Legal
Privacy Policy
Last updated: 19 June 2026
glarno helps small and mid-sized service companies handle email, clients, projects, documents and money in one place. This policy explains what personal data we process, why, and what rights you have. Trust comes first: your data stays in Europe and is not used to train third-party models.
1. Data controller
The data controller is Scalarly S.r.l., registered office at Via Borghetto 3, 20122 Milan (Italy). VAT IT08592260965 · REA MI-2035852 · certified email (PEC) [email protected] · SDI code W7YVJK9. glarno is a service of Scalarly S.r.l. For any request about your data, write to [email protected].
2. What data we process
We process different categories of data depending on how you use glarno:
- Contact and account data: name, email address, company, role, login credentials.
- Website usage data: pages viewed, device and technical data needed to run the site (see the Cookie Policy).
- Demo or contact requests: the information you give us when you book a demo or get in touch.
- Data processed inside the product: when you use glarno you connect your sources (email, documents, business software, bank). Content that enters the product is processed on your behalf as described in section 4.
3. Why we process your data and on what legal basis
- Providing the service and your account (performance of a contract, Art. 6(1)(b) GDPR).
- Responding to demo, support and contact requests (pre-contractual steps and legitimate interest, Art. 6(1)(b) and 6(1)(f)).
- Security, abuse prevention and technical operation of the site (legitimate interest, Art. 6(1)(f)).
- Anonymous statistics and site improvement, only if you consent via the cookie banner (Art. 6(1)(a)).
- Legal obligations (for example accounting and tax, Art. 6(1)(c)).
4. Data processed on behalf of customers
When you connect your sources, glarno reads email, messages, documents and transactions to prepare replies, tasks and quotes that you approve before anything is sent. For this content glarno acts as a data processor: you (or your company) are the controller. We process it only to deliver the service, following your instructions and a data processing agreement (DPA). We do not sell it and do not use it for our own purposes.
5. Where data is processed and AI models
Data is processed and stored in Europe. For AI features we use selected providers with adequate safeguards; your data is not used to train third-party models. Any transfer outside the European Economic Area happens only with the safeguards required by the GDPR (e.g. standard contractual clauses).
6. Who we share data with
We share data only with providers that help us deliver the service (hosting, infrastructure, email delivery, AI model providers), appointed as data processors and bound to confidentiality. We do not sell your data. An up-to-date list of processors is available on request at [email protected].
7. How long we keep data
We keep data for as long as necessary for the purposes described: account data while the account is active, contact and demo data for the time needed to follow up, and product data according to your instructions and the data processing agreement. We delete or anonymise data when it is no longer needed, unless the law requires otherwise.
8. Your rights
At any time you can exercise the rights under Articles 15-22 of the GDPR:
- access to your data and a copy;
- rectification of inaccurate data;
- erasure ("right to be forgotten");
- restriction of and objection to processing;
- data portability;
- withdrawal of consent at any time, without affecting processing already carried out.
To exercise them, write to [email protected]. You also have the right to lodge a complaint with your local data protection authority.
9. Cookies
The site uses only essential technical cookies and, with your consent, anonymous statistics cookies. You can find the details in the Cookie Policy, where you can also change your choices.
10. Security
We apply appropriate technical and organisational measures to protect data from unauthorised access, loss or misuse: encryption in transit, access controls, auditability of operations and the principle of least privilege.
11. Changes to this policy
We may update this policy over time. We will publish the updated version on this page with the new date. For significant changes we will notify you appropriately.
12. Contact
For any question about this policy or how we process your data: [email protected].