We want you to feel comfortable when you are using the DiscoveRig Web Portal or Application, our software and its underlying functions through our online Portal (our “Portal”) and not have to worry about the security of your data. That is why data protection is an important part of our corporate philosophy.

In this Privacy Policy, you will find all the information about which Personal Data we collect and process and for what purpose. Equally, we will also inform you of your data protection rights and how you can assert them.

General Principles

What is Personal Data?

Personal Data is “any information relating to an identified or identifiable natural person. This includes, for example, name or address data, telephone number, mobile number, or online identifiers such as your device id and your IP address.

What is processing?

“Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means. The term is broad and covers virtually any handling of data.

What law applies?

We will only use your Personal Data in accordance with the applicable data protection laws, in particular Italy’s Data Protection Code (“DPC”) and the EU’s General Data Protection Regulation (“GDPR”), and of course only as described in this Privacy Policy.

Who is responsible for data processing?

The responsible party within the meaning of the DPC and the GDPR is DiscoveRig of DiscoveRIG SRLS Via Gabbiola 2, Verona, Italy (“we”, “us”, or “our”). If you have any questions about this policy or our data protection practices, please contact us using info@discoverig.it or write to us at the above address.

What are the Legal Bases for processing Personal Data

In accordance with the DPC and the GDPR, we have to have at least one of the following legal bases to process your Personal Data: a) you have given your consent, b) the data is necessary for the fulfillment of a contract / pre-contractual measures, c) the data is necessary for the fulfillment of a legal obligation, or d) the data is necessary to protect our legitimate interests, provided that your interests are not overridden.

Who is the competent data protection authority?

The supervisory authority in Italy is the Italian Data Protection Authority, Garante per la protezione dei dati personal, Piazza Venezia 11, 00187 Rome, (www.garanteprivacy.it). However, we would appreciate the opportunity to address your concerns before you contact the Garante per la protezione dei dati personal or any other supervisory authority.

How long and where will you keep my data?

We process and store your Personal Data only for the period of time required to achieve the respective processing purpose or for as long as a legal retention period exists (in particular commercial and tax law in accordance with Italy’s Commercial Law and Fiscal Code). Once the purpose has been achieved or the retention period has expired, the corresponding data is routinely deleted. In general, your data is saved and stored using the services of host.it (HOST S.p.A.).

What Personal Data do we process?

Technical Data

When you access our portal, some access data is recorded automatically and stored in a log file on our portal’s server. This means if you browse and simply have a look at our portal, we process a) the IP address of your computer, b) the date and time of your access, c) the name and URL of the accessed file, d) the browser used, e) the amount of bytes transferred, f) the status of the page request, g) the session ID and g) the referrer URL. The legal basis for processing is our legitimate interest.

Hosting of our portal

We use the hosting services of host.it (HOST S.p.A.) for the purpose of hosting and displaying our portal. host.it does so on the basis of processing on our behalf, and that also means that all data collected on our portal is processed on host.it’s servers. The basis for processing is our legitimate interest, and the initiation and/or fulfillment of a contract.

Contacting us and contracting with us

You can contact us in various ways and data is always collected in the process. You provide us with most of the data that we process when you contact us such as your name, and email address. This data is collected and processed exclusively for the purpose of contacting you and processing your request and then deleted again, provided that there is no legal obligation to retain it.

We process the personal data that arises when you use our portal in order to provide our contractual services. In particular, this includes our support, correspondence with you, invoicing, fulfillment of our contractual, accounting and tax obligations. Accordingly, the data is processed on the basis of the fulfillment of our contractual obligations and our legal obligations.

If you register through our website, we will request mandatory and, where applicable, non-mandatory data in accordance with our registration form (Username Full Name, Email Address, Company Details). The entry of your data is encrypted so that third parties cannot read your data when it is entered. For the purpose of logging in to our Portal, you will provide your password together with your username. We will hold your data for further orders as long as you have your account and user contract with us. For further information on our use of your Personal Data in connection with your use of our website, please refer to our Website Privacy Policy.

Lastly, we process data in the context of administrative tasks as well as organization of our operations, financial accounting and compliance with legal obligations, such as archiving. In this regard, we process the same data that we process in the course of providing our contractual services. The purpose and our interest in the processing lies in the administration, financial accounting, office organization, archiving of data, i.e., tasks that serve the maintenance of our business activities, performance of our tasks and provision of our services.

The legal basis for processing the above is our legitimate interest, the provision or initiation of a contractual service and your consent.

Payment Data

If you take out a subscription, your payment data will be processed via our payment service provider through our website. Payment data will solely be processed by our payment service provider and we have no access to any Payment Data you may submit. The legal basis for the provision of a payment system is the establishment and implementation of the user contract for the use of the service.

