1. Controller and scope
This notice describes the processing of personal data carried out through RelaunchLab.it, including browsing, the administration area and, when enabled, the Contact, Network, Project submission and App support forms. RelaunchLab is the name of an independent project; the data controller is Davide Mori.
For data protection questions or to exercise your rights, write to privacy@relaunchlab.it. For general enquiries: hello@relaunchlab.it; for app support: support@relaunchlab.it.
This notice is provided under Articles 12 and 13 of Regulation (EU) 2016/679 (“GDPR”) and, where personal data have not been obtained directly from the data subject, Article 14.
2. Data processed and source
- Browsing and security: IP address, date and time, requested URL or resource, HTTP outcome, user agent, session identifiers and other technical information necessary to deliver and protect the website. Infrastructure logs also depend on the hosting service.
- Contact: name, email address, topic and message.
- Network: name, email address, professional role, interest in collaboration and an optional public URL.
- Project submission: contact person, email address, project name and stage, optional public URL, a non-confidential description of the challenge and the collaboration sought. This is not a job application form.
- App support: app, email address, category, description and optional app and operating-system versions. The form does not accept attachments.
- Administration: authorised-user data, role, credential stored as a hash, session, authentication events and metadata relating to operations performed in the CMS.
- Abuse prevention: pseudonymous keys derived from IP address, user agent and submission identifiers, counters, outcomes and the version of the notice displayed.
As a rule, data are provided directly by the data subject or generated technically while the website is being used. If contact data were obtained from a third party or a public source, the information required by Article 14 GDPR would be provided within the applicable time limits.
Do not send credentials, trade secrets, health data or other special categories of personal data, criminal-offence data, content stored in the apps or unnecessary information about third parties.
3. Purposes and legal bases
- Website delivery and security: providing the requested pages, maintaining integrity and availability, preventing abuse and diagnosing errors, on the basis of the controller’s legitimate interest, Article 6(1)(f) GDPR.
- General contact: receiving, organising and responding to voluntary enquiries, on the basis of the legitimate interest in managing communications, Article 6(1)(f).
- Network: assessing professional interest and enabling an initial conversation, on the basis of legitimate interest, Article 6(1)(f). Submission does not create membership, employment, matching or a partnership.
- Project submission: carrying out an initial assessment of the proposal, Article 6(1)(f); only if and when the proposer requests specific pre-contractual steps, Article 6(1)(b). Submission does not create an NDA, engagement, due diligence, investment or acceptance.
- App support: managing a request connected with the terms applicable to the app, Article 6(1)(b); preventing abuse and protecting the service, Article 6(1)(f).
- Administration and audit: protecting the CMS and reconstructing authorised operations, Article 6(1)(f).
- Legal obligations and protection of rights: complying with legal obligations, Article 6(1)(c), and establishing, exercising or defending legal claims, Article 6(1)(f), for as long as necessary.
The acknowledgement of this notice required by the forms documents transparency and does not constitute consent for any additional purpose. No marketing, profiling or sale of personal data is carried out.
4. Provision of data
Fields marked as required are necessary to receive and handle the request; without those data, the form cannot be submitted or a response cannot be provided. Other fields are optional. Use of these channels is voluntary.
5. Recipients and providers
Data are accessible only to authorised persons and, where necessary, to Aruba S.p.A. as provider of the hosting and database infrastructure and, when enabled, email services; to other technical providers appointed and verified before activation; to professionals subject to confidentiality obligations; and to public authorities where required by law. Data are not disseminated, sold or used for advertising.
The website does not integrate analytics, advertising trackers, social plugins or third-party profiling tools.
6. International transfers
The controller does not intentionally transfer website data outside the European Economic Area. The main hosting and database infrastructure is provided by Aruba. Any use by the provider of subprocessors and every future service are assessed with regard to location and applicable safeguards. If a transfer to a third country becomes necessary, it will be based on an adequacy decision or a safeguard under Articles 46 and following of the GDPR, and this notice will be updated. Information about the applicable safeguards may be requested through the privacy contact.
7. Retention
- General contact and support: identifying data and content are redacted 12 months after the last activity. A technical trace without the message or direct identifiers, the version of the notice and evidence of its acknowledgement remain in order to document the operation correctly and protect rights; this metadata is periodically reviewed and is not used to contact the data subject again.
- Network and project submissions: identifying data and content are redacted 18 months after the last activity; any residual technical trace follows the criterion described above.
- Abuse-prevention and rate-limit keys: they remain until the technical counter or any block expires and are deleted during the next scheduled maintenance operation; hashes associated with a request instead follow the retention period of that request.
- Honeypot: submissions intercepted by the hidden anti-bot field are not recorded by the application.
- CMS email notifications: when email is enabled, records of sent notifications are deleted after 30 days and permanently undeliverable records after 90 days.
- Authentication and audit: authentication events are retained for 180 days; metadata relating to administrative operations for 24 months. The audit log does not retain form bodies.
- Administrative backups: the temporary archive on the server is removed when the download finishes; export metadata expires after 7 days. Downloaded copies and any infrastructure backups follow separate access procedures and retention cycles adopted by the controller and provider.
Application or infrastructure logs, where present, are retained for the time technically necessary for security, diagnosis and continuity according to the configuration of the active service. In the event of incidents, disputes or legal obligations, only the necessary data may be retained for longer with restricted access.
8. Rights
The data subject may request access, rectification, erasure, restriction and, where the relevant conditions are met, data portability. The data subject may object, on grounds relating to their particular situation, to processing based on legitimate interest. If a future processing activity were based on consent, that consent could be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Requests must be sent to privacy@relaunchlab.it. The controller responds without undue delay and normally within one month, subject to an extension in the cases provided for by the GDPR; only the information necessary to verify identity may be requested. A complaint may also be lodged with the Italian Data Protection Authority, or the data subject may seek a judicial remedy.
9. Automated decisions and children
No decisions are made solely on the basis of automated processing that produce legal or similarly significant effects, and no profiling is carried out.
The website is not specifically directed at children and the forms must not be used to submit unnecessary personal data relating to children. If a future service offered directly to children were based on consent, the conditions under Article 8 GDPR and Article 2-quinquies of the Italian Privacy Code would apply.
10. Security and updates
The controller adopts technical and organisational measures appropriate to the risk, including access controls, protected sessions, HTTPS encryption, anti-CSRF protection, prepared queries, minimisation, abuse limitation and backup procedures. No measure eliminates every risk, and the public description remains general in order not to compromise security.
Material changes are published as a new dated version. The notice shown when an enquiry is submitted remains associated with that enquiry.