Skip to content
TicketOS TicketOS
PlatformModulesIntegrationsSecurityFAQ
IT EN
Sign in
PlatformModulesIntegrationsSecurityFAQ Venue portal
IT EN

Privacy notice

This notice describes how Investfood SRL processes the personal data of people visiting this site and of people using the TicketOS platform, under articles 13 and 14 of European Regulation 2016 679.

Last updated: 3 September 2026

On this page

  1. Data controller
  2. Data processed when you visit this site
  3. Data processed when you use the platform
  4. Purposes and legal bases
  5. Who the data is shared with
  6. Transfers outside the European Economic Area
  7. How long data is kept
  8. Your rights
  9. Security measures
  10. Updates to this notice

1. Data controller

The data controller is Investfood SRL, registered and operating office at Via Riva di Trento 11/A, 20139 Milan, Italy, VAT number 12925600962. For any request concerning personal data, write to info@investfood.it.

TicketOS is the internal platform the controller uses to organise support, maintenance and device inventory across its own network of venues.

2. Data processed when you visit this site

The public site has no contact forms, uses no traffic measurement tools and loads no fonts or resources from third party domains: typefaces are hosted alongside the site. The only information processed is listed below.

  • Browsing data. The delivery service hosting these pages records, for technical and security reasons, the IP address, date and time of the request, the page requested, the browser type and the operating system.
  • Local storage on your device. Two entries saved in the browser: the light or dark theme you chose, and the preference you expressed on the consent banner. They stay on your device and are not sent anywhere.

The full list of storage entries, with duration and purpose, is in the cookie notice.

3. Data processed when you use the platform

Access to TicketOS is restricted to the controller staff, to the venues in the network and to authorised suppliers. For these people the controller processes the following categories of data.

  • Account data. First name, last name, work email address, assigned role, companies the person is entitled to, date of last sign in.
  • Request content. Text of tickets and messages, uploaded attachments, the venue concerned, category, priority, status, and the history of assignments.
  • Maintenance data. Work on equipment, HACCP log readings with date, time, value and the person who entered them, supplier documents.
  • Device data. Model, serial number, state and assigned person of a company laptop, tablet or phone, together with the source of the record.
  • Operation log. A technical trail of significant actions performed in the platform, kept for security and to reconstruct anomalies.

No data belonging to the special categories under article 9 of the Regulation is requested or collected. People writing a ticket are asked not to include information that the request does not need.

4. Purposes and legal bases

PurposeLegal basis
Deliver the support service, manage maintenance and the device inventoryPerformance of a contract or pre contractual measures, article 6.1.b, and obligations of the employment relationship
Keep the HACCP log of readings and maintenance documentsCompliance with a legal obligation, article 6.1.c, on food hygiene and safety
Ensure security, continuity and integrity of the platform, including technical logsLegitimate interest of the controller in the security of its systems, article 6.1.f
Remember the chosen theme and the cookie preferenceLegitimate interest in providing a working site, article 6.1.f, this being technical storage
Reply to a request sent by emailLegitimate interest in answering people who write, article 6.1.f

5. Who the data is shared with

Data is neither disseminated nor sold. It is accessible to authorised staff of the controller and to the technical suppliers listed below, appointed as processors under article 28 of the Regulation.

SupplierServiceWhere data is processed
Google Ireland LimitedSite hosting, authentication, application runtime and databaseEuropean Union
ResendSending and receiving the email messages tied to ticketsEuropean Union and United States
Slack TechnologiesInternal notifications to the support and development channelsEuropean Union and United States
Mitsogo, HexnodeSynchronisation of the company device inventoryEuropean Union and United States

Data may also be disclosed to public authorities where a legal provision requires it.

6. Transfers outside the European Economic Area

The application and the database are hosted in a European region. Some notification and mail suppliers may also process data in the United States: in those cases the transfer relies on the standard contractual clauses approved by the European Commission, or on the adequacy decision applicable to the supplier, with the supplementary measures set out in the contract.

7. How long data is kept

DataRetention
Accounts and rolesFor the duration of the relationship, then deleted or anonymised within twelve months
Tickets, messages and attachmentsTwenty four months from the ticket closing, unless a dispute is pending
HACCP log and maintenance documentsFor the period required by the applicable food hygiene rules
Device inventoryFor the duration of the assignment, then two years for administrative purposes
Technical access logsTwelve months
Local storage in the browserTheme and cookie preference stay until you clear the site data

8. Your rights

At any time you can exercise the rights under articles 15 to 22 of the Regulation by writing to info@investfood.it.

  • Access your data and receive a copy of the information concerning you.
  • Ask for inaccurate data to be corrected, or incomplete data to be completed.
  • Ask for data to be erased, where no retention obligation applies.
  • Ask for processing to be restricted in the cases set out by the Regulation.
  • Receive the data in a machine readable format and ask for it to be sent to another controller.
  • Object to processing based on legitimate interest, explaining your particular situation.

A reply arrives within one month of the request. If you believe the processing breaches the rules, you may lodge a complaint with the Italian data protection authority, Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, or with the authority of the country where you live.

9. Security measures

  • Access only after authentication, with expiring tokens and differentiated roles.
  • Data separation per company enforced by the service on every request, not by the interface.
  • Encrypted transmission between browser, application service and database.
  • Integration keys encrypted with a key management service and rotatable without interruption.
  • Outbound traffic from a static address, to limit the surface exposed towards suppliers.
  • A log of significant operations, available for inspection.

10. Updates to this notice

This notice may be updated when processing activities, suppliers or the applicable rules change. The date of the last update is shown at the top of the page. Significant changes are also announced inside the platform.

TicketOS TicketOS

Support, maintenance and devices for a retail network, in one system.

Investfood SRL
Via Riva di Trento 11/A, 20139 Milano, Italia
P.IVA 12925600962
info@investfood.it

Platform

  • Interface
  • Modules
  • Integrations
  • Security
  • FAQ

Access and legal

  • Sign in
  • Venue portal
  • Privacy notice
  • Cookie notice
  • Cookie preferences
© 2026 Investfood SRL. All rights reserved. GitHub GitHub Powered by WLMZZ

Cookies and local storage

This site uses technical storage only, needed to remember the theme you picked and this very preference. Optional categories stay off until you switch them on. Read the cookie notice and the privacy notice.