Legal
Cooperation with the authorities and data requests
This policy is addressed to law enforcement agencies, judicial authorities and other competent authorities. It sets out the address to which requests concerning pik.li should be sent, what they must contain, how InCloud verifies their authenticity and which data it can and cannot provide.
Last updated: 24 September 2026 · Version 2026-09-24.2
This text is published in nine languages. The Italian version is authoritative; the versions in other languages are translations provided for convenience only and, in the event of any discrepancy, the Italian text prevails.
Where to send requests
Requests, orders and data preservation requests must be sent to [email protected] from an official address of the requesting office, with the signed document attached in PDF format. For formal service, and wherever the law requires the use of certified e-mail, the PEC address of InCloud S.r.l. must be used: [email protected].
This channel is reserved for authorities. To report a harmful link, please use the report form. Report a link
In brief
- Upon a valid request from a competent authority, InCloud provides without delay the data in its possession relating to accounts, logins, links, campaigns, clicks, payments and abuse.
- Every request is verified before a response is given: fake requests do exist, and their very purpose is to obtain third parties' data unlawfully.
- InCloud retains the full IP address of anyone who opens a link for the statistics retention period, but does not know their identity and does not host the destination pages: the identity of the person and the content of the pages cannot be provided.
- On request, data are preserved immediately pending the formal order; emergencies involving a threat to life take absolute priority.
- As a rule, the account holder is informed, unless the law or the authority prohibits it.
This summary is for guidance only: the full text below prevails in all cases.
1.Service operator and addressees of this policy
pik.li is a service of InCloud S.r.l., a company incorporated under Italian law with its registered office in Vignola (MO). For the short links it stores, InCloud is a provider of intermediary services consisting of the storage of information (hosting) within the meaning of Regulation (EU) 2022/2065 on a Single Market for Digital Services (the “DSA”); the Digital Services Coordinator for Italy is the Autorità per le garanzie nelle comunicazioni (AGCOM).
This policy is addressed to judicial authorities, police forces, administrative and supervisory authorities and national CERTs/CSIRTs which, under the law applicable to them, are entitled to request information, the preservation of data or the removal of content. The address given here is also the single point of contact for the authorities of the Member States, the European Commission and the European Board for Digital Services (Article 11 DSA).
Users of pik.li, rights holders, lawyers and other private parties must not use this channel: harmful links can be reported through the report form, and matters concerning one's own account should be raised with customer support. InCloud discloses personal data to private parties only by order of a judicial authority or where the law so requires.
2.How to submit requests
Requests must be sent to the address shown at the top of this page. The mailbox is managed directly by InCloud S.r.l. and is checked on working days; urgent requests follow the procedure described in the “Emergency requests” section.
InCloud acknowledges receipt of every request and assigns it a case number, which should be quoted in all subsequent correspondence.
Requests are accepted in Italian and in English; those drafted in other languages are also handled, but translation may take longer.
3.Content of the request
To allow a prompt and accurate response, the request must be complete and must state:
- 1 The requesting authority: the office, and the name, rank or title and official contact details of the official or officer in charge (switchboard number and official e-mail address).
- 2 The case details: the criminal proceedings number, file number or reference number and, if different, the judicial authority conducting the proceedings.
- 3 The legal basis: the provision authorising the request and, where applicable, the decision of the judicial authority (order of the public prosecutor or of the judge) or the European order.
- 4 The data requested, specified precisely: for example, the identifying data of the account, logins with their IP addresses, the list and history of links, clicks, payments, reports; or the preservation of data or the disabling of a link.
- 5 The links or accounts concerned: the short links in full, one per line, exactly as they appear (for example https://lnkz.li/abc1234), or the e-mail address or username of the account, a payment reference or the identifier of a click. Generic searches by content or by destination are not possible.
- 6 The time period of interest, stating the time zone. InCloud's logs are kept in UTC.
- 7 The deadline by which a response is required and, where applicable, the reasons for urgency.
- 8 Whether the request is confidential and, if so, the period during which the account holder must not be informed of it, with a reference to the provision or decision so requiring.
If the request is incomplete, does not allow the authority to be identified with certainty or does not state a clear legal basis, InCloud asks for the necessary additional information before responding. In the meantime, if there is a risk that the data may be lost, InCloud preserves them.
4.Verification of authenticity
Before disclosing any data, InCloud verifies that the request genuinely comes from the authority indicated:
- it checks that the request comes from an official address or from a PEC mailbox attributable to the office, and that the document is signed and consistent;
- in case of doubt, it telephones the office on a number obtained independently from official sources, never the one given in the message, or asks for confirmation by writing to the office's public PEC address;
- it may ask for the original document to be sent by PEC or for confirmation from the judicial authority conducting the proceedings.
