Sulture · legal
Terms & conditions
The terms the platform is used under, the privacy and cookie policies, the data-processing notice, the subprocessors we rely on, and how we use AI.
Last updated 2 September 2026. Prepared by Sulture from the platform’s documented scope.
No tracking. Sulture sets no tracking or advertising cookies, loads no third-party trackers and runs no analytics script. Two strictly necessary cookies exist only once you sign in. Visits are counted on the server, without cookies and without identifying anyone. That is why this site shows no consent banner; the cookie policy below says the same at length.
01
Platform terms of service
These terms govern the use of Diorama, the micro-app platform operated by Sulture S.r.l. (registered office Viale Papa Giovanni XXIII 106, 24121 Bergamo, Italy; VAT IT04238380168), between Sulture and the organisation that holds a space on the platform (the client). They apply from the moment a space is created and to every person the client admits to it.
What the platform is. Diorama runs the client’s applications inside spaces. A space is the boundary every resource, grant, audit record and export is keyed by, and nothing held in one space is readable from another. Applications are installed from published packages, run on the platform’s own services (storage, queues, media processing, secrets, outbound connections) and are operated through the console and the command-line tool.
Accounts and roles. Access is by a personal email address confirmed with a one-time code, or by a passkey. Every subject in a space holds one of two roles, admin or member, and the client is responsible for whom it admits and with which role. Platform oversight — read-only visibility of the platform’s own records across spaces — is exercised only by Sulture staff named in the system space’s allowlist, and every such read is itself recorded on the space it looked at.
The client’s data. Everything an application stores in a space belongs to the client. Sulture does not read it, sell it or use it for any purpose other than operating the platform, and the platform is built so that its own records (the audit trail) never contain it. The client may export the whole of an instance’s data at any time as a machine-readable archive, and may retire, purge or erase an instance or a space.
Destructive acts. Retiring an application stops it and destroys nothing. Purging and erasure destroy data permanently; both require an explicit second-factor confirmation and, unless the client declares out loud that it wants no copy, an export receipt. Sulture keeps no shadow copy: once destroyed, data cannot be recovered by anyone, and the audit record of what was destroyed is the only thing that outlives it.
Data residency. A space may declare its jurisdiction when it is created (European Union, United States, or FedRAMP) and cannot change it afterwards; every resource of that space is placed accordingly. A space that declares nothing is unrestricted and its data is placed near first access.
Availability and change. The platform is provided as is, against the platform standard it declares; the standard is at version 1, and changes to it are additive. Sulture may change infrastructure, backing products and the console at any time without changing the guarantees the standard gives. Planned maintenance and incidents are published on the status page.
Acceptable use. The client may not use the platform to store or process unlawful content, to attack third parties, or to circumvent the isolation between spaces. Sulture may suspend a space that does so and will tell the client why.
Fees, term and termination. Fees, where any apply, are those agreed in writing between Sulture and the client. Either party may end the agreement with thirty days’ notice. The client keeps the right to export its data until the space is deleted, and a space cannot be deleted while it still holds an application.
Liability and law. To the extent the law permits, Sulture’s liability under these terms is limited to the fees the client paid in the twelve months before the event giving rise to the claim, and excludes indirect loss. Nothing here limits liability for wilful misconduct or gross negligence. These terms are governed by Italian law, and the courts of Bergamo have exclusive jurisdiction.
02
Privacy policy
Sulture S.r.l. is the data controller for the personal data the platform needs in order to run: the email address a person signs in with, the passkeys they register, the roles they hold, and the platform’s own records of what was done, by whom and when. Contact: info@sulture.com, or by certified email at info@pec.sulture.com.
Client data. For the data the client’s applications store in their spaces, the client is the controller and Sulture is the processor, under the data-processing terms in the platform terms of service. Sulture processes it only on the client’s documented instructions, which are the acts the client performs on the platform.
What we collect, and why. Sign-in: your email address and the one-time codes sent to it, or your passkey’s public key — on the basis of the contract with the organisation that admitted you. Session: a session cookie and an anti-forgery cookie — necessary to keep you signed in and to refuse requests forged from elsewhere. Audit: platform-authored records of installs, grants, exports, erasures and administrative acts, naming the acting subject — on the basis of our legitimate interest in the security and accountability of the platform, and of the client’s interest in an accountable record. No application payload ever enters an audit record.
Retention. Sign-in codes expire within minutes and are stored only as hashes. A session lasts twelve hours. Accounts and roles are kept for as long as the person is admitted to a space. Audit records outlive the data they describe, because a record of what was destroyed is the only thing that does.
Where. The platform runs on Cloudflare’s network, and the placement of a space’s data follows the jurisdiction the space declared. Transfers outside the European Economic Area, where they occur, rest on the European Commission’s standard contractual clauses in Cloudflare’s data processing addendum.
