IAT Search — Privacy Policy

Effective date: 2 July 2026  ·  Last updated: 2 July 2026  ·  Version 2.0

This Privacy Policy describes how IAT Search collects, uses, and protects personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (Italian Privacy Code).

1. Data Controller

INDEX RERUM S.R.L. SEMPLIFICATA UNIPERSONALE — società a socio unico
Via del Pucino 61, 34151 Trieste, Italy
VAT no. 01453040329 · REA no. TS 218152 · Share capital EUR 3,000 (fully paid-in)
Email: support@admintribunals.com

For all privacy-related enquiries, requests to exercise your rights, or complaints, please contact the Data Controller at the address above.

2. Personal Data Collected

2.1 Account data

2.2 Usage data

2.3 Billing and usage-metering data

Billing, invoicing, and payment processing — for both subscriptions and one-time purchases of credit packs — are handled exclusively by Paddle.com Market Limited ("Paddle"), which acts as Merchant of Record for all transactions (see Section 5). This means Paddle, not the Data Controller, is the legal seller of the subscription or credit pack to you: Paddle issues the invoice, calculates and collects any applicable VAT or sales tax according to your jurisdiction, and handles refunds and chargebacks under its own terms.

The Data Controller does not collect, process, or store payment card details at any point. From Paddle the Data Controller receives only the data strictly necessary to manage your account on this Service: a Paddle customer identifier, your billing email, your country (for tax-jurisdiction reporting), the plan and billing cycle, and the status of each transaction (paid, refunded, failed). Records necessary for the Data Controller's own fiscal and accounting compliance under Italian law are retained as set out in Section 4.

To operate the Premium monthly usage allowance and the credit system, the Data Controller maintains, within your account, a measure of your AI-feature usage against the monthly allowance, your purchased-credit balance, and a ledger of credit movements (allowance resets, purchases, and consumption). This data is generated by your use of the Service, is used solely to provide and meter the contracted service, and is not used for any other purpose.

2.4 Technical and log data

3. Legal Bases for Processing

Data categoryPurposeLegal basis (GDPR Art. 6)
Account data (email, name, password hash) Registration, authentication, account management Art. 6(1)(b) — performance of contract
Query history and saved judgments Providing the service; enabling the user to retrieve past analyses Art. 6(1)(b) — performance of contract
Subscription plan and quota data Access control; enforcement of service tier limitations Art. 6(1)(b) — performance of contract
Billing records Fiscal and accounting obligations under Italian law Art. 6(1)(c) — legal obligation
Server logs Security monitoring, error diagnosis, abuse prevention Art. 6(1)(f) — legitimate interest
Email address (service communications) Account verification, password reset, policy updates Art. 6(1)(b) — performance of contract

4. Retention Periods

Data categoryRetention periodBasis
Account data Until account deletion, plus a 30-day grace period for recovery Contractual necessity
Query history and saved judgments Until the user deletes individual records or closes the account Contractual necessity; user control
Billing and fiscal records 10 years from the date of the underlying transaction Art. 2220, Italian Civil Code (Codice Civile) — mandatory accounting record retention
Server access logs 90 days, then automatically purged Legitimate interest; proportionality
Authentication tokens (cookies) Until logout or browser session end Technical necessity
Right to erasure and billing data. If you request deletion of your account, all account data, query history, and saved judgments will be permanently deleted. However, billing and fiscal records subject to the 10-year retention obligation under Art. 2220 of the Italian Civil Code cannot be erased before the expiry of that period. Any such records retained solely for legal compliance will be isolated from active processing and used for no other purpose.

