Privacy Policy

This page describes how to manage the site https://mybiros.com/ (”Site”) and of the platform (”Platform”) of MyBiros S.r.l. (“MyBiros”, “We”, “Company”), with reference to the processing of personal data of users who consult the web page and who use the Company's services (”SaaS Services”) provided through the Platform. The information is provided only for the Site and for the Platform of MyBiros and not for other websites and platforms that may be consulted by the user.

Following the consultation of the Site and the use of the Platform, data relating to identified or identifiable persons may be processed. We may also receive personal information from the user through the contact details on our Website, for the purposes and in the manner better specified below.

The data will be processed in full compliance with the legislation on the protection of personal data referred to in Regulation (EU) 2016/679 (”GDPR”) and Directive 2002/58/EC (”e-Privacy Directive”).

HOW DO WE COLLECT AND USE PERSONAL DATA?

This Site and our Platform acquire Personal Data (”Personal Data” or”Data”) as part of their normal operation, whose transmission is an integral part of Internet communication protocols and of the functioning of the Platform itself. Among these Data, depending on the way the user interacts with the Site and the Platform, there may be: profile information, contact information, browsing preferences and interests, and information on the user's location.

Data collected when browsing the Site and using the Platform

The Site and the Platform may automatically allow the identification of the user when browsing by collecting certain personal information such as IP addresses or domain names of the computers used by users who connect to the Site or who use the Platform, addresses in URI notation (Uniform Resource Identifier) of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, a numerical code indicating the status of the response given by the web server (successful, error, etc.) and other parameters related to the user's operating system and computer environment.

This Data is used for the sole purpose of obtaining statistical information on the use of the Site and the Platform and to check its correct functioning.

The Data could be used to ascertain responsibility in case of computer crimes against the Site or at the request of the authorities.

- Data provided voluntarily by the user

We may acquire the Personal Data of users by voluntarily sending requests from interested parties.

PURPOSES

MyBiros can offer its services as part of a B2B relationship, to companies interested in the Platform, just as it can establish a contractual relationship with users — individuals — as part of a B2C exchange.

When operating on behalf of companies, MyBiros acts as responsible for the processing of personal data pursuant to art. 28 GDPR, while in relations with individual users interested in the service, the Company acts as Data Controller.

We use the Personal Data collected for multiple purposes such as, for example: for the administration of requests sent to MyBiros through the Site, to properly manage our Platform and to analyze the information collected in order to improve our Site and our Platform. 

The purposes are listed in more detail in the table below.

Categories of Personal Data
Purposes of the treatment
Legal basis for processing
Comments and opinions. When you contact us by email and telephone, we collect your comments, requests and opinions.
By clicking on the “Contact Us” button on our Website, the user can fill out the request form, entering their name, contact details (telephone and e-mail) and the additional information they wish to provide us with for the purpose of requesting assistance
To answer questions, support the user in registering to try the Platform Demo, in the use of the Site and services.
The processing is necessary for the pursuit of our legitimate interest, namely to communicate with users in relation to the services and to manage in an adequate and timely manner customer requests and suggestions regarding the Site and the Platform. If the user is interested in our services and asks us for information about our business, we may process his Data for pre-contractual purposes.
Use of the Platform Demo. We may process the user's Personal Data to allow registration and guarantee the use of the Platform Demo.
To ensure the use of the Platform Demo.
The processing is necessary for the provision of the service and the management of the contractual and pre-contractual relationship.
Information related to the user's profile. We may process the user's Personal Data to allow registration and guarantee the use of the services connected to the Platform.
To provide a personalized service based on user requests and the information provided, in order to fulfill our contractual and pre-contractual obligations.
The processing is necessary for the provision of the service and the management of the contractual and pre-contractual relationship.
Promotional information. We may use the Personal Data provided by the user to send commercial and promotional communications about the activities carried out and the services provided by MyBiros.
To promote the services and activities carried out by MyBiros and to inform the user about the Company's news.
The processing of the user's Personal Data for these purposes will take place only with the explicit consent of the interested party, unless they are communications about services similar to those already received.
Improve the functioning of the Platform.

