PRIVACY POLICY

DATA CONTROLLER
The data controller is “Betella s.n.c. di Betella & C.”, with registered office at Via Brescia 28/c, Chiari, 25032 (BS), Italy. Email: privacy@mio-qr.com - PEC: betella@pec.it

TYPES OF DATA PROCESSED
Through the “Mio” service, the following data are processed:
- Email and account login credentials
- Name of the person/animal associated with the QR Code
- Name and phone number of the emergency contact
- Any additional information freely provided

Any entry of health-related data (e.g. allergies, medical conditions, medications) is made at the user’s own initiative and constitutes explicit consent to the processing and public disclosure of such data.

SERVICE FUNCTIONING
The service allows the user to associate an information page with a unique QR Code, making the entered information publicly accessible to anyone who reaches the web address by scanning the QR Code.

PURPOSE OF PROCESSING
The data are necessary to allow the creation and management of the user account, the association between the entered information and the assigned QR Code, public display in case of need/emergency, technical support, and legal obligations.

LEGAL BASIS
The Controller processes user data if one of the following conditions applies: the user has given consent for one or more specific purposes; processing is necessary for the performance of a contract and/or pre-contractual measures; processing is necessary to comply with a legal obligation to which the Controller is subject; the user has entered health-related data (e.g. allergies, medical conditions, medications) on their own initiative, providing explicit consent to the processing and public disclosure of such data.

It is always possible to request that the Controller clarify the specific legal basis of each processing activity and, in particular, whether the processing is based on law, required by a contract, or necessary to enter into a contract.

PROCESSING METHODS AND SECURITY
Processing is carried out using appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of data. Data are processed using IT systems, stored in databases with a hosting provider (Netsons s.r.l.) with servers located in the EU/Italy, using secure connections and authenticated access for data modification.

DATA RETENTION
Data associated with the account, including those linked to QR Codes, are retained until deletion is requested by the user, which can be done independently through the dashboard. Technical and access logs may be retained for a maximum period of 12 months.

DATA SHARING AND DISCLOSURE
In addition to the Controller, in some cases other parties involved in the organization of this service (administrative staff, legal advisors, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies) may have access to the data, also appointed, if necessary, as Data Processors.

The data provided for the information page displayed at the web address accessible by scanning the QR Code, although not easily predictable, must be considered public as no authentication system is in place.

The user acknowledges that publishing personal data on pages accessible via QR Code involves an inherent risk of access by unauthorized parties.

USER RESPONSIBILITY
The user is responsible for the data entered, the decision to make them public, and any inclusion of third-party data. The user also guarantees that they have obtained the consent of the persons indicated, such as the emergency contact, and of a parent and/or guardian in the case of minors.

DATA SUBJECT RIGHTS
Users may exercise certain rights regarding the data processed by the Controller. In particular, within the limits provided by law, the user has the right to:
- withdraw consent at any time;
- object to the processing of their data;
- access their data;
- verify and request rectification;
- obtain restriction of processing;
- obtain erasure of personal data;
- receive their data or have them transferred to another controller;
- lodge a complaint with a supervisory authority or take legal action.

CHANGES
The Controller reserves the right to make changes to this privacy policy at any time by notifying users on this page and, where possible, via one of the contact details available.




Mio