Privacy policy
Last updated: beta version
Beta version: this is a provisional notice. The operator's details and other missing elements will be completed before the commercial launch.
1. Data Controller and contacts
The data controller is being defined: company name, registered office and VAT/Tax Code will be communicated before the commercial launch.
For any request concerning personal data protection, you may contact the controller at the details (email and certified email) communicated before the commercial launch.
The Data Protection Officer (DPO), if appointed, will be indicated before the commercial launch.
2. Types of data collected
We process only the following categories of personal data:
- Account/authentication data: email, password stored in encrypted form through hashing, user role.
- Client company identification data: company name/business name, contact person name.
- Agency/freelancer identification data: agency name or professional name.
- Talent profile data: stage name/display name, biography, date of birth, category, photographs and comp cards.
- Payment/subscription data: Stripe customer/subscription identifiers; we do not process card data.
- Content and communications: briefs, brief responses, bookings with project description, messages exchanged on the platform.
- Technical and usage data: usage events, acquisition source, logs/technical data necessary for operation and security.
3. Purposes and legal bases
We process data for the following purposes, with the corresponding legal bases:
- Account creation and management, authentication and platform access: performance of a contract or pre-contractual steps pursuant to Article 6.1.b GDPR.
- Provision of the SaaS marketplace service, including publication of briefs, management of responses, bookings and in-platform messages: performance of a contract pursuant to Article 6.1.b GDPR.
- Management of company, agency, freelancer and talent profiles: performance of a contract pursuant to Article 6.1.b GDPR.
- Management of payments and subscriptions through Stripe, including subscription status checks and administrative reconciliation: performance of a contract pursuant to Article 6.1.b GDPR.
- Sending transactional emails and service notifications related to platform use, accounts, briefs, bookings and subscriptions: performance of a contract pursuant to Article 6.1.b GDPR.
- Storage and analysis of logs, usage events and technical data to ensure proper functioning, maintenance, security, abuse prevention and error diagnosis: legitimate interests of the controller pursuant to Article 6.1.f GDPR.
- Management of administrative, accounting and tax obligations related to the contractual relationship: compliance with a legal obligation pursuant to Article 6.1.c GDPR.
- Where communications or content are voluntarily provided by the user for purposes beyond the contract, where necessary: consent of the data subject pursuant to Article 6.1.a GDPR.
- Use of cookies and similar technologies that are not strictly necessary, where enabled: consent of the data subject pursuant to Article 6.1.a GDPR, in accordance with applicable law and the Italian Data Protection Authority’s guidance.
Where processing relies on legitimate interests, we carry out a balancing assessment between our interest and the data subject’s rights and freedoms, in line with Article 6.1.f GDPR.
4. How data are collected
Data are collected:
- directly from the user during registration, profile creation, brief publication, submission of responses, initiation of bookings and use of the platform’s features;
- automatically, through the platform’s technical systems, for logs, security and usage events;
- from Stripe, limited to customer and subscription identifiers required to manage payment;
- from Resend, limited to technical events necessary for sending transactional emails.
Providing the data necessary for the service is required to use the platform; otherwise, some features cannot be made available.
5. Recipients and external processors
Data may be disclosed to the following external processors, appointed under Article 28 GDPR, for the purposes indicated:
- Stripe, for payment processing and subscription management.
- Resend, for sending transactional emails.
- Object storage provider (S3-compatible), for storing images and documents.
- Hosting/infrastructure and database/cache providers, for the technical delivery of the platform, data storage, service availability and security.
Data may also be processed by internal personnel authorized by the controller, within the limits of assigned duties and instructions received.
Specific provider and region:
- Hosting/infrastructure: provider and region being defined
- Database/cache: provider and region being defined
- Object storage: provider and region being defined
6. Extra-EEA transfers
If one or more of the above providers process data outside the European Economic Area, transfers are carried out in compliance with Chapter V GDPR, in particular through the adoption of Standard Contractual Clauses (SCCs) pursuant to Article 46 GDPR, and, where necessary, additional appropriate technical and organizational measures.
In particular, any transfers linked to Stripe, Resend, hosting/infrastructure, database/cache or object storage are governed, where applicable, by SCCs and the additional safeguards provided by the relevant providers. If processing takes place exclusively within the EEA for one or more services, no extra-EEA transfer occurs.
7. Retention period
We retain data for as long as necessary for the purposes for which they were collected, according to the following criteria:
- Account/authentication data: for the duration of the account and until its deletion, unless further retention is required by law or for legal defense.
- Client company identification data and agency/freelancer identification data: for the duration of the contractual relationship and, after termination, for the time necessary to manage any legal obligations or disputes.
- Talent profile data: for the duration of the active profile and until profile deletion, unless further retention is required by law or for defense purposes.
- Payment/subscription data: for the time necessary to manage the relationship, invoicing, administrative checks and related legal obligations.
- Content and communications: for the duration of the relationship and for the time strictly necessary to handle any disputes, checks or legal obligations.
- Technical and usage data: for the time necessary to ensure operation, security, technical auditing, error diagnosis and abuse prevention, according to retention periods proportionate to the purpose.
When retention is no longer necessary, data are deleted or irreversibly anonymized, where technically possible.
8. Data subject rights
Where provided by the GDPR, the data subject may exercise the rights set out in Articles 15–22, including:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to data portability;
- right to object;
- right not to be subject to a decision based solely on automated processing, including profiling, where applicable.
The data subject may submit a request to the controller without formalities, using the contact details indicated in this notice, including through the DPO where appointed. A response will be provided without undue delay and in any event within one month of receipt of the request, subject to any lawful extension.
9. Complaint to the Authority
If the data subject considers that the processing of their personal data breaches applicable law, they have the right to lodge a complaint with the Garante per la protezione dei dati personali, the competent Italian supervisory authority, pursuant to Article 77 GDPR.
The right to seek judicial remedy before the competent court also remains unaffected, where provided by law.
10. Data security
We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration or unauthorized disclosure.
In particular, passwords are stored only after hashing, and never in plain text.
Security measures include, where applicable, access control, privilege separation, security logging, infrastructure protection, backups, encrypted communication channels and internal incident management procedures.
11. Minors
The service is not intended for individuals under 16 years of age.
We do not knowingly collect personal data from persons under 16; if this occurs, we will delete the data unless otherwise required by law.
12. Cookies and similar technologies
The platform may use cookies and similar technologies.
For strictly necessary features, consent is not required; for any non-essential cookies or tracking tools, where present, the applicable law and the Italian Data Protection Authority’s guidance apply, and the relevant processing is described in the dedicated Cookie Policy.
13. Changes and updates
This privacy notice may be updated over time, particularly in the event of legal, technical or organizational changes, or if new platform features are introduced.
Each updated version will be published on this page with the update date.

