Scope of the document
This information covers the wayoutapp.it website, waitlist, pre-sale of Founder Pass, checkout, contact forms and related communications. The WAYOUT App does not regulate treatments after launch, which will be described in a specific privacy policy of the app.
1. Subject and scope of application
This Privacy Policy describes how WAYOUT S.r.l. processes the personal data of people who visit the wayoutapp.it website, join the waitlist, verify their email address, access the pre-sale, create or connect a WAYOUT account during the purchase flow, buy a Founder Pass, request an invoice, contact WAYOUT for support, exercise their right of withdrawal, request a refund or exercise their personal-data protection rights.
The information applies exclusively to the processing carried out within the site and the pre-launch flows mentioned above. The sites, services and platforms of third parties that may be reached via links, including social networks and the Stripe payment environment, apply their privacy statements for treatments performed according to their respective roles. The simple connection to an external service does not mean by itself the activation of tracking tools on the WAYOUT site.
2. Data controller and contacts
The controller is:
- WAYOUT S.r.l.;
- Tax code and VAT: 14805930964;
- registered office: Via Guglielmo Marconi 24/B, 20082 Binasco (MI), Italy;
- PEC: wayout@pec.wayoutapp.it;
- email for privacy and data protection requests: amministrazione@wayoutapp.it;
- email for general assistance: amministrazione@wayoutapp.it.
Requests for the exercise of privacy rights must be sent to amministrazione@wayoutapp.it, indicating in the subject “Privacy request”.
3. Categories and origin of processed data
3. Data provided directly by the user
- waitlist data: email address and choice regarding marketing consent; waitlist does not require name, surname, date of birth or telephone number;
- choice regarding marketing consent, which is optional and separated from the registration to the waitlist;
- checkout, account and purchase data: Founder Pass selected, first name, last name, date of birth, gender, verified phone number, WAYOUT account identifier and automatically generated nickname; if invoice is required, also type of customer, tax code or social reason and VAT number, address, postcode, municipality, Province, State, PEC and recipient code SDI where applicable;
- data inserted in the contact form: name, email, subject and content of the message;
- data and communications provided for assistance, complaints, withdrawal, refunds or privacy requests, including the order number and information necessary to manage the request.
3.2 Data generated during use of the site
- date and time of request and email verification, internal identifiers, verification tokens stored in hash form until expiry/use, waitlist position, offer status and information necessary to manage the limit of available places;
- selected plan, promotional package code, amount, currency, order status or payment, number or internal identification of the purchase, WAYOUT account identifier, Stripe session identifier and technical data required to verify the entity;
- notices relating to the information, consents and accepted conditions, such as date, time, source, version/hash of documents, IP address, user agent and session identifier in hash form, within the limits necessary to document the choice and prevent abuse;
- Technical data of navigation and security, such as IP address, user agent, browser information, session identifiers, CSRF tokens, language preference, application logs, anti-spam events and abnormal access or use attempts.
- data collected, after consent and for the respective category, through Google Tag Manager, Google Analytics 4 and Meta Pixel, such as online identifiers and cookies, device and browser information, IP address, approximate geographical area, page or content displayed, source of origin, events, conversions and interactions with the site and with advertising campaigns.
3.3 Data received by third parties
To protect public contact, waitlist, offer access, confirmation resend, withdrawal and administrative forms from spam and abuse, WAYOUT uses Google reCAPTCHA v3. The service generates a technical token and risk score that the site verifies on the server and may process technical information such as the IP address, browser characteristics and request data. In relation to identity and checkout, WAYOUT also uses Firebase Phone Authentication and its reCAPTCHA to verify the phone number and obtain the technical token needed to create or recognize the account on the WAYOUT backend. The Firebase token is processed temporarily by the site and forwarded to the backend; the verified number is stored in the account profile. In relation to payments, WAYOUT receives from the WAYOUT backend and Stripe the information necessary to reconcile the order, including outcome, amount, currency and session/transaction identifiers. Full card data and CVC are not acquired or stored directly by WAYOUT.
