Atâaâglance summary (iubenda style)
Controller: Mea World S.r.l. â Via Niccolò Machiavelli, 24 â 51100 Pistoia (PT), Italy â VAT/Tax ID: 02069030472
Privacy contacts: privacy@kiuwo.com â (tech) dev@meaworld.com â PEC: pec@pec.meaworld.it
DPO: not appointed.
Data we collect automatically
- Usage data (app events, telemetry, errors, performance)
- Tracking tools (cookies and similar technologies)
- Device and browser information
- IP address, pageviews, clicks, internal browsing history
- [if enabled] heatmaps and session replay
Trusted third parties that help us process them:
- Vercel Inc. (hosting/frontend)
- Supabase, Inc. (database, backend, authentication)
- PostHog, Inc. (analytics, A/B tests, heatmaps, surveys)
How we use them:
- Hosting & backend infrastructure
- Registration and authentication
- Statistics / product analytics
- A/B testing & feature flags
- Heat mapping and session recording [if enabled]
- Forms and surveys management
Data you provide to us
- Email, first/last name [if requested]
- Userâgenerated content (maps, nodes, files, audio/transcripts)
- Answers to questions/surveys
How we use them:
- Service delivery (account, maps, cloud sync)
- Support, service communications, KIU [if you publish content]
- Payments [if any] via Stripe (independent controller)
- Marketing only with consent (with optâout in every email)
Legal basis: contract, legal obligation, legitimate interest, consent (for analytics/marketing/light profiling/geolocation etc.)
Retention (extracts): account for the lifetime of the account; analytics 12 months; security logs 12 months; tax 10 years
Rights: access, rectification, erasure, restriction, objection (incl. marketing), portability, withdrawal of consent
Cookies/CMP: nonâessential cookies are blocked until consent; details at kiuwo.com/cookies
1) Controller
Mea World S.r.l. â Via Niccolò Machiavelli, 24 â 51100 Pistoia (PT), Italy
VAT/Tax ID: 02069030472 â Share capital: ⏠10,000 paidâin
Email for privacy rights/DSR: privacy@kiuwo.com â (tech) dev@meaworld.com
PEC: pec@pec.meaworld.it
DPO: not appointed. Any appointment will be communicated here.
Subjective scope: Mea World acts as Controller. The providers listed in § 8 act as Processors under Art. 28 GDPR, unless marked âindependent controllerâ.
2) Essential definitions
âPlatformâ: the Kiuwo app (web/app).
âKIUâ: shared knowledge graph (public user contributions).
âUCGâ: userâgenerated content (maps, nodes, files, audio/transcripts).
GDPR definitions (Art. 4) continue to apply.
3) Types of data processed
- Identifiers and contact: first name, last name, email.
- Authentication: credentials, tokens, access/security logs.
- Payments (Stripe): transactional data and outcomes (we do not store PAN/CVV).
- UCG: maps, nodes, links, files, attachments, audio/transcripts [if enabled], comments.
- Usage data: app events, telemetry, errors, performance, pageviews, clicks, internal browsing history.
- Device & network: IP, userâagent, device and browser information.
- Cookies and similar technologies: technical, preferences, statistics, marketing (managed by CMP).
- [if enabled] Heatmaps and session replay.
- [if enabled] Geolocation (approx./precise), microphone, push notifications (with consent).
Special categories (Art. 9) and criminal data: not requested nor intentionally processed; please avoid including them in UCG.
4) Minors
For information society services in Italy, standalone consent is valid from age 14; below that, consent of the holder of parental responsibility is required. We apply onboarding notices and reasonable checks.
