Privacy Policy of Kampaay

Who we are

Dear User, pursuant to art. 13 of Regulation (EU) 2016/679 (hereinafter, “GDPR”), Kampaay S.r.l. Benefit company, as the data controller (hereinafter, “Kampaay” or the “Data Controller”), hereby wishes to inform you about the use of your personal data. This privacy policy refers to all those who access and interact with the website www.kampaay.com (hereinafter, the “Website” or the “Site”).

a) Definitions and legal references

Personal data is any information that, directly or indirectly, even in conjunction with any other information, including a personal identification number, makes a natural person identified or identifiable.Personal Data What we collect depends on how you interact with us. The following categories may be provided directly by you or by third parties:
  • Identification data: any data that identifies you, such as your name, surname, your tax code, VAT number, SDI code, the details of your identity card or passport and the data of your accounts (for example, the nickname).
  • Contact details: any information that allows us to contact you through any means, such as physical and e-mail addresses, mobile phone number, push notifications, social media accounts. This category also includes IDs shared by social media (for example, Meta or LinkedIn) that allow us to show you our ads. Social media act as Joint Controllers with us when we use their commercial targeting services.
  • Compiled data: any information entered by you in our Forms, including those provided for the registration of the Account and the provision of the Services.
  • Pics: images or videos that concern you when you become a User or participate in our Events as a Participant.
  • Access data: your presence at a specific Event (also through Images) or by filling out the Attendance Forms.
  • Device data: your IP Address, the date, time and the requested URL, the Unique Identifiers and other information such as the type of Browser or Device, the website from which you arrived (site of origin), the information consulted and any other action taken on our Pages. This information is collected using Cookies and Other Tracking Technologies on your Browser or Device. You can find the full list of Cookies at the bottom of the page and in the privacy settings of our Pages.
  • Payment details: some payment data (for example, IBAN) provided to pay for the Services. Please note that credit/debit card details are processed only by payment gateways (e.g. Stripe/PayPal) or credit institutions acting as independent Controllers. We only see the completion of the payment transaction when the payment is made by credit/debit card.
  • Sensitive data: mostly data relating to your health (for example, your intolerances, allergies or food preferences with respect to an Event, etc.). This information is provided directly by you through the Forms to participate in an Event or by our Customer in aggregated or clear form through the use of the Services.
  • Inferred data: information based on your online and offline interactions with our Forms, Services or Events (for example, if you are interested in specific Events, locations, training or team building topics). When you contact us by e-mail, telephone about our Services or request other information, we will collect and keep a record of your contact details, your communications and our responses) that allow us to create data derived from the Combination and/or the Cross. We do not infer information based on your Sensitive Data.
  • Third-party data: any Identification Data, Contact Data, Compiled Data relating to a person other than you such as referrals, spouses, guests, partners, children, etc., that we may process for the provision of our Services. If you provide us with third-party data (for example, guests, referrals, or payment data), you are responsible for having shared that information with us. You must be legally authorized to share them (i.e. authorized by third parties to share their information or for any other legitimate reason). You must fully compensate us against any claim, claim or claim for damages that may result from the processing of third party Personal Data in violation of data protection law.
  • Joint data: any contact information shared by Business Partners (for example, social media, co-branding companies, etc.) to whom we ask to send or show our ads to their users based on certain criteria/interests. These so-called micro-targeting and/or retargeting activities generally do not involve the direct collection of Personal Data on our part. Usually, however, they allow us to obtain Aggregate Data on the effectiveness of these advertisements or lead to the registration of new Users through our Forms. In accordance with European legislation, in carrying out these activities, both we and our Business Partners make every reasonable effort to verify the legitimacy of the data (including joint ownership agreements) before using them. You can request more information about our list of active Business Partners and the obligations of the respective parties, by writing to dpo@kampaay.com.
  • Public data: these are public or publicly accessible data that we use to confirm or enrich information on Users, Customers and Suppliers. This information is collected and used in accordance with Code for commercial information published by the Privacy Guarantor.
The way in which you relate to us determines the types of data we collect and the purposes for which we process it, as indicated in the tables below. You are not required to provide us with any data, but if you do not do so when requested or if you provide incorrect/truthful data, this will have an impact on some or all of our purposes and services.

