, is not enriched with data taken from elsewhere and is not shared with anyone outside IVEmind.

  6. How long we keep the data

    Contact enquiry emails stay in the mailbox for as long as the conversation needs and in any case no longer than twenty-four months after the last exchange, unless a contractual relationship arises in the meantime: in that case the terms below apply.

    The technical logs of the function that receives the form — which hold the IP address and the content of the request — are deleted automatically after fourteen days. That is a deliberate choice: keeping them as long as application logs would be collection without a purpose.

    Customer data in the service is kept for the duration of the contract; on termination it remains available for export within the agreed period and is then deleted. Documents with accounting or tax relevance are kept for ten years, as Italian law requires.

    Your theme preference stays in your browser until you clear the site data, and never reaches us.

  7. Who we share the data with

    Amazon Web Services EMEA SARL, as a data processor bound by a contract under Article 28 GDPR, provides the infrastructure the site and the service run on: storage, page delivery, function execution and email sending. The data sit in the European region eu-central-1 (Frankfurt, Germany).

    Page delivery goes through a network of edge nodes which, in the configuration we chose, covers Europe and North America: the page you are reading may be served to you from a node in the United States, which processes only the technical data of the connection. Service content and mailboxes stay in Europe.

    Beyond that, no one. We do not sell data, do not pass them to brokers and do not send them to advertising or measurement tools, because the site has none.

    The providers involved in running the service are covered in their own section below.

  8. Transfers outside the European Union

    Amazon Web Services EMEA SARL is a Luxembourg company and hosts the data in Europe. In the residual cases where processing involves a transfer to the United States — such as a page served from a North American edge node — the transfer is covered by the AWS data processing agreement, by the Standard Contractual Clauses approved in decision (EU) 2021/914 and by the EU-US Data Privacy Framework adequacy decision of 10 July 2023, to which Amazon Web Services, Inc. adheres.

    No other transfer outside the EU is envisaged for data collected through the website.

  9. The CargoNode service: who decides and who executes

    For the data a customer enters into its own space — records of its customers and suppliers, orders, stock movements, documents — the customer company is the data controller, determines the purposes and means, and must inform its own data subjects and hold the necessary legal bases. IVEmind acts as processor under Article 28 GDPR, on the basis of a data processing agreement signed alongside the contract, and processes those data only to run the service and on the customer’s instructions.

    For the account data of the customer’s users — name, email address, role, user identifier — and for the administrative data of the relationship, IVEmind is instead the controller: they are needed to manage the contract, access and security.

    Each customer’s data live in a database schema separate from every other customer’s. It is not a column telling rows apart: it is a structural separation, decided at the outset and applied to every table in the product.

  10. The providers involved in the service

    Amazon Web Services EMEA SARL, for the infrastructure and for sending notification emails to the recipients the customer specifies. Region eu-central-1, Frankfurt.

    The provider that transmits electronic invoices to the Italian tax authority’s exchange system, the Sistema di Interscambio — today Openapi — is involved only for customers who choose to switch automatic transmission on: in that case it receives the invoice XML file and returns the outcome. It is an optional function, configured customer by customer.

    If no provider is configured, nothing leaves the service by that route: the customer downloads the invoice XML file and transmits it however it prefers, which is a perfectly legitimate way to work.

    Long-term legal archiving of tax documents, which Italian law requires for ten years, is not part of the service. Where it is needed it is carried out by the provider the customer chooses, under that provider’s own contract.

    An up-to-date named list of processors and sub-processors is available on request from privacy@ivemind.com.

  11. How we protect the data

    Traffic to the site and to the service is encrypted. Access to the service is through named user accounts, permissions are granted by role, and the rules are enforced by the server rather than by hiding buttons in the interface. Each customer’s data are isolated in a dedicated schema, operations leave an auditable trail, and the databases are backed up regularly.

    No measure makes an incident impossible. In the event of a personal data breach the controller complies with the notification and communication duties of Articles 33 and 34 GDPR.

  12. Your rights

    You may at any time request access to your data, their rectification or erasure, restriction of processing and portability, and you may object to processing based on legitimate interest (Articles 15-22 GDPR). Requests go to privacy@ivemind.com and receive a reply within thirty days.

    If your data are processed by IVEmind on behalf of a customer company — because you are one of its customers, suppliers or contacts — address your request to that company first, as it is the controller; we give it the technical support needed to act on it.

    You also retain the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the country where you live.

  13. Minors

    CargoNode is a service for businesses and professionals. The site is not aimed at people under sixteen and does not knowingly collect their data. If you believe a minor has sent data through the contact form, write to privacy@ivemind.com and we will delete it.

  14. Updates to this policy

    This page is updated whenever the tools in use, the providers involved or the purposes of processing change; the date at the top shows the latest revision.

    If the site ever adopts measurement tools, this policy and the Cookie Policy (https://cargonode.app/en/cookie-policy/) will be updated before those tools start collecting anything, and the consent request that is unnecessary today will appear.

  15. Contact

    Privacy and rights requests: privacy@ivemind.com. Commercial enquiries: sales@ivemind.com. Certified email: ivemindscs@pec.it.

    IVEMIND Società Cooperativa Sociale, Via Werner von Siemens 23, 39100 Bolzano (BZ), Italy.

CargoNode

The modular platform that starts in the warehouse. An IVEmind product.

IVEMIND Società Cooperativa Sociale
Via Werner von Siemens 23, 39100 Bolzano (BZ)
P.IVA IT03138990217 · REA BZ-235349

Product

  • The warehouse
  • Compliance
  • Integrations
  • Pricing
  • Glossary

Modules

  • Modules
  • Sales
  • Accounting
  • Analytics
  • Third-party logistics

Who it is for

  • Who it is for
  • E-commerce
  • Import/export
  • Third-party logistics
  • Manufacturing

Company

  • About
  • Contact
  • Go to the console
  • IVEmind
  • sales@ivemind.com
© 2026 IVEMIND Società Cooperativa Sociale · All rights reserved.
  • Privacy
  • Cookie policy
  • Terms