Privacy Policy
1. Introduction
1.1 Purpose of the Privacy Policy
This Privacy Policy explains how Going Macro SRL, the parent company of Intra.FM, collects, uses, discloses, and protects the personal and non-personal data of users. It outlines the measures we take to ensure the confidentiality and integrity of the information we collect and informs users about their rights regarding their data. Our goal is to provide a transparent and clear understanding of our data practices to foster trust and compliance with applicable privacy laws.
1.2 Scope and Application
This Privacy Policy applies to all users of the Intra.FM app and related services, including visitors to our website, individuals who contact us via email or other means, and any other interactions with our company. It covers data collected through the app, website, and any other platform operated by Going Macro SRL, including manual and automated processes. The policy is designed to comply with international data protection regulations, including the European Union's General Data Protection Regulation (GDPR) and other relevant laws.
1.3 Definitions
For the purposes of this Privacy Policy, the following definitions apply:
"Personal Data" refers to any information relating to an identified or identifiable natural person. This may include, but is not limited to, names, email addresses, IP addresses, and other information that can identify an individual.
"Non-Personal Data" refers to information that cannot be used to identify an individual, such as aggregated or anonymized data.
"Processing" refers to any operation or set of operations performed on Personal Data, whether automated or not, including collection, storage, use, disclosure, and deletion.
"User" refers to any individual who accesses or uses the Intra.FM app or website.
"Third-Party Service Providers" refers to external companies or individuals engaged by Going Macro SRL to perform functions on our behalf, such as hosting, analytics, and customer support.
1.4 Acceptance of Policy
By using the Intra.FM app, website, or services, users acknowledge that they have read and understood this Privacy Policy. Users who do not agree with the terms outlined in this policy should discontinue use of the app and related services immediately. Continued use of our services constitutes acceptance of this Privacy Policy and any updates or modifications made to it.
1.5 Changes to the Privacy Policy
Going Macro SRL reserves the right to update or modify this Privacy Policy at any time. Users will be notified of significant changes via email or through prominent notices within the app or website. The effective date of the current version will be clearly stated at the beginning of the policy. Users are encouraged to review this policy periodically to stay informed of any updates.
2. Data Collection
2.1 Types of Data Collected
Going Macro SRL collects various types of data to provide and improve the services offered through the Intra.FM app. This data can be broadly categorized into Personal Data and Non-Personal Data.
2.1.1 Personal Data
Personal Data refers to information that can identify an individual, either directly or indirectly. This may include, but is not limited to:
Contact Information: such as name, email address, phone number, and postal address.
Account Information: such as username, password, and company affiliation.
Demographic Information: such as age, gender, and language preferences.
Usage Data: such as user activity, preferences, and settings within the app.
Payment Information: such as billing address, credit card details, and transaction history (collected and processed by third-party payment processors).
2.1.2 Non-Personal Data
Non-Personal Data refers to information that cannot be used to identify an individual. This includes aggregated data, anonymized data, and other data that is stripped of personal identifiers. Examples include:
Technical Data: such as device type, operating system, browser type, IP address, and app version.
Usage Statistics: such as pages visited, time spent on the app, and user interactions with features.
Performance Data: such as error logs, crash reports, and system diagnostics.
2.2 Methods of Data Collection
We collect data through various methods, including:
Direct Collection: Information provided by users directly through registration forms, account settings, and communication with customer support.
Automated Collection: Information automatically collected through cookies, tracking technologies, and analytics tools when users interact with the app or website. This may include the use of third-party tools like Google Analytics.
Third-Party Collection: Information obtained from third-party services that users link to their accounts, such as Google or Microsoft Entra ID for authentication.
2.3 Data Collected from Third Parties
In some cases, we may collect data from third-party sources to enhance our services. This includes:
Social Media Platforms: If users link their accounts to social media platforms, we may collect publicly available information from those platforms, subject to the user’s privacy settings on those platforms.
Service Providers: Data from third-party service providers, such as payment processors, for transaction processing and fraud prevention.
Corporate Clients: Information provided by companies for the purpose of managing user access to specific workspaces and content.
2.4 Purpose of Data Collection
The data collected is used to:
Provide Services: To facilitate access to and use of the app, including account management, content access, and customer support.
Personalize User Experience: To tailor content, recommendations, and communications based on user preferences and behavior.
Improve Services: To understand user behavior, analyze trends, and enhance the functionality and security of the app.
