Why This Policy
Some personal data may be processed when you browse this website. This page describes how the data collected during your visit is handled. This policy is provided under data protection law (EU Regulation 2016/679, hereinafter “GDPR,” and Italian Legislative Decree 196/2003, as amended) to everyone who interacts with the website galacticriddles.com. It applies only to this website and not to any other websites that may be reached through links.
Data Controller
The data controller is:
Marco Chiesi
Via Ferruccio Parri 8
64021 Giulianova (TE)
Italy
Email: privacy@chiesi.net
What This Website Does
Galactic Riddles is a personal website that publishes logic and math puzzles. It sells nothing, requires no registration, has no comments, contact forms, or newsletters, and shows no ads. Besides the data technically needed to run the server, it collects anonymous, aggregate visit statistics, using a tool installed on the website itself and without cookies. Both are described below.
Data Processed
Browsing data (server logs). Like every web server, the server hosting this website records the requests it receives. These logs contain the IP address the request comes from, the date and time, the page requested, the response code, and information about the browser (user agent). This is the technical minimum needed to serve the pages, keep the website available and secure, and investigate any abuse. This data is not used to identify individual visitors or to build profiles.
Visit statistics (Koko Analytics). To know how many people read the riddles, the website uses Koko Analytics, a plugin installed on the website itself: the data stays in the website’s database and is not sent to any external service. When you open a page, a small script tells the server which page you are viewing and which website you came from (if you came from another website). Only aggregate daily counts are stored: number of visits and visitors, most-read pages, referring websites, and any campaign parameters present in the link (for example utm_source). No IP addresses or other data that could identify you are stored, and no cookies or other information stored on your device are used.
To avoid counting the same person twice on the same day, at the time of the visit the server computes a non-reversible fingerprint (hash) from the IP address, the browser type, and a random value that changes every day. The fingerprint, together with the list of pages already counted for that day, is kept in a temporary file on the server and deleted every night along with the random value: the next day it can no longer be linked either to the previous visit or to you. Visits by the administrator and by bots and crawlers are not counted.
Emails sent voluntarily. If you write to the address given above, your email address and any personal data you choose to include in your message are processed solely in order to reply to you.
Purposes and Legal Bases
- Operating and securing the website (server logs): the controller’s legitimate interest in running the website and protecting it from abuse, Art. 6(1)(f) GDPR.
- Anonymous visit statistics (Koko Analytics): the controller’s legitimate interest in knowing which content is read and how the website is found, in order to improve it, Art. 6(1)(f) GDPR. The processing is minimal: the temporary fingerprint lasts at most until midnight, after which only aggregate numbers remain.
- Replying to emails: the controller’s legitimate interest in replying to correspondence received at your initiative, Art. 6(1)(f) GDPR.
Analytics, Advertising, and Third-Party Content
The only statistics are the Koko Analytics ones described above, which run entirely on the website’s server. No Google Analytics, no external Matomo, no tag manager, and no other third-party measurement systems. There are no ads, affiliate links, social widgets, embedded maps, embedded videos, or other content loaded from third-party websites.
The website contains a few ordinary links to other websites. Following one takes you to a service with its own privacy policy, which this document does not cover. Until you click, nothing is sent to those websites.
Cookies and Local Storage
This website does not set any cookies for visitors: no technical, analytics, or third-party cookies. The visit statistics, too, work without cookies and without storing anything on your device. You can verify this with your browser’s developer tools.
There are only two pieces of information that may be stored on your device, and it is only fair to describe them precisely. Both are kept in the browser’s localStorage: they are never sent to the server, cannot be read by other websites, and are deleted when you clear the website’s data from your browser.
- eg-theme: your preference between the light and dark theme, so the website remembers it on your next visit. It contains a single word (“light” or “dark”) and is created only if you press the theme button.
- eg-risolti: your progress, that is, the list of riddles you have marked as solved (identified by the page’s short address, for example “the-water-lily”) along with the date it happened. It is created the first time you open a solution or use a riddle’s “Unsolved / Solved” button, and it is used only to show you the status of each riddle and the counters on the home page. You can clear it at any time with the “Reset” button on the home page.