5) Purposes, legal bases, categories, retention
Purpose | Legal basis | Data | Retention |
---|---|---|---|
Service delivery (account, maps, sync, realâtime) | Contract Art. 6(1)(b) | Identifiers, authentication, UCG, technical | For the lifetime of the account; content deleted on closure (subject to rotational backups) |
Security & abuse prevention (rateâlimit, antispam, audit) | Legitimate interest Art. 6(1)(f) | Technical logs, IP, device info | 12 months (logs) |
Support/Helpdesk | Contract | Identifiers, content relevant to the ticket | 24 months from closure |
Payments & invoicing (Stripe) | Legal obligation + Contract | Transaction data, outcomes | Taxârelevant documents 10 years |
Analytics & product improvement (PostHog EU) | Consent | Pseudo/anonymous app events, device | 12 months |
A/B testing & feature flags | Consent (if nonâessential cookies) / Legitimate interest (technical only) | Usage data, device | 12 months |
Heatmaps & session replay | Consent | Usage data, device | Up to 12 months or less if configured |
Surveys and forms | Consent | Email, responses, device | 12 months |
Direct marketing (newsletter, promos) | Consent | Email, preferences | Until withdrawal; soft spam to customers with optâout |
Service communications (T&C/Privacy changes, incidents) | Legal obligation / Contract | Email, account ID | Account lifetime |
Geolocation/permissions | Consent (or Legitimate interest for nonâintrusive services) | Location data, permissions | For the session or until you revoke |
KIU (publication to public graph) | Contract + specific consent | UCG marked âpublicâ | As long as published; withdrawal â removal from our copies |
Note: at the end of the retention period, data are deleted or irreversibly anonymized.
6) Marketing, light profiling and soft spam
- Marketing: emails only with consent (optâout in every email).
- Light profiling [optional]: nonâintrusive personalizations based on usage/features; no automated decisions with legal effects (Art. 22).
- Soft spam (Italy): if you are a customer, we may email you about products/services similar to those purchased, with immediate optâout.
7) UCG and KIU (shared knowledge)
- Content is private by default. You may mark nodes/maps as public and link them to KIU.
- If you withdraw publication, we remove copies on our Platform; we cannot remove any thirdâparty copies/indexes already created.
- Avoid uploading thirdâparty personal data or special categories unless strictly necessary and lawful.
8) Recipients / Providers
Processors (Art. 28 GDPR)
- Supabase, Inc. â database, storage, Supabase Auth (EU region selected; DPA/SCC).
- Vercel Inc. â hosting and frontend/backend serverless delivery.
- PostHog, Inc. â product analytics, feature flags/AâB testing, heatmaps & session replay [if enabled], surveys.
- OpenRouter â routing of generativeâAI requests (Zero Data Retention profile when available).
Independent controllers (for specific purposes)
- Stripe â payments, KYC, antiâfraud (extraâEU transfers compliant with DPF/SCC, see § 9).
We keep an upâtoâdate list of subâprocessors at kiuwo.com/subprocessors and notify material changes via inâapp/email.
9) ExtraâEU transfers
- We prefer EU data residency.
- If transfer is necessary: use of DPF (where applicable) or SCC plus supplementary measures (encryption, minimization).
- Generative AI: for OpenAI via API (through OpenRouter or direct), we set profiles with noâtraining and/or zeroâretention when available.
10) Security and retention
- Encryption: TLS in transit; atârest encryption on storage/DB.
- Account: password hashing, key rotation, leastâprivilege, MFA [if enabled].
- Environment segregation and adminâaccess auditing.
- Backups: incremental with typical 35âday retention.
- Security logs: 12 months.
- Tax/accounting: relevant documents 10 years.
11) Data breach
In case of a personal data breach, we will notify the competent Authority within 72 hours where required and, if the breach entails high risk, we will inform the data subjects without undue delay, unless adequate encryption or measures render data unintelligible.
12) Data subject rights
You have the right to access, rectification, erasure, restriction, objection (incl. marketing), portability and withdrawal of consent at any time.
Response time: within 1 month, extendable by 2 months for complex/numerous requests (we will inform you within the first month).
To exercise your rights: privacy@kiuwo.com.
Complaint to the Authority: Italian Data Protection Authority (Garante) (Piazza Venezia 11, 00187 Rome; protocollo@gpdp.it; PEC: protocollo@pec.gpdp.it; phone +39 06 696771).
13) Cookies & similar technologies
- We use a CMP (cookie banner) to capture granular consents (necessary, preferences, statistics, marketing).
- Until consent, we block nonâessential cookies (e.g., PostHog analytics/heatmaps/session replay).
- Updated list of cookies and purposes at kiuwo.com/cookies.
14) Geolocation, notifications and microphone [if enabled]
You can allow/deny geolocation, push notifications and microphone. Choices can be revoked inâapp and from device settings. Legal basis: consent (or legitimate interest for nonâintrusive services, with right to object).
15) Audio & transcription [if enabled]
In audio mode (batch or realâtime) we process your voice and the related transcription to generate/update maps. Involved AI providers are bound to no data training and minimization; we prefer Zero Data Retention when available.
