Controller and contact details
The data controller is Tailor Made Media S.r.l., Via Valsesia 44, 20152 Milano (MI), Italy — VAT / tax code 09219720969. Privacy requests may be sent to info@tmmagency.com.
This notice was last updated on 26 July 2026.
Data processed and sources
- Browsing and security: the server and Aruba hosting process the technical data needed to deliver requests and protect the service, including IP data in ordinary security logs. Full IP address, user agent, referrer and full request URI are not copied into lead records.
- Forms and leads: name, company, email, any telephone number, market, project need, indicative budget, message, selected language, source category and submission date and time. The lead may also include an AI-generated summary, primary_area (main area/category) and recommended_path (recommended route) derived from the brief; these are non-binding support fields. Optional fields are marked or can be left blank.
- Optional account, SSO and callback: name, email, password stored as a hash, account/workspace identifiers and role; when Google or Vokira SSO is chosen, the identifier and profile data returned by that provider; for a requested callback, telephone number, topic and preferred time.
- Data normally comes directly from you. With SSO, the selected identity provider supplies the authentication data you authorise it to share.
Purposes, legal bases and whether data is required
- Operating and securing the site, preventing abuse and maintaining necessary technical records: the controller’s legitimate interest under Article 6(1)(f) GDPR; compliance with binding legal requests: Article 6(1)(c).
- Creating an account, authenticating through password, Google or Vokira SSO and saving conversations at your request: performance of the requested service under Article 6(1)(b).
- The site currently performs no direct-marketing or newsletter processing. Any future optional marketing activity will require a separate, specific choice where consent is the applicable basis.
- Browsing, guest chat and account creation are optional. Chat text is needed to obtain a reply; contact details and a sufficient description are needed for us to answer or call back. The Article 13 notice and privacy link are shown beside the submit control before you send the form; submission is your request, not consent to processing that is based on contract, legitimate interest or law.
AI assistant transparency
Do not enter health, biometric, genetic, political, religious, trade-union or sexual-life data, trade secrets, credentials, confidential client material or personal data about others unless you have a valid basis and authority to do so. Upload only images you are entitled to use.
Every new Vokira reply carries a visible label and machine-readable metadata: system name and version, UTC date, SHA-256 content hash, IPTC digital source type, HMAC signature and the public verification-endpoint address. The marking is retained with saved conversations and only in sessionStorage for guests. It is Vokira-specific integrity evidence and will be supplemented with applicable interoperable standards or state-of-the-art watermarking.
- AI replies are informational, are not a binding offer or professional advice and should be checked before being relied on.
- You can stop using the assistant and contact the TMM team directly at info@tmmagency.com.
Recipients and international transfers
Personal data is not sold or made public. Within their duties it may be accessed by authorised TMM staff and by suppliers that support the service.
Some AI or SSO suppliers, including Vokira’s Supabase infrastructure when Vokira SSO is chosen, may process data outside the EEA, including in the United States; no unverified hosting region is assumed. Where required, transfers rely on an adequacy decision or European Commission standard contractual clauses and appropriate supplementary measures. Information on the applicable safeguard or a copy may be requested at info@tmmagency.com.
- Aruba, for hosting, database and email infrastructure in the European Economic Area, and authorised website maintenance suppliers.
- iubenda, as the consent-management platform, for displaying the notice and recording cookie choices.
- Cloudflare Turnstile is not currently configured. If it is enabled in the future for anti-bot checks, its technical processing will be disclosed and configured before activation.
Retention
- Short-lived anti-abuse counters expire within minutes. Aruba and security logs are kept only for the period needed for security, fault diagnosis and legal obligations under the applicable service arrangements.
- If a contractual relationship begins, records required for performance, accounting, defence of claims or statutory obligations are kept for the applicable legal period.
