/Legal

Privacy & Policy

In accordance with and for the purposes of Article 6 of EU Regulation no. 679/16, Articles 13-14, EU Regulation 2016/679 (hereinafter referred to as GDPR). While using our services, you provide us with your information. This process is sensitive, and that's why we are committed to protecting the management of data. Our blockchain notarization platform aims to authenticate, store, sign, and share documents securely and efficiently. Our application ensures the existence of your document, certifying the document through a timestamp placed on the blockchain. In the blockchain transaction, "ownership" of the document is attributed through a public and private key generated for you at the time of registration, which guarantees the process. The registered document thus becomes immutable. Any further modification of the document results in a change in the hash, thus generating a new document (ensuring immutability). Our application relies on identification through two-factor authentication and on SPID to guarantee the security of the process.

EU Regulation for the protection of personal data no. 679/16 aims to ensure that the processing of your personal data takes place in compliance with the rights to fundamental freedoms and dignity of individuals, with particular reference to privacy and personal identity. Therefore, it is our duty to inform you about our policy regarding the management of data privacy.

BLOCKCHAIN ITALIA SRL Via Brembo, 27 – 20139 Milan (MI) VAT No. 10441490967 blockchainitaliasrl@legalmail.it - as Data Controller, in the person of its legal representative, informs you, pursuant to and for the purposes of Articles 13-14 GDPR, that your data will be processed in the following manner and for the following purposes:

BLOCKCHAIN ITALIA Srl undertakes to respect and protect the personal data voluntarily and explicitly provided by you in compliance with legal provisions aimed at ensuring the security, accuracy, updating, and relevance of the data concerning the contractual purposes defined. Personal data provided by customers are used solely for the purpose of executing the signed service contract and are disclosed to third parties only if strictly necessary and functional to that purpose. The data are processed by appointed personnel (and designated sub-processors contractually appointed) for data processing, only when processing is necessary for the performance of the requested service.

1. Subject of the processing

The Controller processes your personal data in terms of application (registry data, payments, certifications). The contents of your documents to be processed have a high degree of inviolability. The application provided by the Controller processes personal data related to the identity/information of the company/professional Concerned (name, surname, Tax Code, VAT number, SDI code), their contact details (email address, phone number, city, and address of residence or legal headquarters), authentication credentials in the application, and payment data. The data communicated by you, mandatory for the performance of the service subscribed between the parties, are necessary for the use of the application. The platform is not designed to monitor, classify, and/or store "special data" (Art. 9 GDPR), including race or ethnicity, religious or philosophical beliefs, life and sexual orientation, political opinions, trade union membership, health information.

2. Purpose of the processing

Your personal data are processed: A) without your express consent (ex art. 6, c.1 GDPR) for the following service purposes: - collecting data for the formulation of service offers; - fulfilling pre-contractual, contractual, and tax obligations resulting from existing relationships with you; - fulfilling obligations required by law, regulations, EU legislation, or orders from authorities; - exercising the rights of the Controller, such as the right to defend itself in court; B) only with your specific and distinct consent (ex art. 7 GDPR), for the following marketing purposes: - sending you via email, mail and/or SMS and/or telephone contacts, newsletters, commercial communications and/or advertising material on products or services offered by the Controller and assessing the satisfaction level regarding the quality of the services; We inform you that if you are already our customer, we may send you commercial communications related to services and products similar to those you have already used, unless you dissent.

3. Legal basis of the processing

The legal basis for processing lies in the execution of contractual measures specifically requested by the company/professional Concerned who intends to use the application provided by the Controller (Art. 6 EU Reg. 2016/679 lett. B). With regard to the fulfillment of legal obligations (such as those of a fiscal nature), the legal basis for processing concerns precisely the fulfillment of these obligations (Art. 6 EU Reg. 2016/679 lett. C). For statistical analysis and internal management control of the Controller, processing will take place on the legal basis of the legitimate interest of the Controller (Art. 6 EU Reg. 2016/679 lett. F).

4. Processing methods

Pursuant to Art. 5 GDPR, the processing of your data will be based on the principles of fairness, lawfulness, and transparency and may also be carried out through automated means aimed at storing, managing, and transmitting them (by means of the operations referred to in Art. 4 no. 2) GDPR and will be carried out using tools suitable to ensure security and confidentiality through the use of appropriate procedures to prevent the risk of loss, unauthorized access, unlawful use, and dissemination. Your personal data are subject to digital processing. The Controller will process personal data for the time necessary to fulfill the aforementioned purposes and in any case for no more than 10 years from the cessation of the relationship for service purposes and obligations imposed by law.