Marketing and Communications: To send promotional materials, updates, and other communications, subject to user preferences and consent.
Compliance and Legal Obligations: To comply with legal obligations, such as tax and accounting requirements, and to enforce our Terms and Conditions.
2.5 User Consent and Data Collection
Users are informed of the data collection practices at the time of data submission and, where required, consent is obtained. Users have the right to withdraw consent at any time by contacting our Data Protection Officer or using the tools provided within the app to manage their data preferences.
2.6 Cookies and Tracking Technologies
We use cookies and similar technologies to collect data about user interactions with our app and website. These technologies help us understand user preferences and improve the user experience. Users can manage their cookie preferences through browser settings or app features.
3. Use of Data
3.1 Purposes of Data Processing
Going Macro SRL processes the data collected from users of the Intra.FM app for various legitimate business purposes, including but not limited to:
3.1.1 Service Provision
To deliver, maintain, and enhance the functionality of the app, including user authentication, content delivery, and customer support services.
3.1.2 Personalization
To customize user experiences by personalizing content, recommendations, and communications based on user preferences and interactions with the app.
3.1.3 Communication
To send administrative information, updates, promotional materials, and other communications related to the app and our services. Users can manage their communication preferences in their account settings.
3.1.4 Analytics and Performance
To analyze user behavior, app usage, and performance metrics to improve our services, develop new features, and optimize user engagement.
3.1.5 Security and Fraud Prevention
To protect the security of the app and users' data, prevent fraud, monitor for suspicious activity, and enforce our Terms and Conditions.
3.1.6 Compliance and Legal Obligations
To comply with legal requirements, such as tax laws, data protection regulations, and other applicable laws, as well as to respond to legal requests and protect the rights and safety of Going Macro SRL, our users, and the public.
3.2 Legal Basis for Processing
Our processing of Personal Data is based on several legal grounds:
3.2.1 Contractual Necessity
Processing is necessary to perform the contract between the user and Going Macro SRL, including the provision of services through the Intra.FM app.
3.2.2 Legitimate Interests
We process Personal Data based on our legitimate interests in maintaining and improving the app, securing our platform, and engaging in marketing activities. We ensure that these interests are balanced with users' rights and freedoms.
3.2.3 Consent
Where required by law, we obtain user consent for specific types of processing, such as marketing communications and the use of certain cookies. Users may withdraw their consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
3.2.4 Legal Obligations
We process data as necessary to comply with legal obligations, such as tax, accounting, and regulatory requirements.
3.3 Use of AI and Automated Processing
The Intra.FM app utilizes AI technologies to automate and enhance certain tasks, including content creation, voice synthesis, and data analysis. While these technologies help improve efficiency and personalization, they also involve automated decision-making processes. Users are informed about the use of AI and have the right to request human intervention, challenge decisions, and express their point of view regarding any automated decisions affecting them.
3.4 Data Aggregation and Anonymization
We may aggregate and anonymize Personal Data to generate statistical and analytical insights. This anonymized data does not identify individual users and may be used for research, analytics, and marketing purposes, as well as to improve the overall functionality of the app.
3.5 Third-Party Services and Integrations
We may share data with third-party service providers and partners who assist us in delivering our services. These third parties are contractually obligated to use the data solely for the purposes of providing services to us and must adhere to stringent data protection standards. Users are encouraged to review the privacy policies of these third parties, as they may have different practices and standards.
3.6 User Responsibility and Content
Users are responsible for the content they upload or create using the Intra.FM app, including any data processed through AI tools. Going Macro SRL disclaims any liability for content accuracy, quality, or legality, particularly regarding AI-generated outputs. Users must ensure their content complies with applicable laws and does not infringe on the rights of others.
4. Data Sharing and Disclosure
4.1 Third-Party Service Providers
Going Macro SRL may share Personal Data with third-party service providers who perform services on our behalf. These services include, but are not limited to, hosting, data analysis, payment processing, customer service, and marketing assistance. Our service providers are contractually bound to protect the confidentiality and security of Personal Data and are prohibited from using the data for any purpose other than to perform services as instructed by Going Macro SRL.
4.2 Affiliates and Partners
We may share data with our affiliates and partners within the Going Macro SRL corporate group for the purposes of providing and improving our services, offering joint products or services, and for marketing communications, subject to users' consent where required by law. All affiliates and partners are required to uphold privacy and data protection standards consistent with this Privacy Policy.
