Rikipedia is a literary archive and reading journal curated by Riccardo Colombo. The core principle guiding this website is personal data minimization: collecting only the minimum information strictly required for consulting pages or responding to messages sent through the contact form.
1. Who is the Data Controller?
The data controller — the individual determining the purposes and means of personal data processing for this site — is:
Riccardo Colombo
Creator, editorial curator and administrator of Rikipedia (https://rikipedia.it).
2. Commercial Profiling & Ad Tracking
We want to be categorical: there is no commercial profiling of any kind on Rikipedia.
We do not track reading habits to resell them to advertisers, do not share data with brokers, and employ zero invasive third-party tracking pixels (Meta pixels, Google Ads, Criteo, etc.). Your browsing data is never monetized or transferred to third parties for marketing purposes.
3. Reading Statistics & Consent Management (Umami)
To understand which reviews resonate with readers without using invasive surveillance tools like Google Analytics, Rikipedia uses Umami Analytics: an open-source analytics platform self-hosted directly on our own dedicated server infrastructure (stats.nemici.net). No telemetry data is sent to cloud vendors or Umami Software, Inc., ensuring complete data sovereignty.
When you visit Rikipedia for the first time, an unobtrusive banner asks whether you would like to help us evaluate site usability:
If you click "Accept":
Page interaction metrics are activated to help us see which sections perform best, always without storing clear IP addresses and without third-party cookies.
If you click "No thanks":
We respect your decision: session recording is omitted and the server simply logs aggregate anonymous page counts.
How to revoke or change consent at any time:
Your choice is never permanent. In the footer of every page, click "Manage Analytics Consent" to immediately reset your stored preference.
IP Address Protection: Even for aggregate statistics, your IP address is never stored in plaintext. Umami processes IPs solely in volatile memory using a one-way cryptographic hash with a daily salt that rotates every 24 hours. Cross-day tracking is mathematically impossible.
4. What Happens When You Send a Message?
On the Contact page, there is a simple form to send comments, typos or recommendations.
When submitting the form, you provide your name, email address, and message:
- Purpose: Solely to allow me to read your note and reply by email.
- Legal Basis: Execution of an explicit request (GDPR Art. 6(1)(b)) and legitimate interest in communicating with readers (GDPR Art. 6(1)(f)).
- What we will NEVER do: Your email will never be added to promotional mailing lists, never sold, and never shared.
- Retention: Messages are kept only for the duration of the conversation and periodically deleted.
5. Network Security, Technical Cookies & Logs
During browsing, servers automatically log standard technical data (IP address, user agent, requested path, timestamp, HTTP status code) strictly for DDoS mitigation, intrusion detection and SSL/TLS Full Strict encryption.
Admin Area (/admin): Anonymous site visitors receive zero session cookies. The sole session cookie is issued when the curator authenticates to the private editing workspace.
6. External Data Processors & DPA Agreements
To maintain a secure and reliable platform, we use selected technology providers acting as Data Processors under GDPR Article 28, bound by signed Data Processing Addendums (DPA):
Vercel Inc.
Hosting Platform & Serverless ComputeRole & Purpose: Fast page delivery, server-side execution and secure routing of application traffic.
Infrastructure location: United States / Global Edge Network (Data Privacy Framework & SCC)
Supabase Inc.
PostgreSQL Database Infrastructure & File StorageRole & Purpose: Secure storage of editorial catalog (books, poems, authors) and access control for the reserved admin area.
Infrastructure location: European Union (AWS eu-west-1 Region, Dublin, Ireland)
Cloudflare, Inc.
Authoritative DNS, Reverse Proxy, WAF & DDoS MitigationRole & Purpose: Edge network perimeter security against attacks, SSL/TLS Full (Strict) encryption and network performance optimization.
Infrastructure location: United States / Global Anycast Network (Standard Contractual Clauses)
UsePlunk (Plunk)
Technical Transactional Email Forwarding ServiceRole & Purpose: Secure transmission and delivery to author of messages sent via the contact form.
Infrastructure location: European Union (Belgium)
7. Your Rights & How to Exercise Them
Under GDPR Articles 15 to 22, you have fundamental data protection rights that you can easily exercise:
Right of Access
If you previously emailed us and want a copy of stored communication, simply ask and we will provide it.
Right to Rectification
You can request prompt correction of inaccurate or outdated contact information at any time.
Right to Erasure ("To be Forgotten")
Send a note requesting deletion and we will immediately and permanently erase our past email thread from all mailboxes.
How to contact us to exercise any right:
No certified mail or formal bureaucracy is needed. Simply go to the Contact page, fill in your email, and describe your request. You will receive a response within 30 days as required by GDPR.
Intellectual Property & Creative Commons License
Critical essays, reviews and original contents published on Rikipedia are authored by Riccardo Colombo and released under Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0). Sharing and quotation are permitted for non-commercial purposes with attribution.