Personal Data Processing Notice
Updated 29 August 2026. This notice describes which personal data are processed through the Pupiko platform, for what purposes, on what legal basis under Regulation (EU) 2016/679, and which rights may be exercised.
1.Data Controller
- Controller
- Persico Alessio, sole trader
- Registered office
- Via Delia 64, 00155 Rome (RM), Italy
- VAT no.
- IT18550941001
- Contact
- support.pupiko@gmail.com
1.1. Persico Alessio (the «Controller») operates the Pupiko platform, available at https://pupiko.io (the «Platform»), and determines the purposes and means of the processing described in this notice. No Data Protection Officer has been appointed, the conditions under Article 37 of the Regulation not being met.
2.Personal data processed
2.1. Only the categories of data set out below are processed, for the purposes, on the legal bases and for the retention periods indicated alongside each of them.
| Category of data | Purpose | Legal basis (Art. 6) | Retention |
|---|---|---|---|
| Email address and access credentials | Account creation and authentication | 6(1)(b) — performance of the contract | Until the account is deleted |
| Username, display name, profile description, profile image | Public identification on the board | 6(1)(b) — performance of the contract | Until the account is deleted |
| Thoughts sent and received, with author, recipient and date | Provision of the service and moderation | 6(1)(b) — performance of the contract | 30, 90 or 365 days on the public board depending on the plan, then the recipient's private archive |
| Device signature (encrypted combination of IP address and browser) | Abuse prevention and enforcement of sending limits | 6(1)(f) — legitimate interest | 90 days maximum |
| Visits to public boards | Aggregate statistics for the board owner | 6(1)(f) — legitimate interest | Aggregate data; individual detail reduced after 90 days |
| Technical address of browser or device for notifications | Delivery of the notifications requested by the data subject | 6(1)(a) — consent | Until consent is withdrawn or the account is deleted |
| Customer identifier and subscription status | Management of the subscription and active features | 6(1)(b) — performance of the contract | Until the account is deleted |
| Billing data | Tax and accounting obligations | 6(1)(c) — legal obligation | 10 years (Italian tax law) |
| Count of sign-ups per network address | Limiting the creation of multiple accounts | 6(1)(f) — legitimate interest | A few weeks, then automatic deletion |
| Support correspondence and reports | Replying to the requests received | 6(1)(b) — performance of the contract | 24 months from the last reply |
2.2. Payment card numbers, advertising identifiers, precise geolocation data and special categories of data under Article 9 of the Regulation are not processed. The Controller does not obtain account passwords, which are stored in encrypted form by the authentication provider.
3.User-generated content and public visibility
3.1. The username, display name, profile description, profile image and approved thoughts are accessible to anyone visiting the board, without the need to register, and may be indexed by search engines.
3.2. Whoever sends a thought may choose not to have their name shown publicly. That choice takes effect towards third parties visiting the board: the recipient always knows the identity of the author, a condition necessary for the exercise of moderation, blocking and reporting. This is made known to the author before sending.
4.Automated processing
4.1. When a thought is sent, its text is subject to automated filters that prevent the transmission of content amounting to incitement to hatred and, where the recipient has so requested, of vulgar content. The filter may prevent a message from being sent; the decision on publication always remains with the recipient's human assessment.
4.2. No automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them under Article 22 of the Regulation is carried out.
5.Processors and recipients
5.1. To provide the service the Controller relies on the parties listed below, appointed as processors under Article 28 of the Regulation, save as specified in paragraph 5.2.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Database, authentication and file storage | All account and content data | European Union |
| Vercel | Delivery and distribution of the web application | Technical request data | European Union, with standard contractual clauses for the United States |
| Stripe Payments Europe Ltd. | Sale and collection of subscriptions | Email address and billing data | European Union and United States |
| Google Ireland Ltd. | Sign-in with a Google account and notification service | Email address, name, technical device address | European Union and United States |
| Apple Distribution International Ltd. | Notification service on Safari and iOS | Technical device address | European Union and United States |
| Cloudflare | Anti-automation check at sign-up | IP address and request metadata | Global, with standard contractual clauses |
| Resend | Delivery of service communications | Email address and message content | United States, with standard contractual clauses |
5.2. Stripe's position. Subscriptions are sold through Stripe, which acts as seller towards the data subject and fulfils the related tax obligations. As regards the transaction data and the connected obligations, Stripe acts as an independent controller and processes those data under its own privacy policy, over which the Controller exercises no determination.