4.3 Legal Obligations
Going Macro SRL may disclose Personal Data when required to do so by law or in response to valid requests by public authorities, such as courts, law enforcement agencies, or regulatory bodies. This may include disclosures necessary to:
Comply with legal obligations or court orders.
Protect and defend our rights or property.
Prevent or investigate possible wrongdoing in connection with our services.
Protect the personal safety of users or the public.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, Personal Data may be transferred as part of the transaction. We will notify users if their data becomes subject to a different privacy policy as a result of such a transfer. Going Macro SRL will ensure that any party acquiring or merging with us agrees to adhere to this Privacy Policy or implements a substantially similar policy that provides similar levels of data protection.
4.5 Data Sharing With User Consent
We may share Personal Data with third parties outside the scope of this Privacy Policy only when we have users' explicit consent to do so. This consent may be obtained in various forms, such as through opt-in mechanisms at the time of data collection or through user settings in the app.
4.6 Public and Aggregated Information
Going Macro SRL may share aggregated, anonymized, or de-identified data that does not identify individual users with third parties for research, analytics, marketing, or other purposes. This data does not contain any Personal Data and cannot be used to identify or re-identify any user.
4.7 International Data Transfers
Personal Data may be transferred to, and maintained on, servers and databases located outside of the user's country of residence, including to countries that may not have the same data protection laws as the user's home country. Going Macro SRL ensures that any international transfer of Personal Data complies with applicable data protection laws, including the implementation of adequate safeguards such as Standard Contractual Clauses (SCCs) or reliance on Privacy Shield frameworks, where applicable. Users are informed and, where necessary, consent is obtained for such transfers.
4.8 User Responsibility
Users are responsible for any data they choose to share publicly or with other users through the Intra.FM app, including sensitive information. Going Macro SRL is not responsible for the privacy practices of other users or third parties with whom users choose to share their information.
5. Data Security
5.1 Security Measures
Going Macro SRL is committed to protecting the security of Personal Data. We employ a variety of technical, administrative, and physical safeguards to help protect data from unauthorized access, use, disclosure, alteration, or destruction. Our security measures include, but are not limited to:
Data Encryption: We use industry-standard encryption technologies, such as SSL/TLS, to protect data in transit and at rest, ensuring that sensitive information is securely transmitted and stored.
Access Controls: Access to Personal Data is restricted to authorized personnel who have a legitimate business need to access the information. Access controls include multi-factor authentication, role-based access controls, and regular audits of access privileges.
Security Monitoring: We continuously monitor our systems and infrastructure for potential vulnerabilities and threats. This includes the use of intrusion detection systems, firewalls, and security information and event management (SIEM) systems.
Data Anonymization and Pseudonymization: Where applicable, we use techniques such as data anonymization and pseudonymization to minimize the exposure of Personal Data.
5.2 Data Encryption and Protection
All sensitive data, including Personal Data and payment information, is encrypted during transmission using secure protocols (e.g., HTTPS). At rest, data is stored using advanced encryption algorithms to prevent unauthorized access. Encryption keys are managed securely, with regular key rotation and auditing processes in place.
5.3 Physical Security
Data centers and server facilities used by Going Macro SRL and its third-party service providers are protected by physical security measures, including biometric access controls, 24/7 surveillance, and secure access policies. These facilities are compliant with industry standards and certifications such as ISO 27001 and SOC 2, ensuring that they meet rigorous security requirements.
5.4 Incident Response and Breach Notification
Going Macro SRL has a comprehensive incident response plan to address potential data breaches or security incidents. In the event of a data breach that affects the security of Personal Data, we will notify affected users and relevant regulatory authorities in accordance with applicable laws. Our notification will include information about the nature of the breach, the affected data, and the steps we are taking to mitigate the impact.
5.5 User Responsibility
While Going Macro SRL takes significant measures to protect Personal Data, users also play a crucial role in maintaining the security of their information. Users are responsible for keeping their account credentials confidential and secure. We advise users to:
Use strong, unique passwords for their accounts.
Regularly update their passwords and monitor account activity.
Enable multi-factor authentication where available.
Avoid sharing sensitive information over unsecured channels.
5.6 Third-Party Security
We work with reputable third-party service providers that implement robust security measures. However, we cannot guarantee the absolute security of data stored or processed by third parties. Users acknowledge that the transmission of information via the internet is not completely secure, and any transmission is at the user's own risk. Going Macro SRL is not liable for security breaches caused by third-party providers.
