1. Data Controller (Titolare del Trattamento)
The Data Controller responsible for processing your personal data on this website and the ISOT Member App is:
ISOT Community (International Students of Turin Non-Profit Initiative)
Headquarters: Turin (TO), Piedmont, Italy
Official Contact Email: privacy@isotcommunity.com or info@isotcommunity.com
Official Website: https://isotcommunity.com
2. Categories of Personal Data & Purpose of Processing
We collect and process personal data exclusively for non-profit student social integration, community registry management, and event organization:
A. Account Registration & Student Profiles
- Data Elements: Full Name, Email Address, University Affiliation (e.g. UniTo, PoliTo, SAA), Nationality, Spoken Languages, Profile Photo / Avatar, and Member Registration Code.
- Legal Basis: Performance of a contract / membership agreement (Art. 6(1)(b) GDPR) and explicit user consent.
- Purpose: Issuing digital member passes, maintaining community registries, verifying student status, and facilitating peer student connections.
B. Event Check-ins & Karaoke Queue
- Data Elements: RSVP status for cultural events, check-in timestamps, karaoke song titles, artist names, and stage queue position.
- Legal Basis: Legitimate interest in managing event capacity, venue safety, and community activities (Art. 6(1)(f) GDPR).
C. Supporting Membership Contributions & Payments
- Data Elements: Payment receipt confirmation numbers, payment timestamps, and transaction metadata. (Note: Financial credit card processing is handled securely by external PCI-DSS compliant providers; ISOT never stores full credit card numbers).
- Legal Basis: Legal statutory compliance (Art. 6(1)(c) GDPR) and accounting record-keeping under Article 2220 of the Italian Civil Code (Codice Civile).
3. Cookie Notice & Web Analytics Policy
Our website and web application are designed with privacy-first principles in accordance with the Italian Data Protection Authority (Garante per la protezione dei dati personali) Guidelines of 10 June 2021:
A. Technical & Essential Session Storage
We use essential Local Storage keys and session tokens (such as isot_auth_token, isot_profile, isot_friends, isot_rsvps) strictly necessary to keep you securely signed in, preserve your PWA theme preferences, and render your member pass offline. These do not require explicit cookie consent under Art. 122 of D.Lgs. 196/2003.
B. Privacy-Preserving Web Analytics
We use cookieless Vercel Web Analytics (/_vercel/insights/script.js) to monitor general site traffic, page view counts, and platform performance. Vercel Web Analytics does NOT set persistent cookies, does NOT collect IP addresses, and does NOT track users across third-party websites or sell advertising profiles.
C. Third-Party Embedded Maps
For partner venue location maps on our Partners page, we use open-source Leaflet.js with OpenStreetMap tiles, ensuring no third-party tracking pixels or ad networks are loaded.
4. Data Retention & Your GDPR Data Subject Rights
Under Articles 15 to 22 of the EU General Data Protection Regulation (GDPR), you possess the following rights regarding your personal data:
- Right of Access (Art. 15): You have the right to request a complete copy of all personal data held by ISOT Community.
- Right to Rectification (Art. 16): You can update or correct your profile details anytime inside the Account Settings tab.
- Right to Erasure / "Right to be Forgotten" (Art. 17): You can instantly delete your account and profile data self-service inside Account Settings > Danger Zone > Delete Account. Upon deletion, your profile, check-in history, and social connections are permanently erased. Statutory accounting receipts for supporting membership fees are retained for 10 years per Art. 2220 Cod. Civ.
- Right to Restriction & Objection (Art. 18 & 21): You may object at any time to receiving community newsletter announcements.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, machine-readable JSON format.
- Right to Lodge a Complaint: If you believe your data protection rights have been infringed, you have the statutory right to file a complaint with the Italian Supervisory Authority: Garante per la protezione dei dati personali (www.garanteprivacy.it, Piazza Venezia 11, 00187 Roma).
5. Non-Profit Principles & Community Charter
ISOT operates strictly as a student-led non-profit international organization in Turin, preparing for formal association registration under Italian law:
- Non-Profit Principle: ISOT does not distribute commercial profits. All membership contributions (€10/year) and voluntary donations are reinvested 100% into international student cultural events, language exchanges, academic workshops, and community integration initiatives.
- Member Contributions: All community contributions and supporting membership fees are personal, non-transferable, and non-refundable.
- Community Transparency: Supporting community members have full rights to inspect financial summary registers, participate in open community assemblies, and volunteer for community initiatives.
6. Technical Security & Contact Us
All communications between your device and ISOT servers are encrypted using industry-standard TLS 1.3 encryption. Passwords and authentication tokens are hashed and handled via enterprise-grade Supabase Auth infrastructure.
For any privacy inquiries, data access requests, or statutory questions, please contact our privacy compliance team at:
privacy@isotcommunity.com