Who processes your data
The controller for your account and for the platform is the owner, trading as ProfBlu. It is the first fact a privacy policy has to give:
- Owner: Germán Ezequiel Laso Andino.
- Tax identification: VAT number (Partita IVA) 04702090988 · Italian tax code (codice fiscale) LSNGMN88S04Z600M.
- Registration data: professional activity not registered in the Italian Business Register (no REA number).
- Address: Via della Sega 1, 38080 Verdesina, Porte di Rendena (TN), Italia.
- Contact email: privacidad@profblu.com.
No data protection officer has been appointed: the law does not require one for an activity of this size. Write to the contact email and the person responsible will answer.
Two different roles: your organisation and us
The platform's applications are working tools of an organisation — a sports club, a shelter, a lodging — for the people it deals with. That splits responsibility in two, and changes whom you ask for what:
- We are responsible for your account. Email, name, password, sessions, preferences, notifications: that is the identity you use to sign in to every application, and we process it as controller.
- The organisation is responsible for the data it enters about you — the club that registers you, the shelter that processes your adoption. It decides what it keeps, why and for how long, and it asks for your consent when consent is needed. We process that data on its behalf and following its instructions (Article 28 GDPR): we store it, show it to whoever the organisation authorises, and do nothing else with it.
In practice: deleting your account and requesting a copy of your data are done from the application itself, in Account, without writing to anyone and without waiting — set out below. To have an organisation remove or correct what it holds about you, talk to it; if a request about data an organisation manages reaches us, we pass it on.
If you only visit the portal
Almost nothing happens, and it is worth saying precisely. The portal installs no cookies, carries no advertising pixels and loads no third-party resources. Nobody follows you from page to page because there is nothing to do it with. There is a single form, to request a key, and it only does something when you submit it: set out below.
The only thing counted is the visit itself: which page was seen and where it was reached from, with a program of ours hosted on our own server, without cookies and without identifiers. These are aggregate figures — how many visits each page had — and they do not allow reconstructing a specific person's path. It is explained in detail on the cookies page.
What does happen is what happens on any web server: when the page is requested, the server logs the request — IP address, date and time, resource requested and browser. Those logs are used to operate the service and detect abuse, and nothing more. They are not cross-referenced with any account.
If you request a key
The portal has a form to request a demo key. What it stores is what you write in it and nothing else: your name, your email, which product you want to try and, if you fill it in, free text. There is no phone number, no company, no job title, no marketing checkboxes.
Why: to prepare your access to the demo you requested and to write to you. On what basis: because it is what is needed to handle the request you yourself make. It is not a subscription to anything: we will not send you newsletters or offers, because nothing in the code does that.
Where you came from. When the form is submitted, the origin of your visit is attached, if it exists: which link or site you arrived from — only the name of the site, never the specific page — and the first page you opened on this portal. It is stored in your browser, only while the tab is open, and not with cookies: it is deleted when the tab is closed, and goes nowhere until you click the button. What is not stored: your IP address. It is checked at the moment to avoid admitting a hundred requests in a row from the same site, and then discarded.
What data we process if you have an account
Accounts belong to the whole platform: a single identity serves every application. What follows comes from the code, not from a generic list.
About your account
- Email address, first and last name, and a username if you choose one.
- Your password, never in plain text: it is stored as a bcrypt hash. We cannot read it, recover it, or tell you what it is; only check whether the one you type matches.
- Preferences: language, time zone, date and time format, currency and number format.
- The date and time you accepted the terms of use.
- Whether the account is active, and its role within each organisation.
About your profile, only if you fill it in
The profile is entirely optional. It may include a profile picture and a cover picture, a bio, phone number, job title and department, date of birth, sex, address, city and country, skills and languages you speak. What you do not fill in is not stored.
About signing in and about notifications
- If you sign in with Google or Apple we store no password: we store which provider you used and the identifier that provider returns to us, together with the email and name it sends us.
- For each open session we store the device identification your browser or phone sends (the "User-Agent" string) and when it was last used, so you can see and close sessions you do not recognise.
- If you enable notifications on a mobile application, the notification identifier of that device, so we can notify you.
About each application
Each application adds its own, and only its own: what it needs for its work. A training club stores an athlete's profile and what they train, and part of that is information about a person's body; a shelter stores adoption applications; a lodging, bookings. That information is entered by the person or their organisation, not by us, and every application in production details it in its own policy:
About errors
When the server fails, the error is stored so it can be fixed: the error type, its message, the technical trace, the method and address of the request, the identifier of the person who was signed in — if any — and some context. Only server failures are stored; a mistake made by the caller is not.
Why, and on what legal basis
- To provide the service — create the account, let you in, make the applications work: because it is what is needed to perform what you accepted when opening the account.
- To write to you about the essentials — the invitation, a notice about your account, resetting the password: for the same reason. These are service emails, not marketing.
