Privacy Policy

TOUCH AND CONTACT S.R.L., hereinafter referred to as “TAC” for brevity, with registered office at 000131 – ROME, Via Adriano Olivetti No. 24, Tax ID and VAT No. 15372121002, is the Data Controller (hereinafter: “TAC” or “Controller”) pursuant to EU Regulation 679/2016 (hereinafter: “Regulation”) and Legislative Decree 196/2003 and subsequent amendments (hereinafter: “Privacy Code”) and considers the privacy and protection of your personal data to be one of the primary objectives of its business. We therefore invite you to carefully read this Privacy Policy because it contains important information regarding the protection of your personal data.

This Privacy Policy (hereinafter the “Policy”) applies exclusively to the processing of data provided by the user or otherwise obtained as a result of using the App.

We use data to provide and improve the services offered by TAC. By using our services, you consent to the collection and use of your information in accordance with this Privacy Policy. This Privacy Policy is closely linked to the Terms and Conditions of Service.

ART. 1 – Data Controller and Data Protection Officer

The Data Controller—that is, the entity that determines the methods and purposes of processing your personal data—is TOUCH AND CONTACT S.R.L., with registered office at Via Adriano Olivetti 24, 000131 – ROME, Tax ID and VAT Number 15372121002. The Data Controller is available to provide any information regarding the processing of your personal data at the following address: support@touchandcontact.com.

The designated Data Protection Officer (DPO) is Antonella Barbon, Esq., whose office is located at Viale Monte Grappa 27, Treviso. She can be contacted at the following email address:dpo@touchandcontact.com.

ART. 2 – Categories of data processed, purposes of processing, and nature of data provision

The personal data processed are as follows:

  1. Browsing data: The IT systems and software procedures used to operate the App collect, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the App, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters related to the user’s operating system and IT environment. This data is used solely to derive anonymous statistical information on the use of the App to verify its proper functioning, to identify anomalies and/or abuses, and is deleted immediately after processing. The data may be used to ascertain liability in the event of hypothetical cybercrimes against the App or third parties. Data regarding the PC, phone, tablet, or other device used for browsing will also be collected. This processing is based on Article 6(1)(b) of the Regulation, as the processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the data subject’s request. The provision of personal data for these purposes is optional, but failure to provide such data would make it impossible to activate or provide the services requested by the user.
  2. Data provided for the provision of the service: personal data voluntarily provided by the user to use the Application’s features (e.g., for registration, management of contracted products/services), such as first and last name, contact information (email address, mobile phone number), and data related to the use of services/products managed through the Application. The data may be provided to TAC by the Client (the company holding the contractual relationship with the data subject). Within their account, the user may enter, if applicable, a personal photo, the company they work for, fax number, address, website, VAT number, SDI, Tax ID, and personal social media links. This data will be processed for:
    • recognize the user during the login process;
    • to provide the user with the requested services and enable them to manage the products/services they use;
    • to provide users with useful information on how to use and optimize the service.
    The processing of this personal data is necessary for the purpose of providing the requested services. This processing is based on Article 6(1)(b) of the Regulation, as the processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the data subject’s request. The provision of personal data for these purposes is optional, but failure to provide such data would make it impossible to activate or provide the services requested by the user.
  3. Additional Purposes: promotional, commercial, and marketing: unless the data subject has previously objected, the email address may be used to send promotional communications, in accordance with Article 130, paragraph 4, of Legislative Decree 196/03, including for the direct sale of products or services similar to those already purchased by the user/customer. The legal basis is the legitimate interest of the Data Controller as provided for by the Regulation and the Privacy Code. Communications may be suspended at any time by using the unsubscribe options provided in each communication received (opt-out).

In addition, TAC may process personal data for the following purposes:

  • Purposes related to obligations imposed by laws, regulations, or EU legislation, as well as by provisions or requests from authorities legally empowered to do so and/or from supervisory and regulatory bodies. TAC may process personal data to fulfill the obligations to which it is subject. The provision of personal data for this purpose is mandatory, as failure to do so will prevent the Data Controller from fulfilling specific legal obligations.
  • Defense of rights in judicial, administrative, or out-of-court proceedings: Your personal data may be processed to defend our rights or to take action against you or third parties, or to assert claims against you or third parties. The legal basis for this processing is the Data Controller’s legitimate interest in protecting its rights.
ART. 3 – Retention period