5.7 Security Audits and Compliance
We conduct regular security audits and assessments to evaluate our data protection practices and ensure compliance with relevant security standards and regulations. We also engage third-party security experts to perform penetration testing and vulnerability assessments to identify and address potential security weaknesses.
6. Data Retention
6.1 Retention Periods
Going Macro SRL retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, and to comply with legal, regulatory, or internal policy requirements. The specific retention periods for different types of data are as follows:
Account Information: Retained for the duration of the user's account and up to 12 months after account closure, unless a longer retention period is required or permitted by law.
Transaction and Payment Information: Retained for a minimum of 10 years to comply with tax, accounting, and financial regulations.
Usage Data and Analytics: Retained for up to 5 years from the date of collection for analytical and service improvement purposes, after which it is either deleted or anonymized.
Communications and Support Data: Retained for as long as necessary to resolve inquiries, provide support, and maintain a record of communications.
6.2 Criteria for Determining Retention Periods
The criteria used to determine our retention periods include:
The Nature of the Data: Sensitive data may be retained for shorter periods to minimize privacy risks.
Legal Obligations: Compliance with applicable laws, such as financial regulations and data protection laws, may require the retention of certain data for specific periods.
Business Needs: Data may be retained to maintain accurate business records, comply with contractual obligations, and improve our services.
User Requests: Users may request the deletion of their Personal Data at any time, subject to our data retention policies and legal obligations.
6.3 Data Deletion and Anonymization
Upon the expiration of the applicable retention period, or at the user's request, Going Macro SRL will securely delete or anonymize Personal Data, rendering it irrecoverable. Anonymization processes include the removal or transformation of data elements that could directly or indirectly identify an individual. This ensures that the data can no longer be linked to any specific user.
6.4 User Rights to Data Deletion
Users have the right to request the deletion of their Personal Data under certain circumstances, as provided by applicable data protection laws. This may include situations where the data is no longer necessary for the purposes for which it was collected, the user has withdrawn consent, or the processing is unlawful. Users can exercise this right by contacting our Data Protection Officer at info@goingmacro.it. We will respond to deletion requests in accordance with applicable laws and ensure that any retained data complies with legal obligations.
6.5 Exceptions to Deletion
In certain situations, Going Macro SRL may be required to retain data beyond the user's request for deletion. Exceptions include:
Legal Compliance: Retaining data to comply with legal or regulatory obligations, such as financial record-keeping.
Dispute Resolution: Retaining data necessary to resolve disputes, enforce our agreements, or defend against legal claims.
Security and Fraud Prevention: Retaining data to prevent fraud, abuse, or violations of our terms and policies.
6.6 Data Backup and Recovery
We implement data backup and recovery procedures to protect against data loss. While backups are stored securely, they may contain data that has been deleted from our primary systems. Backup data is subject to regular review and secure deletion practices to ensure compliance with our retention policies.
7. User Rights and Data Protection
7.1 Right to Access
Users have the right to request access to their Personal Data held by Going Macro SRL. This includes the right to obtain confirmation as to whether or not their data is being processed, and if so, to access the data and obtain information about the purposes of processing, the categories of data involved, and the recipients or categories of recipients with whom the data may be shared. Users can exercise this right by submitting a request to our Data Protection Officer at info@goingmacro.it.
7.2 Right to Rectification
Users have the right to request the correction of inaccurate or incomplete Personal Data. If a user believes that their data is incorrect or outdated, they may contact us to request its rectification. Users can also update certain information through their account settings in the Intra.FM app.
7.3 Right to Erasure (Right to Be Forgotten)
Users may request the deletion of their Personal Data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected, the user has withdrawn their consent, or the data has been unlawfully processed. We will comply with such requests in accordance with applicable laws, ensuring that data is securely deleted from our systems.
7.4 Right to Restriction of Processing
Users have the right to request the restriction of processing of their Personal Data in specific circumstances, such as when they contest the accuracy of the data, object to the processing, or require the data for legal claims while it is no longer needed for its original purpose. When processing is restricted, we will continue to store the data but will not process it further without the user's consent, except as permitted by law.
7.5 Right to Data Portability
Users have the right to receive their Personal Data in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller, where technically feasible. This right applies only to data provided by the user and processed based on consent or the performance of a contract.
