Version 1.0 — updated: 1 October 2026
1. Data Controller
The data controller for the CDR Apps website is:
CDR APPS DI RUSU COSMIN DUMITRU
VAT No.: 18569901004
REA: RM-1793518
Italy
Certified email (PEC): [email protected]
Contacts:
Privacy: [email protected]
Support: [email protected]
Website: www.cdrapps.com
2. Scope of this Policy
This Privacy Policy applies to the cdrapps.com website and its public pages.
CDR Apps applications and services, including RistoBoost and other products that may be available, may have separate product-specific privacy policies and terms.
Where a website page links to an app-specific privacy policy, that policy governs processing carried out within the relevant app or service.
3. Data processed when browsing
Simply visiting the website may involve technical processing of information normally associated with a web request, for example:
- IP address;
- date and time of the request;
- page or resource requested;
- technical browser and device information;
- information required to transmit, secure and process the request.
Such data may be processed by the infrastructure used to host, distribute and protect the website.
The website currently has no user accounts, registration forms or contact forms that directly submit personal data to a CDR Apps backend.
4. Hosting and Cloudflare
The CDR Apps website is hosted through Cloudflare Pages.
Cloudflare may process technical information associated with network requests to the extent necessary to provide hosting, delivery, caching, reliability and security services.
CDR Apps does not currently configure Google Analytics, Firebase Analytics, advertising pixels or other client-side user-profiling tools in the website source code.
Any infrastructure functionality provided by the hosting service is subject to the relevant provider's terms and privacy information.
5. Language preference
The website may store the language selected by the user in the browser through localStorage.
The key currently used is:
cdr_lang
This information is used only to remember the preferred language among those supported by the website.
It is not used for advertising, profiling or cross-site tracking.
If browser local storage is deleted or blocked, the website continues to function but may not remember the selected language on later visits.
See the Cookie and Browser Storage Policy for further information.
6. Cookies, analytics and tracking tools
In the current version of the website:
- the website code does not create cookies through document.cookie;
- advertising cookies are not used;
- profiling cookies are not used;
- Google Analytics and Firebase Analytics are not used;
- advertising pixels are not loaded;
- fingerprinting tools are not used;
- social iframes or embeds are not loaded for tracking purposes;
- third-party analytics or advertising scripts are not loaded by the website code.
For this reason, the website does not ask users to make a consent choice through a banner for profiling or analytics tools that are not present.
If non-technical tools or other processing requiring consent are introduced in the future, the information and choice mechanism will be updated before or together with their activation where required.
7. Contact by email
The website publishes email addresses for support, privacy and business communications.
If a user independently chooses to contact CDR Apps by email, the following may be processed:
- sender's email address;
- name and other information voluntarily provided;
- message contents;
- attachments voluntarily submitted;
- technical information associated with the communication.
Users should avoid sending personal data that is not necessary for their request.
8. Purposes of processing
Depending on the circumstances, data may be processed to:
- make the website available;
- ensure security, stability and correct content delivery;
- remember the user's language preference;
- respond to support, privacy or information requests;
- prevent abuse or security incidents;
- establish, exercise or defend legal rights;
- comply with legal obligations.
9. Legal bases
Depending on the circumstances, processing may be based on:
Legitimate interests
- technical provision and security of the website;
- protection of infrastructure;
- abuse prevention;
- technical management;
- protection of the controller's rights.
Performance of a contract or pre-contractual measures
- where a user's communication concerns a service, commercial inquiry or contractual relationship.
Legal obligation
- where retention or disclosure of particular information is required by law.
Consent
- where a specific optional processing activity requires consent under applicable law.
10. Retention
Technical data relating to website delivery and security is retained for as long as necessary for the relevant purposes and according to the practices applied by the hosting infrastructure.
The language preference stored in browser localStorage remains on the device until it is changed or deleted by the user, browser or other device settings.
Communications received by email are retained for as long as necessary to handle the request and, where necessary, to comply with legal obligations or protect legal rights.
CDR Apps does not define through the website code retention periods for technical logs independently maintained by the hosting provider.
11. Recipients and providers
Data may be processed by technical providers necessary for operation of the website.
Cloudflare is used for website hosting and delivery.
Communications sent by email may also be processed by the email-service providers used by the sender and CDR Apps.
The website may contain links to external services. Voluntarily opening such links takes the user outside the CDR Apps website, and subsequent processing is governed by the relevant provider.
12. International transfers
Some technology providers may process information outside the European Economic Area.
Where required by applicable law, international transfers are carried out on the basis of mechanisms and safeguards recognized by applicable data-protection law or through mechanisms made available by the relevant provider.
13. Security
CDR Apps applies reasonable measures to limit processing to necessary information and to protect the website and its resources.
No Internet-connected system can guarantee absolute security.
14. Data-subject rights
Where provided under the GDPR, individuals may request:
- access to personal data;
- rectification;
- erasure;
- restriction of processing;
- objection;
- data portability;
- withdrawal of consent where processing is based on consent.
Individuals may also lodge a complaint with the competent supervisory authority, including the Italian Data Protection Authority where applicable.
15. Children
The website presents products, support and business information and is not specifically designed to collect personal data from children.
16. Links to external sites and services
The website may contain links to app stores, providers, social networks or other external resources.
The presence of a link does not mean that those services are automatically loaded within the website.
When a user chooses to open an external link, the destination website or service applies its own terms and privacy information.
17. Changes
This Privacy Policy may be updated when the website, infrastructure, processing activities or legal obligations change.
The updated version will be published on the CDR Apps website with the relevant date.
18. Contacts
Privacy matters:
Support: