PALO Framework Privacy Policy
Privacy information Local-first tools Last reviewed: July 15, 2026
Table of Contents
1. Introduction
Welcome to PALO Framework ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience when using our website, web tools and Android application.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit
our website paloframework.org, use our web tools or use the
P.A.L.O. Framework Toolbox Android app (com.fabriziodegni.paloframework), in
compliance with the General Data Protection Regulation (GDPR - EU 2016/679) and other applicable data
protection laws. This notice describes the current website and mobile implementations and is not legal
advice.
PALO Framework tools are designed with privacy at their core. Model Canvas processing happens locally in your browser. Android app cases, assessments and evidence metadata are processed locally on your device. We do not collect, store, or have access to the governance content you create.
2. Data Controller
For the purposes of GDPR, the Data Controller is:
Organization: PALO Framework
Website: https://paloframework.org
Email: info@paloframework.org
Country: Italy (European Union)
3. Data We Collect
3.1 Data We DO NOT Collect
We want to be clear about what we do not collect:
- Personal data entered in the Model Canvas AI tool (processed locally only)
- Android app cases, assessment data, scores or evidence metadata
- Account information (we don't have user accounts)
- Payment information
- Precise location data
3.2 Android App Local Processing
The P.A.L.O. Framework Toolbox Android app is designed to operate locally without an account. Its optional Approval Inbox connects only after the user provides an HTTPS PALO-AI governance endpoint and an ephemeral bearer token. The app does not automatically transmit app content to PALO.
| Local Data or Operation | How It Is Used | Developer Access |
|---|---|---|
| Cases, assessments, evidence metadata and settings | Stored in local application storage and SQLite to provide the governance workflow. | None |
| Documents selected by you | Accessed through the Android document picker only after your explicit selection. | None |
| Biometric operation | Performed by Android device security to support local evidence signing. The app does not receive raw fingerprint or other raw biometric data. | None |
| Case File and Evidence Bundle exports | Created locally and passed to the Android share sheet only when you explicitly request an export. You choose the destination and recipient. | None, unless you independently choose a PALO contact address as the recipient |
Uninstalling the app or clearing its storage removes app-managed local data. Files that you previously exported remain in the destination you selected and must be deleted there separately.
3.3 Website Data We May Collect
| Data Type | Description | Purpose |
|---|---|---|
| Server Logs | IP address, browser type, pages visited, timestamps | Security and troubleshooting. PALO does not operate product analytics on this website. |
| Contact Form Data | Email, name, message content (if you contact us) | Respond to inquiries |
| Cookie Data | Session identifiers, preferences | Essential website functionality |
4. Legal Basis for Processing
In accordance with GDPR Article 6, we process personal data only when we have a valid legal basis:
| Legal Basis | GDPR Article | When We Use It |
|---|---|---|
| Consent | Art. 6(1)(a) | Newsletter subscription, non-essential cookies |
| Legitimate Interest | Art. 6(1)(f) | Website security, analytics, fraud prevention |
| Contract | Art. 6(1)(b) | Responding to your inquiries |
| Legal Obligation | Art. 6(1)(c) | Compliance with applicable laws |
5. How We Use Your Data
When we do collect data, we use it for:
- Website Operation: Ensuring the website functions properly
- Security: Protecting against malicious attacks and abuse
- Communication: Responding to inquiries you send us
- Improvement: Maintaining the website and responding to reported issues
6. Data Sharing & Transfers
6.1 Who We Share Data With
We do not sell your personal data. The Android app does not automatically share locally stored app content. If you explicitly use Android's share sheet, Android sends the selected export to the destination you choose under that destination provider's terms. For website operations, we may share data with:
- Hosting Providers: Infrastructure necessary to operate the website
- Technical resource providers: Google Fonts, cdnjs, and Tailwind CDN are used on some pages. Their servers may receive technical connection data such as your IP address and browser request details under their own privacy policies.
- Legal Authorities: When required by law
6.2 International Transfers
When your browser loads third-party technical resources, the relevant provider may process connection data outside the European Economic Area (EEA). Please consult that provider's privacy information for the applicable safeguards and transfer mechanisms.
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Other approved transfer mechanisms under GDPR Chapter V
7. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Server Logs | 30 days | Security monitoring |
| Contact Messages | 2 years | Record of communications |
| Android App Local Data | Until you delete it, clear app storage or uninstall the app | Provide the locally stored governance workspace |
8. Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
| Right | GDPR Article | Description |
|---|---|---|
| Access | Art. 15 | Obtain a copy of your personal data |
| Rectification | Art. 16 | Correct inaccurate personal data |
| Erasure | Art. 17 | "Right to be forgotten" - delete your data |
| Restriction | Art. 18 | Limit how we use your data |
| Portability | Art. 20 | Receive data in a machine-readable format |
| Object | Art. 21 | Object to processing based on legitimate interest |
| Withdraw Consent | Art. 7(3) | Withdraw previously given consent |
To exercise any of these rights, please contact us at info@paloframework.org. We will respond within 30 days as required by GDPR.
You have the right to lodge a complaint with a supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (www.garanteprivacy.it).
9. Cookies & Tracking
9.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and improve your experience.
9.2 Cookies We Use
PALO does not intentionally set cookies for advertising, behavioural profiling, or product analytics. Hosting and third-party resource providers may apply their own technical cookies or similar technologies; please review their notices for current details.
The P.A.L.O. Framework Toolbox Android app does not use cookies, advertising identifiers, analytics or tracking SDKs.
9.3 Managing Cookies
You can control cookies through your browser settings. Note that disabling certain cookies may affect website functionality.
10. Children's Privacy
Our website is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at info@paloframework.org.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by:
- Posting the new policy on this page
- Updating the "Last updated" date at the top
- For significant changes, providing a more prominent notice
We encourage you to review this policy periodically.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Privacy Inquiries: info@paloframework.org
Security Issues: info@paloframework.org
General Contact: info@paloframework.org
Android App Support: io@fabriziodegni.com
Website: https://paloframework.org
This Privacy Policy was developed in compliance with the General Data Protection Regulation (GDPR - EU 2016/679), the ePrivacy Directive (EU 2002/58/EC), and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.