7.6 Right to Object
Users may object to the processing of their Personal Data for specific purposes, such as direct marketing or profiling, at any time. If a user objects, we will cease the processing of their data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override the user's interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
7.7 Right to Withdraw Consent
Where processing is based on the user's consent, they have the right to withdraw their consent at any time. This withdrawal will not affect the lawfulness of processing based on consent before its withdrawal. Users can manage their consent preferences through their account settings or by contacting our Data Protection Officer.
7.8 Right to Lodge a Complaint
Users have the right to lodge a complaint with a supervisory authority if they believe that the processing of their Personal Data infringes applicable data protection laws. In Italy, the supervisory authority is the Garante della Privacy (Italian Data Protection Authority). Users may also seek judicial remedies for any infringements of their rights.
7.9 Exercising User Rights
To exercise any of the rights described above, users may contact our Data Protection Officer at info@goingmacro.it. We will respond to requests in accordance with applicable laws, typically within one month of receiving the request. We may request additional information to verify the user's identity before processing the request.
7.10 Limitations and Exceptions
Certain limitations and exceptions may apply to the exercise of these rights. For example, we may not be able to comply with a request for data erasure if the retention of data is necessary for compliance with legal obligations, the establishment, exercise, or defense of legal claims, or other legitimate purposes. In such cases, we will inform the user of the specific reason for denying their request.
8. Cookies and Tracking Technologies
8.1 Use of Cookies and Similar Technologies
Going Macro SRL uses cookies and similar tracking technologies (collectively referred to as "Cookies") on the Intra.FM app and associated websites to enhance user experience, analyze site usage, and assist in our marketing efforts. Cookies are small text files stored on a user's device that allow us to recognize the device and remember certain information about the user's visit.
8.2 Types of Cookies We Use
We utilize various types of Cookies, including:
Essential Cookies: These Cookies are necessary for the app's core functionalities, such as security, network management, and accessibility. Without these Cookies, the app cannot function properly.
Analytical/Performance Cookies: These Cookies collect information about how users interact with the app, including pages visited and any errors encountered. This data helps us improve the app's performance and user experience.
Functional Cookies: These Cookies allow the app to remember user preferences and settings, such as language preferences and login details, providing a more personalized experience.
Marketing/Advertising Cookies: These Cookies track user activity across the app and other websites to deliver targeted advertisements based on user interests. They also help measure the effectiveness of our marketing campaigns.
Third-Party Cookies: We may use third-party service providers that set Cookies on our behalf to assist in analyzing app usage and delivering advertisements. These third parties may have their own privacy policies regarding their use of Cookies.
8.3 Purpose of Cookies
The primary purposes of using Cookies are:
Authentication and Security: To identify and authenticate users, prevent fraudulent use of accounts, and protect user data from unauthorized parties.
Preferences and Features: To remember user settings and preferences, such as language, region, and accessibility options.
Performance and Analytics: To collect data on how users interact with the app, enabling us to improve the user experience and optimize our services.
Marketing and Advertising: To deliver relevant content and advertisements, measure the effectiveness of marketing campaigns, and track user engagement.
8.4 User Control and Cookie Management
Users have the right to control and manage their Cookie preferences. Users can adjust their browser settings to accept, reject, or delete Cookies. However, please note that disabling Cookies may impact the functionality and performance of the app, and some features may not work as intended.
Browser Settings: Users can configure their browser settings to refuse all or some Cookies or to alert them when Cookies are being set. The procedure for managing Cookies varies depending on the browser. Users can refer to their browser's help or support section for instructions.
Opt-Out Mechanisms: Some third-party service providers offer opt-out mechanisms for interest-based advertising. Users can visit the Network Advertising Initiative (NAI) or the Digital Advertising Alliance (DAA) websites for more information on how to opt out.
8.5 Third-Party Analytics and Advertising
We may use third-party analytics and advertising services that employ Cookies and similar technologies to collect information about user interactions with the app and other websites. These services may include Google Analytics, Facebook Pixel, and others. The data collected may be used by these third parties to analyze and track data, determine the popularity of certain content, and deliver advertisements tailored to user interests.
8.6 Cookie Consent
By using the Intra.FM app and associated websites, users consent to the use of Cookies in accordance with this Privacy Policy. Users can withdraw their consent at any time by adjusting their Cookie preferences or browser settings, as described above.