No data are disclosed until the verification has been completed, but InCloud may preserve them so that they are not lost. In emergencies, verification is carried out as quickly as possible, in parallel with the handling of the request.
Falsely claiming to be an authority is a criminal offence: InCloud reports every fake request it receives to the competent authorities.
5.Data that can be provided
InCloud provides without delay the data in its possession at the time of the request that fall within the scope of the request. Depending on the case, these may include:
- Account data: e-mail address, username, recovery e-mail address if any, language, dates of registration, confirmation and last activity, status, plan, version of the Terms of Service accepted; if the account has made purchases, the billing data declared by the account holder (name, address, country, company name, VAT number, tax code, telephone number, PEC address).
- Logins: the open sessions, with full IP address, start date and last activity date, browser, operating system and estimated location; the account's activity log (logins, password changes, activation of two-step verification, changes) with the date and, where recorded, the IP address.
- Links and campaigns: destination, title, tags, UTM parameters, domain, dates of creation and last click, history of destination changes, import batch, including for links deleted by the account holder but still retained.
- Link clicks: date and time, full IP address, estimated country, region and city, device, browser, operating system, language, referring page, user agent and originating network (ASN) of each click, within the retention period of the link owner's plan.
- Payments and orders: provider, transaction reference, amounts, dates, invoices and receipts issued, domains purchased.
- Abuse and moderation: reports received (with the e-mail address of the person who submitted the report, if given), results of automated checks, decisions by InCloud staff, appeals by the account holder, measures taken in respect of the account.
- Support requests and communications between the account holder and InCloud staff.
As a rule, the identifying data of the account are provided upon a written and reasoned request from the judicial police or the judicial authority in the course of proceedings; the IP addresses of logins and clicks, the other click data and the content of communications are provided upon a reasoned order of the judicial authority, save in emergencies.
Unless the authority specifies otherwise, data are transmitted by e-mail or by PEC in a structured file (CSV, JSON or PDF), stating the source and the time of extraction. Files may be encrypted, in which case the password is sent through a separate channel.
6.Data that cannot be provided
- The identity of the person who opened a link: InCloud retains their IP address and the technical data of the click, but not their name or any other identifying data. To trace the subscriber of the connection, the authority must contact the internet access provider to which the IP address was assigned.
- The content of destination pages: pik.li stores the address, not a copy of the site. For the content, the authority must contact whoever hosts the page.
- Data already deleted on expiry of the retention periods set out in the Privacy Policy, including the IP addresses of clicks: once deleted, they cannot be recovered, not even from backups once those have expired.
- Data not processed by InCloud: PayPal account or cryptocurrency wallet details, payment instrument data, Cloudflare logs, data held by the registrar or by the account holder's e-mail provider. InCloud will gladly indicate which provider to contact.
- Interception or real-time monitoring: InCloud is not a provider of electronic communications services. On the order of an authority, however, it can preserve and provide the data that will be generated in relation to a specific account or link.
- Passwords in plain text: they are stored only as irreversible hashes.
- A verified identity: names and addresses are declared by account holders and are not verified by InCloud, with the exception of the VAT number, which is checked in the VIES system.
7.Expedited preservation of data
If there is a risk that data may be lost before the formal order is issued, the authority may request their preservation: InCloud excludes them from the automatic deletion procedures for 90 days, a period that may be extended upon a reasoned request, and discloses them only upon receipt of a valid order.
InCloud executes without delay preservation orders under Article 132(4-ter) of the Italian Personal Data Protection Code (Legislative Decree 196/2003), for the period specified and in any case not beyond that provided for by law, as well as European Preservation Orders under Regulation (EU) 2023/1543 (60 days, extendable by a further 30). InCloud keeps the order received and the steps taken confidential for the period specified by the authority.
Preservation covers the data existing at the time of the request and, if so specified, the data generated until expiry.
8.Emergency requests
In the event of an imminent threat to the life or physical safety of a person (for example, a risk of suicide, a kidnapping, the threat of an attack, the exploitation of a minor), the subject line of the message must begin with “URGENT – DANGER TO LIFE” and the first lines must describe the situation: who is in danger, why, what data are needed and why it is not possible to wait for an ordinary order.
Such requests are handled with absolute priority. To the extent permitted by law, InCloud may disclose the data strictly necessary to deal with the emergency before the formal order is issued (Article 6(1)(d) GDPR) and disable a link immediately; the formal order must follow as soon as possible. For urgent European Production Orders, InCloud complies with the 8-hour deadline laid down in Regulation (EU) 2023/1543.
