English translation of the Italian document. This translation does not change the service conditions.
SERVICE DOCUMENTS · VERSION 2026-09-13
Privacy policy
This policy describes data processing on the CronoVent website and application. Last updated: 13 September 2026.
1. Who operates the service
The controller for the website, accounts, commercial relationship and support is REC Eventi di Andrea Matteo Bassi · Via Dumas 12, 42123 Reggio Emilia, Italy · VAT no. 02472790357. For personal data enquiries: info@cronovent.it.
2. Data and purposes
| Data | Purpose and legal basis |
|---|---|
| Technical connection and security data, IP address during connection | Providing the service and protecting against unauthorised access; legitimate interest in security, Article 6(1)(f) GDPR. |
| Name, organisation, email, protected credentials and email confirmation | Creating and managing accounts, the free trial and requested service; pre-contractual measures and contract (Article 6(1)(b)), or legitimate interest in managing organisation contacts (Article 6(1)(f)), depending on the data subject’s role. |
| Billing profile (Italian fields where applicable): account name, tax code, VAT number, address, SDI/office code, certified email (PEC), email, phone and any CUP/CIG codes; licence requests and their status | Managing the relationship and administrative and tax obligations; Articles 6(1)(b) and 6(1)(c) GDPR. |
| Support messages and privacy requests | Responding to requests, providing support and fulfilling obligations concerning rights; Articles 6(1)(b), 6(1)(c) and, where relevant, 6(1)(f). |
| Accepted version of the terms and data processing agreement, acceptance date | Documenting the contractual relationship and protecting the parties’ rights; Articles 6(1)(b) and 6(1)(f). Recording this information does not constitute marketing consent. |
| Optional public website statistics: pages visited, referral source, interactions with demo/pricing/registration links and pseudonymous browser identifiers | Understanding use of the website and blog and improving content; optional consent (Article 6(1)(a) GDPR). No Analytics collection within events or the private area. |
Account data is required for activation. Without it, registration cannot proceed. Advertising tools, commercial profiling and automated decisions producing legal effects are not active. Newsletter subscription is not requested.
The billing profile is completed in the customer area to request a licence. Each request retains a copy of the tax details and proposed price at submission, together with the date, requester and activation decision. We do not collect payment card details: requests and activations are managed manually. The portal does not issue or submit invoices to the Italian Sistema di Interscambio.
3. Data in festival schedules
Schedules may contain names, roles, professional contact details, crew calls and documents concerning speakers, artists and technicians. The customer decides the purposes, content, recipients and retention period, normally acting as controller with REC Eventi as processor. If the customer acts for an organiser, they must hold the necessary instructions and authorisations; REC Eventi may act as a sub-processor.
For this data, the customer’s or organiser’s privacy notice supplements this document. The customer must inform the people concerned, establish a legal basis and upload only necessary data. The service is not intended to store health records, criminal records or other special categories of data.
Schedules can be viewed using a code or link and the password chosen by the customer, if any. A code can be forwarded. Structured contact fields are excluded from viewing by default; the manager can share them only with an active viewing password. Titles, notes, requirements and attachments still require care from the uploader. Remote links are excluded from responses sent to viewers.
4. Recipients and infrastructure
No sale or sharing for commercial purposes. REC Eventi does not sell, rent or share users’ data, contact details or information uploaded to schedules with third parties for commercial, advertising or profiling purposes. It does not use this content for third-party marketing.
Data may be processed only by authorised staff and technical providers necessary for the service, within their respective roles and applicable confidentiality and protection obligations, or disclosed when required by law or a competent authority. This does not affect sharing of schedules and documents authorised by the customer through the service’s access mechanisms, as described in section 3.
Authorised REC Eventi staff and providers necessary for delivery access data according to their roles. The app is hosted by Hetzner Online GmbH in Germany (Falkenstein area); operational database backups are on the server in that area. Registration confirmation emails are sent through Aruba’s email service from noreply@cronovent.it. Aruba receives the recipient address and the content needed for confirmation.
The cronovent.it marketing website is hosted on Aruba Linux hosting, which processes the technical data needed for connection and hosting. Website fonts and images are served from the same hosting: we do not load Google Fonts in visitors’ browsers.
No systematic transfers of app data outside the EEA are configured. Any new providers or transfers will be assessed and documented with the safeguards required by Chapter V GDPR before activation. When you voluntarily open external links, the respective websites’ policies also apply.
