Legal
Cooperation with authorities and legal requests
This is pik.li's policy for law enforcement agencies, judicial authorities and other competent authorities: where to send a request, what it must contain, how we verify its authenticity, and which data we can and cannot provide.
Last updated: September 24, 2026 · Version 2026-09-24
This text is published in nine languages. The Italian version is authoritative: the others are translations provided for convenience and, in the event of any discrepancy, the Italian version prevails.
Where to write
Requests, orders and preservation requests must be sent to [email protected], from an official address of the office in charge of the proceedings, with the document attached as a signed PDF. For formal service, and when the law requires certified e-mail, use the PEC address of InCloud S.r.l.: [email protected].
This channel is reserved for authorities. To report a harmful link, use the report form. Report a link
In short
- Upon a valid request from a competent authority, we promptly provide the data we hold on accounts, logins, links, campaigns, clicks, payments and abuse.
- We verify every request before responding: fake requests exist, and their very purpose is to obtain someone's data.
- We do not keep the clear-text IP address of people who open a link and we do not host destination pages: we cannot provide this data.
- On request, we immediately preserve data pending the formal order; emergencies involving a danger to life take precedence over everything else.
- As a rule, we inform the user, unless the law or the authority prohibits it.
This summary is only meant to help you find your way; the full text below is what applies.
1.Who we are and who this page is for
pik.li is a service of InCloud S.r.l., a company incorporated under Italian law and based in Vignola (MO). For the short links it stores, InCloud is a provider of intermediary hosting services within the meaning of Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act, “DSA”); the competent Digital Services Coordinator for Italy is AGCOM.
This page is addressed to judicial authorities, police forces, administrative and supervisory authorities and national CERTs/CSIRTs which, under the law applicable to them, may request information, the preservation of data or the removal of content. The address given here is also the single point of contact for the authorities of the Member States, the European Commission and the European Board for Digital Services (Article 11 DSA).
Users, rights holders, lawyers and private individuals must not use this channel: to report a harmful link there is the report form, and for matters concerning one's own account there is support. We disclose personal data to private parties only on a court order or when the law requires it.
2.How to send a request
Write to the address given at the top of this page. The mailbox is managed directly by InCloud S.r.l. and read on working days; urgent requests follow the procedure in the “Emergency requests” section.
We acknowledge receipt of every request with a case number, to be quoted in all subsequent correspondence.
We accept requests in Italian and in English; requests in other languages are handled, but translation may take longer.
3.What a request must contain
To respond quickly and properly, we need a complete request. Please state:
- 1 The requesting authority: office, name, rank or position and official contact details of the responsible official or officer (switchboard number and official address).
- 2 The reference of the proceedings: criminal proceedings number, file number or registry number, and the judicial authority in charge, if different.
- 3 The legal basis: the provision that authorises the request and, if there is one, the order of the judicial authority (decree of the public prosecutor or of the judge) or the European order.
- 4 The data requested, stated precisely: for example account identification data, logins with IP addresses, list and history of links, clicks, payments, reports; or the preservation of data or the disabling of a link.
- 5 The links or accounts involved: the short links in full, one per line, exactly as they appear (for example https://lnkz.li/abc1234), or the e-mail address or username of the account, the reference of a payment or the identifier of a click. We cannot carry out generic searches by content or by destination.
- 6 The time interval of interest, with the time zone. Our logs are in UTC.
- 7 The deadline by which the reply is needed and, if applicable, the reason for the urgency.
- 8 Whether the request is confidential and for how long the user must not be informed of it, with a reference to the provision or order that requires this.
If a request is incomplete, does not identify the authority with certainty or lacks a clear legal basis, we will write to you asking for the missing information before responding. In the meantime, if there is a risk that the data may be lost, we preserve it.
4.How we verify authenticity
Before disclosing any data, we verify that the request really comes from the authority indicated:
- we check that it comes from an official address or from a PEC mailbox attributable to the office, and that the document is signed and consistent;
- if in doubt, we call the office back on a number that we find ourselves from official sources, never the one given in the message, or we write to its public PEC address for confirmation;
- we may ask for the original document to be sent by PEC or for confirmation from the judicial authority in charge of the proceedings.
