Privacy notice

Personal data processing notice

Provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") to users of the DPO Workspace platform (dpoworkspace.eu).

Last updated: 14 maggio 2026Version 1.1
01

Data controller

The controller of the personal data collected through the dpoworkspace.eu platform is Studio Cravero Consulting, VAT 03059830905, based in Sassari (Sardinia), in the person of Mr Pietro Cravero, certified Data Protection Officer (hereinafter "Studio Cravero" or "the Controller").

Office
Studio Cravero Consulting
Sassari, Sardinia · Italy
Contacts
P.IVA 03059830905
info@studiocravero.eu
02

Types of data processed

Studio Cravero processes the following categories of users' personal data:

  • Registration data: first name, last name (if provided), email address, password (stored encrypted via hashing).
  • Professional profile data: workspace or firm name, declared professional certifications, logo, operational contacts.
  • Uploaded documents: files and related metadata (name, type, size, document section, status, internal notes, review interval, last review date) uploaded by the user for the platform's purposes.
  • Data about the user's clients: company records, VAT number, tax code, sector, contacts, DPO mandate information, data possibly contained in uploaded documents.
  • End-client privacy event reports: data collected through the "Event reporting link" generated by the DPO user for their client. May include: event type (e.g. new employee, new processing, data breach), text description of the event, date of occurrence, and any identifying data of the reporter (name, role, email) if voluntarily provided by the person completing the public form.
  • Event handling workflow: data on the DPO's handling of events, including completed checklists, actions taken, documented decisions (chosen legal basis, DPO opinion, operational notes), links to updated documents, timestamps of each step.
  • Public access tokens: cryptographic identifiers (32 URL-safe characters, ~191 bits of entropy, generated with the Web Crypto API) associated with the reporting links, with creation, expiry, usage-counter and revocation-flag metadata.
  • Technical and usage data: IP address, session identifiers, access logs, action logs (audit trail), device and browser information.
  • Payment data: handled exclusively by the sub-processor Stripe (see Section 7). Studio Cravero does not store full payment data on its systems.
Attenzione
Documents uploaded by the user and reports sent through the public form may contain special categories of personal data under Art. 9 GDPR (health data, judicial data, etc.). The DPO user and the controller on whom the document flow depends are responsible for ensuring they have a suitable legal basis to process such data and to share it with the platform.
03

Purposes and legal bases of processing

Personal data is processed for the following purposes:

Purpose
Legal basis
Service provision (account registration, workspace management, document storage, report generation)
Performance of a contract to which the data subject is party — Art. 6(1)(b) GDPR
"Event reporting link" feature and privacy event workflow management: receiving reports from the DPO's clients, storing handling information, tracking the DPO's decisions for accountability purposes under Art. 5(2) GDPR
Performance of the contract / legitimate interest of the Controller and the DPO client — Art. 6(1)(b) and 6(1)(f) GDPR
Generation, validation, expiry and revocation of public access tokens for reporting forms
Performance of the contract / legitimate interest in service security — Art. 6(1)(b) and 6(1)(f) GDPR
Compliance with legal obligations (tax, accounting, anti-money-laundering)
Legal obligation — Art. 6(1)(c) GDPR
Handling support requests, responding to communications
Performance of the contract / legitimate interest — Art. 6(1)(b)/(f) GDPR
IT security, fraud prevention, audit logs, tracking public token usage (access counter, last-use timestamp)
Legitimate interest of the Controller — Art. 6(1)(f) GDPR
Sending service communications (platform notifications, document deadline alerts, contractual communications)
Performance of the contract — Art. 6(1)(b) GDPR
Possible sending of marketing communications about similar products
Legitimate interest / consent — Art. 6(1)(f) / 6(1)(a) GDPR (revocable at any time)
04

Processing methods

Processing is carried out with automated tools and with technical and organisational measures appropriate to ensure the confidentiality, integrity, availability and resilience of processing systems and services (Art. 32 GDPR).

In particular, Studio Cravero adopts:

  • Hosting on Google Firebase infrastructure, region europe-west1 (Belgium)
  • Storage of user-uploaded documents on Google Cloud Storage (bucket dpoworkspace-60ebd.firebasestorage.app, region europe-west1 - Belgium). Files are separated by workspace and client; the per-file limit is 20 MB
  • Encryption of data at rest (AES-256) and in transit (TLS 1.3)
  • User authentication with email/password (hashing) or Google OAuth
  • Database access rules (Firestore Security Rules) and storage rules (Storage Security Rules) ensuring separation between different users' workspaces and that no user can read/write another workspace's files
  • Public access tokens generated with the Web Crypto API (CSPRNG) at 32 URL-safe characters, equivalent to about 191 bits of entropy (computationally impossible to brute-force)
  • Database-side validation (Firestore rules) of token, expiry and clientId/workspaceId consistency for every public report
  • Size limits on text fields submitted via the public form to prevent abuse (anti-spam, anti-payload)
  • Append-only internal audit trail on every relevant action
  • Automatic backups and versioning
  • Security HTTP headers (HSTS with preload, restrictive CSP, X-Frame-Options DENY, Permissions-Policy disabling camera/microphone/USB/bluetooth)
  • Internal data breach management procedures (notification under Art. 33-34 GDPR)
  • Restriction of access to authorised personnel under the need-to-know principle
05

