PRIVACY POLICY
pursuant to Article 13 of EU Regulation no. 679/2016 (GDPR)


In order to conduct correct and transparent processing, Audio & Light Systems S.r.l. provides the following information notice – drafted pursuant to Article 13 of Regulation (EU) no. 679/2016 on the "Protection of natural persons with regard to the processing of personal data" ("GDPR") and of Legislative Decree no. 196/2003 ("Privacy Code"), as amended by Legislative Decree no. 101/2018 – intended for all those who use the "Hiwo Events" app ("Hiwo" or "App").


1. Data Controller – Who processes your data?

The data controller is Audio & Light Systems S.r.l., with registered office in Milan (MI), Via Pasquale Paoli 8, 20143, registered with the Companies' Register of Milan-Monza-Brianza, Fiscal Code and VAT number 04957940150 ("Controller").
For any questions regarding the processing of your personal data, the Controller can be contacted at the following addresses:
(a) Mail: at the registered office;
(b) E-mail: privacy@als.it;
(c) PEC (certified e-mail): pec@pec.als.it.


2. Purposes of the processing – What personal data do we process?

The Controller will process personal data directly provided by the data subject. In particular, the Controller will process:
a) Registration data, such as name, email, password, VAT number, date of birth;
b) Profile data, such as profile photo, place of business, sector, skills, experience, languages spoken, etc., voluntarily provided by the Professionals (as defined in the Hiwo Terms & Conditions);
c) App usage data, such as the creation of productions, applications, shared posts, rentals made;
d) Location data, if necessary for the use of specific features of the App and with the prior consent of the Professional;
e) Contact details, such as e-mail address, for sending communications relating to the App.