5. Data communication

Other workers and collaborators of the Controller may become aware of the data as data processors, and they may also be viewed by the external subject supervising our IT system and whom our structure has appointed as an external controller; your data may also be communicated to subcontractors, of primary national and international level, who provide – outsourced - support activities to the Data Controller, within the limits established by law. We inform you that all our suppliers are appointed as subcontractors and are subject to a validation and control process in terms of privacy and quality of the requested services. Without the need for express consent pursuant to Art. 6, c.1 GDPR, the Controller may communicate your data for the purposes referred to in Art. 2.A) to Oversight Bodies, Judicial Authorities, as well as to those subjects to whom communication is mandatory by law for the fulfillment of said purposes. Your data will not be disclosed in any other way.

6. Storage times

Your personal data will be kept for the time necessary to fulfill the existing relationships between the parties and in any case not for more than 10 years from the cessation of the ongoing contractual relationship for service provision as required by law. After this period of storage, the data will be destroyed and/or deleted, subject to future communications from the Controller or decisions by authorities under the law. Storage of data and rights of the data subject It is possible to delete or update all data about a user (with verification) from our database and from the files stored in the centralized cloud. However, transactions and data recorded on the blockchain and related to the lifecycle of the notarization process (registration on the blockchain) of a document will remain permanently on the blockchain.

7. Data transfer

The data collected by Blockchain Italia, namely: - identity and account information - information on the purchased service, payment, and price - files and documents are not transferred outside the EU/EEA. For the purpose of document storage and building our infrastructure, we use Amazon Web Service (AWS), and we ensure that our data centers are located within European regions (availability zones in Europe: Frankfurt; Dublin; Milan; Paris; Aragon; Stockholm). However, Wallet information, transaction information, document hashes are stored on PPB (Public Permissionless Blockchains), so they are always available worldwide. The data subject can exercise their rights against each subcontractor.

This applies to the TokNox platform. Visitors of the website may in addition be subject to transfers to Google, which can process data outside the EU/EEA, including the United States, when you use Google reCAPTCHA (section 15), watch the embedded YouTube video (section 20) or accept Google Analytics (section 19). In these cases the transfer relies on the EU-US Data Privacy Framework or on Standard Contractual Clauses adopted by Google, and happens only for the features you use or the consent you give.

8. Nature of providing data and consequences of refusing to respond

Providing data for the purposes referred to in point 2.A) is mandatory. In their absence, we will not be able to guarantee the requested Services. Providing data for the purposes referred to in point 2.B) is optional. You can therefore decide not to provide any data or to subsequently deny the possibility of processing data already provided: in this case, you will not receive newsletters, commercial communications, and advertising material related to the services offered by the Controller. You will still be entitled to the Services referred to in point 2.A).

9. Rights of the data subject

You have the right to ask the Controller for access to your data, their correction or deletion, the integration of incomplete data, the limitation of processing (file processed within the scope of registration or notarization on the blockchain); to receive the data in a structured, commonly used, and machine-readable format; to revoke consent given for the processing of your data at any time and to object in whole or in part, to the use of the data; to lodge a complaint with the Authority, as well as to exercise other rights recognized to you under Articles 15-22 of EU Regulation no.679/16. Please note that, upon request of the user, it will be possible to delete the data concerning them and the documents processed from our encrypted cloud archive and from our systems; however, all transactions related to the lifecycle of such process will remain permanently on the blockchain due to the nature of the technology itself (e.g., notarization transaction, user wallet address, signature, document hash).

10. Exercise of rights

You can exercise your rights at any time by sending an email to the email addresses segreteria@blockchainitalia.io for data management and dpo@blockchainitalia.io for complaints. The data subject has the right to lodge a complaint with a supervisory authority. If you are no longer interested in BLOCKCHAIN communications and wish to unsubscribe from the newsletter, you can do so by clicking on the "unsubscribe" link at the bottom of each email sent or by sending an email to: marketing@blockchainitalia.io.

11. Data Controller, processors

BLOCKCHAIN ITALIA SRL Via Brembo, 27 – 20139 Milan (MI) VAT No. 10441490967 blockchainitaliasrl@legalmail.it. The Data Controller uses internal data processors and external sub-processors appointed to achieve the purposes specified in point 2 (technical purposes related to service provision and commercial purposes). Among these, in particular, we highlight: Amazon S3; Algorand Blockchain The updated list of controllers, sub-processors, data processors, and data recipients is kept at the registered office of the Data Controller.