5.3. Data are not disclosed to advertisers or transferred to third parties. No profiling for advertising purposes is carried out. Disclosure to the competent authorities in the cases provided for by law remains unaffected.
6.Transfers to third countries
6.1. Data are stored primarily within the European Union. Where a processor also operates outside the European Economic Area, the transfer is supported by an adequacy decision of the European Commission, by the standard contractual clauses adopted by Decision 2021/914 or, within the limits of Article 49 of the Regulation, by another appropriate safeguard.
7.Security measures
7.1. The Controller adopts technical and organisational measures appropriate to the risk under Article 32 of the Regulation, including: encryption of data in transit; storage of passwords in encrypted form by the authentication provider; row-level access rules on the database preventing the reading of data relating to other data subjects; encrypted storage of the device signature; rate limits on sending; anti-automation checks at sign-up; logging of moderation operations; periodic automatic deletion of anti-abuse logs.
7.2. No measure can entirely exclude risk. Anyone identifying a vulnerability is invited to report it to support.pupiko@gmail.com.
8.Retention and deletion
8.1. Retention periods are set out in the table in Section 2. Deleting the account removes the profile, the board, the thoughts received, the archive, the notification subscriptions and the blocks that were set.
8.2. Thoughts sent to other recipients may remain on their boards, stripped of any reference to the deleted account, unless the data subject requests their removal through the dedicated option available during deletion.
8.3. Billing data are excepted and retained for the period required by tax legislation.
9.Rights of the data subject
9.1. The data subject may exercise the following rights at any time:
- access (Art. 15): obtain confirmation of processing and a copy of the data. Account → Download your data produces a complete export in machine-readable format;
- rectification (Art. 16): correct inaccurate or incomplete data, including directly from the restricted area;
- erasure (Art. 17): obtain the removal of the account and the data, through Account → Delete account;
- restriction (Art. 18) and objection (Art. 21): restrict or object to processing based on legitimate interest;
- portability (Art. 20): receive the data in a structured, commonly used format, through the same export function;
- withdrawal of consent (Art. 7): withdraw at any time the consent given for notifications, without affecting the lawfulness of processing carried out beforehand.
9.2. Requests are sent to support.pupiko@gmail.com or, in writing, to the registered office indicated in Section 1. A reply is provided without undue delay and in any event within one month of receipt, extendable by a further two months in particularly complex cases, with notice to the data subject.
10.Complaint to a supervisory authority
10.1. A data subject who considers the processing not to comply with the Regulation has the right to lodge a complaint with a supervisory authority under Article 77. The authority competent for the Controller is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy — gpdp.it. Data subjects resident in another Member State may address the supervisory authority of their own country.
11.Cookies and tracking tools
11.1. Only technical cookies necessary for the operation of the service are used: the authentication session cookie, the early-access cookie for the closed testing phase, and preference cookies, including the selected language. No profiling cookies, advertising pixels or third-party tracking tools for marketing purposes are employed.
11.2. Any future introduction of traffic measurement tools will be preceded by an update of this notice and, where necessary, by the collection of consent.
12.Minimum age
12.1. The service is reserved to persons who have reached the age of 14, the age set by Article 2-quinquies of the Italian Personal Data Protection Code for giving consent independently in relation to information society services. Data of children under fourteen are not knowingly collected; where the Controller becomes aware of such a case, the account is deleted without delay.
13.Changes to this notice
13.1. This notice may be updated. Substantial changes, such as the introduction of new purposes or new processors, are communicated to the email address associated with the account at least fourteen days in advance. The date shown at the top identifies the latest revision.
Requests concerning the processing of personal data may be sent to support.pupiko@gmail.com.
See also the terms and conditions of use.