3. Purposes and legal basis of the processing – Why do we process your personal data?

The Controller processes personal data, including with the aid of IT, telematic and manual means, for the following purposes:
(a) To allow registration and access to Hiwo.
Your personal data (registration data, profile data, location data, contact details) may be processed to allow you to create an account and access Hiwo. The legal basis for this processing is the performance of a contract to which you are a party (Article 6(1)(b) of the GDPR), represented by the Hiwo Terms and Conditions, accepted during registration. The processing of your personal data for this purpose is necessary, as any refusal would make it impossible to register and access Hiwo.
(b) To provide the services requested by Professionals, such as the creation of productions, application for promotions or the rental of equipment between Professionals.
Your personal data (registration data, profile data, location data, contact details) may be processed to allow you to use the services of Hiwo. The legal basis for this processing is the performance of a contract to which you are a party (Article 6(1)(b) of the GDPR), represented by the Hiwo Terms and Conditions, accepted during registration. The processing of your personal data for this purpose is necessary, as any refusal would make it impossible to register and access Hiwo.
(c) To allow interaction and communication between Professionals through the social features of the App.
Your personal data (profile data) may be processed to allow interaction and communication between Professionals through the social functionality of the App consisting of the publication of posts, in order to allow Professionals to share content, such as presentations of their work, opinions, experiences or other relevant information, with the aim of facilitating networking, collaboration and the exchange of job opportunities between Professionals. The legal basis for this processing is the performance of a contract to which you are a party (Article 6(1)(b) of the GDPR), represented by the Hiwo Terms and Conditions, accepted during registration. The processing of your personal data for this purpose is necessary, as any refusal would make it impossible to register and access Hiwo.
(d) To send notifications relating to Hiwo.
The processing of your personal data (email address, push/registration token) for this purpose is necessary to send you communications strictly related to the operation of Hiwo, such as notifications about the publication of new productions or any updates. These communications are necessary to allow you a complete and informed use of Hiwo. The legal basis for this processing is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR). It is, in fact, a legitimate interest of ALS to keep its Users updated on the services provided. This legitimate interest of the Controller also coincides with the legitimate interest of the Professionals themselves who, by registering with Hiwo, expect that their personal data will be used by the Controller to inform them about the services provided or about relevant changes to the operation of the app. In addition, Professionals have the option to disable notifications in their account settings. The legitimate interest of the Controller thus identified can therefore be considered to prevail over the fundamental rights and freedoms of the data subject, also because of these reasonable expectations. The provision of personal data for this purpose is necessary. Without prejudice to the provisions of point 7(c), you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out for the purpose in question. To exercise this right, you may contact the Controller at one of the addresses indicated in point 1 ("Data Controller – Who processes your data?").
(e) Profiling for commercial purposes.
With the free, specific, informed and unambiguous consent of the data subject (Article 6(1)(a) of the GDPR), ALS may process the personal data provided to create a profile of the data subject's preferences, habits and consumer choices, in order to send personalized commercial communications and recommend services or products of ALS or commercial partners of potential interest. For these purposes, ALS may use the data actively provided by the data subject (e.g., during Account registration or use of Hiwo Services) and information collected during the data subject's use of the App. Profiling for commercial purposes is an automated processing of personal data which consists in using such information to evaluate certain personal aspects relating to the data subject, in particular to analyze or predict their preferences, interests, and behavior. The provision of data for this purpose is optional: there is no legal or contractual obligation on your part. Furthermore, consent for this purpose is revocable at any time by accessing the "Settings" section of the App or by contacting ALS. Any refusal of consent, already at the registration stage or subsequently, will not in any way affect the possibility of registering an Account and using the Services offered by Hiwo.
(f) Communicating your personal data to commercial partners.
With your consent, we may communicate some of your personal data (e.g., email address, interests) to selected commercial partners of ALS, who may use it to send you commercial communications about their products or services. Our partners will be carefully chosen from quality companies operating in sectors that we believe may be of interest to you, based on the preferences you have expressed to us using Hiwo. We undertake to transfer only the data strictly necessary for this purpose and to do so securely, in compliance with applicable law. The provision of your data for this purpose is optional and does not in any way affect the possibility of registering and using all the features of Hiwo. However, by consenting, you will help us support the development and maintenance costs of the platform and you may receive advantageous offers from selected companies. The legal basis for this processing is the express consent of the data subject (Article 6(1)(a) of the GDPR). In the event that you change your mind, you may revoke your consent at any time by contacting the Controller at one of the addresses indicated in point 1 ("Data Controller – Who processes your data?") or through the appropriate "unsubscribe" link present in each commercial communication sent by individual commercial partners. The provision of data for this purpose is optional: there is no legal or contractual obligation on your part.
(g) Improving Hiwo and the User experience, including through aggregated statistical analysis.
Your personal data relating to the use of Hiwo (e.g., frequency of access, features used) may be processed, in aggregate and anonymous form, to analyze the operation of Hiwo, identify any technical problems and develop improvements to offer you an increasingly engaging and personalized experience. The legal basis for this processing is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR). It is, in fact, a legitimate interest of ALS to monitor and improve the quality of its service. In balancing the rights and freedoms of data subjects, ALS has considered that this processing does not have any significant negative impact on their personal sphere. On the contrary, the processing is aimed at improving the service offered, to the direct benefit of all Professionals. The provision of personal data for this purpose is necessary, as any refusal would make it impossible to use Hiwo. Without prejudice to the provisions of point 7(c), you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out for the purpose in question. To exercise this right, you may contact the Controller at one of the addresses indicated in point 1 ("Data Controller – Who processes your data?").
(h) Responding to requests.
Your personal data (registration data) may be processed to process and respond to requests for information, assistance or other requests sent to us. The legal basis for this processing is the performance of the contract, the implementation of pre-contractual measures at the request of the data subject (Article 6(1)(b) of the GDPR) or, depending on the case, the legitimate interest of the Controller (Article 6(1)(f) of the GDPR). It is in the legitimate interest of the Controller to respond to requests for information and/or reports and/or disputes and/or complaints from data subjects. This legitimate interest of the Controller also coincides with the legitimate interest of the data subjects themselves who make the requests and who, therefore, in the context of the relationship with the Controller, can reasonably be expected to expect that their personal data will be used by the Controller to provide feedback. The legitimate interest of the Controller thus identified can therefore be considered to prevail over the fundamental rights and freedoms of the data subject, also because of these reasonable expectations. The provision of personal data for this purpose is necessary, as any refusal would make it impossible to respond to the request. Without prejudice to the provisions of point 7(c), you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out for the purpose in question. To exercise this right, you may contact the Controller at one of the addresses indicated in point 1 ("Data Controller – Who processes your data?").
(i) Fulfilling legal obligations.
Your personal data (registration data and other data that may be requested) may be processed to fulfill obligations under laws, regulations or Community legislation, as well as provisions issued by authorities and supervisory and control bodies. The legal basis for this processing is the fulfillment of a legal obligation to which the Controller is subject (Article 6(1)(c) of the GDPR). The provision of data for this purpose is necessary, as any refusal would make it impossible to use Hiwo.
(j) Allowing you to exercise your rights.
The Controller may process your personal data in order to:
i. Respond to requests to exercise rights in relation to the provision of the App's services;
ii. Carry out the activities that prove necessary as a consequence of the exercise of these rights;
iii. Receive and respond to requests to exercise the rights regarding the protection of personal data provided for by the GDPR and carry out all subsequent activities.
The legal basis for this processing is the fulfillment of a legal obligation to which the Controller is subject (Article 6(1)(c) of the GDPR). The provision of data for this purpose is necessary, as any refusal would make it impossible to use Hiwo.
(k) Ascertaining, exercising or defending a right in court.
The Controller may process your personal data for the establishment, exercise or defense of a right in all competent courts. The legal basis for this processing is legitimate interest of the Controller (Article 6(1)(f) of the GDPR). It is in the legitimate interest of the Controller to take legal action to ensure respect for its rights or to demonstrate that it has fulfilled the obligations imposed by law. This legitimate interest is in turn based on the constitutionally protected right of defense. It can therefore be considered to prevail over the fundamental rights and freedoms of the data subject. Without prejudice to the provisions of point 7(c), you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out for the purpose in question. To exercise this right, you may contact the Controller at one of the addresses indicated in point 1 ("Data Controller – Who processes your data?").