Personal data will be retained for varying periods depending on the purpose for which it was collected: – provision of services: we will retain the data for the time strictly necessary to achieve the purposes. In any case, since this processing is carried out for the provision of services, “TAC” will exercise the right, permitted by law (Art. 2946, Civil Code), to retain the personal data necessary to protect its interests for the period provided by law; – promotional, commercial, and marketing purposes: as a general rule, until the data subject objects and/or the user revokes consent. Further information regarding the data retention period and the criteria used to determine such a period may be requested by sending a written request to the Data Controller at the contact details indicated in this policy. In any case, “TAC” reserves the right to retain personal data for the period of time provided for and permitted by Italian law to protect its interests (Art. 2947, paragraphs 1 and 3, Italian Civil Code). In the event that the User closes their account, please note that personal data will generally no longer be visible to third parties on our Services within 24 hours of the deactivation request, regardless of the reason for such request, while information from the closed account will be deleted within 30 days of its closure for security reasons. In any case, “TAC” reserves the right to retain users’ personal data even after account closure if reasonably necessary to comply with legal obligations (including law enforcement requests), meet regulatory requirements, resolve disputes, maintain security, prevent fraud and abuse, and enforce the License Agreement. Any information retained after the account is closed will be anonymized. Information shared with third parties (e.g., via email, messages, etc.) will remain visible after the account is closed or the information is deleted from the user’s profile. Please note that “TAC” does not control data that other users may have copied from the Services offered.

ART. 4 – Categories of data recipients

For the purposes described above, the user’s personal data collected by “TAC” may be disclosed to:

  • employees and internal consultants who, in the course of their duties, act as authorized data processors and have been instructed accordingly by the Data Controller;
  • external consultants and third parties (providers of technical and technological services, credit and banking institutions, providers of services essential to the management and maintenance of the Application, as well as third-party call center companies, marketing firms, and advertising and market research service providers). The aforementioned categories of entities act as data processors appointed by “TAC”.
ART. 5 – Processing Methods

Data processing is carried out using paper, electronic, and digital media by specifically designated internal personnel. The data is stored in electronic archives and, to a lesser extent, in paper form, with full compliance with the minimum security measures required by law.

ART. 6 – Transfer of data abroad

The user’s personal data collected by TAC will be processed primarily in Italy and, in any case, in countries that are members of the European Union; however, certain processing activities may be carried out in non-EU countries, provided that the necessary standards of security, protection, and data safeguarding are ensured, as required by national and supranational legislation, such as the adoption of Standard Contractual Clauses approved by the European Commission.

ART. 7 – Rights of the Data Subject

Pursuant to the Regulation, data subjects may exercise the following rights with respect to the data controllers:

  • to request and obtain information regarding whether the Data Controller holds personal data about you, as well as regarding the processing of such data carried out by the Data Controller, and to obtain access to such data;
  • to request and obtain their data provided to the Data Controller in a structured, commonly used, and machine-readable format, where the processing is based on consent or a contract and is carried out by automated means, as well as, where technically feasible, the transfer of such data to another data controller;
  • request and obtain the modification and/or correction of data that is inaccurate or incomplete;
  • request and obtain the erasure of your data if such data or information is unnecessary—or no longer necessary—for the purposes set forth above, or if any of the other conditions provided for by law are met (see Article 17 of the Regulation);
  • request and obtain the restriction of the processing of their personal data if the data subject disputes its accuracy or in the other cases provided for in Article 18 of the Regulation;
  • object to the further processing of your data in the cases expressly defined in the preceding article.

Such requests may be addressed to “TAC” by sending an email to support@touchandcontact.com. Requests submitted via email or other channels that do not allow for the identification of the requester must be accompanied by a copy of the requester’s identification document for the purpose of verifying their identity. In accordance with applicable law, in addition to the rights mentioned above, the data subject also has the right to lodge a complaint with the competent supervisory authority, which in Italy is the Garante per la protezione dei dati personali, Piazza di Monte Citorio n. 121 00186 ROME, Fax: (+39) 06.69677.3785, garante@gpdp.it, protocollo@pec.gpdp.it.

ART. 8 – Cookies

For more information on this matter, interested parties are invited to review the Cookie Policy, prepared by the Data Controller, at the following link:https://tac.touchandcontact.com/cookie-policy.

ART. 9 – Amendments and Updates

The Data Controller may freely modify or update this document, in whole or in part, including in light of changes to laws or regulations governing the protection of personal data. It is understood that any modification or update will be notified to users and other interested parties on the Website’s homepage and through other channels available from time to time within the Services (for example, in-app notifications or email communications for registered users). When the data subject next accesses the Website and the Services, the Data Controllers will ask the data subject to confirm that they have reviewed the new version of the Privacy Policy applicable to the processing of their data.

How do you plan touse TAC?

For my team

For personal use