As part of its services, MyBiros may be interested in using the Personal Data provided by the user for additional purposes that concern the improvement and development of the Platform.

Where the Company acts as a manager, this activity must be regulated in the agreement on the processing of Personal Data signed pursuant to art. 28 GDPR with the owner contracting the service.

In case of authorization from the contractor, MyBiros would operate as the data controller of the new treatment, pursuant to art. 28, paragraph 10, GDPR.
To use the Personal Data provided by the user for additional purposes that concern the improvement and development of the Platform.
This activity is carried out within the legitimate interest of the Company that uses this information in the development, design, selection and continuous implementation of its Platform, services and products presented to the user.

If MyBiros intended to use the data to better understand the characteristics and orientations of its users in choosing the services offered, the treatment would take place based on the user's prior consent.
Information provided by third parties. We may receive information about you from third parties and other users, for example, we may obtain information from our business partners, service providers, or other organizations to which you belong. We may obtain information from third parties to improve or supplement existing user information. We may also collect information that is available to the public.
We may combine this information with information that we collect directly from the user. We use this information to contact the user and to improve our service
The processing is necessary for the pursuit of our legitimate interest, in particular to adapt our service to the user and to improve our service in general.
Information about fraudulent or criminal activity related to the user's account.
We will use information about fraudulent or criminal activities related to the use of our service for the purpose of detecting and preventing fraud or abuse.
The processing is necessary for our legitimate interest, namely for the detection and prevention of fraud.
All personal information mentioned above.
We will use all personal information collected to manage, maintain and provide the user with the functionality of our Site, to communicate with the user, to monitor and improve our services and our business.
The processing is necessary for the pursuit of our legitimate interests in protecting our organization.
Information provided by social networks. When the user interacts with us through various social networks, we may receive information from those platforms including profile information, user ID associated with the social media account, the list of his network of acquaintances, and any other information connected to the social network.
We use this information to communicate or interact with the user on the social network, to better understand the characteristics of our visitors and to personalize content and advertising. The Data we receive depends on the privacy settings that the user has activated with the social network. Before connecting or connecting them to our Website or service, we suggest that you periodically review and, if necessary, change the privacy settings on third-party websites and on social networks and services.
The processing is necessary for the pursuit of our legitimate interest, in particular to adapt our service to the user's needs and to improve our service.


WHO DO WE SHARE USER INFORMATION WITH?

The Personal Data provided may be communicated to our suppliers and business partners for the maintenance and updating of this Site. These companies:
- they may also have a non-European office;
- they will never directly use the Personal Data provided by the Company;
- they will not sell the Personal Data communicated by the Company to third parties.
To learn more, please review our Extended Privacy Policy.


WHAT ARE THE USER'S RIGHTS?

Users, as interested in the processing of Data, have the right at any time to obtain confirmation of the existence or not of the Personal Data processed and to know its content and origin, verify its accuracy or request its integration, updating, correction (articles 15 and 16 of the Regulation).

Pursuant to articles 17, 18 and 21 of the European Regulation 2016/679 - GDPR, every user has the right to request the cancellation, the limitation of processing, the transformation into anonymous form or the blocking of Data processed in violation of the law, as well as to oppose in any case, for legitimate reasons, to their processing. Users also have the right to lodge a complaint with the supervisory authority for the protection of Personal Data, pursuant to art. 77 GDPR. The interested party has the right to withdraw their consent at any time, where this constitutes the legal basis for the processing.
The withdrawal of consent does not affect the lawfulness of the processing based on consent before the revocation.

For more information on the rights and methods of exercising them, we invite all users to read our extended Privacy Policy below.


QUESTIONS ABOUT OUR PRIVACY POLICY?

For more information on the processing of personal data and our privacy policy, users can contact us at: e-mail: privacy@mybiros.com.

Before accessing or using our Site or Platform, please ensure that you have read and understand our collection, processing, storage, use and disclosure of your Personal Data as described in this Privacy Policy.