b) Data Controller

The Data Controller of the personal data collected through the Site is Kampaay S.r.l., with registered office atViale Cassala, no. 30, 20143 Milan (MI), VAT no. 11046500960, e-mail address: amministrazione@kampaay.com
Purposes
Data
Legal basis
Fully automated vehicles
Retention periods
Recipients
Respond to your requests through Form, via e-mail, live-chat or call)
Identification Data, Contact Data, Compiled Data
Your request
No
Completion of your request
Personal,
Managers, Authority.
Send marketing/survey communications via e-mail or telephone with operator).
Identification Data, Contact Data, Joint Data, Aggregate Data
Consent
No
2 years or until the marketing consent is withdrawn.
Personal,
Managers, Partner, Commercials.
Personalize our commercial communications, including Content that may be useful to you.
Identification data, Compiled data, Aggregate Data, Inferred Data, Device Data, Login Data.
Consent
No
1 year or until consent is revoked
Personal,
Managers, Partner, Commercials.
Retargeting on social media (for example LinkedIn) and on other platforms of Programmatic Advertising
Contact Data, Device Data, Inferred Data, Joint Data
Consent
Yes
1 year or until consent is revoked
Personal,
Managers, Partner, Commercials.
Analyze and improve our Pages and create new Services and features
Compiled data, Aggregate Data, Inferred Data, Device Data
Our legitimate interest in creating and maintaining Pages and Services that are really useful for you
No
A year for Personal Data | 2 years for Aggregate Data
Personal,
Managers.
If you visited our Pages for an open position or spontaneous application, please refer toApplicant Information here: https://careers.kampaay.com

c) DPO Contact details

Pursuant to article 37 of the GDPR, Kampaay has appointed a Data Protection Officer (also known as “Data Protection Officer” or “DPO”), who can be contacted for specific privacy-related queries at the dedicated e-mail address: dpo@kampaay.com
Purposes
Data
Legal basis
Fully automated vehicles
Retention periods
Recipients
Pre-contractual and negotiation checks with our Personal and that of the Customer (e.g. Users)
Identifying Data, Contact Data, Inferred Data, Compiled Data, Public Data
Your request
No
For the duration of the negotiations and Terms and conditions
Personal and
Managers
Invoicing and tax reporting
Identification Data, Payment Data
No
10 years since the issue
Personal,
Managers and Authority.
Improve our Services and Events and create new ones
Compiled data, Inferred data, Aggregate Data
Our legitimate interest
No
1 year
Personal and
Managers
Retargeting on social media (for example LinkedIn) and on other platforms of Programmatic Advertising
Contact Data, Device Data, Inferred Data, Joint Data
Consent
No
2 years or up to unsubscribe.
Personal and
Managers
Communicate the data of the Customer in the case of our possible corporate transactions (rounds, M&As, etc.)
Identifying data, Payment data.
Our legitimate interest in growing and expanding
No
For the duration of the operation
Investors and buyers subject to NDA.
In the capacity of accountable Pursuant to Terms and conditions and related attachments:
Purposes
Data
Legal basis
Fully automated vehicles
Retention periods
Recipients
Provide our main Services (the Platform, the organization of Events), those on request (Secretarial Service), personalized services and related support.
Identifying Data, Contact Data, Inferred Data, Compiled Data, Public Data, Device Data, Payment Data, Sensitive Data, Access Data
No
Until the cessation of services
Personal and (sub)Managers indicated in the DPA.
Communicate the necessary data of the Customer And of Participants to Suppliers (Holders autonomous) for the management of Events.
Identification Data, Contact Data, Compiled Data, Access Data, Sensitive Data (if shared by Customer Or from Participant)
No
Identification Data, Contact Data, Compiled Data, Access Data, Sensitive Data (if shared by the Customer or Participant)
Personal and (sub)Managers indicated in the DPA.