5. Data Processors and Sub-processors

The Data Controller engages the following third-party processors, each bound by a data processing agreement (DPA) and subject to GDPR-equivalent safeguards:

ProcessorRoleLocationData transferred
Hetzner Online GmbH Cloud infrastructure and hosting Germany (EU) All application data stored on servers within the European Economic Area. No transfers outside the EEA.
Paddle.com Market Limited Merchant of Record (billing, invoicing, payment processing, tax collection — subscriptions and credit packs) United Kingdom (with EU subsidiary Paddle.com Market BV in the Netherlands) Paddle is the legal seller of subscriptions and the controller of the payment relationship with you. Paddle independently determines the means of processing your payment data (card details, billing address, tax identifiers) under its own Privacy Policy and applicable EU/UK adequacy frameworks. The Data Controller receives from Paddle only the limited subscription metadata described in Section 2.3. Paddle's Privacy Policy: paddle.com/legal/privacy.
Resend (Resend Inc.) Transactional email delivery (account verification, password reset, service notifications) United States (with EU sending infrastructure) Your email address and the content of transactional messages (verification links, password reset links, service notices) are transmitted to Resend for delivery. Transfers are covered by Standard Contractual Clauses (SCCs). Resend acts as data processor on behalf of the Data Controller.
Anthropic, PBC AI language model provider (Claude API) United States The text of your legal queries and the retrieved judgment excerpts are transmitted to the Anthropic API to generate AI responses. Anthropic processes this data under its API usage policy and does not use API inputs to train models by default. Transfers are covered by Standard Contractual Clauses (SCCs). Users should avoid including personal data of third parties or confidential client information in queries.
Google LLC / LinkedIn Ireland Unlimited Company (only if you choose to sign in with Google or LinkedIn) OAuth identity providers (authentication) United States (Google) / Ireland (LinkedIn) If you elect to authenticate via Google or LinkedIn, you are redirected to the chosen provider, which authenticates you and returns a stable subject identifier together with your email address and (optionally) your name. The Data Controller does not receive your password or any other account credential. The provider is an independent controller of the authentication transaction; transfers to Google are covered by Standard Contractual Clauses (SCCs).

6. Cookies

CookieTypePurposeDuration
auth_token Essential / HttpOnly Maintains your authenticated session. Cannot be read by JavaScript. Required for the service to function. Until logout or after 2 hours of inactivity
oauth_state Essential / HttpOnly Set only during a sign-in attempt with Google or LinkedIn. Stores a CSRF anti-forgery token used to validate the callback from the identity provider. Deleted as soon as the sign-in flow completes (success or failure). 10 minutes
cookies_accepted Functional Records that you have acknowledged this cookie notice, so it is not shown again. 1 year

No advertising, profiling, or behavioural tracking cookies are used. The only third-party cookies that may be set are those placed by Paddle during a payment or credit-purchase checkout that you actively initiate, strictly to process the transaction; they are governed by Paddle's own policies. A complete description of cookies and browser local storage used by the Service is available in the Cookie Policy.

7. Your Rights under the GDPR

As a data subject, you have the following rights, exercisable by contacting the Data Controller at support@admintribunals.com:

Requests will be responded to within 30 days. The period may be extended by a further two months where necessary, with notification of the reason for the extension.

8. Security Measures

No security measure is infallible. In the event of a personal data breach likely to result in a risk to your rights and freedoms, you will be notified without undue delay in accordance with Art. 34 GDPR.

9. Minors

This service is intended exclusively for legal professionals and is not directed at persons under 18 years of age. The Data Controller does not knowingly collect personal data from minors.

10. Updates to This Policy

This Privacy Policy may be updated to reflect changes in the service, applicable law, or processing activities. Material changes will be communicated to registered users by email at least 14 days before taking effect. The current version and its effective date are always indicated at the top of this page.

Continued use of the service after the effective date of an updated policy constitutes acceptance of the changes.

11. Contact

Data Controller
INDEX RERUM S.R.L. SEMPLIFICATA UNIPERSONALE — società a socio unico
Via del Pucino 61, 34151 Trieste, Italy
VAT no. 01453040329 · REA no. TS 218152
Email: support@admintribunals.com

Supervisory Authority (Italy)
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma
www.garanteprivacy.it