1. Scope and service providers
ISP APP is a mobile service provided by Dieffeitalia.it S.r.l., operational office at Viale Europa 36, 74015 Martina Franca (TA), Italy, Italian tax code and VAT number 02982940732.
The application is a shared technology platform used by independent Internet Service Providers. For customer, contract, invoice, service and support data, the ISP selected by the user normally determines the purposes of processing and is the user’s primary contact. Dieffeitalia.it S.r.l. operates the platform and processes such data on behalf of the ISP, except where it acts as an independent controller for its own legal obligations, platform security and service management.
The identity and contact details of the selected ISP are shown in the branded area of the application or can be requested directly from the ISP.
2. Data processed
Depending on the role and modules enabled by the selected ISP, the application may process:
- Identity, contact and account data: name, surname or company name, email address, telephone number, customer or operator identifiers, selected ISP, role, permissions and authentication information.
- Contractual and service data: services, installation and billing addresses, contracts, quotes, invoices, payment status, orders, support tickets, messages, appointments, activities and other information made available by the selected ISP.
- Content provided by the user: form entries, ticket messages, documents, images, signed contracts and other files intentionally uploaded through an available feature.
- Notification data: notification preferences, Firebase Cloud Messaging registration token, messages sent, delivery or opening state and related technical metadata.
- Technical and security data: IP address, session and device identifiers, access and event timestamps, browser, operating system or WebView information, diagnostic logs and information needed to prevent abuse and protect accounts.
- Payment information: payment amount, status and transaction references when a payment feature is used. Full card or bank credentials are handled by the payment provider selected by the ISP and are not intended to be stored by ISP APP.
Camera access may be requested to scan an ISP QR code or to select content for an upload. The scanned code is used to identify the ISP; images and files are transmitted only when the user intentionally submits them through an application feature.
3. Purposes of processing
Data are processed to:
- identify the selected ISP and authenticate the user;
- provide customer, staff and reseller functions enabled for the account;
- display and manage services, documents, invoices, payments, quotes, orders, tickets, messages, appointments and activities;
- send transactional and service notifications, including push notifications requested or enabled by the user or ISP;
- provide support, diagnose failures and maintain service continuity;
- protect users, accounts and systems, prevent fraud and abuse, and keep security records;
- comply with legal, accounting and regulatory obligations and defend legal claims.
ISP APP does not sell personal data and does not use it for third-party behavioural advertising.
4. Legal bases
Depending on the data and context, processing is based on performance of a contract or pre-contractual measures, compliance with legal obligations, the legitimate interest in providing and securing the service, or consent where specifically required. Optional notifications and communications can be managed through the available preferences, without affecting processing required to provide the service or comply with the law.
5. Recipients and service providers
Data may be accessed, only as necessary, by:
- the selected ISP and its authorised staff, according to assigned roles and permissions;
- Dieffeitalia.it S.r.l. personnel and authorised technical suppliers;
- hosting, infrastructure, security, communication, document and support providers;
- Google Firebase Cloud Messaging, for push notification delivery;
- email, SMS, WhatsApp, payment or other integration providers only when the relevant channel or feature has been enabled by the ISP and used for the requested service;
- public authorities or other parties where disclosure is required by law.
Third-party providers process data according to their own terms and privacy information when acting as independent controllers.
6. International transfers
Some technology or communication providers may process data outside the European Economic Area. Where required, transfers are governed by an adequacy decision, Standard Contractual Clauses approved by the European Commission or another safeguard permitted by applicable data-protection law.
7. Retention
Data are retained only for the time needed for the purposes described above and according to the selected ISP’s contractual and legal obligations. In particular:
- the in-app notification history is normally retained for up to six months for each recipient;
- push registration tokens are retained until they are replaced, disassociated or no longer required;
- session and security data are retained for the period needed to protect the account and service;
- contracts, invoices, payment references and related business records may be retained for longer periods required by tax, accounting or other applicable laws;
- uploaded content and support communications follow the retention rules of the selected ISP and the related service.
Data are then deleted, anonymised or restricted where a legal obligation requires continued retention.
8. Security
Appropriate technical and organisational measures are used to protect data, including encrypted transport, access controls, role-based permissions, protected sessions, logging and backup procedures. No internet service can guarantee absolute security; users must keep their credentials confidential, use an updated device and immediately report suspected unauthorised access.
9. User rights
Subject to the conditions of applicable law, users may request access, rectification, erasure, restriction, portability or objection to processing and may withdraw consent at any time without affecting earlier lawful processing.
Requests concerning a customer relationship, contract, invoice or ISP-managed account should first be sent to the selected ISP. Users may also contact Dieffeitalia.it S.r.l. at gdpr@dieffeitalia.it or its Data Protection Officer at dpo@dieffeitalia.it. Users may lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority.
10. Account and data deletion
ISP APP accounts are normally created and managed by the selected ISP and are linked to an existing customer, staff or reseller relationship. To request account deletion, use the ISP contact shown in the application or send a request to gdpr@dieffeitalia.it, specifying the selected ISP and the email or customer identifier associated with the account.
The request will be forwarded to or coordinated with the competent ISP when necessary. Account access will be disabled and personal data will be deleted or anonymised unless retention is required for invoices, contracts, security, legal obligations or the establishment, exercise or defence of legal claims. Deleting the app from a device does not by itself delete the account or data held by the ISP.
11. Children
ISP APP is intended for customers, authorised ISP personnel and resellers and is not directed to children. A minor may use the service only where permitted by law and under the responsibility of a parent, guardian or contracting party.
12. Changes and contacts
This policy may be updated when application functions, providers or legal requirements change. Material changes will be communicated through the application, the selected ISP or this page where appropriate.
Privacy contacts: gdpr@dieffeitalia.it · DPO: dpo@dieffeitalia.it.
Last updated: 29 August 2026