Users

From the moment you created a Account On Platform on behalf of or in the interest of Customer, are you considered a User and we process your data for the following purposes.
Purposes
Data
Legal basis
Fully automated vehicles
Retention periods
Recipients
Pre-contractual and negotiation checks with our Personal and that of the Customer (e.g. Users)
Identifying Data, Contact Data, Inferred Data, Compiled Data, Public Data of Customer
Your request
No
For the duration of the negotiations and Terms and conditions
Personal and
Managers
Registration and management ofAccount
Identification Data, Contact Data
No
Until the cessation of services
Personal and
Managers
Improving our services Ed Events and create new ones
Compiled data, Inferred data, Aggregate Data
Our legitimate interest
No
1 year
Personal and
Managers
Post your feedback related to services Ed Events on our Pages to sponsor us.
Identifying data (or Aggregate Data)
Consent (for Identifying Data)
No
10 years
Personal and
Managers
Send commercial communications via e-mail to services Ed Events similar to those already purchased by the Customer (so-called soft-spam)
Contact data, Compiled data, Inferred data
Our legitimate interest
No
2 years or up to unsubscribe.
Personal and
Managers

Participants

If you have been invited to participate in a Event, we process your data as accountable on behalf of Customer typically for the purposes below. The types of data collected and the purposes depend on the type of Event and from the instructions we receive from Customer.
Purposes
Data
Legal basis
Fully automated vehicles
Retention periods
Recipients
Collect your participation inEvent via Form created by Customer.
Typically: Identifying Data, Contact Data, Compiled Data, Public Data,
Instructions of the Customer
No
For the duration of the negotiations and Terms and conditions
Personal and (sub)Managers indicated in the DPA.
Collect any dietary needs or special situations with respect to the Event through Form created by Customer.
Sensitive Data or Aggregate Data
Instructions of the Customer
No
Until the cessation of services
Personal and (sub)Managers indicated in the DPA.
Manage theEvent, coordinate the Suppliers (hotel, transport, catering), inform about your participation and manage unforeseen events. Collect Images duringEvent at the request of Customer.
Typically: Identifying Data, Compiled Data, Access Data.

Pics
Instructions of the Customer
No
1 year
Personal and (sub)Managers indicated in the DPA.

Suppliers

If you have been chosen as Vendor Of a Event ofthe Customer (e.g. location, catering, transport, etc.), we process your data as titular as specified below.
Purposes
Data
Legal basis
Fully automated vehicles
Retention periods
Recipients
Pre-contractual and negotiation checks with our Personal And that of the Vendor for accreditation in our register.
Identifying Data, Contact Data, Inferred Data, Compiled Data, Public Data
Our legitimate interest in establishing a relationship with the Vendor.
No
10 years unless opposed.
Personal and Managers.
Present your information, services/products, promotions to Customers For their Events
Identifying Data, Contact Data, Public Data
Our legitimate interest in creating services useful to Customer and commercial opportunities for the Supplier
No
10 years unless opposed.
Personal and Managers.
Invoicing and tax reporting on behalf of Customer on your request (Secretarial service)
Identification Data, Payment Data
No
10 years unless opposed.
Personal and Managers.
Improving our services Ed Events and create new ones
Compiled data, Inferred data, Aggregate Data
Our legitimate interest
No
1 year
Personal and Managers.
Regardless of whether you are a Visitor, Customer, User, Participant or Supplier, we process the data you provide as required by law and regulations in force. In addition, we process your data to prevent behavior or activities contrary to ours Terms and conditions, as well as fraudulent and illegal ones that could compromise you, our security, services. These processing operations are based on legal obligations incumbent on us and on our legitimate interest. With the exception of the storage periods/criteria described in the above grids or the mandatory periods defined by law, we can process your data for these purposes for a period not exceeding 10 years (art. 2946 of the Italian Civil Code).

Where is your data

Your data may be stored, consulted, used, processed and disclosed outside your jurisdiction, including within the European Union, the United States of America or any other country where our Managers and our sub-Managers, or where their servers or cloud computing infrastructures can be hosted. We strive to ensure that the processing of your data by our Recipients (as defined in the tables above) complies with applicable data protection laws, including the Italian laws to which we are subject. Where required by Italian and/or European Union data protection law, transfers of your data to Recipients outside the European Union will be subject to adequate guarantees (such as the standard contractual clauses of the European Union for data transfers between the European Union and countries not belonging to the European Union), and/or to other legal bases according to European Union legislation. For more information on the appropriate guarantees that we have implemented in relation to data transferred to third countries, you can write to: dpo@kampaay.com 

