Privacy Policy

This Application collects some Personal Data from its Users.

This document can be printed using the print command available in the settings of any browser.

Data Controller

MADDALOZZO BRUNO
Tax Code: MDDBRN56P17A443G
Tel. 0439 588033
Email inform.az@libero.it
PEC bmaddalozzo@pec.it

Data Controller's email address: bmaddalozzo@pec.it

Types of Data collected

Among the Personal Data collected by this Application, either independently or through third parties, there are: Usage Data; Tracking Tools; number of Users; session statistics.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific informational texts displayed before the Data collection itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to communicate it, it may be impossible for this Application to provide the Service. In cases where this Application indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequences on the availability of the Service or its operability.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
The possible use of Cookies - or other tracking tools - by this Application or the owners of third-party services used by this Application has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application.

Methods and place of processing of collected Data

Processing methods

The Data Controller adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification or destruction of Personal Data.
Processing is carried out using computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes. In addition to the Data Controller, in some cases, other subjects involved in the organization of this Application may have access to the Data (administrative, commercial, marketing, legal staff, system administrators) or external subjects (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Processors can always be requested from the Data Controller.

Location

Data is processed at the Data Controller's operating locations and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section relating to details on the processing of Personal Data.

Retention period

Unless otherwise indicated in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to any legal obligations or based on Users' consent.

Purposes of Processing of collected Data

The User's Data is collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), identify any malicious or fraudulent activities, as well as for the following purposes: Display of content from external platforms, Tag management and Statistics.

To obtain detailed information on the processing purposes and on the Personal Data processed for each purpose, the User can refer to the section "Details on the processing of Personal Data".

Details on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Tag management

This type of service is functional to the centralized management of tags or scripts used on this Application.
The use of such services involves the flow of User Data through them and, if applicable, their retention.

Google Tag Manager (Google Ireland Limited)

Google Tag Manager is a tag management service provided by Google Ireland Limited.

Personal Data processed: Usage Data; Tracking Tools.

Place of processing: Ireland -- Privacy Policy.

Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to track User behavior.

Google Analytics 4 (Google Ireland Limited)

Google Analytics is a statistics service provided by Google Ireland Limited ("Google"). Google uses the Personal Data collected to track and examine the use of this Application, compile reports and share them with other services developed by Google.

Google may use Personal Data to contextualize and personalize ads on its advertising network.

In Google Analytics 4, IP addresses are used at the time of collection and then deleted before data is recorded in any data center or server. To learn more, you can consult Google's official documentation. For an understanding of Google's data usage, please consult Google's partner policies.

Personal Data processed: Usage Data; number of Users; session statistics; Tracking Tools.

Place of processing: Ireland -- Privacy Policy -- Opt Out.

Image Processing Service (Face Swap)

This Application offers an optional service for personalizing souvenir postcards ("Village Card") through intelligent face replacement technology (face swap). The use of this service involves the processing of personal data according to the methods described in this section.

Service Description

The service allows users to:

The use of the face swap service is completely optional. Users can download the postcard keeping the original image without transmitting any personal data to third-party systems.

Face-Related Data Collected

The application exclusively collects:

The app does not collect or permanently store biometric templates, facial prints, or other persistent biometric identifiers.

Intended Uses of Face-Related Data

Face-related data is used exclusively for the following purposes:

  1. Face swap processing: a. Intelligent replacement of the face present in the historical photo with the user's face b. Generation of the personalized postcard
  2. Necessary technical purposes: a. Optimization of processing quality b. Image adaptation to the dimensions and characteristics of the historical photo c. Guarantee of proper service functioning

Non-intended uses include:

Legal Basis

Processing is based on the user's explicit consent, manifested through:

Sharing with Third Parties and Storage

Face-related data is shared with third parties for service operation:

Third parties involved:
Service name: PiAPI

Description: Web service specialising in intelligent face replacement

How the service works:PiAPI’s Faceswap API is based on a custom AI model, which allows developers to integrate advanced face swapping capability into their own apps or platforms, providing their users with the ability to quickly personalize desired images. Faceswap API is created for developers who want to incorporate face swapping capabilities into their generative AI software applications. This feature is ideal for social apps, picture editing apps, and/or entertainment apps. Non-developers can also use our API with tools such as Postman/Make/Zapier to swap faces as well.