Retention period

Personal data is retained for as long as strictly necessary to pursue the purposes for which it was collected:

  • User account and associated data: for the entire duration of the contractual relationship and for 24 months after termination, unless otherwise agreed.
  • Uploaded documents: for the duration of the contractual relationship; made available for export for 30 days after termination, then deleted.
  • Event reports and handling workflows: for the duration of the contractual relationship and for 5 years after their closure, to ensure accountability under Art. 5(2) GDPR and any legal defence.
  • Public access tokens: until the natural expiry set by the DPO user, explicit revocation, or regeneration. Expired/revoked tokens remain in the database as "inactive" to allow the audit trail of past reports, but can no longer be used.
  • Tax and billing data: 10 years under the Italian Civil Code and tax law.
  • Audit trail: 5 years from log generation, unless defence needs require otherwise.
  • Payment data: according to the sub-processor Stripe's policies.
06

Disclosure and dissemination of data

Personal data may be disclosed to:

  • Studio Cravero's internal staff, duly authorised and trained
  • Sub-processors listed in Section 7
  • Competent authorities, on reasoned request and within the limits of the law
  • Professional advisers (accountants, lawyers) within the limits of what is strictly necessary

Personal data is not disseminated and is not transferred to third parties for marketing purposes.

07

Sub-processors

Studio Cravero uses the following sub-processors, appointed under Art. 28(4) GDPR. The list is kept updated and available in a consultable format.

Google Ireland Limited (Firebase)
Role
Hosting, authentication, database, file storage
Location / Server
Ireland · Server: europe-west1 (Belgium)
Safeguards
Google Cloud DPA, ISO 27001/27017/27018 certifications, SOC 1/2/3
Stripe Payments Europe, Limited
Role
Payment processing (when enabled)
Location / Server
Ireland · EU
Safeguards
Stripe DPA, PCI-DSS Level 1 certification
Cloudflare, Inc. (domain registrar, where applicable)
Role
DNS management
Location / Server
USA · with SCC and appropriate mechanisms
Safeguards
EU Standard Contractual Clauses, Cloudflare DPA
08

"Event reporting" link and public data flows

The platform lets the DPO user generate a unique link for each client, to collect reports of privacy-relevant events (hires, new processing activities, data breaches, etc.) from the client. This feature involves a public data-processing flow and requires clarification.

Link generation

  • The link contains a 32-character cryptographic token generated client-side via the Web Crypto API (CSPRNG), with about 191 bits of entropy (2.27 × 1057 combinations). It is not derived from client data nor predictable.
  • The token is saved in a separate collection (event_tokens) that does NOT contain sensitive client data, only: client identifier, client name (for public-form UX), workspace identifier, creation date, expiry date (if set), revocation flag, usage counter.
  • Each new generation immediately revokes the previous token for the same client.
  • The DPO user can set an expiry on the link (90, 180, 365 days, or none). Choosing "no expiry" is NOT recommended.
  • The DPO user can revoke an active link at any time. Revocation is immediate.

Completing the public form

  • The public form verifies the token (existence, non-revocation, time validity, clientId/workspaceId consistency) before allowing submission.
  • Data submitted via the form (event type, description, date, any reporter data) is transmitted exclusively to the DPO designated for the relevant client. It is not visible to other users nor shared with third parties.
  • The person completing the form is not required to provide their own identifying data (name, role, email): those fields are optional.
  • For anti-abuse reasons, reports include a reference to the token used (for audit purposes) and are subject to length limits on text fields.
  • Each use of the token increments a usage counter and records the timestamp of the last use, to allow the DPO to monitor activity.

DPO user responsibilities

Attenzione
The DPO user who generates and shares a link must: (a) share the link only with authorised people (privacy, HR, compliance contacts); (b) transmit the link through authenticated channels (personal email, corporate messaging, NOT public groups); (c) document delivery of the link in their internal records; (d) immediately revoke the link if the relationship with the recipient ends, their role changes, or compromise is suspected; (e) periodically regenerate the link (at least annually) even without specific events.

Studio Cravero cannot control to whom the DPO user delivers the link, nor the use recipients make of it.