How you can control your data and your choices

Depending on how you contacted us, you can ask at any time to:
  • Access your Personal Data: we will provide the data we hold about you, such as identification data, contact details, expressed preferences, etc., together with the version of the Policy that you received when you provided it and the source of the data (if, for example, it was provided to us by a third party);
  • Exercise the right to the portability of your Personal Data: we will provide you with an interoperable file containing your data (e.g. csv, json, xml file);
  • Correct your Personal Data: for example, you can ask us to change your e-mail address or your telephone number if they are not correct;
  • Limit the processing of your Personal Data: for example, when you believe that the processing of your data is illegal or that processing based on our legitimate interest is not appropriate;
  • Delete your Personal Data: for example, when you don't want to use our Services or you don't want us to keep your data anymore;
  • Update your preferences for processing based on your consent or legitimate interest: you can ask us not to send you promotional communications for similar Services, including Content that may be useful to you. More precisely:
    • Revoke your consent for the purposes for which we collected it;
    • Stop sending promotional communications by clicking on the link at the bottom of each email in any text or other message you receive;
    • Set your preferences regarding the data collected by the Browser and the Device through our cookie banner at the bottom of each page of our site.
    • Block the sharing of some of your data within Programmatic Advertising platforms that allow us to send you Content that may be useful to you, using the tool AdChoices; those provided by Digital Advertising Alliance Or Dalla European Interactive Digital Advertising Alliance in Europe.
    • Block the processing of Other tracking technologies (for example, pixels) in our email communications through your email application. For example, on Outlook, blocking such tracking is turned off by default, unless you press 'Download Pictures'.
    • Contact the competent Supervisory Authority, whose contact details are available hither.

In accordance with applicable data protection laws, we will respond to your request within one month of receipt (extendable by another two months in case of particular complexity). Please note that some of your rights may not be available or may be restricted if applicable law allows it.

You can exercise any of the rights listed above:

  • using the easy to use web form hither;
  • by writing to our Data Protection Officer (dpo@kampaay.com).
  • By writing to the third parties that have shared your data with us (for example, Business Partners, social media) through their email address or your account settings on their platforms.

What's not covered by this policy

This Information explains and covers the processing operations that we carry out as titular. Some illustrated icons are below Free license or CC BY 4.0 of the University of Maastricht.

The Information does not cover treatments carried out by subjects other than Kampaay and in particular it does not cover treatments carried out by our Business Partners, Customers and Suppliers In the capacity of Holders autonomous, including those carried out by social media platforms within our Pages. In this regard, we do not assume any responsibility for the processing of your data not covered by this Policy.

Changes to the Information

This Policy is effective as of the date indicated at the beginning of the document. We reserve the right to modify or update this Policy, in whole or in part, at our discretion or as a result of changes in applicable regulations. We will notify you of material changes using your contact details.

Definitions

Other tracking technologies: pixel tags (trackers used with cookies and embedded in images on web pages to track certain activities, such as displaying Content that may be useful to you, or to see if an e-mail has been read) or Unique Identifiers incorporated into links to promotional communications that send us information when they are clicked.

Authority: refers to a government, whether supranational, federal, state or governmental, prefectural or local, a statutory, administrative or regulatory body, a court, an agency, including law enforcement agencies, or any other authority anywhere in the world (even outside your jurisdiction) whose regulations, directives, notices, resolutions, orders, decrees, injunctions, warrants, subpoenas or judgments are binding on us and require us to disclose your Personal Data. We will not share your data without your consent, unless we have a legal obligation to comply with those regulations.

Browser: refers to programs used to access the Internet (for example, Safari, Chrome, Firefox, etc.).

Combination and/or intersection: this is the set of fully automated and non-automated operations that we have used to create derived data about you. We may also combine and/or cross-reference information from different sources.

Content that may be useful for you: for example, if you search for a certain Event, we can display similar Events on our Pages or through Programmatic Advertising. The personalization of the content can take place through the combination and/or the crossing of data.

Cookie: A cookie is a small text file that is downloaded to your Device (for example, smartphone, computer) when you access our Pages. It allows websites to recognize your Device and to store information about your preferences or past actions (for example, the fact that you visited our Pages, your language and other information). The information collected through cookies may relate to you, your preferences or your Device and is primarily used to make our Pages work as you expect. The information collected through cookies does not usually identify you directly, but it can offer you a more personalized experience on our Pages that you are visiting, as it could be used to record your preferences on the use of cookies (technical cookies), analyze and improve our Services and create new services and features or customize our Services, including Content that may be useful to you.

