Version 2026-09-12-v1 ยท effective from 12 September 2026

1. Controller and privacy contact

FIERO Academy is the operating name of FIERO GROUP DI FURMAN BRUNA FABIULA, sole proprietorship and data controller, Piazza Serragli 5 B, 36010 Chiuppano (VI), Italy, VAT no. 04665180248, tax code FRMBNF87E68Z602X. Privacy contact: amministrazione@fierogroup.it. No Data Protection Officer has been appointed.

2. Data processed

We process identity and contact details; role, profession, company and experience; billing data; course, venue, Partner Code, promotional code and notes; dietary or organisational needs; payment amount, status and references; support requests; attendance, online and in-person completion, assessments and certification status; communication preferences, consents and their history. Image, voice, photographs and video recordings are processed only under separate authorisations.

Payment providers collect payment details directly. FIERO receives identifiers, amount, status and result, but not the full card number. Only minimised technical data needed for security and evidence is retained.

3. Purposes and legal bases

  • Enquiry, enrolment and course: pre-contractual steps and performance of a contract, GDPR Article 6(1)(b).
  • Payment, invoice and tax duties: contract and legal obligation, Article 6(1)(b) and (c).
  • Operational messages: necessary confirmations, changes, payment, access, safety, support, activities and certification; e-mail is the ordinary channel.
  • Operational WhatsApp: optional preference; refusal does not prevent enrolment.
  • Dietary needs/allergies: optional explicit consent under Article 9(2)(a), limited to meal safety.
  • Documented serious-impediment extension: management of a contractual request. Health evidence must have clinical details redacted and is deleted after the decision; only the minimum outcome is retained.
  • Marketing: separate consent for e-mail, WhatsApp and SMS under GDPR Article 6(1)(a) and Italian Privacy Code Article 130. Soft spam is not applied automatically.
  • Images, video and voice: separate consent for internal, institutional and advertising uses under GDPR Articles 6(1)(a) and 7 and Italian Copyright Law Articles 96-97.
  • Security, audit and legal claims: legal obligation or documented legitimate interests.
  • Analytics: cookie consent; Google Analytics remains blocked before a positive choice.

4. Required and optional data

Required fields are necessary to manage enrolment, billing or course delivery. Company, certified e-mail and SDI code are required only where relevant. Dietary needs, operational WhatsApp, virtual assistance, marketing and every image or voice use are optional.

5. Recipients and SkyGloss flow

Authorised FIERO personnel and, where necessary, Hostinger, Stripe, PayPal, Google Analytics after consent, Meta/WhatsApp, the accountant, advisers and authorities may receive only the data needed for their role. A local venue partner receives only minimum organisational or safety details.

After payment, FIERO enters the data required for online access into the SkyGloss portal: name, surname, e-mail, telephone, country, address details requested by the portal and FIERO Partner identifier. SkyGloss manages the portal, online content and certification under its own terms and privacy notice.

6. AI-based virtual assistant

Some communications may in future be prepared or managed by an AI-based virtual assistant under the Controller's responsibility. At the first direct interaction, the system identifies itself as an AI-based virtual assistant. A person or exclusively human assistance may be requested at any time. No enrolment, payment, attendance, extension, assessment or certification decision is delegated solely to AI.

7. International transfers

Some international suppliers may process data outside the EEA. For each service FIERO verifies the processing location, the provider's role and the mechanism available under GDPR Chapter V, such as an adequacy decision or Standard Contractual Clauses, where applicable. Updated information on the mechanism used may be requested from the privacy contact.

8. Retention

  • leads/incomplete requests: 12 months;
  • enrolment, contract, payment, attendance, completion, SkyGloss authorisation and fiscal records: 10 years;
  • marketing: no more than 24 months from consent or last meaningful interaction, and earlier upon withdrawal or objection;
  • dietary needs: 30 days after the course;
  • technical/security logs: 90 days;
  • cookie choice: 6 months; Google Analytics: 14 months;
  • authorised image, video and voice: 5 years, subject to earlier withdrawal and the image release.

The system calculates deadlines, displays Admin alerts and automatically blocks expired marketing. Material deletion requires authorised review and is logged.

9. Rights and preference management

Data subjects may request access, rectification, erasure, restriction, applicable portability and objection, and may withdraw consent as easily as it was given. Requests may be sent to amministrazione@fierogroup.it or through the secure one-use preference link. The system tracks the ordinary one-month response period. A complaint may be lodged with the Italian Data Protection Authority.

10. Cookies and tracking

Strictly necessary technologies support security, session and choice storage. Google Analytics is the only analytics tool detected and loads only after consent. No active advertising pixels were found. Accept and refuse are equally easy and choices may be changed later.

11. Versions and evidence

Acknowledging this notice is not general consent. The system separately records the exact document/version, UTC time, language, source, channel, Terms acceptance and every grant, refusal, change, objection or withdrawal. New events do not overwrite earlier ones.