4. Communication of data – To whom are your data communicated?

Your personal data may be communicated to:
(a) Employees of the Controller, specifically authorized pursuant to Articles 29 of the GDPR and 2-quaterdecies of the Privacy Code;
(b) Collaborators and suppliers of the Controller – such as, for example, IT service providers (hosting and cloud) –, expressly appointed as data processors, pursuant to Article 28 of the GDPR;
(c) Public authorities, in the case of legitimate requests.
The data subject may request from the Controller, at any time, an updated list of the data processors who carry out processing operations on their personal data. Your personal data will not be disseminated under any circumstances, i.e. it will not be disclosed to indeterminate subjects, in any form, even by simply making it available or accessible.


5. Data transfer – Where are your data transferred?

Generally, the Controller does not transfer the personal data of data subjects to countries outside the European Union or to international organizations. In the event that this should occur, the Controller guarantees that all transfers will be subject to the appropriate safeguards described in Article 46 of the GDPR.


6. Period of retention of personal data – How long do we keep your data?

Your personal data will be kept for the time strictly necessary for the pursuit of the purposes for which it was collected, in compliance with the principle of minimization referred to in Article 5(1)(c) of the GDPR.
In particular:
(a) For the purposes of registration and access to Hiwo (point 3(a)), to provide the services requested by Professionals (point 3(b)) and to allow interaction and communication between Professionals (point 3(c)), your data will be kept for the entire period in which you remain registered on Hiwo. If you decide to delete your account or if it remains inactive for 24 consecutive months, your data will be deleted within 60 days;
(b) Notifications relating to the App will be sent as long as you remain registered on Hiwo, unless you decide to deactivate them from your account settings;
(c) For profiling for commercial purposes, we will keep your data for 24 months from your last consent, without prejudice to our right to request new consent from you to continue sending you such communications;
(d) For communication to commercial partners, your data will be kept by the partners for 12 months from the time of communication;
(e) The data used for statistical analysis in aggregate and anonymous form, aimed at improving Hiwo, will be kept for 36 months;
(f) Data relating to requests for information or assistance will be kept for the time necessary to provide a comprehensive response and in any case for no more than 12 months from the last interaction, after which it will be deleted or anonymized;
(g) Where processing is necessary to comply with a legal obligation, the data will be kept for the period of time imposed by the specific legislation;
(h) The data processed to allow you to exercise your rights will be kept for the time necessary to manage your request and to document compliance (generally, no more than 10 years);
(i) If the data is processed to ascertain, exercise or defend a right in court, the retention may continue for as long as necessary to pursue these purposes, based on the envisaged procedural deadlines (generally, no more than 10 years).
At the end of the periods indicated above, your data will be deleted, anonymized or aggregated, in accordance with the provisions of Article 17 of the GDPR.


7. The rights of the data subject – What are your rights?

The GDPR grants you, as the data subject, certain important rights that you may exercise with respect to the Data Controller. Among the rights recognized to you are the following:

a. Request from the Data Controller access to your personal data and information relating to them (pursuant to Article 15 of the GDPR), the rectification of inaccurate data or the completion of incomplete data (pursuant to Article 16 of the GDPR), the erasure of personal data concerning you (when one of the conditions set forth in Article 17(1) of the GDPR applies and subject to the exceptions provided for in Article 17(3) of the same), or the restriction of the processing of your personal data (when one of the circumstances indicated in Article 18(1) of the GDPR applies).

b. Request and obtain from the Data Controller—in cases where the legal basis for processing is the contract or consent, and the processing is carried out by automated means—your personal data in a structured, machine-readable format, also for the purpose of transmitting such data to another data controller (the so-called right to data portability, pursuant to Article 20 of the GDPR).

c. Object at any time to the processing of your personal data where the legal basis for such processing is the legitimate interest of the Data Controller (pursuant to Article 21 of the GDPR). In the event that you exercise your right to object, the Data Controller will refrain from any further processing of the personal data, unless it can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and fundamental freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims.

d. Withdraw consent at any time, limited to instances in which processing is based on your consent for one or more specific purposes and involves either common personal data (e.g., date and place of birth, or place of residence) or special categories of data (e.g., data revealing your racial origin, political opinions, religious beliefs, health status, or sexual orientation). The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal (pursuant to Article 13(2)(c) of the GDPR).

e. Lodge a complaint with a supervisory authority (Data Protection Authority – garanteprivacy.it) (pursuant to Article 13(2)(d) of the GDPR).

Pursuant to Article 12 of the GDPR, the Data Controller will provide you with information about the actions taken in relation to a request to exercise your rights without undue delay and, in any event, within one month of receiving the request. This period may be extended by up to three months in particularly complex cases. In such cases, the Data Controller will inform you of any extension and the reasons for the delay within one month of receiving your request. If you submitted your request by electronic means, the information will be provided to you, where possible, by the same means, unless you request otherwise.


Last update: May 10, 2024


Mobirise

HIWO