pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR)
Data Controller
The Data Controller is Studiolabo S.r.l., Via Palermo 1, 20121 Milan, Italy, VAT No. 06443950966,
email: privacy@studiolabo.it
(hereinafter, the “Controller” or “Fuorisalone Passport”).
Data Protection Officer (DPO)
The Data Protection Officer function is carried out internally by Studiolabo S.r.l.
For any request, clarification or to exercise your rights, you may contact the DPO at:
privacy@studiolabo.it
1. Introduction
Welcome to Fuorisalone Passport, the digital service that allows you to register for participating Fuorisalone events and to facilitate your check-in at partner companies.
This Privacy Policy explains:
- which personal data we collect;
- how we use them;
- with whom they may be shared;
- how you can exercise your rights.
Please read this policy carefully before using the service.
2. Description of the Service
Fuorisalone Passport is a browser-based web app that allows users to:
- create a personal account;
- generate a personal QR Code to access participating events;
- manage check-ins at partner companies.
Within the reserved user area, you can view the list of participating companies and events and freely decide whether to grant consent to share your personal data with each company before attending an event.
In some cases, companies may require such consent as a mandatory condition for event access. Personal data may be shared with hosting companies only upon explicit and informed consent, whether the user actually attends the event and performs the check-in, or merely expresses interest in participating.
3. Categories of Personal Data Collected
3 A. Essential / Identifying data
- First name, last name
- Date of birth
- Gender
- Email address
- Profession
- Country, city
3 B. Statistical / profiling data
- Company
- Role
- Language
Essential data are used to manage the service and enable event access. Statistical and profiling data are used exclusively in aggregated form for analytical and service-improvement purposes and are not shared with third parties for commercial use.
We also collect:
- registration and login data;
- check-in data (user ID, event, company, date and time, consent status, policy version);
- technical data (IP address, browser, operating system, server logs) for security and audit purposes.
4. Purposes of Processing
Personal data are processed for:
- account creation and authentication;
- event access and check-in management;
- recording and verifying user consent;
- service communications related to check-ins;
- legal obligations, security and internal audits.
Optional purposes subject to consent:
- promotional and marketing communications;
- sharing data with participating exhibitors for their independent promotional activities;
- profiling activities for statistical and analytical purposes only.
Such activities do not produce legal effects nor significantly affect the data subject pursuant to Article 22 GDPR.
5. Legal Basis
- Service registration: performance of a contract (Art. 6(1)(b) GDPR)
- Event check-in and data sharing: explicit consent (Art. 6(1)(a) GDPR)
- Marketing communications: separate and optional consent
Consent is specific for each company, revocable at any time, and may be mandatory or optional depending on the event configuration.
6. Consent Management
You may grant consent in advance through your reserved area by selecting individual companies. Consent:
- is specific and informed;
- remains valid even if you do not physically attend the event;
- may be revoked at any time prior to data sharing.
Failure to attend an event or to use the QR Code does not invalidate the consent previously granted.
7. Data Sharing
Data are shared with participating companies only upon your consent and only for the declared purposes. Studiolabo S.r.l. does not sell or disclose personal data to third parties without consent.
8. Data Retention
- Account data: until account deletion + 6 months
- Check-in and consent records: minimum 5 years for audit purposes
- Technical logs: 12 months
After retention, data are anonymized or deleted.
9. Data Subject Rights
You may exercise your rights under Articles 15–21 GDPR, including:
- access, rectification, erasure;
- restriction or objection;
- data portability;
- withdrawal of consent;
- lodging a complaint with the supervisory authority.
Requests may be sent to privacy@studiolabo.it.
10. Security Measures
Data are protected through HTTPS, authenticated access, backups and access controls.
11. Policy Updates
This Privacy Policy may be updated at any time. The latest version will always be available online.
12. Contact Details
Studiolabo S.r.l.
Via Palermo 1, 20121 Milan – Italy
Tel. +39 02 36638150
Final Notes for Users
- Check-in is valid only with explicit consent
- The web app requires an active internet connection
- Emails or notifications are confirmations only and do not replace consent