Last updated: 28 August 2026

This privacy policy describes the processing of personal data carried out through the website ciaq.it and the CIAQ web app dedicated to accreditations, programme, community, QR badges, event bookings and applications, and the people's jury, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).

1. Data controller

The Data Controller is INNOVA HUB ASSOCIAZIONE CULTURALE, with its registered office at Via Indipendenza 13, 67100 L’Aquila (AQ), tax code 93123260668, VAT number 02228570665.

For information on data processing or to exercise your rights, you can write to info@innovahubaq.it or to info@ciaq.it, or call the number 339 148 2007.

Scope and origin of the data

The privacy policy applies to individuals who create an account, are invited or accredited by the staff, use the digital badge, consult the programme, book or request to attend events, choose to be included in the directory and use networking, take part in the people's jury, or contact the organisation through the website or app.

Data is normally provided directly by the data subject. Some data may be entered by CIAQ staff or imported from lists prepared by the organisation to invite or accredit participants. In such cases, the privacy information is provided to the data subject within the timeframes stipulated by the GDPR.

3. Categories of data processed

  • Identification and contact details: first name, last name, display name, email address and, if provided, phone number.
  • Professional and profile details: role, any secondary roles, organisation, job title, city, country, photograph, biography, website, social media profiles, languages, sectors, interests and information that the user chooses to share with the community.
  • Account and credit details: secure credentials, edition, type and status of accreditation, registration date and email verification.
  • Event data: requested event, booking or application status, waitlist position, any reason and attendance recorded by staff.
  • Networking and moderation data: contact requests, accepted or revoked connections, blocks and reports.
  • Data relating to the lay jury: voter authorisation and information on the completion of voting. The content of the ballot paper is stored separately from the user's identity in accordance with the technical configuration of the service.
  • Preferences and declarations: majority of age, having read the privacy policy, optional choice to participate in networking and optional consent to the newsletter, with date, text version and withdrawals.
  • Technical and safety data: account and badge identifiers, temporary tokens, operation logs, date and time, IP address hashed with a secret key, technical cookies, session data and information necessary to limit abuse and repeated attempts.
  • Communication data: recipient, subject, content and technical result of the emails sent from the website, recorded in the mail system and in the email log accessible only to authorised administrators.

No special categories of personal data are requested. You are advised not to enter them in the free text fields, unless necessary and following specific instructions from the organisation.

4. Purpose and legal bases

  • Account creation and protection, email verification, credit and badge: performance of the requested service or pre-contractual measures, Art. 6.1.b GDPR.
  • Programme, bookings, applications, waiting lists, service announcements and reminders: performance of the requested service, art. 6.1.b GDPR.
  • Management of capacities, access control, security, prevention of abuse, service continuity and technical logs: legitimate interest of the Data Controller, Article 6(1)(f) GDPR.
  • Directory visibility and networking: consent, Art. 6.1.a GDPR, optional and withdrawable at any time.
  • Newsletter and promotional communications not necessary for the service: specific consent, Art. 6.1(a) GDPR, optional and revocable at any time.
  • Reports, blockages, disputes and the protection of individuals and the organisation: legitimate interest and, where necessary, the establishment, exercise or defence of legal claims.
  • Citizens' jury, prevention of multiple voting and aggregated results: performance of the requested service and legitimate interests, Articles 6(1)(b) and 6(1)(f) GDPR.
  • Legal obligations and requests from authorities: Article 6(1)(c) GDPR.
  • Measurement or marketing using non-technical tools: prior consent, Art. 6.1(a) GDPR and Section 122 of the Privacy Code.

The privacy policy checkbox serves to confirm that the user has read it; it does not constitute the legal basis for the processing activities essential for providing the service. The choices regarding the directory, networking and newsletter are optional and separate.

5. Nature of the contribution and age of majority

The fields marked as mandatory are required to create the account, verify the email and process the accreditation. Without this data it is not possible to use the restricted functions. The other fields and the choices regarding the directory, networking and newsletter are optional.

The service is restricted to individuals who declare they are at least 18 years old. Any registration by minors requires a separate procedure set up by the organisation and, where necessary, the intervention of those exercising parental responsibility.

6. Profile, directory, networking and QR badges

The profile is created hidden from the directory. The user can choose whether to make it visible and can modify the visibility of individual fields. Data set as visible in the directory can be viewed by other verified participants; those reserved for connections are shown after a contact request is accepted. Email and telephone are private by default.

The badge contains a random, revocable code, not unencrypted personal data. Anyone who possesses or scans the code can view exclusively the information provided for the badge and permitted by the visibility settings. The code can be regenerated or revoked. The current app does not create an individual scan history or personal counts of badge reads; technical requests may be processed temporarily for security and abuse prevention.

7. Bookings and automatic processes

Some events can automatically confirm a booking or place it on a waiting list based on capacity and order of arrival, while others require staff assessment. The freeing up of a space may result in the automatic promotion of the first person on the waiting list.

No profiling is carried out and no decisions are adopted based solely on automated processing, including profiling, which produce legal effects concerning the data subject or similarly significantly affect them pursuant to Article 22 of the GDPR.