  1. What is the privacy policy about?
  2. Who is the Data Controller?
  3. What Personal Data do we collect?
    3.1. What type of Personal Data do we process?
    3.2 Information collected automatically
  4. Why do we process the user's Personal Data?
  5. Who is the user's Personal Data communicated to?
  6. What are the user's rights in relation to the processing of Personal Data, how can they be exercised?
  7. How long do we keep Personal Data?
  8. What transfers can we make?
  9. How do we protect your Personal Data?
  10. Cancellation of services
  11. Applicable law
  12. Complaint to the Guarantor Authority

Table 1 — Suppliers

PRIVACY POLICY
Extended information

1. What is the privacy policy about?

This privacy statement (”Privacy Policy”) describes how this website (”Site”) and the platform (”Platform”) by MyBiros S.r.l. (”MyBiros”,”Noi”,”Company”) manage the processing of Personal Data (”Data”) of users who consult our web page, who use our Platform and the automatic document processing services offered by the Platform (SaaS Services).

The information is provided only for the Company's Site and Platform and not for other websites and/or platforms that may be consulted by the user through external links.

Following the consultation of this Site and the Platform, Data relating to identified or identifiable persons may be processed. The Data will be processed in full compliance with the legislation on the protection of Personal Data referred to in Regulation (EU) 2016/679 (”Regulation” or”GDPR”) and Directive 2002/58/EC (”e-Privacy Directive”).


2. Who is the Data Controller?


MyBiros S.r.l., with registered office in Via Antonio Schivardi 60, 00144 Rome (RM), can offer its services as part of a B2B relationship, to companies interested in the SaaS Services offered by the Platform, just as it can establish a contractual relationship with customers - individuals - as part of a B2C exchange.

When operating on behalf of companies, MyBiros acts as responsible for the processing of personal data pursuant to art. 28 GDPR, while in relations with individual users interested in the service, the Company acts as owner (”titular”).


3. What Personal Data do we collect?

We collect and process Personal Data in different ways:

- Personal Data provided by the user: we collect personal information about the user when it is actively provided, for example when the user contacts us to provide immediate assistance, when he decides to register on our Site and on the Platform by creating a personal profile to test our Demo.

- Personal Data collected through the use of the Site and/or Platform: we automatically collect some personal information while browsing and using the Site and/or Platform by the user.

3. 1 What type of Personal Data do we process?

Personal and contact information of the user interested in the Company's services
: personal information requested for the purpose of filling out the form on the Site, such as name and surname, e-mail address, information relating to the reason why the user is contacting us and Personal Data that the user wishes to provide us voluntarily by writing us an e-mail to learn more about our services.

Information on preferences and interests: preferences set for notifications and viewing our Site

Location data: we can approximate the user's location based on their IP address.

Social Profiles: when the user registers on our Site through social media, when interacting with the Site through social networks, we can receive information from the social platform on his personal account and any other information that allows the social media to share with third parties. For more information on the processing of data through this social network, please refer to the appropriate privacy policy on the reference website.

Data processed by the API: MyBiros processes data sent through requests to SaaS Services through the APIs offered by the Platform.

3.2 Information collected automatically

When the user uses our Site or Platform, interacts with us through a computer or any mobile device, we may automatically collect information on how to access and use the Site and Platform, as well as information on the device used to access the Site. We use this information to improve and personalize the user experience, to monitor and improve our Website, and for other internal purposes. The user can accept and reject these technologies by changing the privacy preference settings in the profile settings of their browsing browser.

The information that we automatically collect may be combined with other personal information that we collect directly from users. 

The information that we can automatically collect is:

- information related to the use of the Site And of the Platform (for example which website the user comes from, how many times he has clicked on an object);
- Personal Data relating to interactions with our marketing communications (for example, whether or not a user clicks on an image or a hyperlink);
- information on the devices used to access and interact with the Site and the Platform (for example, this allows us to know if you are using a computer, tablet or smartphone, screen resolution, operating system, Wi-Fi connection, Internet browser and IP address, information on server log files).
- Behavioral data: information derived from the combination of device ID and system events that can be used to identify behavioral trends and behavioral patterns and send marketing communications related to services offered by the Company. Consumption habits;
- analytical information: we may collect Analytical Data, or use third-party analysis tools, to help us measure traffic and usage trends of the Site and to better understand the demographic characteristics and behaviors of our users.