Until verification is complete, we do not disclose data, but we may preserve it so that it is not lost. In emergencies, verification is carried out as quickly as possible, in parallel with the handling of the request.
Impersonating an authority is a criminal offence: we report every fake request we receive to the competent authorities.
5.What data we can provide
We promptly provide the data we hold at the time of the request and to which the request relates. Depending on the case, this may include:
- Account data: e-mail address, username, any recovery e-mail, language, dates of registration, confirmation and last activity, status, plan, version of the terms accepted; if the account has made purchases, the billing data declared by the customer (name, address, country, company name, VAT number, tax code, telephone number, PEC).
- Logins: the open sessions, with full IP address, start date and date of last activity, browser, operating system and estimated location; the account's activity log (logins, password changes, activation of two-step verification, changes) with the date and, where recorded, the IP address.
- Links and campaigns: destination, title, tags, UTM parameters, domain, dates of creation and of last click, history of changes to the destination, import batch, including for links that the user has deleted but that we still retain.
- Link clicks: date and time, estimated country, region and city, device, browser, operating system, language, referring page, user-agent and originating network (ASN) of each click, for the retention period provided for by the link owner's plan.
- Payments and orders: provider, transaction reference, amounts, dates, invoices and receipts issued, domains purchased.
- Abuse and moderation: reports received (with the reporter's e-mail, if provided), verdicts of the automated checks, decisions by our staff, the user's appeals, measures taken on the account.
- Support requests and communications between the user and our staff.
As a rule, we provide account identification data upon a written, reasoned request from the judicial police or the judicial authority in the context of proceedings; login IP addresses, click data and the content of communications upon an order of the judicial authority, except in emergencies.
Unless the authority specifies otherwise, we deliver the data by e-mail or by PEC in a structured file (CSV, JSON or PDF), stating the source and the time of extraction. We may encrypt the files and send the password through a separate channel.
6.What we cannot provide
- The clear-text IP address of whoever opened a link: we do not record it. We keep only a hash computed with a key that changes every day and is destroyed within two days, from which not even we can trace back the address. We can, however, say whether two clicks on the same day came from the same address.
- The content of destination pages: pik.li stores the address, not a copy of the website. For the content, you need to contact whoever hosts the page.
- Data already deleted in accordance with the periods set out in the Privacy policy: once deleted, it cannot be recovered, not even from backups once these have expired.
- Data that we do not process: details of the PayPal account or of the cryptocurrency wallet, payment instrument data, Cloudflare logs, data held by the user's registrar or e-mail provider. We will gladly tell you which provider to contact.
- Interception or real-time monitoring: we are not an electronic communications operator. Upon an order, however, we can preserve and provide the data that will be generated on a specified account or link.
- Passwords in clear text: we store them only as an irreversible hash.
- A verified identity: name and address are declared by the user and we do not verify them, except for the VAT number in the VIES system.
7.Expedited preservation of data
If you fear that data may be lost before the formal order, ask us to preserve it: we exclude it from the automatic deletion processes for 90 days, renewable upon a reasoned request, and disclose it only when a valid order arrives.
We execute without delay preservation orders under Article 132(4-ter) of the Italian Personal Data Protection Code (Legislative Decree 196/2003), for the duration indicated and in any case not beyond that provided for by law, and European Preservation Orders under Regulation (EU) 2023/1543 (60 days, extendable by 30). We keep the order and the activities carried out confidential for the period indicated by the authority.
Preservation covers the data existing at the time of the request and, if so indicated, the data that will be generated until the expiry date.
8.Emergency requests
If there is an imminent danger to the life or physical safety of a person (for example a risk of suicide, a kidnapping, a threat of an attack, the exploitation of a minor), write “URGENT – DANGER TO LIFE” at the start of the subject line and describe the situation in the first lines: who is in danger, why, what data is needed and why an ordinary order cannot be awaited.
We treat these requests with absolute priority. Within the limits permitted by law, we may disclose the data strictly necessary to deal with the emergency before the formal order is issued (Article 6(1)(d) GDPR) and immediately disable a link; the formal document must follow as soon as possible. For urgent European Production Orders, we comply with the 8-hour deadline laid down in Regulation (EU) 2023/1543.