When using the DiscoveRIG Web Portal and our Services

We process the data involved in your use of our Services (“Service Data”) in order to be able to provide you access to the DiscoveRIG Web Portal and use of our Services. Provided that you are using the DiscoveRIG Web Portal and our Services for the intended purpose to recover your skydiving equipment, we will track the location of your DiscoveRig Hardware GPS system and display the distance between your position and that of your DiscoveRig Hardware GPS system using the DiscoveRig Hardware GPS system`s device location.

Please be aware that location data could be revealing your life habits as well as your centers of interest and may possibly reveal sensitive information through the places visited. The legal basis for the data processing is the fulfillment of our contractual obligations.

For this purpose all Service Data processed by us will be processed using the following sub-processors: Traccar (Tananaev Solutions) a GPS Tracking Platform, LocationIQ (Unwired Labs) to track your DiscoveRig Hardware GPS system and display the device location and Google Firebase (Google LLC) for notifications and take appropriate legal precautions and corresponding technical and organizational measures to ensure the protection of your Service Data.

We recognize that you own your Service Data. We provide you complete control of your Service Data by providing you the ability to (i) access your Service Data, (ii) share your Service Data through supported third-party integrations, and (iii) request export or deletion of your Service Data. Where we process Service Data as Data Processor or in other words on behalf of you, we will process the Service Data involved in your use of our services in accordance with your instructions and shall use it only for the purposes agreed between you and us.

We ensure that access by our employees to your data is only available on a need-to-know basis, restricted to specific individuals, and is logged and audited. We communicate our privacy and security guidelines to our employees and enforce privacy and protection safeguards strictly.

Support ticket

If you create a support ticket, we will request Personal Data and, where applicable, non-Personal Data in accordance with your request, this may include your name, email address and other order related data you voluntarily provide. The data provided is not shared with third parties and cannot read your data when it is entered. If you submit a support ticket, we process the data for the purpose of processing and handling your ticket.

Our employees will also have access to data that you knowingly share with us for technical support or to import data into our services. We communicate our privacy and security guidelines to our employees and enforce privacy safeguards strictly. The legal basis of the data processing is our obligation to fulfill the contract and/or our legitimate interest in processing your support ticket.

Data Sharing

In certain cases, it is necessary to transmit the processed Personal Data in the course of data processing. In this respect, there are different recipient bodies and categories of recipients.

Internal

If necessary, we transfer your Personal Data within DiscoveRIG. Of course, we comply with the associated legal framework and ensure that your data is processed properly. Access to your Personal Data is only granted to authorized employees who need access to the data due to their job, e.g., to provide our services or to contact you in case of queries.

We may also share your Personal Data with our Business Partners for the purposes described in this Privacy Policy, including (but not limited to) conducting the services you request, or customizing our business to better meet your needs.

External bodies

Personal Data is transferred to our service providers in the following instances:

  • in the context of fulfilling our contract with you,
  • to use marketing services and to advertise our services online,
  • to communicate with you,
  • to provide our portal, and
  • to state authorities and institutions as far as this is required or necessary.

International transfers

We may transfer your Personal Data to other companies as necessary for the purposes described in this Privacy Policy. In order to provide adequate protection for your Personal Data when it is transferred, we have contractual arrangements regarding such transfers. We take all reasonable technical and organizational measures to protect the Personal Data we transfer.

Security of your data

In order to protect the data stored with us in the best possible way against accidental or intentional manipulation, loss, destruction or access by unauthorized persons, we use appropriate technical and organizational security measures. The security levels are continuously reviewed in cooperation with security experts and adapted to new security standards.

Nevertheless, internet-based data transmissions can always have security gaps, so that absolute protection cannot be guaranteed. And databases or data sets that include Personal Data may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, we will notify all affected individuals whose Personal Data may have been compromised as expeditiously as possible after which the breach was discovered.

Your Rights and Privileges

Privacy rights

Under the DPC and the GDPR, you can exercise the following rights:

  • The right to access;
  • The right to rectification;
  • The right to erasure;
  • The right to restrict processing;
  • The right to object to processing;
  • The right to data portability;
  • The right to complaint to a supervisory authority

Updating your information

If you believe that the information we hold about you is inaccurate or request its rectification, deletion, or object to its processing, please do so by contacting us.

Withdrawing your consent

You can withdraw consents you have given at any time by contacting us.

Access Request

In the event you want to make a Data Subject Access Request, please contact us. We will respond to requests regarding access and correction as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days, we will tell you why and when we will be able to respond to your request. If we are unable to provide you with any Personal Data or to make a correction requested by you, we will tell you why.

What we do not do

  • We do not request Personal Data from minors and children;
  • We do not use Automated decision-making including profiling; and
  • We do not sell your Personal Data.

Validity and Questions

This Privacy Policy was last updated on Sunday, 4th of February, 2024, and is the current and valid version. However, we may update this policy for a number of reasons, such as to reflect a change in the law or to accommodate a change in our business practices and the way we use cookies. We recommend that you check here periodically for any changes. If you have any questions or comments about our Privacy Policy or wish to exercise your rights under applicable laws, please contact us.