16) Disclosures to third parties (vs. selling)
- Disclosure: recipients process data only on our behalf and purposes (§ 8).
- Selling: we do not sell data to third parties for their own marketing. Mandatory disclosures to law/authorities remain.
17) Sources of data
Data provided directly by the data subject; [if you use social login] we may receive data from Identity Providers (e.g., Google/Apple) in line with your settings.
18) Detailed retention (extract)
- Account & UCG: account lifetime; deletion on closure; rotational backups autoâexpire (§ 10).
- Analytics / A/B / Heatmaps/Replay: 12 months.
- Marketing: until withdrawal; soft spam until optâout.
- Security logs: 12 months.
- Tax/accounting: 10 years.
19) Complaints
Besides contacting us, you can contact the Italian Data Protection Authority (Garante) (instructions/contacts on the Authorityâs website).
20) Changes to this notice
We may update this notice to reflect legal/technical evolutions. In case of material changes, we will notify via email/inâapp and request renewed consent where necessary. Always check the âlast updateâ date above.
Annex A â Details of services/providers (iubendaâstyle cards)
A.1 Forms & surveys â PostHog surveys (PostHog, Inc. â USA; EU instance when available)
Data processed: usage data, email, device information, IP, responses, cookies/IDs.
Purpose: form creation/analysis, feedback collection and research.
Legal basis: consent.
Retention: 12 months (unless anonymized).
A.2 Heat mapping & session replay â PostHog Replay (PostHog, Inc.)
Data processed: usage data, device information, cookies/IDs.
Purpose: UX improvement, areas of interest, friction analysis.
Legal basis: consent.
Retention: up to 12 months or less if configured.
Notes: we mask/anonymize sensitive fields where technically possible.
A.3 Hosting & backend â Vercel Inc. / Supabase, Inc.
- Vercel: hosting, CDN, edge/serverless. Data: usage data, technical logs, any metadata required by the service.
- Supabase: database, storage, Supabase Auth. Data: usage data, cookies/IDs, various types necessary for the service.
Legal basis: contract (service delivery) and legitimate interest (security).
Retention: consistent with § 10 and § 18.
Data residency: EU preferred for Supabase; Vercel may be geoâdistributed.
A.4 Registration & authentication â Supabase Auth (Supabase, Inc.)
Data processed: email/credentials, tokens, minimal usage data.
Purpose: user identification and access management.
Legal basis: contract.
Retention: for the lifetime of the account.
A.5 Statistics & A/B â PostHog product analytics (PostHog, Inc.)
Data processed: clicks, pageviews, internal browsing history, browser/device info, IP, cookies/IDs.
Purpose: measurements, funnels, product insights, feature flags/AâB testing.
Legal basis: consent (if nonâessential cookies).
Retention: 12 months (aggregated/anonymous data longer).
A.6 Payments â Stripe (independent controller)
Data processed: transactional data, outcomes, antiâfraud/KYC.
Legal basis: legal obligation + contract.
Retention: taxârelevant documents 10 years.
A.7 Generative AI â OpenRouter (routing to model providers)
Data processed: prompts and content necessary for processing (minimization by default).
Assurances: Zero Data Retention profile (when available), no training without consent, encryption in transit.
Legal basis: contract (feature delivery) and/or consent for specific modes.
Retention: minimum necessary for technical processing; none when ZDR is active.
Annex B â Security measures (extract)
- Organizational: access control, needâtoâknow, training, vendor dueâdiligence (DPA/SCC).
- Technical: encryption in transit/at rest, environment segregation, backup + disaster recovery, hardening, secret vault, intrusion monitoring, rateâlimiting, CSP.
- Processes: incident response (72h SLA toward Authority), change management, privacy by design/default, RoPA, DPIA when necessary (e.g., AI/minors).
Annex C â Summary record of purposes
- Auth & account â basis: contract â data: identifiers/credentials â retention: account lifetime.
- Maps & KIU â contract / specific consent â data: UCG â retention: account lifetime / as long as published.
- Audio/RT â contract â data: audio/transcripts â retention: see § 18.
- Analytics (EU) â consent â data: app events â retention: 12 months.
- Marketing â consent / soft spam â data: email/preferences â retention: until withdrawal.
- Payments â legal obligation/contract â data: transactions â retention: 10 years.
More information not contained herein
Further details about processing can be requested from the Controller at privacy@kiuwo.com.