12. Commercial communications

The company's commercial approach is expressly non-invasive and has an informative and promotional nature. Our primary desire is to protect the customer to the maximum from any unwanted communications. From the moment you provide your personal data, they will be used to send you commercial communications and notifications regarding new services offered that we believe may be of interest to you. To deactivate the receipt of promotional emails, please follow the instructions in the emails themselves (unsubscribe) or send a communication to the address marketing@blockchainitalia.io.

13. Website visitors: hosting and server logs

The toknox.com website is hosted on Amazon Web Services (AWS). When you visit it, our hosting infrastructure automatically processes technical data such as your IP address, browser type, requested page and date and time of the request. These data are used only to deliver the site, keep it secure and detect abuse (legitimate interest, Art. 6(1)(f) GDPR) and are kept in server logs for a limited period.

14. Contact form

If you write to us through the contact form we collect the name, email address and message you enter, together with your acceptance of this Privacy Policy. We use them only to reply to your request (Art. 6(1)(b) and (f) GDPR) and, where you have agreed, to follow up on it. Messages are delivered by email through Amazon Simple Email Service (Amazon SES), which also sends you an automatic confirmation of receipt, and are kept only for as long as needed to handle your request, or longer if required by law. Providing these data is voluntary, but without them we cannot answer you.

15. Anti-spam protection (Google reCAPTCHA)

The contact form and the file verification tool are protected by Google reCAPTCHA v3, provided by Google. It analyses signals such as your IP address, browser and interaction with the page to tell people from bots, and sends them to Google. We use it on the basis of our legitimate interest in protecting the site from spam and abuse (Art. 6(1)(f) GDPR). Google's Privacy Policy and Terms of Service apply: https://policies.google.com/privacy and https://policies.google.com/terms.

16. File verification tool

The "Verify" section lets you check whether a file has been tokenized on TokNox. The file you select is sent to our servers and then to the TokNox platform only to compute its SHA-256 fingerprint and look it up among the blockchain records; the website does not keep a copy of the file or link it to you. If a match exists, the page shows the name, description, fingerprint and asset ID that were made available when the file was tokenized. Do not upload files you are not entitled to share.

17. Language preference

The site is available in English and Italian. On your first visit we choose the language from your browser settings (the Accept-Language header), without storing it. When you pick a language with the language switcher, or open a page in a language different from the one your browser prefers, we save that choice in a technical cookie named "toknox_locale", which lasts up to 12 months, so that the site opens in your language next time. This cookie is strictly necessary to provide the feature you requested and does not require consent. You can delete it from your browser settings at any time.

18. Cookie banner and your consent choice

When you first visit the site, a banner asks whether you accept or reject analytics cookies. Your answer is saved only in your browser (local storage key "toknox_cookie_consent") and is not sent to our servers. You can change or withdraw it at any time using the "Cookie settings" link in the footer. Withdrawing consent does not affect the lawfulness of processing carried out before.

19. Google Analytics

With your consent only, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited (and Google LLC), to understand how the site is used and to improve it. Until you accept, Google Analytics is not loaded and no analytics cookie is set. After you accept, Google Analytics sets the cookies "_ga" and "_ga_<container-id>" (up to 2 years) and collects information such as the pages you view, how long you stay, the referring page, device, browser, language and approximate location. According to Google, IP addresses are not logged or stored in Google Analytics 4.

Google analyses these data on our behalf to produce aggregated reports about the use of the site, which we use to measure and improve it. We do not use them to identify you. Since the data sharing settings of our Google Analytics account are enabled, Google may also use the data collected for its own purposes, such as maintaining and improving its services, as described in its terms and Privacy Policy. Data may be transferred to Google servers outside the EU/EEA, including the United States, on the basis of the EU-US Data Privacy Framework or Standard Contractual Clauses.

The legal basis is your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code). If you reject, or withdraw consent from "Cookie settings", the cookies are removed and no further data are sent. More information: https://policies.google.com/technologies/partner-sites. You can also install the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout.

20. Embedded YouTube video

The home page includes a product demo video hosted on YouTube (Google). The video is not loaded when you open the page: only after you press play does your browser connect to YouTube, using the privacy-enhanced domain youtube-nocookie.com. From that moment Google may process technical data such as your IP address and set its own cookies, according to its Privacy Policy: https://policies.google.com/privacy. If you do not press play, no data is sent to YouTube.

21. Changes

This information may be subject to changes. If substantial changes are made to the use of customer data by BLOCKCHAIN, this will notify the user by publishing them prominently on its pages.