- To notify you on your phone: with your permission, given when you accept notifications and withdrawn by turning them off.
- To process sensitive data an application needs — about a body, health or a person's situation: with that person's explicit consent, obtained by the organisation that registers them and withdrawable at any time.
- To keep the service running — server logs, error logs, abuse control, backups: on our legitimate interest in the platform working and being secure.
We do no profiling, no advertising, no automated decisions that affect you, and we neither sell nor share data with third parties for commercial purposes. That is not a statement of intent: nothing in the code does that.
Where it is processed, and who else sees it
The platform runs on Hetzner servers in Nuremberg (Germany), and backups are kept encrypted in the same provider's object storage in the same region, for 35 days. All within the European Economic Area: hosting involves no international data transfer.
Outgoing email is delivered by SMTP through IONOS, with the account in its Spanish region.
Mobile application notifications are relayed by Expo (Expo, Inc., United States): it receives the device identifier and the text of the alert to hand it to Apple or Google. It is the only piece of daily operation outside the EEA, and it runs under the safeguards of Chapter V GDPR (standard contractual clauses).
Apple and Google are involved if you choose to sign in with their account — to verify that access is valid — and as the stores distributing the mobile applications. They process that data under their own terms. If you prefer to avoid it, sign in with email and password.
Within an organisation, whoever has a role that allows it sees that organisation's data. That is the normal working of a shared tool, and it is worth bearing in mind. Each organisation may also configure its own outgoing mailbox; in that case its credentials are stored encrypted and email is sent from its own address, not ours. There is nobody else.
For how long
As long as the account exists. And when you decide it should stop existing, the deletion happens at that moment: you request it from the application, in Account → Delete my account, and it is done while you wait. There is no grace period, no email to send, and no overnight job to trust.
What disappears is everything that identifies you: your email, your name, your username, your phone number, your photos and your password — the row is left with nobody in it — plus your open sessions, the devices where you received alerts, and your memberships in organisations. The application shows you that list at the moment of deletion, not afterwards.
And what does not disappear, because we cannot delete it: the data an issued invoice points to. Invoicing law requires keeping it, and deleting it would leave invoices pointing at nothing. Nor is the record of which documents you accepted and in which version deleted: it is the proof that consent existed, and it is as much yours as ours. Both things are told to you in the same response.
The backup remains, and here there is a deadline: backups rotate every 35 days, so until then your earlier row keeps existing inside an encrypted backup that is never consulted for anything. After that period, it is gone even there.
What an organisation keeps about you is kept for as long as it decides; ask it, or ask us and we will pass it on. And if you administer an organisation, before deleting your account you will need to hand ownership to someone else or close the organisation: we cannot leave a club with nobody answering for its members' data.
Your rights
You may exercise the rights the General Data Protection Regulation gives you:
- Access: know what data of yours we hold.
- Rectification: correct what is wrong.
- Erasure: request its deletion. This one does not need to be requested: you do it yourself from the application, in Account, and it happens at that moment — see for how long.
- Portability: receive it in a machine-readable format. This is also in Account: the application hands you the file right there, to keep or share. What each product knows about your activity — training, bookings, adoptions — is exported from that product, and the file itself reminds you of that.
- Objection: object to processing we do on legitimate interest.
- Restriction: ask us to keep the data but stop using it while something is resolved.
- Withdraw your consent, without affecting what was done before.
To exercise any of these rights, write to privacidad@profblu.com.
We reply within the legal deadline, one month at most. And in any case you may complain to a supervisory authority: in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it); in Spain, the Agencia Española de Protección de Datos (www.aepd.es); or the authority of the EU country where you live.
Minors
The platform is not directed at children under fourteen and we do not offer it to them directly. If an organisation registers a minor, it is the organisation that guarantees it holds the authorisation of the person with parental responsibility or guardianship. If we detect a minor's account without that authorisation, we close it.
Security
Communications are encrypted (TLS), passwords are stored as hashes, mobile application credentials live in the phone's secure store, backups are encrypted, and access to data depends on each person's role in their organisation. If we detect a breach that affects you, we will tell you, and the supervisory authority within the 72 hours the law sets.
A note about demos
The platform has two kinds of environment, and it is worth telling them apart. The demonstration ones — those living under demo.profblu.com and demo.prosecco.group — are rebuilt, emptied and reseeded: there are no customers, nothing is charged, and access is authorised by us, one by one. Since September 2026 there are also applications in production, on their own domains under profblu.com, with real data of real people. What each document says applies to both kinds; where a rule changes by environment, it says so.
As a practical consequence: do not put other people's real data into a demo. A demonstration environment is rebuilt, emptied and reseeded, and it is no place for anyone's profile.
Changes
If we change what we do with data, we change this text and move the revision date. When the change is significant, we also notify account holders inside the applications or by email.