1. Data Controller
The data controller for personal data collected through the website openacademia.eu is:
- Name
- OpenCom i.s.s.c.
- Address
- Piazza Giotto n. 13 – 52100 Arezzo (AR), Italy
- Tax Code / VAT No
- IT02096350513
- info@opencom-italy.org
- Institutional website
- https://opencom-italy.org
- Certified email (PEC)
- [insert PEC]
2. Internal Data Protection Contact
OpenCom i.s.s.c. has designated an internal data protection contact as the point of contact for requests from data subjects and for overseeing compliance with the GDPR.
The appointment of a Data Protection Officer (DPO) under Article 37 GDPR is not mandatory for OpenCom i.s.s.c., as the organisation does not fall within the cases provided for by that provision: it is not a public authority, it does not carry out large-scale systematic monitoring of data subjects, and it does not process special categories of data as a core activity.
To exercise your rights or for any matter relating to the processing of personal data, you may contact the internal contact by writing to: info@opencom-italy.org
3. Categories of Personal Data Processed
In connection with the various features of the site, we process the following categories of personal data:
3.1 Registration and account management
- First and last name
- Email address
- Password (stored in encrypted form)
- Selected role (student / teacher / instructor)
- Any profile data voluntarily provided by the user
3.2 Course purchases and payments
- Billing data (first and last name, address, tax code / VAT number)
- Payment data: processed exclusively by PCI-DSS-certified providers (e.g. Stripe, PayPal). OpenAcademia does not store full credit card details.
- Order history and purchased courses
3.3 Comments and forums
- Display name (or username)
- Email address (not publicly visible)
- IP address and browser user agent (for anti-spam purposes)
3.4 Newsletter and promotional communications
- Email address
- First name (if provided)
- Email preferences and interactions (opens, clicks), where the service allows
3.5 Browsing data
During normal browsing, technical data are automatically collected, including: IP address, browser type, operating system, pages visited, time and duration of visits. Such data are used exclusively for aggregate statistical purposes and to ensure the proper functioning of the site.
4. Purposes and Legal Bases for Processing
4.1 Performance of a contract (Art. 6(1)(b) GDPR)
Data relating to registration, course purchases, and use of educational content are processed to fulfil contractual obligations with the user: account creation and management, delivery of purchased services, issuance of completion certificates, and technical support.
4.2 Compliance with legal obligations (Art. 6(1)(c) GDPR)
Billing data and data relating to financial transactions are processed to comply with fiscal, accounting, and legal obligations under applicable Italian and European legislation.
4.3 Consent of the data subject (Art. 6(1)(a) GDPR)
The newsletter and promotional communications are sent exclusively on the basis of the user’s explicit consent, given at the time of subscription or via a dedicated opt-in option. Consent may be freely withdrawn at any time via the unsubscribe link included in every email or by contacting the data controller.
4.4 Legitimate interest (Art. 6(1)(f) GDPR)
Technical browsing data and data collected in connection with the publication of comments are processed on the basis of the data controller’s legitimate interest in ensuring platform security, preventing fraud and unlawful activity, and detecting and blocking spam.
5. Data Retention Period
Personal data are retained for no longer than is necessary for the purposes for which they were collected, in accordance with the principles of data minimisation and storage limitation (Art. 5 GDPR):
- Account data: for the duration of the contractual relationship and for 10 years following account closure, for the purposes of legal obligations.
- Billing data: 10 years from the date of the transaction, pursuant to the fiscal and accounting obligations under Presidential Decree 600/1973 and VAT legislation.
- Comments: indefinitely, unless a deletion request is submitted by the data subject, as they form part of the platform’s editorial content.
- Newsletter: until consent is withdrawn or the user unsubscribes; consent logs are retained for up to 3 years from withdrawal for evidentiary purposes.
- Browsing data: no longer than 12 months, unless required by security needs or legal obligations.
6. Recipients and Data Transfers
Personal data may be communicated, to the extent strictly necessary, to the following categories of recipients:
- Technical service providers: hosting providers, email services, and CDN providers, acting as data processors under Art. 28 GDPR.
- Payment platforms: certified payment operators (e.g. Stripe, PayPal), subject to their own privacy policies and security certifications.
- Email marketing services: newsletter providers (e.g. Mailchimp, Brevo), limited to subscribers who have given their consent.
- Consultants and professionals: legal, fiscal, and administrative consultants, within the scope of their respective professional mandates.
- Public authorities: in cases provided for by law or upon request from competent authorities.
Personal data are not sold, transferred, or disclosed to third parties for commercial purposes not authorised by the data subject.
Transfers outside the EU: where certain providers process data outside the European Economic Area, the transfer takes place in compliance with the safeguards provided for under Arts. 44–49 GDPR (Adequacy Decisions, Standard Contractual Clauses).
7. Cookies and Tracking Technologies
OpenAcademia uses cookies and similar technologies for the operation of the platform and to improve the user experience. For detailed information on the types of cookies used, their duration, and how to manage or withdraw consent, please refer to the Cookie Policy available at: https://openacademia.eu/cookie-policy-eu/
8. Rights of Data Subjects
Under Arts. 15–22 GDPR, users have the right to:
- Access (Art. 15): obtain confirmation of whether processing is taking place and receive a copy of the personal data being processed.
- Rectification (Art. 16): request the correction of inaccurate or incomplete data.
- Erasure (Art. 17): obtain the deletion of data in the cases provided for by law (
right to be forgotten
). - Restriction (Art. 18): request the suspension of processing in certain circumstances.
- Portability (Art. 20): receive data in a structured format and transfer it to another controller, for processing based on consent or contract.
- Objection (Art. 21): object to processing based on legitimate interest or carried out for direct marketing purposes.
- Withdrawal of consent (Art. 7(3)): withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- Complaint (Art. 77): lodge a complaint with the competent supervisory authority (Garante per la Protezione dei Dati Personali – www.garanteprivacy.it).
To exercise their rights, data subjects may contact the data controller at the details set out in section 1 of this policy.
The data controller will respond to requests within 30 days of receipt, extendable to 90 days in cases of particular complexity (Art. 12 GDPR).
9. Data Security
OpenAcademia adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR), including: encrypted connections (HTTPS/TLS), password hashing, access controls, platform monitoring, and incident response procedures. In the event of a data breach posing a risk to the rights of data subjects, the data controller will notify the supervisory authority within 72 hours and, where necessary, will inform the data subjects in accordance with Arts. 33–34 GDPR.
10. Minors
OpenAcademia is a platform intended for users aged 16 or over. Under Art. 8 GDPR and Legislative Decree 101/2018, for users aged between 14 and 16, the consent of the holder of parental responsibility is required. We do not knowingly collect personal data from children under the age of 14. Should we become aware of any non-compliant processing, we will proceed with the immediate deletion of the data.
11. Changes to This Policy
The data controller reserves the right to update this policy at any time, in particular following regulatory changes or developments to the platform. The updated version will be published on this page with the revision date indicated. For material changes affecting the purposes or categories of data processed, registered users will be notified by email or via a notice in their personal account area.
12. Contact
For any questions regarding this policy or the processing of personal data:
- Data Controller
- OpenCom i.s.s.c.
- info@opencom-italy.org
- Address
- Piazza Giotto n. 13 – 52100 Arezzo (AR), Italy
- Website
- https://openacademia.eu