Where InCloud itself becomes aware of information giving rise to a suspicion of a criminal offence involving a threat to the life or safety of persons, it informs the competent authorities on its own initiative (Article 18 DSA).
9.Removal and disabling of links
A link that breaches the rules of pik.li is disabled as soon as InCloud becomes aware of it, without waiting for an order: the destination can no longer be reached and anyone who opens the link sees a page explaining that it has been disabled. Anyone can report such a link through the Report abuse page; an authority can request that it be disabled by writing to the address given on this page.
InCloud gives effect to orders to act against illegal content (Article 9 DSA) and orders to provide information (Article 10 DSA), and informs the issuing authority without undue delay of the effect given to the order, specifying when effect was given to it.
On request, InCloud disables the link without deleting it, so that the data remain available for the investigation.
10.Requests from authorities of other States
- Authorities of other Member States of the European Union: InCloud executes European Production Orders and European Preservation Orders under Regulation (EU) 2023/1543, applicable from 18 August 2026, and orders under Articles 9 and 10 DSA. Other requests must be transmitted by means of a European Investigation Order (Directive 2014/41/EU) or through the Italian authorities.
- Authorities of third countries: InCloud discloses data only through mutual legal assistance channels (international letters rogatory, mutual legal assistance treaties – MLATs, the Budapest Convention on Cybercrime) or through the competent Italian authorities, since a decision of a foreign authority is not in itself sufficient to justify the transfer (Article 48 GDPR). InCloud may nevertheless preserve the data pending the formal request, including when alerted by the contact points of the 24/7 network established by the Budapest Convention.
- In emergencies where a person's life is in danger, InCloud also considers direct requests from foreign authorities on a case-by-case basis, within the limits of the law.
11.Informing the account holder
As a rule, InCloud informs the account holder of the request or order concerning them and of the action taken on it, as required by Articles 9 and 10 DSA for orders issued by authorities.
InCloud does not inform the account holder, or defers doing so, where the law or the authority prohibits it (for example for preservation orders under Article 132(4-ter) of the Privacy Code, or for European orders, where it is for the authority to inform the person concerned), where the authority makes a reasoned request to that effect so as not to prejudice the investigation, or where informing the account holder would endanger anyone's safety. The request should state how long the confidentiality obligation is to last: when it expires, unless it is extended, InCloud informs the account holder.
12.Records and transparency
InCloud records every request and every order: date of receipt, authority, reference, checks carried out, data provided and date of the response. The register is confidential and is kept as set out in the Privacy Policy.
InCloud is a small enterprise and, for as long as it retains that status, is not required to publish the transparency report provided for by the DSA (Article 15(2)); it may nevertheless publish a summary on a voluntary basis.
13.Disclaimers
- This policy describes InCloud's procedures: it does not constitute legal advice, confers no rights on third parties and does not extend the obligations that the law imposes on InCloud.
- InCloud provides only the data present in its systems at the time of the request, as they stand: it does not generate data it does not hold and does not reconstruct deleted data.
- InCloud does not guarantee that the data are accurate or complete: names, addresses and contact details are declared by account holders; the location is an estimate derived from the IP address; an IP address may belong to a VPN, a proxy, the Tor network or an operator that shares it among several users; times are those of InCloud's servers, expressed in UTC.
- InCloud may refuse or challenge a request, or seek clarification of it, where it appears unlawful, disproportionate, lacking a clear legal basis, unverifiable or relating to data that InCloud does not process. Nothing in this policy constitutes a waiver of the rights and remedies available to InCloud or to account holders.
- InCloud has no general obligation to monitor links or to actively seek facts indicating illegal activity (Article 8 DSA); the measures it takes voluntarily do not alter that principle.
- An e-mail sent to this address is no substitute for the forms of service prescribed by law: for documents that require formal service, PEC must be used.
- This address is reserved for authorities: messages from other senders will not receive a reply.
- InCloud may update this policy; the version in force is the one published on this page, bearing the date shown at the top. The Italian text is authoritative.
Contact details for authorities
Requests, orders, preservation requests and questions about this policy must be sent to the address given below, which is also the point of contact under Article 11 of the Digital Services Act.
- E-mail for requests
- [email protected]
- PEC for formal service
- [email protected]
- Service operator
- InCloud S.r.l. · IT04209270364
- Registered office
- Via Unità d'Italia 135, 41058 Vignola (MO), Italy
Languages accepted: Italian and English. Requests in other languages are handled, but may take longer.
Retention periods and legal bases are described in the Privacy Policy, which is the reference document.