Skip to content

Privacy

Notice given under articles 13 and 14 of Regulation (EU) 2016/679. It covers visitors to this website, people who write to us, and customers who take out a subscription.

Courtesy translation. Only the Italian version of this document has legal value: if the two texts diverge, the Italian text prevails. Italian law applies to the relationship in any case.

Data controller

The data controller is Collaborazioni Digitali Srl, Via Ludovico Muratori 29, 20135 Milano (MI), Italy, VAT number IT11899440967.

For any question about personal data you can write to info@flarseo.com or to the certified email collaborazionidigitali.srl@legalmail.it.

This notice covers data processed by the company as controller. For the content that a customer entrusts to the platform we act instead as processor on the customer behalf.

Summary of the data processing agreement

Categories of data processed

  • Account data: first and last name, email address, telephone, business role, access credentials in protected form.
  • Billing data: company name, VAT number or tax code, registered address, legal representative, SDI recipient code or certified email, invoice history. Card data never passes through our systems.
  • Brand content: descriptions of the business, services, tone of voice, uploaded materials, generated articles and posts, websites built in the platform.
  • Usage logs: date and time of access, IP address, browser type, actions taken in the platform, technical outcomes of processing runs.
  • Communications: messages sent through the website forms and email correspondence with support.

We do not ask for and do not want special categories of data under article 9 of the GDPR. If your sector involves health data, do not upload it to the platform.

Purposes and legal bases

PurposeLegal basis
Deliver the service, create and manage the account, generate and publish the requested contentPerformance of the contract, article 6.1.b
Issue invoices, keep accounting records and meet tax obligationsLegal obligation, article 6.1.c
Answer requests sent through the website formsPre contractual steps at the request of the data subject, article 6.1.b
Ensure security, abuse prevention and technical continuityLegitimate interest in protecting the platform, article 6.1.f
Improve the product using aggregated usage dataLegitimate interest in developing the service, article 6.1.f
Send product updates to people who asked for themConsent, article 6.1.a, revocable at any time
Defend a legal claimLegitimate interest, article 6.1.f

Where the basis is legitimate interest we assessed that the processing does not override your rights. You can still object by writing to us.

Provision of data

Account and billing data are necessary: without them we cannot activate the subscription or issue the electronic invoice.

Brand content is optional in its detail, but it drives the quality of the result: the more context the assistant receives, the fewer corrections are needed afterwards.

Consent to product updates is entirely optional and withholding it has no effect on the service.

Recipients and processors

Data is accessible to authorised staff of the controller, instructed and bound to confidentiality, on a least privilege basis.

We also use suppliers appointed as processors under article 28 of the GDPR, in defined categories: cloud infrastructure, language model providers for content generation, payments, transactional email delivery, SEO data providers, error monitoring.

Data is never sold, nor transferred to third parties for their own marketing purposes.

It may be shared with the professionals who assist us on accounting and legal matters, and with authorities where the law requires it.

Categories of subprocessors we use

Transfers outside the European Economic Area

We prefer suppliers that process inside the European Economic Area. Some services, in particular those tied to language models and to certain technical tools, may involve a transfer to third countries.

When that happens, the transfer only takes place under one of the safeguards in chapter V of the GDPR: an adequacy decision of the European Commission, or the standard contractual clauses together with the supplementary measures required.

You can ask us for a copy of the safeguards applied by writing to the addresses given in this notice.

How long we keep data

We apply a simple criterion: we keep data for as long as the purpose requires, then delete it or make it anonymous.

CategoryRetention criterion
Account data and brand contentFor the whole duration of the relationship, plus the limited recovery period stated in the framework agreement after it ends.
Billing data and documentsFor the period imposed by Italian tax and civil law on the keeping of accounting records.
Technical and security logsFor as long as useful for security and diagnostics, then deleted or aggregated.
Requests sent through website formsFor as long as needed to handle the request and any follow up.
Data processed on the basis of consentUntil consent is withdrawn.

After the relationship ends you can still ask for early deletion of anything we are not legally required to keep.

No automated decision about the visitor

We do not take decisions based solely on automated processing that produce legal effects, or that similarly significantly affect, people who visit the site or subscribe to the service.

The platform uses artificial intelligence systems to generate editorial content, not to profile or score people.

How we use AI systems

Data security

We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest, encrypted secrets, access control, separation between customer workspaces, logging of relevant events and backups.

Read the security page

Your rights

At any time you can exercise the rights set out in articles 15 to 22 of the GDPR.

  • Access: find out which data we process and obtain a copy of it.
  • Rectification: correct inaccurate data or complete it.
  • Erasure: obtain deletion in the cases the regulation provides for.
  • Restriction: ask that processing be paused while a dispute is examined.
  • Portability: receive the data in a structured, commonly used format, or have it sent to another controller.
  • Objection: object to processing based on legitimate interest, explaining your reason.
  • Withdrawal of consent: withdraw a consent already given at any time, without affecting the lawfulness of earlier processing.

How to exercise your rights

Write to info@flarseo.com or to the certified email collaborazionidigitali.srl@legalmail.it, stating the right you want to exercise and something that lets us identify you.

We answer within the deadlines set by article 12 of the GDPR. If the request is complex we may extend, explaining why.

Exercising your rights is free. Only for manifestly unfounded or excessive requests does the regulation allow a fee or a reasoned refusal.

If the request concerns content that one of our customers uploaded to the platform, we forward it to that customer, who in that case is the controller.

Complaint to the Garante

If you believe the processing of your data breaches the GDPR you can lodge a complaint with the Garante per la protezione dei dati personali, the Italian supervisory authority, or bring the matter before the courts.

We would ask you, where possible, to write to us first: it usually resolves faster.

Changes to this notice

We may update this notice when processing activities, suppliers or legal duties change. Every version carries a number and a date.

Material changes are notified by email to active customers before they take effect.

This page is the public notice. The contractual obligations on processing data for the customer are set out in the agreement delivered as an annex to the contract, in Italian, at signup.

Want to exercise a right?

Write to us and we will answer within the deadlines the Regulation sets. No special form is needed: a clear email is enough.