Skip to content
gradient-pattern-background-reverse-hero-16-9-2560x1440px

Privacy Policy

Epassi Italia S.r.l. is a company belonging to the Epassi Group. It respects your privacy and aims to maintain the protection of personal data of individuals using Epassi Italia's services. This Privacy Policy describes how Epassi Italia processes personal data, including what types of personal data are collected, the purposes for which personal data is used, and to whom personal data may be disclosed.

Epassi Italia believes that you should know how we use your personal data, and how you can affect the collection and use of your personal data. In this Privacy Policy we explain the purposes of collecting and using your personal data as well as how we have ensured that you have adequate control over your own personal data.

Personal data refers to any information relating to a natural person ("data subject") that can identify the person directly or indirectly. Terms such as personal data, data subject, and controller are defined in the General Data Protection Regulation ((EU) 2016/679, "GDPR"), which applies to all processing of personal data by Epassi. Epassi complies with the GDPR and other applicable national data protection laws ("data protection legislation") in all personal data processing.

Our services may also include links to external websites and services to which this Privacy Policy does not apply. These websites or services are operated by other organisations that Epassi does not control and therefore Epassi is not responsible for their processing of personal data. For this reason, we encourage you to review the applicable privacy policies of those websites or services.

Should you have any questions on the use of your personal data, you are always welcome to contact us at rpd@epassi.com or our Group DPO at dataprivacy@epassi.com.


  • Controller: Epassi Italia S.r.l. 
  • Address: Piazza Pietro Pajetta, 2 – 13100 Vercelli (VC) 
  • Telephone number: +39 0161 182 8500 
  • VAT number, Tax Code, and registration with the Companies Register: 03269680967 
  • Email: rpd@epassi.com 
  • Epassi Group Data Protection Officer (DPO): Ms. Taika Pöntinen – dataprivacy@epassi.com

Purposes, type of data, legal bases and retention times for processing

Epassi Italia processes only personal data that is relevant and necessary to fulfil the purposes defined in this Privacy Policy. 

Personal data is processed separately from other Epassi systems and is not combined with other processing purposes. Below, you will find tables listing the purposes of processing identified by Epassi Italia, the categories of personal data involved, a description of the processing and retention periods, and the applicable legal basis under the GDPR.
Epassi Italia services

The personal data is processed for the distribution, use, maintenance, and development of Epassi Italia services and products.

Description and retention period: As long as the contract for welfare services remains in force. The data connected to the use of the services and the service requests made will be kept for a period of 10 years for evidentiary purposes in accordance with article 2946 of the Civil Code (until the end of the litigation in the case of valid judicial requests proposed within the indicated deadline).

Sensitive data for Epassi Italia services

Some Epassi Italia services involve the acquisition by the Data Controller of data relating to health which fall within the scope of the particular categories of data referred to in art. 9 of the GDPR. In order to guarantee maximum security and protection of the services against any unauthorised access and/or use, in some cases, it may be required to provide an identity document to uniquely identify the applicant. 

Retention period: As long as the contract for welfare services remains in force. The data connected to the use of the services and the service requests made will be kept for a period of 10 years for evidentiary purposes in accordance with article 2946 of the Civil Code (until the end of the litigation in the case of valid judicial requests proposed within the indicated deadline).

User communications and marketing

Personal data provided in connection to the service is used to provide communications regarding the service and marketing Web analytics and cookies: The personal data is processed in order to develop our services and improve marketing activities using web analytics and cookies as well as to administer our website and fulfil user requests.

Data detention period: Maximum 2 years

Learn more on the cookies policy

Interest

Categorise users in one or more clusters in order to provide: personalised proposals for additional welfare services deemed appropriate to users' needs, possibly included in the specific "recommended for you" section of the portal or sent via email; assistance for choosing and using welfare services deemed suitable for users' needs through a dedicated physical (welfare coach) or virtual assistant. 

Data detention period: As long as the contract for welfare services remains in force.

Support matters

The personal data is processed in order to administer the support matters for end-users as well as to provide phone line support. 

Data detention period: As long as necessary for the purpose and + 2 years; phone call recordings up to 3 months.

Complying with legal obligations (accounting, bookkeeping, etc.)

The personal data is processed in order to fulfil our legal obligations, e.g. accounting and tax legislation-related obligations. 

Data detention period: As long as required by applicable law; financial statements up to 10 years.

