Legal

Privacy Policy

Last updated: 30 September 2026

This policy explains how Alexandria Scientific Consulting (“Alexandria”, “we”) handles your personal data when you visit alexandria.sc, contact us, or use Athena, our AI platform. We process personal data in line with the EU General Data Protection Regulation (GDPR).

1. Who is responsible

The controller of your personal data is Alexandria Scientific Consulting (Alexandria S.C.), Via Scapolla 12, 27100 Pavia (PV), Italy, VAT number IT02976900180. You can reach us about anything in this policy at:

[email protected]

2. What we collect on this website

Contact form

When you send us a message, we receive your name, email address, subject, and message, and they reach us by email. We use them only to reply to you and to follow up on your request. The legal basis is taking steps at your request before a possible contract, or our legitimate interest in answering your questions (Art. 6(1)(b) and (f) GDPR).

Spam protection

The contact form is protected by ALTCHA, which has your browser solve a small computation in the background before a message can be sent. It runs on our own infrastructure: no third party is involved, no cookies are set, and it collects no information about you. The form also contains a hidden field that only bots fill in. The legal basis is our legitimate interest in keeping spam out of our inbox (Art. 6(1)(f) GDPR).

Hosting

The website and the service that delivers contact messages run on DigitalOcean, which processes technical data such as your IP address to deliver pages and keep the service secure (Art. 6(1)(f) GDPR).

Cookies and analytics

We don't use analytics or advertising trackers, and this website sets no cookies.

3. Data in Athena

When a company uses Athena, it gives Athena business data such as documents, process descriptions, and information about its teams and roles. We process that data on the company's behalf, as a processor under a data processing agreement. The company remains the controller, so people whose data it contains should contact that company first.

Client data is never used to train any AI model other than that client's own. It is not shared with other clients or used to improve models for anyone else.

Athena is built and operated in compliance with the GDPR and the EU AI Act. The data processing agreement sets out where client data is stored and which sub-processors are involved.

4. Who we share data with

We don't sell personal data. We share it only with the service providers that help us run this website and Athena, under data processing terms:

Google and DigitalOcean are based in the United States. Transfers of personal data to them rely on the EU-U.S. Data Privacy Framework or on the European Commission's standard contractual clauses.

5. How long we keep it

We keep contact messages only as long as we need them to handle your request and any follow-up that comes from it, and delete them afterwards unless the law requires us to keep them longer. Athena client data is kept for the duration of the contract and deleted or returned when it ends, as set out in the data processing agreement.

6. Your rights

You have the right to access your personal data, have it corrected or deleted, restrict or object to its processing, and receive it in a portable format. Where we rely on your consent, you can withdraw it at any time. To use any of these rights, email us at the address above.

You also have the right to lodge a complaint with a data protection authority, in particular in the EU country where you live or work. In Italy, where we are based, this is the Garante per la protezione dei dati personali (garanteprivacy.it).

7. Security

We use technical and organizational measures to protect personal data against loss, misuse, and unauthorized access, including encrypted connections (HTTPS) for this website.

8. Changes to this policy

We may update this policy when our services or the law change. The date at the top always shows the latest version.