Privacy notice
This notice describes how Investfood SRL processes the personal data of people visiting this site and of people using the TicketOS platform, under articles 13 and 14 of European Regulation 2016 679.
1. Data controller
The data controller is Investfood SRL, registered and operating office at Via Riva di Trento 11/A, 20139 Milan, Italy, VAT number 12925600962. For any request concerning personal data, write to info@investfood.it.
TicketOS is the internal platform the controller uses to organise support, maintenance and device inventory across its own network of venues.
2. Data processed when you visit this site
The public site has no contact forms, uses no traffic measurement tools and loads no fonts or resources from third party domains: typefaces are hosted alongside the site. The only information processed is listed below.
- Browsing data. The delivery service hosting these pages records, for technical and security reasons, the IP address, date and time of the request, the page requested, the browser type and the operating system.
- Local storage on your device. Two entries saved in the browser: the light or dark theme you chose, and the preference you expressed on the consent banner. They stay on your device and are not sent anywhere.
The full list of storage entries, with duration and purpose, is in the cookie notice.
3. Data processed when you use the platform
Access to TicketOS is restricted to the controller staff, to the venues in the network and to authorised suppliers. For these people the controller processes the following categories of data.
- Account data. First name, last name, work email address, assigned role, companies the person is entitled to, date of last sign in.
- Request content. Text of tickets and messages, uploaded attachments, the venue concerned, category, priority, status, and the history of assignments.
- Maintenance data. Work on equipment, HACCP log readings with date, time, value and the person who entered them, supplier documents.
- Device data. Model, serial number, state and assigned person of a company laptop, tablet or phone, together with the source of the record.
- Operation log. A technical trail of significant actions performed in the platform, kept for security and to reconstruct anomalies.
No data belonging to the special categories under article 9 of the Regulation is requested or collected. People writing a ticket are asked not to include information that the request does not need.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Deliver the support service, manage maintenance and the device inventory | Performance of a contract or pre contractual measures, article 6.1.b, and obligations of the employment relationship |
| Keep the HACCP log of readings and maintenance documents | Compliance with a legal obligation, article 6.1.c, on food hygiene and safety |
| Ensure security, continuity and integrity of the platform, including technical logs | Legitimate interest of the controller in the security of its systems, article 6.1.f |
| Remember the chosen theme and the cookie preference | Legitimate interest in providing a working site, article 6.1.f, this being technical storage |
| Reply to a request sent by email | Legitimate interest in answering people who write, article 6.1.f |
5. Who the data is shared with
Data is neither disseminated nor sold. It is accessible to authorised staff of the controller and to the technical suppliers listed below, appointed as processors under article 28 of the Regulation.
| Supplier | Service | Where data is processed |
|---|---|---|
| Google Ireland Limited | Site hosting, authentication, application runtime and database | European Union |
| Resend | Sending and receiving the email messages tied to tickets | European Union and United States |
| Slack Technologies | Internal notifications to the support and development channels | European Union and United States |
| Mitsogo, Hexnode | Synchronisation of the company device inventory | European Union and United States |
Data may also be disclosed to public authorities where a legal provision requires it.
6. Transfers outside the European Economic Area
The application and the database are hosted in a European region. Some notification and mail suppliers may also process data in the United States: in those cases the transfer relies on the standard contractual clauses approved by the European Commission, or on the adequacy decision applicable to the supplier, with the supplementary measures set out in the contract.
7. How long data is kept
| Data | Retention |
|---|---|
| Accounts and roles | For the duration of the relationship, then deleted or anonymised within twelve months |
| Tickets, messages and attachments | Twenty four months from the ticket closing, unless a dispute is pending |
| HACCP log and maintenance documents | For the period required by the applicable food hygiene rules |
| Device inventory | For the duration of the assignment, then two years for administrative purposes |
| Technical access logs | Twelve months |
| Local storage in the browser | Theme and cookie preference stay until you clear the site data |
8. Your rights
At any time you can exercise the rights under articles 15 to 22 of the Regulation by writing to info@investfood.it.
- Access your data and receive a copy of the information concerning you.
- Ask for inaccurate data to be corrected, or incomplete data to be completed.
- Ask for data to be erased, where no retention obligation applies.
- Ask for processing to be restricted in the cases set out by the Regulation.
- Receive the data in a machine readable format and ask for it to be sent to another controller.
- Object to processing based on legitimate interest, explaining your particular situation.
A reply arrives within one month of the request. If you believe the processing breaches the rules, you may lodge a complaint with the Italian data protection authority, Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, or with the authority of the country where you live.
9. Security measures
- Access only after authentication, with expiring tokens and differentiated roles.
- Data separation per company enforced by the service on every request, not by the interface.
- Encrypted transmission between browser, application service and database.
- Integration keys encrypted with a key management service and rotatable without interruption.
- Outbound traffic from a static address, to limit the surface exposed towards suppliers.
- A log of significant operations, available for inspection.
10. Updates to this notice
This notice may be updated when processing activities, suppliers or the applicable rules change. The date of the last update is shown at the top of the page. Significant changes are also announced inside the platform.