When we ourselves become aware of information giving rise to a suspicion of a criminal offence involving a threat to the life or safety of persons, we inform the competent authorities on our own initiative (Article 18 DSA).
9.Removal and disabling of links
A link that breaks our rules is disabled as soon as we become aware of it, without waiting for an order: the destination stops working and whoever opens the link sees a page explaining that it has been disabled. Anyone can report it using the Report abuse form; an authority can request it at the address on this page.
We give effect to orders to act against illegal content (Article 9 DSA) and to orders to provide information (Article 10 DSA), and we inform the issuing authority, without undue delay, of the effect given to them and of when it was given.
On request, we disable the link without deleting it, so that the data remains available for investigations.
10.Requests from authorities of other countries
- Authorities of other European Union Member States: we execute European Production Orders and European Preservation Orders under Regulation (EU) 2023/1543, which applies from 18 August 2026, and orders under Articles 9 and 10 of the DSA. Other requests go through the European Investigation Order (Directive 2014/41/EU) or through the Italian authorities.
- Authorities of countries outside the Union: we disclose data only through mutual legal assistance channels (letters rogatory, mutual legal assistance treaties, the Budapest Convention on Cybercrime) or through the competent Italian authorities, because a decision by a foreign authority is not, on its own, sufficient to justify the transfer (Article 48 GDPR). We may, however, preserve the data pending the formal request, including upon notice from the contact points of the 24/7 network of the Budapest Convention.
- In emergencies in which a person's life is in danger, we also assess direct requests from foreign authorities case by case, within the limits of the law.
11.Notifying the user
As a rule, we inform the account holder of any request or order that concerns them and of the action we have taken on it, as Articles 9 and 10 of the DSA provide for orders from authorities.
We do not inform them, or we postpone informing them, when the law or the authority prohibits it (for example for preservation orders under Article 132(4-ter) of the Italian Personal Data Protection Code or for European orders, for which it is the authority that informs the person concerned), when the authority makes a reasoned request to that effect so as not to jeopardise the investigation, or when informing them would put someone in danger. Please state in the request how long confidentiality must last: when that period expires, unless it is extended, we inform the user.
12.Records and transparency
We record every request and every order: date of receipt, authority, reference, checks carried out, data provided and date of reply. The register is confidential and is kept as indicated in the Privacy policy.
InCloud is a small enterprise and, as long as it remains one, it is not required to publish the transparency report provided for by the DSA; we may publish a summary of it on a voluntary basis.
13.Disclaimers
- This page describes our procedures: it is not legal advice, it does not create rights for third parties and it does not extend the obligations that the law imposes on InCloud.
- We provide only the data that exists in our systems at the time of the request, in the state in which it is found: we do not create data that we do not have and we do not reconstruct deleted data.
- We do not guarantee that the data is true or complete: names, addresses and contact details are declared by users; the location is an estimate derived from the IP address; an IP address may belong to a VPN, a proxy, the Tor network or an operator that shares it among several users; times are those of our servers, in UTC.
- We may refuse, challenge or ask for clarification of a request that appears to us to be unlawful, disproportionate, lacking a clear legal basis, unverifiable or relating to data that we do not process. Nothing on this page waives the rights and remedies of InCloud or of users.
- We have no general obligation to monitor links or to actively seek facts indicating illegal activity (Article 8 DSA); the voluntary measures we adopt do not change this principle.
- An e-mail to this address does not replace the forms of service prescribed by law: for documents that require formal service, use PEC.
- The address is reserved for authorities: messages from other senders do not receive a reply.
- We may update this policy; the version in force is the one published here, with the date shown at the top. The Italian text is authoritative.
Contact details for authorities
Requests, orders, preservation requests and questions about this page should be sent to the address below, which is also the point of contact under Article 11 of the Digital Services Act.
- E-mail for requests
- [email protected]
- PEC for formal service
- [email protected]
- Service operator
- InCloud S.r.l. · IT04209270364
- Registered office
- Via Unità d'Italia 135, 41058 Vignola (MO), Italy
Accepted languages: Italian and English. Requests in other languages are handled, but may take longer.
Retention periods and legal bases are described in our Privacy policy, which is the reference document.