Personal-data information notice
Italiarena · · Italy
Official version: Italian. This English text is a translation.
This notice is provided under Articles 12, 13 and 14 of Regulation (EU) 2016/679 (the «GDPR») and the Italian Personal Data Protection Code (Legislative Decree no. 196 of 30 June 2003, as amended by Legislative Decree no. 101 of 10 August 2018, the «Codice privacy») to users of Italiarena in Italy or using the service from Italy. It is written in clear language as required by Articles 12–14 GDPR, the Article 29 Working Party transparency guidelines (WP260 rev. 01, 11 April 2018), and Garante guidance. If versions conflict, the Italian text prevails.
1. Applicable legal framework
Processing is governed by the following rules, to the extent they apply to the data Italiarena actually processes (accounts, matches, preferences, optional Google sign-in, optional push reminders, optional AI explanations, reports, and community submissions):
- Regulation (EU) 2016/679 (GDPR), in particular Articles 5–7, 12–22, 24–25, 28, 32, 37, 44–49, and 77–79.
- Legislative Decree no. 196 of 30 June 2003 (Codice privacy), as aligned with the GDPR by Legislative Decree no. 101 of 10 August 2018, in particular Articles 2-quinquies (digital consent age), 2-terdecies (deceased persons), 122 (storage of information on a user’s device), 130 (electronic communications), 141 (complaint to the Garante), and 152 (judicial protection).
- Directive 2002/58/EC (ePrivacy), implemented in Italy by Articles 122 and 130 of the Codice privacy.
- Garante guidelines on cookies and other tracking tools, measure no. 231 of 10 June 2021.
- Regulation (EU) 2024/1689 (AI Act), for transparency aspects of the service’s AI features.
- Italian Law no. 132 of 23 September 2025 (artificial intelligence), in particular Articles 3 and 4 on transparency, confidentiality, and minors’ access to AI.
2. Data controller
The data controller is Ali Arman Dai, a natural person operating Italiarena (website: https://italiarena.com), established in Italy. The service is provided free of charge and is not a business activity, so there is no registered office or place of business to state. For any request relating to your personal data, including rights under Articles 15–22 GDPR, contact [email protected]. No EU representative has been appointed under Article 27 GDPR, because the controller is established in the European Union.
3. Data Protection Officer (DPO)
No Data Protection Officer has been appointed, because processing does not fall within the mandatory cases in Article 37 GDPR (we are not a public authority, we do not carry out large-scale regular and systematic monitoring, and we do not process special categories or criminal-offence data on a large scale).
4. Categories of personal data processed
We process only data needed for the service, in line with data minimisation and purpose limitation (Article 5 GDPR). These categories match what the app actually collects:
- Identification and contact data: email address, hashed password (handled by our authentication provider), display name (username), internal role (user or admin), and email-verification status.
- Google sign-in (only if you choose it): Google account identifier, name, and email that Google sends at authentication.
- Guest mode: an auto-generated display name and, if guest authentication is used, a technical non-real email (guest-…@guest.local). Guests do not appear on the leaderboard and cannot submit community questions.
- Learning profile: Italian proficiency level (CEFR), target language (Italian), sound and haptic preferences.
- Gameplay data: statistics, seen questions, match history, scores, result (win/loss/tie), opponent type, mistakes and mistake-practice progress, and in-progress session answers and scores.
- Ghost matches: answers from a completed match may be reused for an automatic opponent. The interface shows a generic name («Ghost Opponent»), not the original user’s username.
- Leaderboard: for registered accounts, display name and PvP results (matches, wins, win rate, points) visible to other authenticated users.
- Reports and contributions: the type of issue reported on a question; submitted question text, options, correct answer, optional rationale, and reviewer notes.
- Artificial intelligence (only on request): question text, the correct option text, the selected option text, and the generated «Ask AI» explanation; a per-match count of AI requests; and, for community submissions, an automatic pre-check (advisory only for a human reviewer).
- Push notifications (only if enabled): subscription endpoint, technical keys (p256dh and auth), browser user-agent, IANA timezone, preferred daily reminder hour, and last-sent timestamp.
- Authentication and security technical data: session cookies and tokens, and IP address / user-agent that may appear in hosting technical logs, with access timestamps.
- Device storage: sound/volume/haptics preferences, colour theme, local match state, and short-lived navigation data (see the cookies section).
5. Source of the data (Articles 13 and 14 GDPR)
Data comes from these sources:
- Data you provide: registration, onboarding, settings, matches, reports, submissions, «Ask AI» requests, and enabling notifications.
- Data generated by the service: scores, statistics, leaderboard, game sessions, AI pre-checks of submissions, and security logs.
- Data from third parties: if you use «Sign in with Google», Google LLC sends the account data needed for authentication. Google processes its own account data as an independent controller, under its own notice.
- We do not buy contact lists or collect public-source data to profile users.
