Legal · Privacy

Privacy Policy

Last updated28 August 2026
Version3.0
Applies tomiutifin.com and ESCO

1. In short

Before the formal version, here's what actually happens.

  • If you join the ESCO waiting list you give us one contact — phone or email — and we use it to tell you when a spot opens in your city. If you choose the phone we message you on WhatsApp or SMS: we don't call.
  • If you write through the miutifin.com contact form, we keep what you enter so we can reply about your project.
  • If you become an ESCO member, we keep your account, your taste preferences and what you save: that's the data that lets the app compose journeys for you.
  • We record when you gave consent, because the law requires us to be able to prove it.
  • We rely on a small number of trusted providers. We don't sell your data, we don't run profiled advertising, we don't pass it to marketers.
  • You can ask to see or delete your data at any time. We reply within 30 days.

The rest of this page is the formal version of those six lines.

2. Who processes your data

The data controller is [LEGAL ENTITY NAME], registered at [FULL ADDRESS], VAT [NUMBER], operating miutifin.com and the ESCO service.

For anything about your data, write to miutifin.ask@gmail.com.

We have not appointed a Data Protection Officer: we don't fall within the cases where the GDPR makes it mandatory.

3. What we collect

It depends on how you interact with us. We never collect more than a specific purpose requires.

3.1 If you write through the miutifin.com form

  • Full name, company, work email
  • Project type and, if you provide it, an indicative budget
  • The message you write
  • Your consent and the date you gave it

3.2 If you join the ESCO waiting list

  • Your phone number or your email — one of the two, your choice. We don't ask for both.
  • Your consent and the moment you gave it (date and time).
  • Which part of the site you signed up from and which language you were browsing in.
  • A one-way fingerprint of your IP address: it only serves to count sign-ups from the same connection and prevent abuse. The address cannot be recovered from it.

If you leave an email, we also store a normalised form of it (without dots and without the +suffix some providers ignore) to spot duplicate sign-ups from the same mailbox.

3.3 If you subscribe to the newsletter

  • Your email address
  • Optionally, your phone number

3.4 If you become an ESCO member

When you complete registration after an invitation, we collect:

  • Authentication data: email, password (stored as a hash, never in clear text), session tokens
  • Profile: username, nickname, avatar (optional), short bio (optional), city, birthday (optional)
  • Taste preferences: preferred categories, music interests, price tier, day/night preference, dress code
  • Activity: places you save, events you attend, ratings you give, journeys you compose

Preferences and activity are what allow ESCO to compose personalised journeys: without that data the service cannot work.

3.5 Technical data (anyone visiting)

  • Device and browser: type, version, language
  • IP address: our hosting providers receive it to deliver pages. On the waiting list we only keep an encrypted fingerprint, to limit repeated attempts.

3.6 Public numbers

The pages show aggregate counts — how many people are on the list, how many cities are live, how many sign-ups came this week. They are sums: no individual can be identified from them.

4. Why we use them

PurposeData used
Running the service: accounts, journeys, preferences, invitesAccount data, preferences, activity
Telling you when the beta opens in your cityWaiting list phone or email
Replying to your project enquiryContact form data
Proving you gave consentConsent and timestamp
Preventing automated sign-ups and abuseIP fingerprint, attempt count
Improving the productAggregate statistics, no individual tracking
Meeting legal obligationsWhatever is required at the time

We don't use your data for profiled advertising and we don't make fully automated decisions producing legal effects on you. ESCO's suggested journeys are proposals: the choice stays yours.

5. Legal basis

ProcessingLegal basis (GDPR art. 6)
miutifin contact formPre-contractual measures — art. 6.1.b
ESCO waiting listYour consent — art. 6.1.a
NewsletterYour consent — art. 6.1.a
Account and member featuresContract performance — art. 6.1.b
Security and abuse preventionLegitimate interest — art. 6.1.f
Aggregate statisticsLegitimate interest — art. 6.1.f
Regulatory obligationsLegal obligation — art. 6.1.c

Where the basis is consent you can withdraw it whenever you want, by writing to the address at the bottom. Withdrawal doesn't make what we did before unlawful.

Our legitimate interest in abuse prevention is keeping the service working and the list clean. We assessed it doesn't override your rights: the IP address is never stored in clear text.

6. Who we share them with

We don't sell your data and we don't give it to advertisers or marketing networks. It's only processed by the providers running our infrastructure.

ProviderWhat it processes
Supabase — database, authentication, storageAccounts, profile, preferences and content. Region: [CHECK YOURS: Frankfurt / other]
Vercel — website hostingTechnical request data (IP, headers) for delivery and security
Anthropic / OpenAI — journey compositionOnly the preference signals needed for a single composition. No profile data, no identifiers. Inputs are not used to train their models.
Google Places — place dataPlace lookups and coordinates needed to show you venues

All providers are bound by data processing agreements under GDPR art. 28.

7. Transfers outside the EU

Our main infrastructure is in the European Union. Some providers — notably the AI and hosting ones — are US-based and may process data outside the EU. In those cases the transfer is protected by:

  • Standard Contractual Clauses approved by the European Commission
  • or an adequacy decision, such as the EU–US Data Privacy Framework
  • plus technical safeguards: encryption, minimisation of what is sent, no training on inputs

8. How long we keep them

DataRetention
Contact form messages24 months from the last exchange
Waiting list contact (not approved)18 months, then deleted
Active member accountsFor the life of the account, plus 30 days after deletion
Newsletter subscribersUntil you unsubscribe
Consent and timestampFor the duration of processing and 5 years after, as evidence
IP fingerprintDeleted within 30 days
Aggregate statisticsIndefinitely: they contain no personal data

If you ask us to delete your data we do it within 30 days, unless a law requires us to keep something longer (invoices, for example).

9. How we protect them

We protect personal data with technical and organisational measures proportionate to the risk:

  • Encryption in transit (TLS 1.2+) and at rest
  • Passwords stored only as hashes, never in clear text
  • Row-level security on every table: each person only reaches their own data
  • The browser can neither read nor write the contact list: every sign-up goes through our server, and the database grants no public read permission
  • The IP address is stored only as a one-way fingerprint, with a per-connection attempt limit
  • Access limited to the team members who need it
  • Regular security reviews and dependency updates

No system is 100% secure. If we detect a breach affecting you, we'll notify you and the supervisory authority within 72 hours, as required by GDPR art. 33–34.

10. Your rights

At any time you can ask us to:

  • Access the data we hold about you and receive a copy
  • Correct anything wrong or incomplete
  • Delete everything about you
  • Restrict or object to processing based on legitimate interest
  • Receive your data in a format another service can read
  • Withdraw consent, without having to explain why

Just write to miutifin.ask@gmail.com. We reply within 30 days, free of charge, unless a request is manifestly unfounded or excessive.

If you think we're handling your data improperly you can contact the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or the authority in your country of residence.

12. Children

The platform is not intended for anyone under 16 and we don't knowingly collect their data. If you believe a minor has left us their contact, write to us: we delete it immediately.

13. Changes

We may update this policy. Material changes are communicated to active members by email at least 14 days in advance. The date and version at the top show the latest revision.

14. Contact

For any question or request about your data: miutifin.ask@gmail.com

We aim to reply within 24 hours, and always within the 30 days the GDPR allows.

Questa informativa è disponibile anche in italiano — cambia lingua dalla barra di navigazione.