In relation to sending communications, WAYOUT may receive technical information about sending, delivery, rebounds and disiscrimination from Brevo. At the date of this version, the individual tracking of openings and clicks by pixels or equivalent tools is disabled. For electronic billing, Qonto can return customer/invoice identifiers, invoice status and transmission status, SdI events, technical errors and courtesy PDFs. In relation to measurement and online advertising, Google and Meta can return statistics, events, segments and aggregated or pseudonymized information exclusively after relevant consent.
The WAYOUT backend, connected to the site via signed server-to-server API, receives the data strictly necessary to create/recognize the account, verify the suitability, generate Stripe checkout and confirm the entity. The site retains the necessary references to reconcile accounts, order and pre-launch benefit.
3.4 Special data and free content
WAYOUT does not require, through the site, particular categories of personal data pursuant to Article 9 of the GDPR, such as health, biometric, religious, political or sexual life related data. It is therefore called upon not to include such information in the fields free of charge, unless it is strictly necessary for a specific request and is a legal basis.
4. Purposes, legal bases and retention times
The data are processed for the purposes and according to the legal bases indicated below. The retention periods may be extended when necessary to comply with legal obligations, to respond to requests from authorities, to ascertain, exercise or defend a right, or to manage an accident or a concrete dispute.
4.1 Technical operation of the site and security
Data processed: Navigation data, session, CSRF tokens, language preference, IP, user agent, technical logs and anti-spam or security events.
Purpose: Enable form and session functioning, maintain access to pre-sale flow, prevent abuse and fraud, protect the site, diagnose abnormalities and ensure operational continuity.
Legal basis: The legitimate interest of WAYOUT to the safety and proper functioning of the service, as well as to fulfil the applicable security obligations (Article 6(1)(c) and f), GDPR).
Retention: Session data are stored for the configured technical duration. Ordinary technical logs are kept, as a rule, for 30 days. Security and administrative logs can be stored up to 12 months; for accesses of any system administrators is ensured a storage not less than 6 months, where applicable. Data can be kept longer when this is necessary to handle accidents, abuses, litigations or requests of authorities.
Provision of data: The strictly necessary technical data are collected automatically; their lack of treatment can prevent the proper functioning of the site.
4.2 Registration and management of waitlist
Data processed: Email, timestamp, identification and status of registration, token verification in hash form, date/time verification, waitlist position, offer status and marketing consent if expressed.
Purpose: Register the request, verify control of the email address through a magic link, assign a waitlist position only after verification, manage the valid-user limit and enable the allocation of the Waitlist Pass under the applicable conditions.
Legal basis: Execution of pre-contractual measures taken at the request of the data subject and legitimate interest of WAYOUT to organize and protect the pre-launch phase (Art. 6, par. 1, letter b) and f), GDPR).
Retention: Up to the public go-live of the app and for the next 12 months. After this period, the data is deleted or anonymized if the user has not created an account in the app and has not made a purchase, unless a different legal basis, legal obligations or rights protection requirements.
Provision of data: The email address and acceptance of the Waitlist Terms are necessary to complete registration. Marketing consent is optional and does not affect the waitlist position or access to offers.
4.3 Verification of age, phone and account creation/recognition
Data processed: Name, surname, date of birth and outcome 18+, gender, prefix and phone number, OTP/token Firebase treated temporarily, account identifier and nickname generated automatically.
Purpose: Check that the buyer is older, check the phone number, prevent abuse and create or recognize the WAYOUT account needed to connect the Founder Pass. These operations take place in checkout and not in the waitlist form.
Legal basis: Execution of pre-contractual and legitimate interest measures by WAYOUT to ensure the safety and compliance of the service (Article 6(1)(b) and f), GDPR).
Retention: Firebase technical tokens are treated for the time strictly necessary for verification. Your account details are stored according to your relationship; if the account is created during a checkout then abandoned and is not used for other services, cancellation or anonymization is expected within 30 days of the last attempt, except security, disputes or other legal basis. Data linked to an order concluded follow the applicable contractual/fiscal retention.