6. Special categories and criminal-offence data
We do not intentionally collect special-category data under Article 9 GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation) or criminal-offence data under Article 10 GDPR and Article 2-octies of the Codice privacy. Please do not put such data in question or report text.
7. Purposes, legal bases, and retention periods
For each purpose we state the legal basis (Article 6 GDPR) and the retention period (Article 13(2)(a) GDPR):
- Account creation and management (email, credentials, username, profile): performance of a contract or pre-contractual steps, Article 6(1)(b) GDPR; kept for as long as the account is active.
- Email verification and password reset: performance of a contract, Article 6(1)(b); links expire after a short technical period.
- Google sign-in: performance of a contract, Article 6(1)(b), and, for Google cookies/scripts needed for that login, Article 122(1), second sentence, Codice privacy (strictly necessary for the service you requested).
- Guest mode: performance of a contract, Article 6(1)(b); kept for the guest session or until conversion to a registered account.
- Matches, leaderboards, statistics, mistake practice, ghost matches, and session state: performance of a contract, Article 6(1)(b); kept for as long as the account is active. Ghost data may be used for matchmaking while the account remains active.
- Sound, haptics, and theme preferences: performance of a contract, Article 6(1)(b); they remain on the device until you clear them.
- Reporting incorrect or ambiguous questions: legitimate interest in keeping learning content accurate (Article 6(1)(f)); the interest is question quality for all users, with limited impact on the reporter (we keep the issue type and reporter id); kept until the report is resolved, and in any event no longer than 24 months.
- Community question submissions: performance of a contract, Article 6(1)(b); kept until review; if approved, the question remains in the game pool (without exposing the submitter’s email to other players).
- «Ask AI» explanations: consent, Article 6(1)(a), given by the specific request; generated explanations may be stored in a shared cache per question/answer pair in non-nominative form; per-match request counts are kept for the life of the account. You withdraw consent by no longer using the feature.
- Automatic pre-check of submissions: performance of a contract, Article 6(1)(b), and, as use of an AI system, in line with Article 4 of Law 132/2025 (clear information and the option not to use submissions). A human admin always makes the final decision; this is not automated decision-making under Article 22 GDPR.
- Daily push reminders: consent, Article 6(1)(a) GDPR, given by enabling the feature in Settings and granting the browser permission. Article 122 Codice privacy also applies (storing the push subscription on the device) and, because the message nudges you back into the app, Article 130 Codice privacy (electronic communications: prior, free, specific, informed, and documented consent). Kept until you disable reminders or delete the account.
- Usage analytics with Microsoft Clarity (heatmaps and text-masked session replay): consent, Article 6(1)(a) GDPR and Article 122 Codice privacy, given through the cookie banner. Without consent the tag is not loaded and no Clarity cookie is written. Retention follows Microsoft’s notice (as a rule up to 30 days for session recordings). You can withdraw consent at any time in Settings → Privacy & data.
- Security, abuse prevention, and technical operation: legitimate interest, Article 6(1)(f); technical logs as a rule for up to 90 days, unless a longer legal retention applies.
- Compliance with legal obligations (for example responding to a competent authority): Article 6(1)(c) GDPR.
8. Whether data is required and consequences of refusal
Providing email and password (or a Google account) and, in guest mode, Italian proficiency level is necessary to enter into the contract and use the service (Article 13(2)(e) GDPR). Refusal prevents account creation or access to matches. A custom username, reports, community submissions, «Ask AI», and push notifications are optional; not using them does not block core play, but limits the related features. Service messages (email verification, password reset) are required to operate the account and are not promotional.
9. Recipients and processors
Data may be shared, within the purposes above, with parties that process it on our behalf as processors under Article 28 GDPR, bound by a data-processing agreement, or, in specific cases, with independent controllers:
- Supabase Inc. — database, authentication, and application-data hosting (https://supabase.com/privacy).
- Vercel Inc. — web application hosting (https://vercel.com/legal/privacy-policy).
- Groq Inc. — «Ask AI» explanations and submission pre-checks, only if you use those features (https://groq.com/privacy-policy).
- Google LLC — «Sign in with Google», only if you choose it. Google is an independent controller for its own account processing (https://policies.google.com/privacy).
- Microsoft Ireland Operations Limited / Microsoft Corporation — usage analytics via Microsoft Clarity, only with the consent you give in the cookie banner (https://privacy.microsoft.com/privacystatement).
- Browser/OS push services (for example Apple, Google FCM, or Mozilla, depending on the device) — delivery of notifications, only if enabled.
- Public authorities, where required by law.
10. Transfers to third countries
Some providers may process data outside the European Economic Area, including the United States. Transfers take place under Articles 44–49 GDPR, on the basis of a European Commission adequacy decision (including the EU–US Data Privacy Framework where the importer is certified) and/or Standard Contractual Clauses (SCCs) approved by the Commission, plus supplementary safeguards adopted by the providers. Copies of the applicable safeguards may be requested at [email protected].