8. Recipients and suppliers

The data may be processed by the Data Controller's authorised staff and collaborators and, within the limits of their respective duties, by the following suppliers:

  • VHosting Solution S.r.l., Via San Vito 18, 20123 Milan, VAT No. IT06439660827, for WordPress hosting, databases, backups, infrastructure security and email transmission via SMTP servers. The plan in use is Cloud Low Cost 01; VHosting states that the hosting service data centre is in Italy, with separate email infrastructure and data processing carried out in data centres located within the European Economic Area. The technical backups for the plan are stated to be daily with a 14-day retention period and disaster recovery replication.
  • Reflection Media S.r.l. (TranslatePress), based in Romania, for multilingual management and the TranslatePress AI service. When a page contains untranslated text, the text content, site URL, languages, plugin version, and licence information are sent to the translation service. TranslatePress can forward texts to translation engines selected from Google, DeepL, Microsoft, and other supported engines. The service must not be used to translate confidential fields or personal data entered by users.
  • WP Mail SMTP and WP Mail Logging, components installed in the WordPress environment, used respectively to route emails to the VHosting SMTP and log sent communications. The log is accessible to authorised administrators.
  • PixelYourSite and Meta Platforms Ireland Limitedthe site contains a Meta Pixel configuration designed for measuring visits and interactions. The activation of the Meta Pixel and other non-technical identifiers must only take place after user consent. Visited URLs, interactions, traffic source, UTM parameters, online identifiers and technical device data may be processed.
  • Cloudflare, Inc. – cdnjs, used on some pages to distribute technical libraries; the connection involves the communication of technical data such as IP address, browser and requested resource.
  • Automattic, Inc. – Gravatar, when images or avatars provided by the relevant service are displayed.

The site also contains links to Facebook, Instagram, WhatsApp, FilmFreeway and partner sites. A simple link does not necessarily imply the communication of data; by opening the external service, the terms and privacy policy of the respective operator apply.

Data may be disclosed to authorities and other parties when required by law or necessary to protect rights and safety. Data is not sold.

9. Transfers outside the European Economic Area

Hosting and email hosting services by VHosting are provided on infrastructures located within the European Economic Area. Certain additional providers, including the engines used by TranslatePress AI, Meta, Cloudflare and Automattic, may involve transfers to or access from countries outside the EEA. In such cases, the transfer takes place on the basis of an adequacy decision, the EU–US Data Privacy Framework where applicable, standard contractual clauses or another safeguard provided under Articles 44 et seq. of the GDPR.

10. Storage

  • Account, profile, accreditation and events: As a rule, up to 12 months from the conclusion of the edition, barring renewal of the relationship, a request for deletion or the need for further retention.
  • Incomplete invitations or requests: as a rule, 6 months.
  • Verification and recovery token: until the technical expiry; the email verification link expires after 24 hours.
  • Badge for the duration of the edition or until revocation; the technical copy intended for reprint may be kept for up to 90 days.
  • Networking: until the choice is revoked, the connection is removed, or the account is deleted.
  • Reports and blocks: for the time necessary to handle the case and protect the rights involved.
  • Security, audit and mail logs: for the period proportionate to the requirements of security, assistance, proof of sending, and protection of rights, with access restricted to authorised administrators.
  • Proof of consents and withdrawals: for as long as is necessary to demonstrate compliance and handle any disputes.
  • Newsletter until the consent is revoked, retaining the minimum information necessary to document the unsubscription.

Once the applicable period has elapsed, the data shall be deleted or irreversibly anonymised, subject to legal obligations or the need to establish, exercise or defend a legal claim.

11. Cookies, local storage and offline functions

The site and the app use cookies and technical tools necessary for authentication, security, preferences and operation. Some public content, such as the programme, may be temporarily stored on the device to allow offline functions; restricted areas and personal data are not included in the app's public cache.

Unnecessary analytics, profiling or marketing tools can only be activated following a free and documentable choice by the user. Detailed information on individual cookies and the option to modify preferences must be made available via the cookie policy and the corresponding consent management panel.

12. Security

Technical and organisational measures appropriate to the risk are adopted, including encrypted connections, access control, email verification, passwords protected using WordPress secure functions, random and revocable tokens, rate limiting, logging of relevant operations, backups and pseudonymisation of IP addresses in the plugin logs. The IP address hash is pseudonymised data and not anonymous data.

13. Rights of the data subject

The data subject may request access to the data, rectification, erasure, restriction of processing, and data portability where applicable, and may object to processing based on legitimate interests. They may withdraw consents relating to networking, profile publication and newsletters at any time, without prejudice to the lawfulness of the processing carried out prior to the withdrawal.

The web app also allows you to update certain information, modify visibility, and request the export or deletion of data. Requests can be sent to info@innovahubaq.it o info@ciaq.it. The Data Controller shall respond within the timeframes established by the GDPR and may request the information necessary to verify the identity of the requester.

The data subject may lodge a complaint with Data Protection Authority or appeal to the competent judicial authority.

14. Updates

This privacy policy may be updated when the service, suppliers or applicable legislation change. Relevant changes will be communicated via the website, the app or the email address associated with the account. The date of the last update is indicated at the top of the page.