1. Controller and privacy roles
For processing related to ixotrack.com, commercial enquiries and contract management, the controller is INNOVA Società Cooperativa, Via Colonnello Berte 100, 98057 Milazzo (ME), Italy, VAT IT 03477590834, contactable at info@ixotrack.com. When a customer uses Ixotrack to manage workers or users, the customer is normally the controller and INNOVA acts as processor under Article 28 GDPR.
2. Scope
This notice covers the public website, commercial contacts, accounts, platform use and operational or entry/exit events. Customers must provide their workers with their own notice reflecting the chosen configuration and purposes.
3. Data processed
We may process name, surname, email, telephone number and, optionally, an identification photo. The photo is not used for facial recognition or biometric processing. Entry and exit records contain user ID, event type and server timestamp. Security-related technical data such as IP address, user agent, request time and error logs may also be processed.
4. Purposes and legal bases
Data is processed to provide the service, manage accounts and contracts, ensure security and support, meet legal obligations and protect rights. Legal bases include contract or pre-contractual steps, legal obligations and legitimate interests in security and legal defence.
5. Data not collected
Ixotrack does not collect GPS coordinates, perform geolocation or continuous tracking, record audio or video, use biometric data, or conduct advertising or behavioural profiling.
6. Retention
Platform data is retained for the contractual relationship and according to periods set by the customer, unless longer retention is required by law or for legal protection. Commercial data is kept as needed for the enquiry and pre-contractual relationship. Technical logs are retained for periods proportionate to security needs.
7. Recipients and hosting
Data may be processed by authorised staff, the customer and authorised users, and contractually bound technical providers. Infrastructure is managed by Infomaniak and hosted in Switzerland, which benefits from an adequacy decision of the European Commission.
8. Security
Ixotrack uses risk-appropriate measures including HTTPS/TLS, credentials and roles, session management, logical separation and application-event logging. Users must protect credentials and report anomalies.
9. Data-subject rights
Where applicable, individuals may exercise rights of access, rectification, erasure, restriction, portability and objection and may complain to a supervisory authority. For data managed by a customer, requests should first be addressed to that customer as controller.
10. Contacts and updates
Questions may be sent to info@ixotrack.com. This policy may be updated to reflect legal, technical or organisational changes.