Aggregate Data: they refer to statistical information about you that does not contain your Personal Data. We use this information to analyze and improve our Services and create new services and functionality and to create statistical reports for Business Partners.

Personal Data: means any information relating to an identified or identifiable natural person, directly or indirectly, as well as any information linked to or reasonably linked to a particular individual or family unit. For example, an email address (if it relates to one or more aspects of a person), IP addresses, and unique Identifiers are considered Personal Data.

Sensitive Data: in general, we mean Personal Data that reveals racial or ethnic origin, political opinions, religious or philosophical convictions, trade union membership and the processing of genetic data, biometric data aimed at uniquely identifying a natural person, data relating to health or data relating to the sexual life or sexual orientation of a natural person. For the purposes of this Policy, we typically mean data on food preferences at Events.

Device: refers to the electronic device (for example, iPhone) that you use to visit our Pages or Apps.

Events: refer to any physical or digital event organized or managed by us as Customer Manager.

Managers: refers to subjects that we commission to process your Personal Data exclusively on behalf and based on written instructions provided by us or to external parties (contractors) to whom we delegate certain processing activities. For example, providers of security systems, accounting, administrative, legal, tax, financial and debt collection consultants, providers of data hosting platforms, etc. Kampaay is also Responsible on behalf of the Customer (Owner) for certain purposes. You can request the disclosure of service providers that process your Personal Data using an easy-to-use web form. hither.

Unique Identifiers: consist of information that can uniquely identify you through your Browser and your Device. On the Browser, the IP address and Cookies are considered unique identifiers, which we use to analyze and improve our Services and to create new services and features, including Content that may be useful to you, are considered unique Identifiers. Please note that for these purposes and in line with the opinions of the European and Italian Authorities, we do not use other Unique Identifiers such as MAC addresses and IMEI, as they are not resettable by you.

IP address: it is a unique number used by your Browser or Device to connect to the Internet. The internet service provider provides this number that allows you to identify the provider and/or the approximate area where you are located. Without this data, you cannot connect to the internet and use our Services or Content that may be useful to you.

Form: any form through which we can directly collect your data (for example, Account registration, memberships and data for Events, etc.)

Pages: includes our website (https://www.kampaay.com) and our social media pages.

Business Partners: these are third-party entities that communicate your Personal Data to us only after having contractually assured us that they have obtained your consent or that they have another legal basis that justifies their communication/sharing of such data with us. This definition includes Users or Customers who suggest referrals but also selected partners with whom we may share aggregated data for business intelligence or partnership purposes.

Personal: our employees and collaborators who have assumed an obligation of confidentiality and comply with specific rules relating to the processing of your Personal Data. This category also includes our system administrators or our service providers who assist us in the management of our computer systems and who therefore can access, modify, suspend and limit the processing of your Personal Data. These people have been previously selected, properly trained and their activities are monitored by systems that they cannot modify.

Programmatic Advertising: these are platforms that share the information collected about you, such as your IP address and data collected by Cookies, and Other Tracking Technologies, with entities that are interested in showing you Content that may be useful to you. In our case, if you view a particular product on our Pages, we will ask the participants in Programmatic Advertising to grant us advertising space on one of the websites you visit, in order to show Content that may be useful to you. In this regard, we would like to reiterate that the communication of your Personal Data to the participants in Programmatic Advertising is based on your prior and specific consent provided on the banner at the time of the first visit to our Pages. If I want to know how you can object to these communications, follow the instructions in the “How you can control your data and manage your choices” section above.

services: collectively, we mean all services/products available and accessible through the Platform. Therefore, those indicated in the Terms and Conditions and their respective annexes are included.

Owner or joint owner (s): refers to the legal person, public authority, service or other entity that, individually or jointly, determines the purposes and means for the processing of your Personal Data. In other cases, you may be preceded by the word 'autonomous' (for example, 'independent controller') to indicate that your Personal Data is being processed by a person other than us.

User: a Visitor who has registered an Account on the Platform by accepting the Terms and Conditions on behalf of or in the interest of a Customer.

Participant: the natural person employee/collaborator or third party invited by the User or Customer to participate in the latter's event.

Customer: the legal entity that has signed Kampaay's Terms and Conditions for the provision of Services.Platform: Kampaay's software as a service for the organization and management of Customer Events to which the User can access. Terms and conditions: the contractual conditions and respective attachments signed by the Customer for the provision of the Services.