Public website statistics with Google Analytics
Only after consent, we use Google Analytics 4 on the marketing website and blog. The provider for EEA customers is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with the involvement of Google LLC and the sub-processors listed in the service terms. The browser sends browsing data and pseudonymous identifiers to Google to produce statistics. An IP address is needed to connect to Google’s systems; according to GA4 documentation, it is not logged or stored as an IP address.
We have disabled Google Signals, ad personalisation, user-provided data collection, granular location/device details and optional account data sharing. We do not send names, emails, billing data, schedule content, event codes or CronoVent account identifiers. Page addresses sent contain no queries or fragments; permitted campaign information is limited to predefined values. A registration-link click is a website statistic, not evidence of a completed registration.
Analytics is not loaded before consent or if consent is refused. The app, events, demo and private area on app.cronovent.it do not integrate Analytics. Statistical cookies are restricted to the individual public website host and are not shared with the portal.
Google’s service may involve processing outside the EEA, including in the United States. Google’s data processing terms provide for applicable transfer safeguards, including the Data Privacy Framework for certified recipients and standard contractual clauses where applicable. Details and copies of safeguards are available in Google’s legal frameworks, or can be requested from the controller. See also how Google uses data from partner sites.
You can refuse without affecting the service and withdraw consent through “Cookie preferences” in the footer. Withdrawal stops subsequent collection and removes statistical cookies from this browser; it does not make previous processing unlawful or automatically delete data already received by Google. Contact us about data already collected.
5. Retention
- Website cookie choice: six months (183 days), on the device, together with the date and policy version. Analytics cookies: up to 180 days, without automatic renewal on each visit. Detailed Analytics user and event data: two months, without resetting for new activity. This setting does not limit standard aggregated reports, which may remain available longer under Google’s service rules.
- Access cookies: up to 12 hours or logout. Expired sessions are removed by daily maintenance.
- Unconfirmed registrations: link valid for 24 hours; pending data is deleted at the first daily maintenance after expiry. Registration anti-abuse identifiers: 24 hours plus the interval until the next cleanup.
- Login attempts: a 15-minute window, removed at subsequent logins or during daily maintenance.
- Browser preferences: 180 days from last use, removed on the next visit or immediately through the clearing action. Tab preferences last until the browser session ends.
- Accounts and schedules: for the duration of the relationship or according to the customer’s documented instructions. Trial expiry restricts editing and is not a deletion request. At closure, return and removal of content are agreed, normally within 30 days of request verification, subject to legal obligations.
- Automatic server backups: 7 days. Server maintenance copies: up to 30 days. Any operator working copies must be deleted as part of closure; data remaining in backups is not used for ordinary purposes and restoration must respect previously requested deletions.
- Dedicated app web logs: daily rotation and 14 archives; new access logs do not record IP addresses, queries, event codes, cookies or referrers. Error logs may contain identifying technical data, with restricted access and limited rotation. Evidence needed for an incident or dispute may be retained separately for the strictly necessary period, with the reason documented.
- Billing profile and licence requests: to manage the request and relationship; on closure, the removal criteria above apply, except for data required by law or for documented protection of rights. Profile changes do not overwrite copies associated with previous requests.
- Tax documents and contractual evidence: for legal obligations and applicable rights-protection periods. Account deletion does not remove documents that must legally be retained.
6. Rights
Where Articles 15–22 GDPR apply, you can request access, rectification, erasure, restriction, portability and object to processing, particularly processing based on legitimate interest. Email info@cronovent.it; proportionate identity verification may be necessary. Do not send passwords. We respond within Article 12 GDPR time limits, normally within one month, with any justified extensions allowed by law.
For data uploaded by an organiser, requests are handled with the relevant controller. You can complain to the Italian Data Protection Authority or the competent authority. In the portal, account holders can download their profile data; schedule export is available to users authorised to manage the relevant event.
7. Cookies and preferences
The public website uses a banner for optional statistics; the portal and events retain only technical service tools. Details, durations and choices are on the Cookies & preferences.
Website language
To suggest Italian or English, we estimate the country from the IP address using a DB-IP database stored on our hosting, without sending the IP address to DB-IP. This is not a precise location and may be inaccurate, for example with a VPN. If unavailable, we use the browser language. Your manual choice takes priority and is stored for 180 days; the automatic preference lasts for the session. These tools present the website in the appropriate language and are not used for statistics or advertising.