Provision of data: Providing this data is mandatory to access flows reserved for adults.
4.4 Service communications related to waitlist and launch
Data processed: Email and information concerning registration verification, waitlist position and eligibility for the Waitlist Pass.
Purpose: Send registration confirmations, updates strictly necessary on the availability of the service, instructions to complete the registration to the go-live and operational information on the Waitlist Pass.
Legal basis: execution of pre-contractual measures or of the service requested by the user (art. 6, par. 1, letter b), GDPR).
Retention: For the duration of the waitlist and for the time required to complete any activation of the benefit; afterwards, for the periods applicable to the profile or contractual relationship.
Provision of data: Registration involves receiving only communications strictly necessary for the management of the waitlist and the benefit required.
4.5 Marketing, newsletters and promotional communications
Data processed: Email, marketing consent and relevant evidence; technical data relating to sending, delivery, rebound and unsubscribing of communications managed through Brevo. The individual tracking of openings and clicks is disabled at the date of this version.
Purpose: Send offers, invitations to pre-sale, promotions, commercial news and initiatives of WAYOUT.
Legal basis: Free consent, specific, informed and revoked (art. 6, par. 1, lit. a), and art. 7 GDPR; art. 130 of Legislative Decree 196/2003).
Retention: Until the withdrawal of consent and, however, for a maximum of 24 months from the last active and documentable interaction of the user. Proof of consent and revocation may be retained for further 5 years for purposes of accountability and defence. The technical sending logs are kept according to the configuration of the provider and the Data Retention Policy of WAYOUT, within the necessary limits.
Provision of data: The consent is optional, it is not pre-selected and the lack of consent does not prevent the entry to waitlist or purchase.
4.6 Access to pre-sale, checkout and purchase attempts
Data processed: Email, personal and contact data, selected plan, amount, currency, checkout status, timestamp, internal identification and technical data necessary for the temporary booking of the pass.
Purpose: Show the pre-sale offer, check requirements, temporarily reserve availability, pre-checkout, manage unfinished errors and attempts.
Legal basis: Execution of pre-contractual measures at your request and legitimate interest of WAYOUT to properly manage availability and prevent abuse (Art. 6, par. 1, letter b) and f), GDPR).
Retention: Data relating to uncompleted, failed or expired attempts are kept, as a rule, for a maximum of 30 days from abandonment or last attempt, except for technical, anti-fraud or protection requirements.
Provision of data: The data required at checkout are mandatory to proceed to purchase.
4.7 Purchase and management of Founder Pass
Data processed: Personal and contact data, selected pass, price, currency, order number, date of purchase, order status and payment, Stripe identifiers, contractual communications and activation data.
Purpose: End and execute the sales contract, register and confirm the order, associate and activate the pass, provide assistance and manage contractual communications.
Legal basis: Execution of the contract and fulfilment of legal, tax and accounting obligations (Article 6, paragraph 1, letter b) and c), GDPR), as well as legitimate interest in the protection of rights (lett. f).
Retention: As a rule, 10 years after the conclusion of the operation or the relationship, or for the different period provided for by the applicable legislation and the requirements of contractual protection.
Provision of data: The provision of the required data is necessary to purchase and manage the Founder Pass.
4.8 Payment via Stripe
Data processed: Order data, email, amount, currency, identification and transaction status. The complete data of the paper, CVC and further anti-fraud data are processed directly by Stripe.
Purpose: Execute payment, verify outcome, prevent fraud, reconcile order and manage refunds or disputes.
Legal basis: Execution of the contract, legal obligations and legitimate interest in the prevention of fraud and the protection of rights (Article 6, paragraph 1, letter b), c) and f), GDPR). Stripe processes data according to the roles and legal bases described in its statement.
Retention: WAYOUT retains transaction references for the period applicable to the order, as a rule 10 years. Stripe applies its retention times.