WordPress sets some technical cookies only for those who log in to the website’s administration area, that is, for the controller.
Why There Is No Cookie Banner
You won’t be asked to accept anything, and that is a deliberate choice. Consent is required when information is stored on or read from the user’s device without being strictly necessary to provide the service requested. This website stores nothing, except the theme preference and your riddle progress: these are saved only when you use the related features, stay on your device, and serve exclusively to do what you asked for. There is nothing to consent to, so there is no banner.
How and Where Data Is Processed
The controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of personal data. Data is processed using computer and online tools, in ways strictly related to the stated purposes. This is a personal website run by a single person: the only parties with access to the data are the controller and the hosting provider, acting as data processor.
The website’s data and its backup copies are stored on servers located in data centers within the European Union. It cannot be ruled out that the hosting provider processes some data outside the European Union: in that case, the transfer takes place only to countries that ensure an adequate level of protection under an adequacy decision of the European Commission, or subject to appropriate safeguards, such as standard contractual clauses (Art. 46(2)(c) and (d) GDPR). You can request information about this by writing to the controller.
Recipients and Data Processors
The website is hosted by Hostinger International Ltd., which acts as data processor for the server logs and for the statistics data stored on the website, processing them according to the controller’s instructions. The processing of visitor data collected on behalf of customers is described in Hostinger’s privacy policy and governed by the relevant data processing agreement.
For full transparency: the controller works for Hostinger. Hostinger is the provider chosen to host the controller’s personal websites, and this does not change the data processor relationship described above.
The data is not disclosed or transferred to third parties, except where required by law (for example, at the request of the competent authorities).
Retention Period
- Server logs: retained by the hosting provider for a limited period, as part of the normal operation of the service.
- Visit statistics: the temporary fingerprint and the related file are deleted every night; the aggregate counts, which contain no personal data, are retained for a maximum of 36 months.
- Emails received: for as long as the conversation is useful, and no longer.
Legal Defense
Personal data may be used by the controller in legal proceedings, or in the steps leading up to their possible initiation, to defend against abuse in the use of the website. The controller may also be required to disclose data at the request of public authorities.
Your Rights
Under Articles 15–22 of the GDPR you may exercise, where applicable, the following rights:
- access: obtain confirmation as to whether data concerning you is being processed, and receive a copy of it;
- rectification: have inaccurate data corrected or updated;
- erasure: have your data erased, where the required conditions are met;
- restriction: obtain restriction of processing, where the required conditions are met;
- objection: object at any time, on grounds relating to your particular situation, to processing based on legitimate interest;
- portability: receive your data in a structured, commonly used, and machine-readable format, where processing is based on consent or on a contract and is carried out by automated means.
To exercise your rights, you can write to the controller at the email address given on this page. Requests are free of charge and are handled as soon as possible, and in any case within one month.
Complaints to a Supervisory Authority
If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the EU member state where you live or work.
“Do Not Track” Requests
This website does not track visitors and does not build profiles: the statistics are anonymous and aggregate. For this reason, it does not behave differently in response to “Do Not Track” signals. If you prefer not to be counted even anonymously, you can block JavaScript or use an extension that blocks analytics scripts.
Changes to This Policy
The controller reserves the right to change this policy at any time, with notice given on this page. We therefore encourage you to check it periodically, referring to the last-updated date shown at the bottom.
Definitions
- Personal data: any information that makes it possible to identify a natural person, directly or indirectly.
- Browsing data: information collected automatically by the server during a visit, such as IP address, date and time, page requested, response code, and browser characteristics.
- Data subject: the natural person to whom the personal data relates.
- Data controller: the person who determines the purposes and means of the processing of personal data.
- Data processor: the party that processes personal data on behalf of the controller.
- Cookie: a small piece of data stored on the user’s device.
Last updated: September 26, 2026.