8.7 Changes to Cookie Policy
We may update our use of Cookies and related technologies from time to time, and any changes will be reflected in this section. Users are encouraged to review this section periodically to stay informed about our use of Cookies and their choices.
9. International Data Transfers
9.1 Scope of International Transfers
Going Macro SRL may transfer Personal Data collected from users in the European Economic Area (EEA) and other regions to countries outside of the EEA, including to servers and third-party service providers located in the United States and other jurisdictions. These transfers are necessary for the provision of our services and for the management of our business operations.
9.2 Legal Basis for International Transfers
We ensure that international transfers of Personal Data are conducted in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR). The legal basis for these transfers includes:
Performance of a Contract: Transfers necessary for the performance of a contract between Going Macro SRL and the user, or for the implementation of pre-contractual measures taken at the user's request.
Consent: In certain cases, users may be required to provide explicit consent for the transfer of their data to third countries. This consent can be withdrawn at any time.
Legitimate Interests: Transfers based on our legitimate interests, provided that such interests are not overridden by the user's fundamental rights and freedoms.
9.3 Adequacy Decisions
Where applicable, we rely on adequacy decisions made by the European Commission, which determine that certain countries outside the EEA provide an adequate level of data protection. Personal Data transferred to these countries is protected in a manner consistent with EU standards.
9.4 Standard Contractual Clauses (SCCs)
For countries that do not have an adequacy decision, we use Standard Contractual Clauses (SCCs) approved by the European Commission as a legal mechanism for data transfers. These SCCs provide appropriate safeguards for the protection of Personal Data, ensuring that data transferred outside the EEA is subject to equivalent protections as those provided within the EEA.
9.5 Additional Safeguards
In addition to SCCs, Going Macro SRL implements supplementary measures to ensure the security and confidentiality of Personal Data during international transfers. These measures may include:
Encryption: Utilizing strong encryption protocols to protect data during transit and storage.
Access Controls: Limiting access to Personal Data to authorized personnel and ensuring that third-party providers have adequate security measures in place.
Data Minimization: Limiting the amount of Personal Data transferred and ensuring that only the data necessary for specific purposes is shared.
9.6 User Rights in Relation to International Transfers
Users have the right to be informed about the safeguards in place for international data transfers and to request a copy of the relevant documentation, such as the SCCs, where applicable. Users can exercise these rights by contacting our Data Protection Officer at info@goingmacro.it
9.7 Risks Associated with International Transfers
While Going Macro SRL takes all reasonable measures to protect Personal Data during international transfers, users should be aware that data protection laws in some jurisdictions may not offer the same level of protection as those in the EEA. By using our services and providing Personal Data, users acknowledge and accept these potential risks.
9.8 Continual Assessment and Compliance
We regularly review and assess our international data transfer practices to ensure compliance with applicable laws and regulations. We are committed to maintaining a high standard of data protection and will take appropriate actions if any changes in the legal landscape require adjustments to our transfer mechanisms.
10. Children's Privacy
10.1 Intended Audience
The Intra.FM app is a business-oriented platform designed exclusively for use by corporate clients and their employees. It is not intended for personal use or for individuals outside of a corporate or professional context. Consequently, the app is not designed, marketed, or intended for use by children or minors under the age of 18.
10.2 Age Restriction
Users must be at least 18 years old to use the Intra.FM app. By accessing or using the app, users represent and warrant that they are at least 18 years of age. We do not knowingly collect, solicit, or store Personal Data from individuals under the age of 18. If we become aware that we have inadvertently collected Personal Data from a user under the age of 18, we will take immediate steps to delete such information from our records.
10.3 Employer Responsibility
As the Intra.FM app is used in a professional setting, it is the responsibility of employers to ensure that their use of the app complies with applicable employment laws and regulations, including those concerning the employment and protection of minors. Employers are responsible for verifying the age of their employees and ensuring that only individuals who meet the age requirement have access to the app.
10.4 Parental Rights
In the unlikely event that Personal Data from a minor is collected, parents or legal guardians have the right to review and request the deletion of their child's information. If a parent or guardian becomes aware that their child has provided us with Personal Data without their consent, they should contact our Data Protection Officer at info@goingmacro.it. We will take prompt action to remove the information and ensure that the minor's data is not retained or used in any way.
