Privacy notice on data processing

(ex article 13 of EU Regulation 2016/679)

Abilitya S.r.l., as Data Controller, processes personal data in compliance with the general principles and special provisions of EU Regulation 2016/679: in compliance with the provisions of article 13 of the aforementioned legislation, we inform you of the following characteristics of the processing, as well as the rights that the law guarantees you.

Personal data subject to processing

The Data Controller may collect and process the following personal data:

  • Personal information of the Data Subject (e.g., name, surname, date of birth, and gender).
  • Contact details (e.g., email address and telephone number).
  • Profile icon or image for profile completion.

Purposes pursued in the processing and legal bases

The Data Controller collects and processes the personal information of the Data Subject for the following purposes:

  • To allow the Data Subject to register on the platform and use the services.
  • To assign personal authentication credentials to the Data Subject, enabling access to the reserved area.
  • To manage any issues related to access to the reserved area (e.g., password reset).
  • To provide assistance and support to the Data Subject.

The Data Controller also processes the identification and contact information of the Data Subject for purposes of commercial communication regarding the services offered. The legal basis for this processing is the consent of the Data Subject.

The legal basis for other processing activities is the performance of contractual obligations between the Parties.

Methods of processing personal data and retention periods

The personal data of data subjects is processed electronically (e.g. through the use of databases, application software). The Data Controller retains the personal information of data subjects as long as needed to meet the purposes for which they were collected and in compliance to the Law.

Internal and external scope of communication of personal data

The personal data may be disclosed to employees of the Controller who need to know it in order to manage the platform, with particular reference to administrative, IT and marketing staff. Our employees have been trained and instructed in the legal requirements for protecting personal information.

The Data Controller shares the personal data of data subjects with certain suppliers who assist the Controller in the management of the platform: if the supplier becomes aware of the data, he shall do so in compliance with the legislation in force on data protection, and with the instructions given by the Controller in the relevant deeds of appointment as External Data Processor. The Data Controller does not disclose personal information to other third parties without the consent of the data subjects, unless required to do so by law or by an Authority (e.g. where it is necessary for reasons of national security, public interest).

Purpose of Data Transfer to Third-Party Partners

If you provide consent for the transfer of data to third-party partners, the Data Controller may transfer your personal data to trusted partner companies operating in the various sectors (e.g., hospitality, clothing, land and maritime transportation, advertising, food and beverage, education, energy, industrial and pharmaceutical, insurance, credit and banking institutions, digital gaming, automotive, and real estate) for their independent processing with marketing and commercialization purposes of their own products or services. These companies will process your personal data as independent data controllers (“Third-Party Recipients”) and will provide you with the necessary information regarding their processing of the data received from the Data Controller.

The legal basis for the transfer of data to third parties is your consent (Article 6 (1) a) GDPR). Providing consent is optional, and failure to do so will not prevent your registration on the platform but will only exclude the possibility for the Data Controller to transfer your data to third parties operating in the specified sectors for independent marketing and commercialization of their products and services.

If you provide consent, you may revoke it at any time by accessing your user profile in the app. The withdrawal of consent will take effect going forward and will not affect the lawfulness of processing carried out by us up until its revocation.

In any case, you may also exercise your rights, as listed below, with regard to the Third-Party Recipients.

Transfer of data outside the EEA

Your data will not be transferred outside the European Economic Area.

Rights of the data subject and how to exercise them

EU Regulation 2016/679 guarantees data subjects specific rights (article 15-22). For each processing, in particular: right of access, right to rectification, right to object to the processing of personal data for commercial purposes, right to object to decisions based on purely automated processes, right to withdraw a consent given, at any time, right to apply to the Data Protection Authority if they have doubts about the processing of personal data by the Controller. The following rights may also be exercised, subject to certain circumstances: right to erasure, right to object to processing, right to limit the processing, right to data portability.

The Data Subject may, at any time and in any manner, exercise his or her rights under the law by contacting Abilitya S.r.l., Vioa Baldissera 2, Milano – P.IVA 11667520966 -privacy@abilitya.tech.

The Data Controller shall take care to reply within the time limits laid down by law.