Privacy Policy and Personal Data Protection
Ultimo aggiornamento : September 3, 2026
This document sets out, in a rigorous, transparent and comprehensive manner, the full set of rules, procedures and mechanisms implemented to ensure the protection of personal data in connection with the use of our digital platforms, interactive applications and associated financial services.
Article 1. Identification of the Data Controller and Governance Framework
The controller responsible for the processing of personal data collected and processed across our entire IT and application infrastructure is the operating entity of the platform. Data governance is based on strict internal directives guaranteeing ongoing compliance with applicable regional and international regulations.
The organisation has appointed a Data Protection Officer (DPO), duly authorised and provided with the material and legal resources necessary to oversee respect for the rights of data subjects. The DPO is the single point of contact for any request relating to personal data, whether from a user, a partner or a supervisory authority.
The general legal framework governing processing operations is based primarily on the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679), as well as on all national laws relating to data protection and individual freedoms applicable within the territory of operation.
Management is committed to allocating permanent resources to update processing maps, carry out Privacy Impact Assessments (PIAs) and maintain records of processing activities that comply with the strictest regulatory requirements.
In addition, an internal steering committee meets quarterly to reassess risk exposure, review minor or major security incidents, and revise the organisational protocols governing access to customer data.
Any change to the organisational structure or to the designation of the data controller will be the subject of an explicit and immediate notification across all of the company's official portals.
| Identification Area | Controller Details & Contacts | Legal Scope & Directives |
|---|---|---|
| Publishing Entity | Service / Official Digital Platform | Principal operator of the information system |
| Officer (DPO) | compliance@domain.com / privacy@domain.com | Dedicated point of contact for GDPR and third-party rights |
| Legal Reference | GDPR (EU 2016/679) & National Laws | Compliance with European and local requirements |
| Escalation Channel | dpo-support@domain.com | Priority handling of formal requests |
Article 2. Full Categories of Personal Data Collected
When accessing the features of our platforms, data is collected in accordance with the principle of minimisation. Only the information strictly necessary to achieve the intended purposes is collected and retained.
Personal identification data includes surname, first name, date and place of birth, nationality, postal address of residence, primary email address and telephone numbers. For services subject to enhanced regulatory obligations (KYC), scanned copies of official identity documents (passport, national identity card, residence permit) are also collected.
| Data Category | Specific Elements Collected | Collection Method | Sensitivity Level |
|---|---|---|---|
| Official Identity | Surname, first name, date/place of birth, ID document | Registration form & supporting documents | High (KYC) |
| Contact Data | Email address, phone number, home address | User input & SMS/email verification | Medium |
| Connection & Tech | IP address, connection logs, user-agent, cookies | Automatic collection via web servers | Standard |
| Financial & Flows | Payment history, IBAN, encrypted cards | Secure payment gateways (PSP) | Very High |
Technical and connection data includes the user's public IP address, unique device identifiers, browser type and version, operating system, and timestamped logs detailing requests sent to the servers.
Financial and transactional data includes bank details (IBAN, BIC), a full history of deposits and withdrawals, records of financial transactions, and supporting documents evidencing the origin of deposited funds.
Finally, we record user preferences regarding advertising tracking, acceptance or refusal of non-essential cookies, and the complete history of consents granted while using our services.
The processing of behavioural data on the platform is systematically pseudonymised in order to prevent any direct re-identification of the user during internal statistical performance analyses.
Article 3. Legal Bases and Explicit Purposes of Processing
Each processing of personal data carried out by our organisation is based on a clearly established legal basis, in accordance with the requirements set out in Article 6 of the General Data Protection Regulation (GDPR).
The first legal basis concerns the performance of contractual commitments. It covers day-to-day management of user accounts, handling of support requests, delivery of application services, and management of associated financial flows.
The second legal basis is based on compliance with our legal and regulatory obligations. It notably includes customer identity verification, the prevention of money laundering and terrorist financing (AML/CFT), and accounting and tax obligations.
The third legal basis rests on the legitimate interest pursued by the organisation. It covers securing the IT infrastructure, fraud detection, the prevention of cyberattacks, and the continuous improvement of application features.