Provision of data: The processing of payment data is necessary to complete the purchase.
4.9 Invoice and accounting requirements
Data processed: Name, surname, order data and, only if you require invoice, tax code, address, postcode, municipality, province, state, any billing email and other data strictly necessary for the issue and retention of the tax document.
Purpose: Enter the required invoice, register the transaction, manage refunds and fulfill tax and accounting obligations.
Legal basis: Compliance with legal obligations and execution of the contract (Art. 6, par. 1, lit. c) and b), GDPR).
Retention: As a rule, 10 years, or for any different period required by applicable tax, accounting and civil-law provisions.
Provision of data: The invoice request is optional; the tax code becomes mandatory only when the invoice is requested.
4.10 Contacts, support and information requests
Data processed: Name, email, object, message and more information voluntarily provided.
Purpose: Respond to requests from users, creators, locals, partners or others interested in maintaining the necessary history of contact management.
Legal basis: Execution of pre-contractual measures at the request of the data subject or legitimate interest of WAYOUT to manage communications and relationships with users and partners (Art. 6, par. 1, letter b) and f), GDPR).
Retention: Up to 24 months from closing the request. If a contract, a complaint or a dispute arises from the contact, the relevant period shall apply.
Provision of data: The mandatory fields of the form are necessary to receive and manage the request.
4.11 Refunds, complaints and complaints
Data processed: Identity, email, order number and data, request, communications, motivation provided, outcome, amount and reference of the refund.
Purpose: Manage the right of withdrawal, refund requests, complaints, disputes and related documentation.
Legal basis: Execution of the contract, fulfilment of legal obligations and legitimate interest in the management and defence of rights (Article 6, paragraph 1, letter b), c) and f), GDPR).
Retention: 10 years when the request is linked to an order or payment; in other cases, as a rule, 5 years after closing, subject to litigation or further obligations.
Provision of data: The necessary data must be provided to allow the identification of the order and the evaluation of the request.
4.12 Management of privacy requests
Data processed: Identification and contact data, content of the request, any elements necessary to verify the identity, response and documentation of the activities carried out.
Purpose: Receiving, verifying and responding to the claims for exercise of the rights provided by the GDPR and documenting compliance.
Legal basis: Compliance with a legal obligation (Art. 6, par. 1, lit. c), GDPR).
Retention: As a rule 5 years after closing the request, unless longer storage is required for disputes or requests of the authorities.
Provision of data: WAYOUT may request reasonable information to verify the identity of the applicant.
4.13 Proof of consent, information and accepted conditions
Data processed: User identifier or order, date and time, source, text version, choice made and, where proportional, IP address.
Purpose: Demonstrate compliance with transparency obligations, the validity of marketing consent and applicable contractual conditions.
Legal basis: Consent, execution of the contract, legal obligations and legitimate probatory interest (art. 6, par. 1, letter a), b), c) and f), GDPR, according to the individual case).
Retention: log marketing is kept for the duration of consent and for 5 years from revocation; the evidence for sale is kept by order, as a rule for 10 years; the indications related to the waitlist, as a rule, for the duration of the report and 5 years later.
Provision of data: Registration of the view or acceptance is necessary when required to access the relevant service or conclude the contract.
4.14 Statistical analysis, measurement and online advertising
Data processed: Online identifiers and cookies, IP address, browser and device data, approximate geographical area, URL and page displayed, referrer, navigation events, content interactions, conversions and campaign data. The tools provided are Google Tag Manager, Google Analytics 4 and Meta Pixel in the browser and, when configured, the server-side Conversions API.
Purpose: Measure the use of the site and the effectiveness of the campaigns, produce statistics, identify navigation problems, optimize content and streams of waitlist/pre-sale and, through Meta Pixel, measure campaigns, create public or carry out remarketing, where activated.