Event handling workflow

Each report received can be handled by the DPO through a structured multi-step workflow (preliminary check, operational actions, DPO decisions, linked documents). The information entered by the DPO in this workflow (completed checklists, documented decisions, reasons) is saved for accountability purposes under Art. 5(2) GDPR and may be produced in case of a supervisory-authority inspection or a third-party request.

8-bis

Public DPO profile (opt-in)

DPO Workspace lets its DPO users activate an opt-in public profile in the /cerca-dpo directory, where organisations and companies can find certified DPOs for engagements. This feature is disabled by default and requires the data subject's (the DPO's own) explicit consent under Art. 6(1)(a) GDPR.

The data published in the opt-in profile includes:

  • DPO's first and last name
  • Profile photo and cover photo (voluntarily uploaded by the DPO)
  • Professional headline (e.g. "IDcert-certified Data Protection Officer")
  • Professional bio, work experience, academic background, certifications
  • Declared areas of expertise and languages spoken
  • Professional email contact (only if the DPO chooses to expose it)
  • City and region of operation

EDPB Guidelines 03/2026 compliance: the system complies with the EDPB guidelines of 12 May 2026 on public DPO profiles. In particular:

  • Legal basis: explicit consent only under Art. 6(1)(a) GDPR; legitimate interest is NOT used for this purpose
  • Right to immediate removal: the DPO can disable the public profile at any time from the Profile section, with immediate effect; the profile is no longer indexable within a few minutes of deactivation
  • Separation of purposes: consent to the public profile is separate from newsletter consent and any other promotional purpose
  • Exportability: all profile data is exportable in JSON format from the Backup section
  • Audit logging: access to the public profile and any contact requests are tracked for a maximum of 12 months
  • Minimisation: only the fields the DPO fills in voluntarily are published. Empty fields do not appear on the public page

Categories of recipients: the public DPO page is visible to anyone who accesses the URL /dpo/{slug} without authentication. No transfer of data to third parties for marketing purposes is provided.

Retention after deactivation: after the public profile is deactivated, the profile data remains in the DPO's private account (for internal use) but is no longer publicly visible. If the account is deleted, all profile data is permanently deleted within 30 days, save for legal obligations (e.g. invoicing, tax audit).

09

Non-EU data transfers

As a rule, data remains within the European Economic Area. Any transfers to third countries (e.g. DNS infrastructure) take place exclusively to countries covered by a European Commission adequacy decision or on the basis of Standard Contractual Clauses (SCC) under Art. 46 GDPR and appropriate supplementary measures (Schrems II compliance).

10

Data subject rights

Under Art. 15-22 GDPR, the data subject has the right to:

  • Access to their data (Art. 15)
  • Rectification of inaccurate or incomplete data (Art. 16)
  • Erasure of data ("right to be forgotten", Art. 17)
  • Restriction of processing (Art. 18)
  • Portability of data in a structured format (Art. 20)
  • Objection to processing based on legitimate interest (Art. 21)
  • Not to be subject to solely automated decisions (Art. 22)
  • Withdraw consent at any time, without affecting the lawfulness of processing based on consent given before withdrawal

Rights can be exercised by writing to info@studiocravero.eu. A response will be provided within 30 days of receiving the request, save for justified extensions.

11

Complaint to the supervisory authority

A data subject who believes that the processing of their personal data breaches the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or another competent supervisory authority, under Art. 77 GDPR.

12

Nature of data provision

Providing registration data is necessary to deliver the service. Refusal makes it impossible to access the platform. Providing further data (e.g. workspace logo, certifications) is optional and does not affect the usability of essential features.

13

Automated decision-making

The platform does not carry out solely automated decision-making, including profiling, that produces legal effects on the data subject or similarly significantly affects them, under Art. 22 GDPR.

Any automatic document classification features are of a suggestion nature and are subject to manual confirmation by the user.

14

Cookies and similar technologies

The platform uses three categories of cookies and similar technologies, managed through a consent banner compliant with the Italian DPA measure of 10 June 2021:

  • Technical / necessary cookies — always active, do not require consent (Art. 122 Privacy Code). Used for authentication, security, session maintenance.
  • Analytics cookies — opt-in, require explicit consent. They help understand use of the platform in aggregate and anonymous form.
  • Marketing / profiling cookies — opt-in, require explicit consent. Currently not actively used.

Consent is valid for 6 months and can be withdrawn at any time through the "Cookie preferences" link in the site footer. All consents are recorded with date, time and document version for the purposes of Art. 7(1) GDPR (ability to demonstrate consent).

15

Changes to this notice

This notice may be updated over time to align with regulatory, organisational or technological developments. The current version is always available on this page, with the date of last update. Substantial changes will be communicated to registered users by email.

Questions about how your data is processed?

Write to us. We reply within 5 working days.

info@studiocravero.eu