The fourth legal basis is the explicit consent of the user, obtained prior to sending electronic commercial prospecting or placing non-essential advertising targeting cookies.
| Purpose of Processing | GDPR Legal Basis | Description of Purpose |
|---|---|---|
| Account Management | Performance of Contract (Art. 6.1.b) | Creation, maintenance and access to application services. |
| AML/KYC Compliance | Legal Obligation (Art. 6.1.c) | Identity verification and anti-fraud monitoring. |
| System Security | Legitimate Interest (Art. 6.1.f) | Protection against hacking and infrastructure maintenance. |
| Direct Marketing | Explicit Consent (Art. 6.1.a) | Sending of newsletters and personalised offers. |
In the event of a change to the original purposes, a compatibility assessment will immediately be carried out. If the new purpose is incompatible, the user's consent will once again be formally sought.
Article 4. Recipients, Sharing and Secure Data Transfers
Access to personal data is strictly limited to authorised internal staff who require such access exclusively for the performance of their duties, and subject to enhanced confidentiality commitments.
Third-party processors may receive certain data in order to carry out specific services: secure cloud hosting providers, payment solution providers, identity verification providers and statistical analysis services.
All processors are subject to a rigorous prior assessment procedure to ensure they offer sufficient guarantees regarding the implementation of appropriate technical and organisational measures.
| Recipient Category | Role and Service | Data Location |
|---|---|---|
| Cloud Hosting Providers | Storage of databases and application servers | European Union (EU) |
| Payment Providers | Secure processing of financial transactions | European Economic Area (EEA) |
| KYC Analysis Tools | Biometric verification and document compliance | EU / Switzerland (adequacy decision) |
| Legal Authorities | Response to mandatory judicial requests | Competent national jurisdiction |
Personal data is primarily hosted and processed within the European Economic Area (EEA). No unregulated transfer to third countries will take place without guarantees of an equivalent level of protection.
In the event of a transfer to a country outside the EEA that does not benefit from an adequacy decision of the European Commission, we implement Standard Contractual Clauses (SCCs) incorporating supplementary security measures.
We do not sell, rent or transfer any personal data to third parties for independent commercial prospecting purposes without the prior, free and explicit agreement of the user concerned.
Article 5. Retention Periods and Archiving Protocols
Personal data is kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which it is processed.
For as long as the user account remains active, all identification and profile data remains accessible in order to ensure the continued delivery of the application services ordered by the user.
Upon closure of the account or at the end of the contractual relationship, the data is subject to intermediate archiving with restricted access, in order to comply with legal tax, accounting and regulatory retention obligations.
| Data Type | Active Database Period | Legal Archiving Period | Destruction / Anonymisation |
|---|---|---|---|
| User Account | Duration of the contractual relationship | 5 years from closure | Permanent deletion from servers |
| KYC & ID Documents | Duration of active account | 5 years (AML obligation) | Automated secure erasure |
| Accounting Data | Current financial year | 10 years (tax / commercial code obligation) | Purged in accordance with tax law |
| Connection Logs | Rolling 6 months | 1 year (security obligation) | Automatic daily overwrite |
Data used for commercial prospecting purposes is kept for a maximum of three years from the end of the business relationship or the user's last contact.
At the end of the applicable legal and archiving periods, personal data is either securely and irreversibly destroyed, or anonymised for overall research statistics purposes.
Automated IT procedures periodically carry out the purging and deletion of records that have reached their maximum retention period.
Article 6. Your Data Protection Rights (Rights of Data Subjects)
In accordance with the European and national regulatory framework, every natural person has extensive rights to control and manage the personal data processed by us.
The right of access (Article 15 GDPR) allows the user to obtain confirmation that data concerning them is being processed and to receive a full copy of that information in a clear format.
| Right Guaranteed | GDPR Ref. | Exercise Procedure | Processing Time |
|---|---|---|---|
| Right of Access | Art. 15 GDPR | Written request + proof of identity | 30 days maximum |
| Rectification | Art. 16 GDPR | Direct update via customer account or support | 15 business days |
| Erasure ("Right to be Forgotten") | Art. 17 GDPR | Reasoned request, subject to legal obligations | 30 business days |
| Portability | Art. 20 GDPR | Export of data in JSON or CSV format | Immediate or 15 days |
The right to rectification (Article 16 GDPR) allows inaccurate, incomplete or outdated data to be updated directly, upon simple request to our support team or our DPO.