Legal basis: Preventive consent of the user (art. 6, par. 1, lit. a), GDPR and art. 122 of Legislative Decree 196/2003). Google Tag Manager and Google Analytics 4 are blocked until consent to the Analytics category; Meta Pixel is blocked until consent to the Marketing category. The initial configuration uses Google Allow Mode in Basic mode and does not require sending Google or Meta tracking signals before the relevant consent.
Retention: User-level data and event in Google Analytics 4 are configured for 14 months retention, except for aggregate data without personal identification. The data and identifiers managed by Meta are stored according to the account settings, the durations indicated in the Cookie Policy and the rules of the provider. The cookie choice is kept, as a rule, for 6 months, unless prior modification of preferences or need to document consent.
Provision of data: The consent is optional and distinct for the categories Analytics and Marketing. In case of refusal, the site and the essential services remain usable and the relevant unnecessary tools are not activated.
5. Compulsory or optional nature of the award
Fields marked as mandatory are necessary to provide the required service. Failure to provide may prevent waitlist registration, verification of 18+ requirement, access to pre-sale, purchase completion or request management.
- Marketing consent is always optional and separate. Its failure to perform does not result in access to the waitlist or the possibility to purchase.
- The invoice request is optional. The tax code is only required if you select the option to receive the invoice.
- The technical data strictly necessary for the operation and safety of the site are collected automatically.
- Consent to Analytics and Marketing tools is optional and can be provided separately. The refusal does not prevent access to the site, the waitlist or the pre-sale; prevents only the activation of unnecessary tags.
6. Service Communications and Marketing Communications
The communications necessary to confirm the registration, manage the waitlist, inform about the actual availability of the service, activate the Waitlist Pass, confirm or manage a purchase, communicate delays, contractual changes, withdrawal or refunds are service or contractual communications and may also be sent in the absence of marketing consent, as long as they are strictly connected to the request or relationship with the user.
Communications that promote offers, Founder Pass, commercial advantages, initiatives or other promotional activities are sent only to users who have expressed a specific marketing consent. The consent can be revoked at any time by means of the unsubscribe link in the communications, when available, or by writing to amministrazione@wayoutapp.it. The revocation shall not prejudice the lawfulness of the processing carried out before the revocation and shall not interrupt the communications strictly necessary for the management of the waitlist or the contract.
On the date of this version, WAYOUT does not use tracking pixels or equivalent features to detect opening or clicking in transactional emails or marketing. Any future activation of such instruments will be preceded by updating the information and, when required by applicable legislation, by collecting a specific consent.
7. Data controllers
The data can be communicated, within the necessary limits, to the following categories of subjects:
- staff, administrators and collaborators authorized by WAYOUT, in compliance with specific instructions and the principle of necessity;
- Aruba and any subjects involved in hosting, infrastructure, database, backups, logs and site security. The hosting infrastructure chosen by WAYOUT is located within the European Union;
- development, maintenance, technical assistance and cybersecurity providers;
- Brevo, used for sending and managing transactional emails and marketing communications, including delivery, rebounds and disiscrimination. The individual tracking of openings and clicks is disabled at the date of this version;
- Google, for Google Tag Manager and Google Analytics 4, and Meta Platforms, for Meta Pixel and Conversions API, only after relevant consent and according to their privacy roles;
- Stripe and its financial and technical partners for payment processing, fraud prevention, reconciliation and refunds;
- accountant, tax consultants, billing systems and other subjects necessary for administrative and accounting purposes;
- Legal advisers, privacy, insurance or security when necessary to protect WAYOUT or users;
- judicial, administrative, tax or public security authorities and other subjects to which the communication is mandatory by law or necessary to ascertain, exercise or defend a right.
Data is not widespread. Suppliers who process data on behalf of WAYOUT are appointed processors under Article 28 of the GDPR, where required; other subjects, such as Stripe for specific activities, may also operate as independent owners.
8. Payments via Stripe
Founder Pass checkout is managed via Stripe. When the user initiates the payment, it interacts with an environment and with technical tools provided by Stripe. Stripe can collect and process payment data, transaction, device, network and fraud prevention, and, depending on the activity, can act as responsible for processing on behalf of WAYOUT and/or as independent owner.