Epassi uses tools that leverage artificial intelligence (AI), including large language models and machine learning models, in the delivery of its services. However, Epassi's use of AI is strictly limited by contractual agreements, technical restrictions, and internal policies to ensure that personal data is never disclosed to AI models in a way that would compromise data protection, such as by training the AI. The use of these tools and applications within Epassi does not affect or hinder the exercise of data subject rights. You always have the option to refuse the processing of your personal data by AI by notifying Epassi as described in section 8, "Rights of the Data Subjects".

Data sources

We may collect the personal data from the following sources:

  • Directly from you: for example, at the time of registration or use of our services or during a customer relationship, when ordering a newsletter or participating in a survey, when contacting our customer services or purchasing services or products.
  • Your employer, in relation to services which are provided by us to your employer.
  • Information collected from other sources which may be combined with the user account details – such as updated delivery information from delivery agents and public sources.

Disclosures, transfers and recipients of personal data

We consider all disclosures of personal data carefully and ensure that the partners and processors who receive personal data have committed to comply with the applicable data protection laws.

We disclose data to the service locations which you use as part of our services, and on an ongoing basis in cases where you use our services to have an ongoing subscription with the service provider in question.

We may, when necessary, disclose personal data to authorities, other companies within the same group of companies of Epassi Italia, and to selected third parties, such as third-party service providers (such as our IT vendors and marketing agencies conducting marketing on our behalf). In such cases, the personal data will only be disclosed for purposes defined above and any disclosure is always limited to only the strictly necessary personal data included in such purposes. We do not sell personal data to any third party.

List of processors and other recipients:

Accademia Società cooperativa sociale onlus

    • Company name, tax code and VAT number, registered office: Via Fratelli Ponti n. 5 – 13100 Vercelli (VC) Tax code: 02167000021
    • Location where the data processing is conducted:Italy
    • Type of data processing:Remote Customer Care services (recording, consultation, cross-checking)

AMAZON WEB SERVICES EMEA SARL

    • Company name, tax code and VAT number, registered office: 38 Avenue John F. Kennedy, L-1855 Lussemburgo
    • Location where the data processing is conducted: EU
    • Type of data processing: Cloud Providing Services (Recording, storage, processing, retention)

EPASSI GROUP OY

    • Company name, tax code and VAT number, registered office: Linnoitustie 11 – 02600 Espoo, Finland VAT: 2950841-4
    • Location where the data processing is conducted: Finland (EU)
    • Type of data processing:IT Management and IT Security services (logging, storage, processing, retention, monitoring, and analysis of data)

HubSpot, Inc.

    • Company name, tax code and VAT number, registered office: 25 First Street, Cambridge, MA 02141, USA
    • Location where the data processing is conducted:EU
    • Type of data processing:CRM tool – B2B data (employer and merchant customer contacts)

Noigroup Soc. Coop. Soc.

    • Company name, tax code and VAT number, registered office: Via del Credito 5 – 31033 Castelfranco Veneto (TV) VAT: 03489120265
    • Location where the data processing is conducted: Italy
    • Type of data processing: Remote Customer Care services (recording, consultation, cross-checking)

Salesforce.com Italy S.r.l.

    • Location where the data processing is conducted: Piazza Meda n. 5 – 20121 Milano (MI) VAT: 04959160963
    • Location where the data processing is conducted: Italy
    • Type of data processing: Cloud Providing services and management of email communications to Users through a Marketing Automation platform (Recording, storage, processing, retention, sending of communications)

Data transfers outside the EU/EEA

Some of the services used by Epassi Italia for processing personal data may operate outside the territory of the European Union (EU) or the European Economic Area (EEA). Thus, your data may be transferred outside the European Union and the European Economic Area.

In cases where personal data is transferred outside the EU/EEA, such transfers are either made to a country that is deemed to provide a sufficient level of privacy protection by the European Commission, or transfers are carried out by using appropriate safeguards such as Standard Contractual Clauses (SCC) adopted by the European Commission, including any supplementary measures where assessed to be necessary, or otherwise approved by the EU Commission or competent data protection authority in accordance with the GDPR.

Protection of personal data

Securing the confidentiality, integrity, and availability of personal data is important to Epassi Italia. Our Security Management System is based on the requirements of laws, regulations, contracts and standards. The Epassi service and IT systems are certified according to the ISO 27001 information security standard. The Security Management System consists of appropriate technical, administrative, and organisational security measures to protect personal data against unauthorised access, disclosure, destruction, or other unauthorised processing.

