This notice is provided under Articles 12, 13 and, where applicable, 14 GDPR and describes processing carried out through Italia Quality.
1. Controller and contacts
The controller is UESE ITALIA S.p.A., Piazza Trivulziana 4/A, 20126 Milan, Italy, VAT IT04398760274. Privacy contact: privacy@uese.eu. DPO: Dr Giuseppe Izzo, dpo@uese.it.
2. Categories of data subjects
Website visitors, registered users, Quality Scouts, business representatives and contacts, persons submitting notices or complaints, communication subscribers, institutional and technical contacts.
3. Data processed
Identity/contact data; credentials and authentication data; public Scout profile; declared location; content, scores and images; visit data; information extracted from receipts or storefronts; documentary evidence; business claim data; preferences; consents; technical/security logs, IP and session identifiers; support and moderation communications.
4. Geolocation
Device location is requested only when the user activates a feature requiring it. Coordinates may be used to find nearby places or link a visit. Browser/OS permissions control access; users can deny permission and use manual search. The platform does not require continuous location tracking.
5. Visit evidence
Receipts and other evidence may be processed to verify authenticity, date and place of a visit, prevent abuse and handle disputes. Verification evidence is not published as part of a review. Users should avoid unnecessary third-party data.
6. Purposes and legal bases
Service/account performance: Art. 6(1)(b) GDPR. Legal duties and authority requests: Art. 6(1)(c). Security, fraud prevention, ranking integrity, rights protection, moderation and defence: Art. 6(1)(f), subject to balancing. Promotional communications and non-essential tracking: consent under Art. 6(1)(a), where required.
7. Public data and visibility
Public name, profile photo, bio, territory, badges, contributions and rankings may be visible according to settings and service design. Users should consider that public content may be indexed, shared or quoted by third parties.
8. Data sources
Data come from the data subject, service use, authorised business representatives and, for place information, external geographic sources or directories. Article 14 GDPR applies where relevant to data not collected directly.
9. Providers and recipients
Data may be processed by hosting, email, security, mapping/geocoding/places, AI and technical-support providers appointed as processors where required. Data may also be disclosed to advisers, authorities or entitled parties where required by law or necessary to protect rights.
10. Maps and Places services
Where the browser directly queries mapping or place-search providers, those providers may receive IP address, search coordinates, technical data and referrer under their own terms. Italia Quality limits data to what is necessary for the feature and favours configurations consistent with minimisation and security.
11. Artificial intelligence features
AI features may process images, text or data supplied by the user to extract information, structure a draft or provide assistance. AI must not autonomously determine a Scout’s rating. Users must review outputs before publication. See the AI Transparency Policy.
12. International transfers
Where a provider processes data outside the EEA, UESE relies where required on an adequacy decision, Standard Contractual Clauses, supplementary measures or another Chapter V GDPR mechanism. Information on applicable safeguards may be requested.
13. Retention
Account and contractual data are retained for the relationship and periods needed for legal duties and rights protection. Security logs are kept proportionately to risk. Visit evidence is retained as needed for verification, disputes and applicable duties. Public content may be archived or removed under review and moderation rules; review law may impose specific recency rules.
14. Automated processing and profiling
Italia Quality uses algorithms to calculate scores, confidence, rankings and reputation indicators from platform data. These processes are not intended to produce legal or similarly significant effects on users under Article 22 GDPR. Anti-abuse systems may generate risk signals subject to controls and challenge procedures.
15. Security
Technical and organisational measures consistent with Articles 25 and 32 GDPR are adopted, including access separation, password hashing, application controls, session management, backups and architecture-appropriate logging. No system can be considered risk-free.
16. Rights
Where applicable, data subjects may exercise access, rectification, erasure, restriction, portability, objection and withdrawal of consent under Articles 15-22 GDPR and may lodge a complaint with the Italian Data Protection Authority.
17. Requests and identity verification
Requests may be sent to privacy@uese.eu or the DPO. UESE may request proportionate information to verify identity and entitlement and responds within GDPR time limits.
18. Updates
This policy is versioned. Material processing changes may be highlighted appropriately and, where necessary, require updated information or consent.
19. Key legal references
- Regolamento (UE) 2016/679 – GDPR
- D.lgs. 196/2003 – Codice in materia di protezione dei dati personali
Mobile app, PWA and device permissions
Italia Quality may also be used as a Progressive Web App or privately distributed mobile application. Features requiring location, camera, photo library, microphone or notifications rely on operating-system permissions and are activated only when needed or requested by the user. Refusing a permission may limit the relevant feature without preventing use of areas that do not require it. The app does not embed account credentials or secret API keys on the device and uses HTTPS connections to the Italia Quality domain and providers described in this notice.