WAYOUT receives and retains only the information necessary to manage the order, such as the outcome, amount, currency, session identifier or transaction and reconciliation data. WAYOUT does not receive or retain the full card number or CVC code. To learn more about the treatments carried out by Stripe, you are invited to consult the privacy policy of Stripe available on the website.
8.1 Electronic billing via Qonto.
If you require invoice, WAYOUT sends Qonto the tax data necessary to create the customer and document, register it as paid and, in production, manage electronic transmission and the related states. WAYOUT retains the necessary identifications and events for tax, accounting, assistance and reconciliation obligations for the period prescribed by law.
9. Cookies, technical tools, analytics and advertising
The site uses cookies and technical tools necessary for the operation of the Laravel application, session management, CSRF protection, storage of language preference and registration of cookie choices. Google reCAPTCHA v3 protects sensitive public forms; in checkout, Firebase Phone Authentication and its reCAPTCHA may also use technical identifiers, network requests and storage strictly necessary for phone verification and abuse prevention. Stripe payment tools are used in checkout managed by the WAYOUT backend. Strictly necessary tools are used only for the requested function and not for advertising purposes, without prejudice to the transparency obligation.
9.1 Google Analytics 4
After consent Analytics, WAYOUT uses Google Analytics 4 to obtain statistics on site usage, visited pages, traffic sources, events and conversions. Google Analytics may treat cookies, online identifiers and information on browsers, devices, IP address, approximate geographical area and interactions. The initial configuration includes Google Signals, advertising customization, User-ID, cross-domain tracking and Enhanced Conversions disabled. WAYOUT does not send Google emails, telephone number, tax code or other directly identifiable data.
9.2 Google Tag Manager
Google Tag Manager is used to manage and distribute site tags and not as a user database. The container and Google Analytics 4 are loaded only after consent Analytics, according to Google Allow Mode in Basic mode. Tags belonging to other categories, including Meta Pixel, can only be activated after specific consent to the relevant category.
9.3 Meta Pixel
After Marketing consent, WAYOUT uses Meta Pixel in the browser and, when configured, the server-side Conversions API to measure campaign visits and conversions, understand the effectiveness of advertising communication and, where enabled, create customized publics or perform remarketing. Meta can receive online identifiers, cookies, IP address, browser and device information, page visited, referrer and events on the site. Automatic Pixel Advanced Matching remains disabled. When configured, the Conversions API requires Marketing consent.
9.4 Choice and revocation of consent
Google Analytics 4 and Meta Pixel are not required to use the site. You can accept, reject or change the Analytics and Marketing categories separately through the banner and cookie preferences panel. The revocation shall have effect for the future and shall not prejudice the lawfulness of the processing carried out before the revocation. The refusal does not prevent the entry to waitlist, access to pre-sale or purchase.
For the updated list of cookies, the respective durations, suppliers and management methods refer to the Cookie Policy published on the site.
10. Data transfer outside the European Economic Area
The main hosting of the site uses Aruba with MySQL database. Brevo is used for email communications; Google/Firebase for telephone verification, reCAPTCHA and, after consent, analytics; Meta, after consent, for marketing measurement; Stripe for payments and Qonto for electronic billing. Some of these suppliers or subcontractors may process or make data accessible even outside the European Economic Area according to their contractual arrangement.
In such cases WAYOUT checks, as far as it is competent, that the transfer takes place in accordance with Articles 44 and following of the GDPR, on the basis of a decision of adequacy of the European Commission, of the accession of the recipient to a framework recognized as appropriate, of the Standard Contractual Clauses approved by the European Commission or another valid mechanism, with any additional measures where necessary.
Further information on the guarantees applied and, where available, a copy of the same can be requested by writing to amministrazione@wayoutapp.it.