Administrative and organisational measures:

  • Dedicated servers in two different geographical locations within the EU. Facilities are certified against internationally recognised information security standards.
  • Role-based access rights management.
  • Firewalls
  • Backups
  • Access controls
  • Monitoring of processing
  • Secure encryption technologies
  • Encrypted network connections (HTTPS)

Technical measures:

All parties processing personal data have a duty of confidentiality in matters related to the processing of personal data. Access to personal data is restricted to those employees and parties who need it to perform their duties. We also require our service providers to have appropriate methods in place to protect personal data.

Rights of the data subjects

You have certain rights in relation to the processing of personal data under applicable data protection laws.

Right of access and right of inspection

You have the right to obtain confirmation as to whether or not personal data concerning you is being processed. You have the right to inspect and view data concerning you and, upon request, the right to obtain the data in written or electronic form. This applies to information that you have provided to us insofar as the processing is based on a contract or consent.

Right to rectification and right to erasure

You have the right to request the rectification of incorrect personal data concerning you and to have incomplete personal data completed. You have the right to require us to delete or stop processing your personal data, for example where the data is no longer necessary for the purposes of processing. However, please note that certain personal data is strictly necessary to achieve the purposes defined in this Privacy Policy and may also be required to be retained by applicable laws.

Right to data portability

To the extent applicable, you have the right to receive the personal data that you have provided to us in a structured, commonly used, and machine-readable format and, if desired, to transmit that data to another controller.

Right to restriction of processing

You have the right, under conditions defined by data protection legislation, to request the restriction of processing of your personal data. In situations where personal data suspected to be incorrect cannot be corrected or removed, or if the removal request is unclear, we will limit the access to such data.

Right to object to processing

You have the right to object to the processing of your personal data where we are relying on legitimate interests as the legal ground for processing. For example, you may object to your personal data being used for certain marketing purposes.

Right to withdraw consent

In cases where the processing is based on your consent, you have the right to withdraw your consent to such processing at any time.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a competent data protection authority if you consider that the processing of your personal data by us infringes applicable legislation.

The competent authority is the Garante per la protezione dei dati personali (garante@garanteprivacy.it) – http://www.garanteprivacy.it/

Exercising rights

Requests regarding the rights of data subjects shall be made in written or electronic form and shall be addressed to the controller presented in section 2 of this Privacy Policy. We reserve the right to verify your identity before providing any information, which is why we may ask for additional details. The request will be responded to within a reasonable time and, where possible, within one month of the request and the verification of identity.

If the data subject's request cannot be met, the refusal shall be communicated to the data subject in writing. We may refuse the request (e.g. erasing data) due to a statutory obligation or a statutory right of the company, such as an obligation or a claim relating to our services. Please note that we may charge a reasonable fee where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character.

Changes to this privacy policy

We may make changes to this Privacy Policy at any time by giving notice on the website and/or by other applicable means. Data subjects are strongly recommended to review the Privacy Policy on our website regularly.

Whistleblowing

In order to prevent and counter unlawful conduct and conduct inconsistent with its values, Epassi Group has adopted a general framework, set out in the "Epassi Group Whistleblowing Policy", governing the procedures for reporting perceived or identified violations.

In compliance with the specific legal obligations under Legislative Decree No. 24/2023, the Company has implemented its own procedure governing the receipt, management, and investigation of reports of unlawful conduct identified in said Legislative Decree. To this end, the Company has made reporting channels accessible to all its employees and website users through the procedure contained in the document "Segnalazioni_Canale Whistleblowing", available in the Governance section of this website. Reports may be submitted through the channel made available by Epassi Group (Epassi Whistleblowing Channel: https://epassileaks.epassi.com).

The aim is to prevent non-compliance or irregularities within the organisation, and to engage all stakeholders in active and responsible participation in countering unlawful conduct.

Regardless of the reporting channel used, the protection and confidentiality of the identity of both the reporting person and the reported person is always guaranteed, in accordance with applicable laws. If a report proves to be false, unfounded and/or made solely with the intent to harm the reported person, or aimed at reporting matters of a purely personal nature and outside the scope of the applicable legal provisions, it will not be taken into consideration.