10.5 Compliance and Monitoring
Going Macro SRL is committed to ensuring that our platform adheres to all relevant regulations concerning the privacy and protection of minors. While the app is not designed for use by minors, we regularly review our data collection and processing practices to prevent the unauthorized handling of Personal Data from individuals under 18.
10.6 Notification of Changes
If we make any changes to this section of the Privacy Policy, we will notify users through appropriate means, such as email or in-app notifications, especially if these changes affect how we handle data related to age restrictions. Users are encouraged to review this section periodically to stay informed about our policies regarding children's privacy.
11. Security Measures
11.1 Commitment to Data Security
Going Macro SRL is committed to protecting the confidentiality, integrity, and availability of Personal Data. We employ a comprehensive security program that incorporates administrative, technical, and physical safeguards to protect against unauthorized access, alteration, disclosure, or destruction of Personal Data.
11.2 Technical Safeguards
We implement a range of technical security measures to protect Personal Data, including but not limited to:
Encryption: All data transmissions between users and our servers are encrypted using industry-standard encryption protocols (e.g., TLS). Data at rest is also encrypted to ensure its protection.
Access Controls: Access to Personal Data is restricted to authorized personnel who require access to perform their job duties. We utilize multi-factor authentication, role-based access controls, and other security mechanisms to enforce access restrictions.
Network Security: Our systems are protected by firewalls, intrusion detection and prevention systems, and regular vulnerability assessments. We monitor our network for security incidents and respond promptly to any detected threats.
11.3 Administrative Safeguards
Our administrative safeguards include:
Data Protection Policies: We have established comprehensive data protection policies and procedures to ensure that all employees, contractors, and third-party service providers understand and comply with data protection requirements.
Employee Training: We provide regular training and awareness programs to employees regarding data protection and security best practices. This training includes recognizing and reporting security incidents, phishing, and other potential threats.
Vendor Management: We conduct thorough due diligence on third-party service providers and require them to adhere to stringent data protection standards. We enter into data processing agreements with these providers to ensure they implement appropriate security measures.
11.4 Physical Safeguards
Physical security measures include:
Secure Facilities: Access to data processing facilities is controlled and monitored. We use security systems, such as surveillance cameras and access card systems, to prevent unauthorized physical access.
Data Storage: All Personal Data is stored on secure servers located in Europe, protected by robust physical security measures. Only authorized personnel are allowed access to these facilities.
11.5 Incident Response and Breach Notification
Despite our efforts, no security measure is entirely infallible. In the event of a data breach that affects the security of Personal Data, Going Macro SRL has an incident response plan in place. This plan includes:
Immediate Action: Prompt investigation and containment of the breach to mitigate any potential harm.
Notification: If a data breach poses a high risk to users' rights and freedoms, we will notify the affected individuals and the relevant data protection authorities without undue delay, in accordance with applicable laws and regulations.
Remediation: Taking appropriate steps to remedy the breach and prevent future incidents, including reviewing and improving security measures.
11.6 User Responsibilities
While Going Macro SRL takes extensive measures to protect Personal Data, users also play a role in maintaining the security of their information. Users are responsible for:
Keeping Credentials Secure: Users must keep their account credentials confidential and not share them with anyone. They should use strong, unique passwords and change them regularly.
Recognizing Phishing Attempts: Users should be vigilant against phishing attempts and report any suspicious activity or communications to us immediately.
11.7 Review and Improvement
We continuously review and update our security measures to keep pace with evolving threats and technological advancements. Regular audits and assessments are conducted to evaluate the effectiveness of our security controls and identify areas for improvement.
11.8 Limitation of Liability
While we strive to protect Personal Data, users acknowledge that no method of transmission or storage is completely secure. As such, we cannot guarantee absolute security. Users agree that Going Macro SRL is not liable for any unauthorized access to Personal Data that is beyond our reasonable control.
13. Third-Party Services and Integrations
13.1 Overview
Going Macro SRL collaborates with various third-party services and integrates their technologies into the Intra.FM app to enhance user experience, streamline processes, and provide robust functionalities. This section outlines our use of third-party services and integrations, including their role in data processing and user authentication.
13.2 Third-Party Websites and Services
The Intra.FM app and associated websites, including www.intra.fm and www.corporatefm.it, may contain links to third-party websites or services not operated or controlled by Going Macro SRL. While we strive to work with reputable third parties, we are not responsible for the content, privacy policies, or practices of these external sites. Users are encouraged to review the privacy policies of any third-party websites they visit.
