Last updated: 01/07/2026
This notice describes how Trainect S.r.l. processes the personal data of natural persons authorized to access and use the Iris platform on behalf of the client organization, hereinafter collectively referred to as "Users". This notice applies to the processing of personal data relating to Users of the Iris platform, with regard to the creation and management of accounts, access to the platform, use of its features, system security, product improvement, technical support, and administrative activities connected to the provision of the service. This notice does not cover the processing of personal data of assessment recipients or persons invited to complete them, for whom specific dedicated privacy documentation is provided (Respondents Privacy Notice).
The data controller is:
In connection with the management and use of the Iris platform, Trainect may process the following categories of personal data relating to Users:
Users' personal data are processed for the following purposes:
to create, configure, manage, update, suspend, or deactivate Users' accounts and enable access to the platform;
to verify credentials, prevent unauthorized access, protect the platform, monitor security events, and ensure the correct functioning of the service;
to enable Users to use the features available in Iris within the service activated by the client;
to analyze how Users interact with the platform in order to improve its features, usability, navigability, and overall quality, as described in section 4;
to manage support requests, reports, technical interventions, maintenance, and communications strictly connected to the functioning of the platform;
to comply with legal or regulatory obligations or requests from competent authorities, as well as to establish, exercise, or defend a right before a court or out of court.
The legal bases for processing are, depending on the case:
For processing based on legitimate interest, Trainect carries out a balancing assessment (LIA) and the User has the right to object pursuant to Article 21 of the GDPR and section 11 of this notice.
To improve the platform's features, usability, and user experience, Trainect analyzes how Users interact with Iris, using product analytics and user experience analysis tools provided by third parties, accessed via instances located within the European Union.
Such tools are sent interaction events, technical data, and internal identifiers of the User. These internal identifiers do not contain the User's name or e-mail address and can be attributed to the individual only by Trainect, by means of additional information stored separately in its own systems. The data transmitted to such tools therefore constitute pseudonymized personal data and remain subject to applicable regulations; in the event of unauthorized access to the data present in such tools alone, that data would not be attributable to a specific person or organization without the additional information held by Trainect.
Such tools are not used to produce assessments of individual survey respondents, nor to return individual respondent data to the client. Their use is limited to the technical and aggregated analysis of usage, service quality, and operational improvement of the platform. The legal basis is Trainect's legitimate interest in the improvement of the product and user experience.
The provision of data required for account creation and management is necessary to allow access to and use of the Iris platform.
Failure to provide the required data may result in the inability to activate the account, access the platform, or properly use the service's features.
Personal data of Users registered on the Iris platform are not used by Trainect to send newsletters or commercial or promotional communications, except upon a specific and separate request by the data subject.
Personal data are processed by electronic means and, where necessary, also manually, in compliance with the principles of lawfulness, fairness, transparency, minimization, integrity, confidentiality, and storage limitation.
Trainect adopts appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, improper disclosure, or alteration, taking into account the nature of the data processed and the risks associated with the processing. Such measures also include the pseudonymization of data, where applicable; it is understood that pseudonymized data remain personal data.
Personal data may be processed by authorized Trainect personnel and communicated, within the limits of the purposes indicated above, to providers of technical, infrastructure, hosting, maintenance, support, security, and product analytics services, to providers of e-mail and collaboration services (Google Workspace), as well as to consultants and persons legally entitled to receive them.
Such parties act, depending on the case, as processors, authorized persons, or independent controllers. The distinction between controller and processor depends on the role actually performed with regard to the purposes and means of processing. The updated list of providers and sub-processors is available upon request and in the dedicated documentation made available by Trainect.
As of the date of this notice, the personal data processed within the Iris platform are hosted on infrastructure located in Italy, and the product analytics tools used operate via instances located within the European Union.
Certain ancillary e-mail and collaboration services, used by Trainect also for managing Users' support requests, are provided via Google Workspace, which may involve the processing of personal data also in the United States. This transfer takes place on the basis of the European Commission's adequacy decision regarding the EU-US Data Privacy Framework, to which the provider adheres.
Any further transfers of personal data to countries outside the European Economic Area will take place in compliance with applicable regulations and following the adoption of the guarantees required by law. Where applicable, such guarantees may include adequacy decisions or standard contractual clauses approved by the European Commission, together with any necessary supplementary measures.
Personal data of Users are stored for a period no longer than necessary for the purposes for which they are collected and processed. In particular, data relating to Users' accounts and other data processed for service delivery are stored for the entire duration of the contractual relationship or service authorization.
Termination of the relationship, export, and anonymization. Upon termination of the contractual relationship or service authorization, the client has a period of 30 days to request the export of its data. After that period, or once the export has been carried out, Trainect proceeds, within the following 30 days, to irreversibly anonymize the personal data, unless their further storage is necessary to comply with legal obligations or to establish, exercise, or defend a right of the controller.
Anonymization as a means of erasure. Trainect implements the erasure of personal data also by means of irreversible anonymization, carried out using techniques such that the data can no longer be attributed to an identified or identifiable data subject. Data thus rendered anonymous no longer constitute personal data and may be retained and used by Trainect for its own purposes.
Technical and security data and data contained in support requests are stored for the time strictly necessary for the purposes for which they are collected, and in any case according to criteria of proportionality and necessity with respect to platform security, operational continuity, and protection of the controller's rights.
Users, as data subjects, may exercise the following rights where provided by applicable law:
Relationship between erasure and anonymization. Trainect may implement the right to erasure also by means of irreversible anonymization of the data, at the end of which the data are no longer attributable to the data subject and cease to constitute personal data.
Requests may be submitted to the contact details indicated in this notice, also for the attention of the Data Protection Officer. The controller will normally respond within one month.
Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures provided by applicable regulations.
This notice may be updated over time for regulatory, organizational, or technical reasons. The updated version will be made available through appropriate channels, with an indication of the date of last update.