Your rights. You may ask for access to, rectification of, or erasure of the personal data Sulture holds about you, ask for its processing to be restricted, object to it, and receive it in a portable form; you may also lodge a complaint with the Garante per la protezione dei dati personali. Write to info@sulture.com. Data that your organisation’s applications hold about you is the organisation’s to answer for, and we will forward your request to it.
No profiling, no advertising. The platform contains no advertising and no third-party tracking, and takes no automated decision about you. Traffic is counted on the server without cookies and without personal data — the page path, the country, a coarse device class, the referring site’s host and the status of each request, never an IP address, a user agent string or a user id — so that count is not a processing of personal data and needs no consent. It sends no email except the codes and confirmations you ask for.
03
Cookie policy
The platform sets two cookies, both strictly necessary, and only once you sign in. __Host-dio_token is the session: secure, HttpOnly, twelve hours. __Host-dio_csrf is a token the console echoes with every request that changes something, so that a request forged from another site is refused. Both are set only when you sign in and removed when you sign out; neither needs your consent under the ePrivacy rules, because without them there is no session to keep.
Your browser’s own storage (localStorage) keeps preferences and nothing else: the theme, the language, and the width of the navigation rail. They never leave the browser and are never read by the platform. No cookie is used for analytics, advertising or tracking, no cookie or script is set or loaded by a third party, and no consent banner is shown because there is nothing to consent to.
Traffic is counted on the server, without cookies and without identifying anyone. For each request the platform records the page path, the country, a coarse device class (desktop, phone or tablet), the host of the referring site and the response status — and never an IP address, a user agent string or a user id. Nothing is stored on your device for it, and no record can be traced back to a person, which is why it needs no consent either.
Maps. Where an application shows a map, the tiles are fetched from OpenFreeMap (tiles.openfreemap.org), which sees the request as any web server does — the address it came from and the tile asked for. No cookie is involved.
04
Data-processing notice (art. 13 GDPR)
Controller: Sulture S.r.l., Viale Papa Giovanni XXIII 106, 24121 Bergamo (BG), Italy; VAT IT04238380168; info@sulture.com; certified email info@pec.sulture.com.
Data processed: identification data (email address); authentication data (passkey public keys, hashed one-time codes); role assignments; and records of the platform’s own operations attributed to the acting subject. The server-side traffic count (page path, country, coarse device class, referrer host, status) holds no identifier and is not personal data.
Purposes and legal bases: (a) providing the service to the organisation that admitted you — performance of a contract, art. 6(1)(b); (b) security, accountability and the prevention of abuse — legitimate interest, art. 6(1)(f); (c) compliance with legal obligations — art. 6(1)(c).
Nature of the provision: an email address is necessary to use the platform; without it no account can exist. No other data is required.
Recipients: the subprocessors listed on this page, each bound by a data-processing agreement; public authorities where the law requires it. Data is not communicated to anyone else and is never disseminated. Cloudflare, which delivers the site, processes the IP address of every request in order to do so and keeps short-lived edge logs for security and abuse prevention, on the basis of legitimate interest; the platform’s own request logs carry a request id, never an address.
Transfers: within the European Economic Area by default; outside it only under the safeguards of Chapter V of the GDPR (the standard contractual clauses).
Retention: as stated in the privacy policy above.
Rights: articles 15 to 22 of the GDPR — access, rectification, erasure, restriction, portability and objection — exercised by writing to info@sulture.com; and the right to lodge a complaint with the Garante per la protezione dei dati personali (garanteprivacy.it).
No automated decision-making within the meaning of article 22, including profiling, is carried out by the platform.
05
Subprocessors
Sulture engages the following processors to run the platform. Each is bound by a data-processing agreement, and this list is updated before a new one is engaged.
Cloudflare, Inc. (San Francisco, United States; European processing under its data processing addendum and the standard contractual clauses) — the network the platform runs on: Workers (compute), D1 (the platform’s directories), R2 (object storage and exports), Durable Objects (per-instance storage and queues), Workers KV, Containers (media processing) and Email Service (sign-in codes and confirmations).
OpenFreeMap (a public, non-commercial map-tile service) — map tiles, only where an application renders a map, receiving the viewer’s request as any web server does.
External providers that the client connects an application to, through the platform’s connect mechanism, are engaged by the client and not by Sulture, and are the client’s own processors.
06
Use of AI
Sulture uses artificial-intelligence systems, including large language models, in engineering the platform: to write and review code, documentation and texts such as these. Everything so produced is reviewed by a person before it ships, and the platform’s guarantees are held by its test suites, not by the tools that helped write them.
The platform itself contains no AI feature that reads client data. No client data is used to train, fine-tune or evaluate any model, by Sulture or by anyone Sulture engages.
An application may use an AI provider, but only through a connection the client has set up and authorised for it, under that provider’s terms. The platform records that the connection exists and what it is allowed to reach, and never the content that crosses it.
Agents. Software agents may be given their own identity in a space by an admin, at no more authority than that admin holds, and every act they take is recorded in the audit trail under that identity.