4. Why do we process the user's Personal Data?

Users' Personal Data is processed for:

a) Allow the user to register and create their personal account to use the Platform Demo  

For the purpose of activating the profile, we may request the indication of the e-mail address.
In order to ensure the security of user data, we ask you to enter a strong reference password for accessing the profile.

Legal basis for the processing: contractual relationship and pre-contractual negotiations.

b) Allow the use of the services offered by MyBiros

When operating on behalf of companies, MyBiros acts as responsible for the processing of Personal Data pursuant to art. 28 GDPR, while in relations with individual users interested in the service, the Company acts as the Data Controller uploaded to the Platform.

Legal basis for the processing: contractual relationship and pre-contractual negotiations.

When operating on behalf of companies, MyBiros acts as responsible for the processing of Personal Data pursuant to art. 28 GDPR, while in relations with individual users interested in the service, the Company acts as the Data Controller uploaded to the Platform.

c) Respond to questions and fulfill user requests 

To respond to requests and questions related to our services that the user sends using the Contact Data indicated by the Company.

Legal basis for the processing: manage, in an adequate and timely manner, user requests and guarantee the service offered by us.

d) Ensure the technical functioning of the Site and/or Platform

We collect and use the user's Personal Data to technically administer the Site and/or Platform and ensure that they work properly. We may use the personal information provided by the user to respond to reports or complaints regarding the proper functioning of the Site.

Legal basis for the processing: our legitimate interests in ensuring the proper functioning of the Site and/or Platform from a technical/IT point of view.

e) Marketing communications

To send or have our IT service providers send our direct marketing communications via e-mail to the user.

Legal basis for the processing: the user's prior explicit consent.

We remind you that the user always has the option of refusing to receive marketing communications, simply by unsubscribing from the newsletters or communicating it to us via e-mail.

f) Notify the user about changes to the terms and conditions of use of the Site and our Platform and provide this Privacy Policy

To send information about changes to the terms and conditions of use of the Site and Platform and to provide this Privacy Policy.

Legal basis for the processing: our legitimate interest in informing the user well in advance of the entry into force of these changes.

g) Compliance with legal obligations

To comply with our legal obligations, under orders from government authorities that may also include measures from government authorities outside your country of residence, when we reasonably believe that we are obliged to such communications and when the disclosure of your Personal Data is strictly necessary to comply with the above-mentioned legal obligations or government orders.

Legal basis for the processing: compliance with our legal obligations.

h) Data Analysis to improve the Site and Platform

As part of its services, MyBiros may be interested in using the Personal Data provided by the user for additional purposes that concern the improvement and development of the Platform. Where the Company acts as a controller, this activity must be regulated in the agreement on the processing of personal data signed pursuant to art. 28 GDPR with the owner contracting the service. In case of authorization from the contractor, MyBiros would operate as the Data Controller of the new treatment, pursuant to art. 28, paragraph 10, GDPR.

Legal basis for the processing: legitimate interest of the Company to improve and develop the Platform.

i) Preventing fraud and abuseWe will use information about fraudulent or criminal activities related to the use of our services for the purpose of detecting and preventing fraud or abuse.

Legal basis for the processing: our legitimate interests in protecting our organization from fraudulent activity.

j) Legal protection of our interests

To enforce our contractual terms and conditions under the law, protect our business operations, protect our rights, privacy, security or property, and/or that of our affiliates, and allow us to pursue available legal remedies or limit any damages to us.

Legal basis for the processing: our legitimate interests in legally protecting our organization.


5.
Who is the user's Personal Data communicated to?

The Personal Data provided may be communicated to our business partners and suppliers for the maintenance of this Website and/or the Platform (see Table 1).

These companies:
- they may also have a non-European office;
- they will never directly use the Personal Data provided by the Company;
- they will not sell the Personal Data communicated by the Company to third parties.

