GDPR Data Processing Information (Addendum)

Regulatory Reference: Regulation (EU) 2016/679 (GDPR)

This document is an addendum to the Flipeando.com Privacy Policy and is primarily intended for residents of the European Economic Area (EEA) and the United Kingdom, fulfilling the transparency obligations required by the General Data Protection Regulation (GDPR).

Table of Contents:


1. Data Controller and DPO

The Data Controller for your personal data, as described in the Privacy Policy, is:

Flipeando di Miriam Vadillo
Milan - Italy
Email: privacy@flipeando.com

Data Protection Officer (DPO):
The Controller has appointed a Data Protection Officer (DPO), who can be contacted for all matters related to the processing of your personal data and the exercise of your rights:
DPO Email: dpo@flipeando.com


2. Legal Bases for Processing (Art. 6 GDPR)

We process your personal data only when we have a valid legal basis to do so. The legal bases we rely on to process your data include:


3. Purposes of Processing

The purposes of processing are detailed in Section 2 of our Privacy Policy. The purposes are linked to the legal bases as follows (non-exhaustive examples):


4. Your Rights Under GDPR (Art. 15-22)

As a data subject, you have the following rights, which you may exercise by contacting the Controller or DPO at the email address provided above:

We will respond to your requests within the timeframe mandated by law (typically one month from receipt of the request).


5. International Data Transfers (Art. 44)

Your personal data is primarily processed in Italy. However, we may transfer your data to servers or service providers (third parties) located outside the European Economic Area (EEA), such as the United States, for the performance of our services (e.g., hosting, email marketing).

In such cases, we ensure that the transfer complies with legal provisions, guaranteeing an adequate level of personal data protection through the adoption of:


6. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you consider that the processing relating to you infringes the GDPR.

For Italy, the competent supervisory authority is the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority) (Piazza Venezia n. 11 - 00187 Roma - Fax: (+39) 06.588.1884 - protocollo@pec.gpdp.it).


End of GDPR Data Processing Information (Addendum)