MondoPet

Privacy Policy

Information on the processing of personal data pursuant to Regulation (EU) 2016/679 (GDPR).

Version 1.0 — effective date: [to be defined]

Document being finalised: the company details shown in square brackets will be completed before final publication.

1. Data controller

The controller of personal data is: MondoPet — Registered office: [full address] — VAT / Tax code: [to be defined] — Email: [privacy email] — Certified email (PEC): [to be defined].

For any request concerning the processing of personal data or the exercise of the rights provided by applicable law, data subjects may contact the controller using the details above.

2. Personal data processed

As part of registration and use of the services provided by MondoPet, the following data may be processed:

  • data provided during registration (first name, last name, email, business/organisation where applicable and other necessary data);
  • credentials and authentication data;
  • temporary tokens for email verification and password recovery;
  • technical and security data such as IP address, date and time, browser, device, user agent, authentication attempts and security events;
  • data relating to the use of the service's features.

Passwords are never stored in plain text; they are protected with secure hashing techniques.

3. Purposes of processing

Data may be processed for: account creation and management; authentication; email address verification; security and abuse prevention; account recovery; support; legal compliance; protection of rights; MondoPet newsletters and direct marketing, only where the applicable conditions are met and with consent where required; communication to third parties for commercial purposes, exclusively with specific, separate consent where required.

4. Legal basis

Account creation and management and the provision of the requested services are based, depending on the activity, on the performance of a contract or pre-contractual measures. Legal compliance is based on legal obligation. Certain security and protection activities may be based on legitimate interest, subject to verification of the relevant conditions. Newsletters, consent-based marketing and communication to third parties for promotional purposes are carried out only where the conditions set by law are met and, where required, on the basis of consent.

5. Mandatory and optional provision of data

The data needed to create and manage the account must be provided in order to use the service. Consent for newsletters/marketing and consent for communication to third parties are optional: refusing them does not prevent registration or the use of normal features.

6. Processing methods and security

Data are processed using IT and telematic tools, adopting technical and organisational measures appropriate to the risk. Measures may include authentication, access control, session protection, encrypted communications, password hashing, security event logging, backups and updates.

7. Data retention

Account data are kept for the duration of the relationship and, afterwards, for the period necessary to comply with legal obligations or protect rights.

Technical logs and IP addresses: [period to be defined, e.g. 90/180 days], except for further needs arising from incidents, requests from authorities or judicial protection. Authentication attempts and security events: [to be defined].

Email-verification and password-recovery tokens are temporary and are invalidated on expiry or after use.

The information needed to prove the acquisition, modification or withdrawal of consents may be kept for the period necessary to document compliance with the applicable obligations.

8. Record of consents

MondoPet may keep proof of the declarations and consents expressed by the user, including user identifier, type of consent/declaration, status, date and time, version of the policy or text presented, any withdrawal/change and the technical information reasonably necessary to document the operation.

9. Recipients

Data may be processed by authorised personnel and by suppliers necessary for the operation of the service, such as hosting, IT infrastructure, email, maintenance, security, support and backup providers. Where applicable, these parties act as data processors. Data may also be disclosed to authorities where required by law.

For any communication to third parties for marketing purposes, the categories of recipients, the data communicated, the purposes and the methods must be precisely defined before activation.

10. Transfers outside the EEA

Should the suppliers actually used involve transfers outside the European Economic Area, such transfers must comply with the GDPR and will be described in the final policy.

11. Rights of the data subject

Where provided for, data subjects may exercise the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Withdrawal does not affect the lawfulness of processing carried out before it.

Requests: [MondoPet privacy email]. Data subjects may also lodge a complaint with the competent supervisory authority.

12. Changes to this policy

MondoPet may update this policy following regulatory, technical or organisational changes. The updated version will state its version number and effective date. Where necessary, a new declaration by the user will be requested.