11. Automation and decision-making processes
After consent, Google Analytics 4 and Meta Pixel can process interactions with the site to produce statistics, measure campaigns and, in the case of Marketing tools, create segments or publics that can be used for promotional and remarketing activities. Such activities may fall within the notion of profiling, but do not in itself produce decisions with legal or similarly significant effects to the user.
WAYOUT uses automated package availability controls, purchasing suitability, age, telephone verification, payment status and entities. These controls are aimed at performing the contract, preventing abuse and preventing invalid purchases and, according to the current provision, are not intended to produce decisions solely automated with legal or similarly significant effects within the meaning of Article 22 GDPR. In case of an abnormal outcome, the user may contact amministrazione@wayoutapp.it for a verification. Stripe can also use its anti-fraud systems according to its information.
12. Minorities
The WAYOUT service and pre-sale are reserved for users aged at least 18. The form waitlist does not collect the date of birth; the requirement is verified in checkout and in subsequent account/activation flows. If WAYOUT becomes aware of data related to a minor in violation of the applicable conditions, it will take reasonable measures to erase or limit the processing, unless legal obligations or need for protection.
13. Data security
WAYOUT adopts reasonable and risk-proportionate technical and organizational measures to protect data from loss, improper use, unauthorized access, alteration or disclosure. The measures include, according to the actual configuration, encrypted connections, session management and security tokens, limiting and permission of accesses, backups, logging, anti-spam controls and limiting installments.
However, no computer system can guarantee absolute security. In case of violation of personal data, WAYOUT will adopt the measures provided for by applicable legislation, including, when required, the notification to the Guarantor and the communication to the interested parties.
14. Rights of the interested party
In the cases and limits provided for by the GDPR, the data subject may exercise the following rights:
- obtain confirmation that a processing and access to your data and information relating to the processing is either ongoing;
- obtain inaccurate data correction and incomplete data integration;
- obtain the deletion of data when the legal requirements apply;
- obtain restriction of treatment;
- receive data in structured format, of common use and readable by automatic device and transmit them to another holder, when the right to portability is applicable;
- to oppose, for reasons related to its particular situation, treatments based on legitimate interest;
- object at any time to the processing for direct marketing purposes;
- revoke consent at any time, without prejudice to the lawfulness of the processing carried out before revocation;
- not be subject to a decision based solely on automated processing in cases provided for in Article 22 of the GDPR;
- lodge a complaint with the Data Protection Authority or other competent supervisory authority.
15. How to exercise rights
Requests can be sent to amministrazione@wayoutapp.it or the PEC wayout@pec.wayoutapp.it. It is useful to indicate the right you intend to exercise, the email address used on the site and any information necessary to identify the data concerned.
WAYOUT may request additional information reasonably necessary to verify the identity of the applicant. The reply is provided without undue delay and, as a rule, within a month of receipt of the request. This term may be extended for two more months in cases provided for by the GDPR, taking into account the complexity and number of requests; In this case the data subject is informed of the extension and of the related reasons within a month.
The exercise of rights is normally free. In the presence of manifestly unfounded or excessive demands, in particular for their repetitive character, WAYOUT may apply the measures permitted by law.
16. Reclaim to the Guarantor
The data subject who believes that the processing of his/her data infringes the applicable legislation can lodge a complaint with the Data Protection Authority in accordance with the methods indicated on the website www.garanteprivacy.it, or contact the supervisory authority of the Member State in which he resides or works or where the alleged infringement occurred.
17. Links and services of third parties
The site may contain links to Instagram, TikTok, Stripe or other external sites and services. The simple link does not involve, in itself, the installation on the site of pixels or tracking tools of the third party. Since the user accesses the external service, the processing is governed by the information and conditions of the relevant supplier.
18. Privacy Policy Updates
WAYOUT can update this Privacy Policy to reflect regulatory, organizational, technical or service changes and suppliers used. The updated version will be published on the site with the date of review. In case of significant changes, WAYOUT may inform users through the site or through the available contact details, when appropriate.
19. Effective date
This Privacy Policy is effective from the date of its publication on wayoutapp.it.