The right to erasure, or "right to be forgotten" (Article 17 GDPR), allows the deletion of data to be required, except where the law requires us to retain it on an interim basis.
The right to restriction of processing (Article 18 GDPR) and the right to portability (Article 20 GDPR) guarantee a temporary freeze on the use of personal data, or its structured export.
Finally, the right to object (Article 21 GDPR) allows the user to object at any time to the use of their data for commercial prospecting purposes or on the basis of legitimate interest.
Article 7. Technical and Organisational Security Architecture
We implement a comprehensive set of technical and organisational measures designed to protect data against accidental or unlawful destruction, loss, alteration or unauthorised disclosure.
Data transmissions between the user's browser and our servers are carried out using state-of-the-art encryption protocols (TLS 1.3), guaranteeing the confidentiality and integrity of exchanges over the internet.
| Security Measure | Standard Used | Protection Objective |
|---|---|---|
| Encryption in Transit | TLS 1.3 / HTTPS | Protection of data against interception on the network |
| Encryption at Rest | AES-256 bit | Protection of physical databases and backups |
| Access Control | MFA + RBAC (Role-Based Access) | Access restricted exclusively to authorised staff |
| System Monitoring | SIEM / IDS / IPS 24/7 | Detection of intrusions and abnormal attacks |
Storage of sensitive data at rest is secured with AES-256 encryption. Encrypted backup copies are generated daily and stored in physically separate environments.
Internal access to databases is subject to strict role-based access control (RBAC) and requires strong multi-factor authentication (MFA) for all system administrators.
In the event of a data breach likely to result in a high risk to the rights and freedoms of individuals, we undertake to inform the competent supervisory authority within a maximum of 72 hours.
Security audits and penetration tests are regularly entrusted to independent expert organisations in order to continuously verify the resilience of the entire information system.
Article 8. Cookie Management and Web Tracking Technologies
A cookie is a small text file placed on a user's device when browsing a website or mobile application, allowing certain data relating to their browsing to be retained.
Cookies that are strictly necessary for the technical operation of the platform do not require the user's prior consent. They enable session management and transaction security.
| Cookie Type | Main Purpose | Consent Required | Lifespan |
|---|---|---|---|
| Essential Cookies | Session, authentication & security | No (strictly necessary) | Session / 12 months max |
| Analytics Cookies | Audience and traffic measurement | Yes (consent banner) | 13 months maximum |
| Functional Cookies | Remembering display preferences | Yes (consent banner) | 6 to 12 months |
| Advertising Cookies | Marketing and social-media targeting | Yes (explicit consent) | 6 months maximum |
Analytics, functional personalisation and advertising targeting cookies are subject to your prior explicit agreement, obtained via a consent banner on your first visit.
You may change your choices or withdraw your consent at any time by accessing the dedicated settings panel available at the bottom of the page throughout the website.
The maximum validity period of consent given to the placing of cookies is set at 6 months. At the end of this period, your choice will be requested again when accessing the services.
Refusing or blocking certain non-essential cookies does not result in any restriction on access to the main features of our platform.
Article 9. Updates and Changes to the Privacy Policy
We reserve the right to amend this Privacy Policy at any time to reflect technical, legal or regulatory developments, or the introduction of new application features.
In the event of a substantial change affecting the purposes of processing, the procedures for exercising rights, or the identity of recipients, registered users will be notified by email.
Users are strongly encouraged to regularly review this page in order to stay informed of the most recent version of the provisions governing the protection of their personal data.
The effective date shown at the top of the document is systematically revised with each update published on the company's official portal.
Continued use of the platform's services after the entry into force of any changes constitutes unreserved acceptance of the revised privacy policy by the user.
| Version | Effective Date | Nature of Major Changes |
|---|---|---|
| v1.0 | January 1, 2024 | Initial launch and baseline GDPR compliance |
| v1.5 | November 15, 2025 | Update to sub-processing and cloud security procedures |
| v2.0 | September 3, 2026 | Full revision, addition of detailed tables and DORA/MiCA clauses |
For any further questions or legal clarification regarding the interpretation of this document, our compliance team remains available at the official address: compliance@domain.com.