Sharing methods:

Where information will be stored:

Retention Period for Face-Related Data

Data storage has these durations:

  1. On external provider's servers:
  1. Duration: 3 days from the date of service use
  2. Deletion: Automatic and definitive at the end of the period
  1. On devices and Application servers:
  1. Original biometric data is never stored on Application servers
  2. Duration: Only finished postcards (without biometric data) are stored for 7 days
  3. Deletion: Automatic and definitive at the end of the period

Specific timelines of the processing phase:

No permanent data storage is planned or technically possible.

User Rights

Users maintain all rights provided by the GDPR, including:

For the exercise of rights relating to data processed by the external service, the Data Controller will provide assistance within the limits of its technical possibilities.

Cookie Policy

This Application uses Tracking Tools. To learn more, Users can consult the Cookie Policy.

Additional information for users

Legal basis for processing

The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

It is always possible to ask the Data Controller to clarify the specific legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract or necessary to conclude a contract.

Additional information on storage time

Unless otherwise indicated in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to any legal obligations or based on Users' consent.

Therefore:

When processing is based on the User's consent, the Data Controller may retain Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period to comply with a legal obligation or by order of an authority.

At the end of the retention period, Personal Data will be deleted. Therefore, upon expiration of this term, the right of access, deletion, rectification and the right to data portability can no longer be exercised.

User rights under the General Data Protection Regulation (GDPR)

Users may exercise certain rights with reference to Data processed by the Data Controller.

In particular, within the limits provided by law, the User has the right to:

Users have the right to obtain information regarding the legal basis for data transfer abroad including to any international organization governed by international law or established by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect their Data.

How to exercise rights

Any requests to exercise User rights can be addressed to the Data Controller through the contacts provided in this document. The request is free and the Data Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectifications, deletions or processing restrictions will be communicated by the Data Controller to each of the recipients, if any, to whom the Personal Data has been transmitted, unless this proves impossible or involves a disproportionate effort. The Data Controller communicates such recipients to the User if requested.

Additional information on processing

Legal defense

The User's Personal Data may be used by the Data Controller in court or in the preparatory phases for its possible establishment for defense against abuse in the use of this Application or related Services by the User.
The User declares to be aware that the Data Controller may be obliged to reveal the Data by order of public authorities.

Specific information

Upon User request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operational and maintenance needs, this Application and any third-party services it uses may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application as well as, where technically and legally feasible, sending a notification to Users through one of the contact details in its possession. It is therefore recommended to consult this page frequently, referring to the date of last modification indicated at the bottom.

Should the changes affect processing whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

Any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable constitutes personal data.

Usage Data

This is information collected automatically through this Application (including from third-party applications integrated into this Application), including: IP addresses or domain names of computers used by Users connecting to this Application, addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful outcome, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example, the time spent on each page) and the details relating to the itinerary followed within the Application, with particular reference to the sequence of pages consulted, to the parameters relating to the operating system and the User's computer environment.

User

The individual using this Application who, unless otherwise specified, corresponds to the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural person, legal person, public administration and any other entity that processes personal data on behalf of the Data Controller, according to what is set out in this privacy policy.

Data Controller (or Controller)

The natural or legal person, public authority, service or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

This Application

The hardware or software tool through which the Users' Personal Data is collected and processed.

Service

The Service provided by this Application as defined in the related terms (if present) on this site/application.

European Union (or EU)

Unless otherwise specified, all references to the European Union contained in this document are intended to be extended to all current member states of the European Union and the European Economic Area.

Cookies

Cookies are Tracking Tools consisting of small portions of data stored within the User's browser.

Tracking Tool

Tracking Tool means any technology - e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that allows Users to be tracked, for example by collecting or saving information on the User's device.

Legal references

Unless otherwise specified, this privacy policy relates exclusively to this Application.

Last modified: August 07, 2025