Last updated: 8 September 2026
Which processing this notice covers. Here Data Driven Solutions S.r.l. is the Controller: this concerns the data of the customer and of its contact persons collected to enter into and perform the subscription contract. The data the customer enters into its own CRM remains the customer’s and is governed by the Data Processing Agreement (DPA), under which Data Driven Solutions acts as Processor.
Data controller
Data Driven Solutions S.r.l.
Via Francesco Albergati 45/B, 40059 Medicina (BO) — Italy
VAT no. and tax code IT04134041203 — Email: [email protected]
Personal data processed
- Identification and contact data of the customer and its contact persons: first and last name, role, company name, email address, phone number, address.
- Administrative and tax data: VAT number, tax code, e-invoicing recipient code/certified email, billing details, payment and non-payment history. Payment card data is processed directly by Stripe and is not stored by Data Driven Solutions.
- Account and usage data: credentials of the instance users, access logs, technical data on the use of the Service, needed for security and support.
- Communications: content of emails, Regya Care tickets and notes relating to kick-off and review calls.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Entering into and performing the subscription contract: activation of the instance, kick-off call, support, management of plans and modules | Performance of the contract or pre-contractual measures — art. 6.1.b GDPR |
| Invoicing, collection of fees, tax and accounting obligations, retention of documents | Legal obligation — art. 6.1.c GDPR |
| Platform security, abuse prevention, access logs, backups | Legitimate interest of the Controller — art. 6.1.f GDPR |
| Payment reminders, debt collection and any litigation | Legitimate interest of the Controller — art. 6.1.f GDPR |
| Sending communications about products and services similar to those already purchased, with the option to object in every message | Legitimate interest / art. 130(4) Italian Legislative Decree 196/2003 |
| Sending marketing communications about other Data Driven Solutions services and invitations to events or training | Consent — art. 6.1.a GDPR, revocable at any time |
Provision of data
Providing identification, contact and administrative data is necessary to enter into and perform the contract: refusal makes it impossible to activate the Service. Consent to marketing communications is optional and does not affect the provision of the Service.
Recipients
Data may be disclosed to parties acting as processors or as independent controllers:
- the infrastructure and hosting provider in the European Union;
- Proweb, technical partner for the development and maintenance of the instances;
- Stripe, for the management of recurring payments;
- the provider of the electronic invoicing platform and the Italian Revenue Agency’s Exchange System (SDI);
- accounting and tax advisers, legal advisers in the event of litigation;
- public authorities, where required by law.
Data is not disclosed or sold to third parties for their own marketing purposes.
Transfers to third countries
Data is processed on servers located in the European Union. Where certain providers involve a transfer to third countries (for example for payment services), this takes place on the basis of an adequacy decision of the European Commission or of Standard Contractual Clauses supplemented by additional measures.
Retention period
- Contractual and account data: for the whole duration of the relationship and, afterwards, for the time needed to settle any pending matters.
- Tax and accounting data: 10 years from recording, pursuant to art. 2220 of the Italian Civil Code and tax legislation.
- CRM instance and backups: deleted within 30 days of termination of the Service, unless otherwise requested in writing.
- Contact data for marketing purposes: until objection or withdrawal of consent.
- Security logs: for the time needed for security purposes and in any case no longer than permitted by applicable law.
Automated decision-making
The Controller does not carry out automated decision-making or profiling that produces legal effects on customers or similarly significantly affects them. The platform’s artificial intelligence features operate on the data the customer enters into its own instance and provide non-binding suggestions, under the user’s control.
Rights of the data subject
Data subjects may at any time exercise the rights provided for in arts. 15–22 GDPR: access, rectification, erasure, restriction, portability and objection, as well as withdrawal of consent, which does not affect the lawfulness of processing carried out before withdrawal. Requests should be sent to [email protected]; the Controller replies within one month, extendable by two months in complex cases.
It is also possible to lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or with the supervisory authority of the Member State of residence.
The Controller may update this notice; material changes are communicated by email with at least 30 days’ notice.
This is an English translation provided for convenience. In the event of any discrepancy, the Italian version prevails.