12. Electronic communications and push notifications (Article 130 Codice privacy)
Under Article 130 of the Codice privacy we do not send promotional communications, newsletters, or advertising by email, phone, or automated systems without prior free, specific, informed, and documented consent. We do not rely on the «soft spam» exception in Article 130(4). The service sends only: (i) messages strictly necessary for the account (email verification, password reset); (ii) daily push reminders, only if you enable them in Settings, grant the browser permission, and can turn them off at any time. Reminders are not used for commercial profiling.
13. Artificial-intelligence systems
Italiarena uses third-party AI systems (models hosted by Groq) in two optional cases, both with human oversight, in line with Articles 3 and 4 of Italian Law no. 132 of 23 September 2025 and the transparency principles of Regulation (EU) 2024/1689:
- «Ask AI»: on an explicit request, the question text, the correct option text, and the selected option text are sent to the provider to generate an educational explanation in English. We do not send your name, email, the full option list, or other contact details in the prompt. You can simply not request explanations.
- Submission pre-check: if you submit a community question, an AI model gives a non-binding opinion (for example on language, CEFR level, and category). A human administrator decides whether to approve or reject. This is not solely automated decision-making with legal or similarly significant effects (Article 22 GDPR).
- Italiarena does not use AI-sent data to train its own models. The provider processes the data under its contract and privacy notice.
- AI features, like the rest of the service, are for users aged 14 and over. Under-14s would need consent from the holder of parental responsibility (Article 2-quinquies Codice privacy and Article 4(4) of Law 132/2025); the service is not intended for that age group.
14. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects or similarly significantly affects you under Article 22 GDPR. Matchmaking is based on declared Italian proficiency solely to organise fair matches, without commercial profiling. We do not sell or share personal data with third parties for marketing.
15. Security measures
We apply appropriate technical and organisational measures under Article 32 GDPR and privacy by design / by default (Article 25 GDPR), including encryption in transit (HTTPS/TLS), credential handling through our authentication provider (passwords not stored in plain text), restricted access to production data, contracts with processors, and account deletion on request.
16. Your rights
Under Articles 15–22 GDPR and the Codice privacy, you have the right of access, rectification, erasure, restriction, objection (where applicable, in particular for legitimate-interest processing), and data portability, and to withdraw consent for «Ask AI» and push notifications without affecting processing that already took place. You can update your profile in Settings, delete your account at any time, or write to [email protected]. We respond within one month, extendable by two further months in complex cases, under Article 12(3) GDPR. Exercising these rights is in principle free of charge (Article 12(5)).
17. Rights relating to deceased persons (Article 2-terdecies Codice privacy)
Rights under Articles 15–22 GDPR relating to personal data of deceased persons may be exercised by someone with their own interest, acting to protect the data subject as a representative, or for family reasons meriting protection, subject to legal limits and any express, specific, and informed prohibition by the data subject, as provided by Article 2-terdecies. Send such requests to [email protected].
18. Right to lodge a complaint and judicial protection
You may lodge a complaint with the Garante per la protezione dei dati personali under Article 77 GDPR and Article 141 of the Codice privacy, or bring proceedings before the ordinary courts under Articles 78 and 79 GDPR and Article 152 of the Codice privacy. A complaint does not affect any other administrative or judicial remedy.
- Website: https://www.garanteprivacy.it
- How to lodge a complaint: https://www.garanteprivacy.it/home/diritti/come-agire-per-tutelare-i-tuoi-dati-personali
- Address: Piazza Venezia 11, 00187 Roma
- Telephone: +39 06 696771
- PEC: [email protected]
19. Children
The service is intended for users aged 14 and over, in line with Article 8 GDPR and Article 2-quinquies of the Codice privacy (age of consent for information-society services in Italy) and, for AI features, Article 4(4) of Law 132/2025. We do not knowingly collect personal data from anyone under 14. If you believe a minor provided data without valid consent from the holder of parental responsibility, contact [email protected] and we will delete it without undue delay.
20. Account deletion and residual retention
When you delete your account from Settings, we erase your profile, statistics, match history, mistakes, push subscriptions, «Ask AI» logs linked to you, and other linked personal data without undue delay. Residual copies may remain in encrypted backups for a limited technical period (up to 30 days) before automatic deletion. AI explanations stored in a shared cache per question/answer and already-approved community questions may be kept in anonymised or non-identifiable form. Data strictly needed to defend legal claims or to meet Italian legal obligations may be kept for the time required by law.
21. Changes to this notice
We may update this notice to reflect changes to the service or applicable law. The updated date appears at the top of this page. For material changes, we will provide a clear notice in the app where appropriate.
Contact
For privacy requests, email [email protected]. To lodge a complaint with the Italian supervisory authority, contact the Garante per la protezione dei dati personali.