Legal
Privacy Policy
Version 2026-05-06. Updates published here.
1. Data controller
Rinoova S.r.L., VAT IT18432621003, registered office in Italy. Contact: rifesta@rinoova.com.
2. Data collected
- Account: email, name, password (hash).
- Photos and media: uploaded transiently, according to configured retention periods.
- Minimal telemetry: application logs, security events, aggregated technical metrics.
3. Legal basis
- Contract performance: service delivery.
- Legitimate interest: security, abuse prevention, service improvement.
- Consent: non-essential analytics and cookies (GA4 opt-in).
4. Retention period
According to the chosen retention plan: 30, 180 or 365 days for event media. Account data kept until deletion request.
5. User rights
At any time you may exercise the rights under articles 15-22 GDPR: access, rectification, erasure, restriction, portability and objection. Write to privacy@rinoova.com.
6. DPO and privacy contact
For any privacy matter: privacy@rinoova.com.
7. Subprocessors
- Cloudflare R2 — media storage (EU region).
- Stripe — billing and payments (Ireland).
- Postmark / Mailgun — transactional email delivery (EU).
- Google Photos — optional, activated by the user for sync.
8. Extra-EU transfers
Stripe may involve transfers regulated by Standard Contractual Clauses (SCC) approved by the European Commission.
9. Changes
Any substantial changes will be notified at least 30 days in advance.
For full details contact us at privacy@rinoova.com.