By joining the Site and/or Platform Services, the user acknowledges that he allows MyBiros, through the analysis of the Data carried out by the service provider, to come into possession of the following information:
- number of times the email relating to the Company's services was opened;
- number of clicks on links contained in the email sent;
- do not open e-mails related to the Company's services;
- unsubscribe;
- possible use of the contents of the e-mail through social media;
- complaints;
- number and value of purchases per user


6. What are the user's rights in relation to the processing of Personal Data, how can they be exercised?

The subjects to whom the Personal Data refer have the right at any time to obtain confirmation of the existence or not of the same Data and to know its content and origin, verify its accuracy or request its integration, updating, correction (articles 15 and 16 of the Regulation), and precisely:
- Right of access. The right to obtain access to personal information about the user together with certain related information;
- Right to Data Portability. The right to receive personal information in a common format and to have it transferred to another data controller;
- Right to rectification. The right to obtain the correction of Personal Data without undue delay if the Personal Data is inaccurate or incomplete;

Pursuant to articles 17, 18 and 21 of the Regulation, you have the right to request the cancellation, limitation of processing, transformation into anonymous form or blocking of Data processed in violation of the law, as well as to object in any case, for legitimate reasons, to their processing, namely:
- Right to cancellation. The right to obtain the cancellation of your Personal Data without undue delay under certain circumstances, such as if the Personal Data is no longer necessary in relation to the purposes for which it was collected or processed;
- Right to restrict processing. The right to obtain, under specific circumstances identified by applicable law, a restriction on the processing of your Data for a certain period of time, for example when you dispute the accuracy of the Personal Data, for the time to verify the accuracy and accuracy of such Data.
- Right to object. The right to object, for reasons relating to your particular situation, to the processing of Personal Data, and to object to the processing of Personal Data for direct marketing purposes, to the extent that this is linked to such direct marketing.

The rights can be exercised by contacting the Company at the following addresses:
- email: privacy@mybiros.com
-
by post, at Via Antonio Schivardi 60, 00144 Rome


7. How long do we keep Personal Data?

The Personal Data relating to the user's profile are protected and stored until the interested party requests cancellation, while the Data contained in the uploaded documents stored by the APIs are categorized as protected, and are kept for a limited period of time. If the relationship is B2B, the data retention period is defined in the processing agreement signed between the owner and the manager pursuant to art. 28 of the GDPR. In the case of a B2C relationship, the data relating to the documents is kept for 12 months. save the storage of Personal Data, for a longer period, within the limits of the limitation period of rights, in relation to needs related to the exercise of the right of defense in the event of disputes.


8. What transfers can we make?

We may disclose certain User Data and Personal Information to our business partners and suppliers. For some of the treatments mentioned above, we may use business partners and suppliers that are located outside the territory of the European Union. In these circumstances, we now ensure that the transfer of non-EU Data will take place in accordance with the applicable legal provisions by stipulating, if necessary, agreements that guarantee an adequate level of protection and/or by adopting the standard contractual clauses provided by the European Commission.


9. How do we protect your Personal Data?

Information security is very important to us, and we have put in place safeguards to preserve the integrity and security of the information we collect and that we share with our Site and Platform providers. However, no security system is impenetrable and we cannot guarantee the security of our systems at 100%. In the event that any information under our control is compromised due to a security breach, we will take reasonable steps to investigate the situation and, if appropriate, notify individuals whose information may have been compromised and take other measures, in accordance with applicable laws and regulations.


10. Cancellation of marketing services

To stop receiving commercial and promotional information from the Company, the user can send an e-mail to Us at the addresses indicated in this document.

11. Applicable law

This Privacy Policy is governed by and will be interpreted in accordance with provisions and with any other mandatory legislation applicable in the European Union.

12. Complaint to the Guarantor Authority

The interested party has the option of lodging a complaint with the Guarantor Authority for the Protection of Personal Data, which can be contacted on the Website https://www.garanteprivacy.it/.

Table. 1 - Suppliers

MyBiros providers mean:

Vendor
Purpose
Locality
Context
Hubspot
Customer support service
ME
Web site
Google
Analytics
USA
Web site
Microsoft
Analytics
USA
Web site
Amazon
Cloud Infrastructure
ME
SaaS Services