Personal data processing notice
Last updated: 22 August 2026
This page provides the information on the processing of personal data of the users of the services delivered through the AloVault application (the "Service") required by the applicable data protection legislation, in particular pursuant to Art. 13 of EU Regulation 2016/679 (the "GDPR").
1. Data controller
The controller of the data of the users of the Service is:
ALOSYS COMMUNICATIONS S.R.L. (the "Controller" or "Alosys")
Registered office: Via Giovanni Paisiello 12 Int. S29, Roma 00198, Italy
Tax code and VAT: 08974171004
Tel: +39 06.51964757 | Fax +39 06.54224210
Contact: e-mail comunicazione@alosys.it
2. Types of data processed
The personal data (the "Data") that may be collected and processed within the Service are the following:
- (a) personal details (e.g. first and last name) and contact details (e.g. email and phone number) of the users, required for registration to the Service;
- (b) Service access data (e.g. date and time of each access, IP address, device identifiers) and Service usage data (e.g. log files such as the date and time of sending or receiving encrypted content transferred through the Service). Neither the Controller nor any party other than the recipient users can access in clear text the content transferred through the Service (documents, messages, chats, attachments, voice notes and shared locations), as it is protected by end-to-end encryption;
- (c) data relating to the payment of license fees for the use of the Service (e.g. billing data), normally referring to the user's organization.
Failure to provide certain Data (e.g. the data required at user registration) may make it impossible to provide the Service. Should the User provide the Controller with third parties' data, the User relieves the Controller of any liability for its processing for purposes instrumental to the provision of the Service.
The Controller does not collect or process users' biometric data: the Service relies on the systems offered by the user's own device to generate unique, personal codes based on biometric authentication. Biometric data never leaves the device.
The Service does not use tracking systems for advertising, marketing or profiling purposes.
3. Purposes of processing
- (a) to allow the Controller to provide and improve the Service;
- (b) to protect users' accounts and the Service, including preventing abuse and external attacks;
- (c) to comply with legal obligations to which the Controller may be subject (for example in tax matters);
- (d) to respond to users' requests.
4. Legal bases of processing
- processing for the purposes under letters (a), (b) and (d) of paragraph 3 is carried out as necessary for the performance of a contract with the user and/or for pre-contractual measures, pursuant to Art. 6, par. 1 lett. b) of the GDPR;
- processing for the purposes under letter (c) of paragraph 3 is carried out, pursuant to Art. 6, par. 1 lett. c) of the GDPR, to comply with legal obligations to which Alosys is subject as Controller.
The Controller may also process Data for further purposes necessary to pursue the legitimate interest of Alosys, or to protect the data subjects or third parties, pursuant to Art. 6, par. 1 lett. f) of the GDPR. In such cases, the Controller will process the Data only after having verified that the pursuit of its own or third parties' legitimate interests does not compromise the fundamental rights and freedoms of the data subjects, and will inform the data subjects of the processing in question.
5. Recipients
Only the following categories of recipients will have access to personal data:
- Alosys personnel expressly authorized to process personal data for the management of the Service (e.g. administrative, technical, legal personnel, system administrators);
- external parties (e.g. third-party technical service providers, hosting providers, IT companies, external consultants) processing data on behalf of the Controller, appointed by Alosys as data processors pursuant to Art. 28 of the GDPR;
- third parties processing data as independent controllers, for example to comply with legal obligations (tax communications etc.).
Some Data (e.g. date of sending and receiving encrypted content, type of smartphones used) will also be accessible to other members of the same community/organization with special privileges.
6. Processing methods
The Data is processed by the Controller with automated tools, with organizational methods and logic strictly related to the indicated purposes. Specific security measures are observed to prevent data loss, unlawful or incorrect use and unauthorized access. All communications between the application and the servers take place over encrypted channels.
7. Place of processing and data transfer
The Data is processed within the European Union and will not be transferred outside the European Economic Area.
8. Retention period
- Data collected for purposes related to the performance of the contract between Alosys and the user of the Service will be retained as long as the user's account is active and for two years after any deactivation; payment data and accounting and tax data in general will be kept for ten years after the deactivation of the account;
- contact details of users required to start the registration process, provided by other users, will be deleted within two months of receipt if those users do not register within the same term;
- personal data collected for purposes attributable to the legitimate interest of the Controller will be retained until such interest is satisfied;
- Alosys may be required to keep personal data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, personal data will be deleted.
9. Account deletion
AloVault users can request at any time the deletion of their account and the data associated with it:
- by sending an e-mail to comunicazione@alosys.it from the e-mail address registered with the Service, with the subject "AloVault account deletion"; or
- by contacting the administrator of their organization, who can deactivate the account through the management console.
Following the request, the following will be deleted within 30 days: the account's personal and contact details, device registrations and the related public keys, and usage metadata. Data that the Controller is required to keep by law (e.g. accounting and tax data, kept for the terms indicated in paragraph 8) is excepted.
Encrypted content on the users' devices (their own or the recipients') resides exclusively on those devices and can be removed by uninstalling the application.
10. Users' rights
Data subjects have the right, in relation to their data, to: access their personal data; request its deletion or rectification; restrict its processing; request its portability; object to its processing. In any case, data subjects may lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali). To exercise the rights listed above, requests should be addressed to the Controller at comunicazione@alosys.it, through which the Data Protection Officer, if designated by the Controller, can also be contacted.
11. Changes and updates to this privacy policy
The Controller reserves the right to make changes to this privacy policy at any time, giving notice to users and making the updated notice available.