Vokira, roles, persistence and lead qualification
- For processing carried out through this website, Tailor Made Media S.r.l. (TMM) is the controller. Vokira is a product of CMARK DI COCCIOLO ALESSANDRO, sole trader, Via Prato 30, 20152 Milan (MI), Italy — VAT no. 09374580968, tax code CCCLSN91E10F205A, info@vokira.ai — and is also distributed by TMM. CMARK acts as processor when it supplies the TMM Vokira tenant and processes data on TMM’s instructions; it is a separate controller for Vokira ID and for platform accounts and services requested directly by the user. These distinct roles do not imply joint controllership. CMARK qualifies as processor only for documented processing performed on TMM’s instructions and subject to an Article 28 GDPR agreement: this notice does not certify that the DPA has already been signed; TMM must verify and formalise it before or when that processing is activated.
- When you send a message, including as a guest, text, optional images and the history needed for continuity may be sent to the Vokira tenant and retained server-side in conversation records. Records may include a visitor/session reference, name and email when authenticated, language, page, date and time, user agent, referrer, origin and technical security data. Leads may include name, company, email, telephone, message, budget, summary, score, tier/priority, reason, external identifiers and CRM links or status. Clearing sessionStorage removes only the device copy, not data already transmitted to the server.
- TMM and Vokira use these data to provide the requested reply, maintain conversation continuity, handle a contact or callback, prevent abuse, qualify the lead and route it to a person or CRM. Summaries, scores, tiers and recommended routes may be produced by heuristic rules or with AI assistance and are not binding. A person decides the commercial follow-up; no decision producing legal or similarly significant effects is taken solely by automated processing. The legal bases are pre-contractual steps or performance of the requested service (Article 6(1)(b) GDPR) and, for security, request organisation and non-contractual follow-up, TMM’s legitimate interests (Article 6(1)(f)), with a right to object and request human review where applicable.
- Recipients may include authorised TMM personnel, CMARK/Vokira and its Supabase infrastructure, the CRM connected to the tenant, OpenRouter and the AI provider actually configured, including OpenAI or Anthropic. The provider, model and technical route may change with the active configuration; TMM does not assume zero retention or EU location unless verified for the specific route. Transfers outside the EEA must be covered by an adequacy decision, standard contractual clauses and, where necessary, supplementary measures.
- WordPress lead copies, including legacy records whose expiry is derived from their creation date, are deleted within 365 days; WordPress account conversations after 365 days of inactivity. Copies in the Vokira tenant, Vokira ID data, activities, CRM integrations and any backups follow the documented periods for the relevant service and may not be removed by clearing the browser or only the WordPress account. TMM does not claim automatic remote deletion until its execution has been verified. For access, copy, rectification, objection, restriction, portability or erasure write to info@tmmagency.com; TMM will coordinate the request with CMARK and other recipients, normally within one month. For Vokira ID/platform processing under CMARK’s separate control, you may also write to info@vokira.ai and read https://vokira.ai/privacy.
Your rights and complaint
By writing to info@tmmagency.com you may exercise, where applicable, the rights under Articles 15–22 GDPR. We may ask for information needed to verify your identity.
- Obtain confirmation, access and a copy of your personal data.
- Request rectification, erasure or restriction of processing.
- Receive data you supplied in a portable format where the legal conditions are met.
- Object, on grounds relating to your situation, to processing based on legitimate interest.
- Withdraw any consent used for a genuinely optional future purpose, without affecting prior lawful processing.
- Lodge a complaint with the Garante per la protezione dei dati personali at www.garanteprivacy.it, or with the supervisory authority of your habitual residence, workplace or place of the alleged infringement.
Cookie choices and preference evidence
When Iubenda is available, the platform records a random preference identifier, date and time and IP address to document the choice. Iubenda technical access logs may include IP, user agent, referrer and HTTP headers for up to 15 days; preference evidence may be retained for up to 5 years unless the controller sets a shorter period or deletes it. Iubenda processes these data on TMM’s behalf under its data processing agreement.
If the Iubenda banner is temporarily absent, for example because of network unavailability or plan limits, the TMM panel shows the necessary-only state and stores only on the device the localStorage key tmm-cookie-choice-v1 with the choice, version and date. The value is not sent to TMM, does not enable trackers and can be removed by clearing site data.