13.3 Integrations with Third-Party Services
To provide a seamless and secure experience, the Intra.FM app integrates with various third-party services, including but not limited to:
Large Language Models (LLMs): As outlined in the Terms and Conditions, the app uses LLMs such as GPT from OpenAI, Claude by Anthropic, Gemini by Google, and others for tasks like text generation, script production, and content creation. Users acknowledge that content generated by these AI models is subject to their respective terms of service and data privacy practices.
Authentication Services: User authentication is facilitated through integrations with Google and Microsoft Entra ID, providing secure login options and protecting user accounts. We do not store passwords, and authentication credentials are handled securely by these providers.
Mailgun API: We use Mailgun API services for email communications, including notifications, updates, and user support. These services may collect and store user email addresses and communication history as part of their functionality.
App Distribution Platforms: The Intra.FM app is available on the Apple App Store and Google Play Store. These platforms may collect user data in accordance with their privacy policies, including device information, app usage, and user feedback.
13.4 Data Sharing with Third-Party Services
We may share certain user data with third-party services to facilitate app functionalities, improve user experience, and provide customer support. This data sharing is governed by contractual agreements that ensure compliance with applicable data protection laws, including GDPR. Shared data may include:
Authentication Data: Basic user information, such as email addresses, necessary for authentication and account management.
Usage Data: Aggregated and anonymized data on app usage patterns, which helps third-party providers optimize their services and support our app's functionality.
13.5 Future Integrations
Going Macro SRL may incorporate additional third-party services and integrations in the future to enhance the Intra.FM app's capabilities. We will update this Privacy Policy to reflect any new integrations and ensure users are informed about how their data may be used and shared.
13.6 User Consent and Data Protection
By using the Intra.FM app and associated services, users consent to the integration and data sharing practices described in this section. We take reasonable steps to ensure that third-party providers maintain high standards of data protection and security. However, Going Macro SRL is not responsible for the privacy practices or data processing activities of these third parties.
13.7 Limitation of Liability
While we carefully select our third-party partners and strive to ensure their compliance with data protection standards, Going Macro SRL cannot be held liable for any issues or damages arising from the use of third-party services. Users acknowledge that they use these services at their own risk and that any disputes or issues should be resolved directly with the respective third parties.
13.8 Changes to Third-Party Service Use
Any changes to our use of third-party services, including the addition or removal of providers, will be communicated to users through updates to this Privacy Policy or via email. Users are encouraged to review this section periodically to stay informed about our use of third-party services.
Appendix A: Transfer of Rights and Business Entity Reorganization
A.1. Right to Reorganize Business Entities
Going Macro SRL reserves the right to create a new business entity or entities for the purposes of managing and operating the brands and products associated with Corporate-FM and/or Intra.FM. This reorganization may include, but is not limited to, the transfer of assets, operations, and responsibilities to the newly established entity or entities.
A.2. Transfer of Agreements and Terms
In the event of such a reorganization, Going Macro SRL may transfer the terms and conditions, privacy policy, and all related agreements and obligations from the existing corporate structure to the newly formed business entity or entities. This transfer will include all rights and responsibilities under these agreements, ensuring continuity of services and adherence to the established terms.
A.3. Notification to Clients and Users
Prior to any transfer of terms and conditions, privacy policy, or other contractual agreements, Going Macro SRL will notify affected clients and users. Notification will be provided via email, in-app notifications, or other appropriate channels, at least 14 days in advance of the transfer. The notification will include relevant details about the new business entity and any potential impacts on users.
A.4. User and Client Acknowledgement
By agreeing to the terms and conditions and privacy policy, users and clients acknowledge and accept the possibility of such a business entity reorganization. They further agree that their continued use of the Intra.FM app and associated services after the notification period constitutes acceptance of the transfer of agreements to the new entity.
A.5. Limitation of Liability
Going Macro SRL will not be liable for any changes in management, ownership, or operational structure resulting from the creation of a new business entity. Users and clients agree to release Going Macro SRL from any liability arising from the reorganization, provided that the services and obligations under the existing agreements are honored by the new entity.
A.6. Continued Compliance and Protection
The newly established business entity will be bound by the same commitments to data protection, security, and compliance as outlined in the original terms and conditions and privacy policy. This includes adherence to GDPR and other applicable regulations, ensuring that users' and clients' rights and data protection standards are maintained.