Privacy Notice for Users of the Iris Platform

Last updated: 01/07/2026

This notice describes how Trainect S.r.l. processes the personal data of natural persons authorized to access and use the Iris platform on behalf of the client organization, hereinafter collectively referred to as "Users". This notice applies to the processing of personal data relating to Users of the Iris platform, with regard to the creation and management of accounts, access to the platform, use of its features, system security, product improvement, technical support, and administrative activities connected to the provision of the service. This notice does not cover the processing of personal data of assessment recipients or persons invited to complete them, for whom specific dedicated privacy documentation is provided (Respondents Privacy Notice).

1. Data Controller

The data controller is:

Trainect S.r.l. – Società Benefit
Via Calatafimi 21, 00185 Rome (Italy)
VAT: 15691841009
PEC: trainect@pec.it
E-mail: info@trainect.it
Data Protection Officer (DPO): Loris Nanni – loris.nanni@trainect.it

2. Categories of Data Processed

In connection with the management and use of the Iris platform, Trainect may process the following categories of personal data relating to Users:

  • identifying data, such as first and last name;
  • contact data, such as corporate e-mail address;
  • data relating to the organization, such as company name, company size, industry, area of activity, possible presence of offices abroad, and company description;
  • account data, such as access credentials, user identifiers, roles, authorizations, and account status;
  • technical and access data, such as IP address, date and time of access, authentication logs, browser, device, and operating system information;
  • data relating to the use of the platform, including operations performed, configurations, and interactions with available features;
  • data contained in support requests or communications sent to Trainect in connection with use of the service.

3. Purposes and Legal Basis of Processing

Users' personal data are processed for the following purposes:

a) activation, configuration, and management of accounts

to create, configure, manage, update, suspend, or deactivate Users' accounts and enable access to the platform;

b) authentication, security, and operational continuity

to verify credentials, prevent unauthorized access, protect the platform, monitor security events, and ensure the correct functioning of the service;

c) provision of platform features

to enable Users to use the features available in Iris within the service activated by the client;

d) product improvement and user experience

to analyze how Users interact with the platform in order to improve its features, usability, navigability, and overall quality, as described in section 4;

e) technical support and operational assistance

to manage support requests, reports, technical interventions, maintenance, and communications strictly connected to the functioning of the platform;

f) regulatory compliance and protection of controller's rights

to comply with legal or regulatory obligations or requests from competent authorities, as well as to establish, exercise, or defend a right before a court or out of court.

The legal bases for processing are, depending on the case:

  • performance of a contract or pre-contractual measures taken at the client's request, for purposes a), b), and c);
  • the legitimate interest of the controller in the correct management, security, and protection of the platform and its rights, as well as in the improvement of the product and user experience, for purposes b), d), and f);
  • compliance with legal obligations, for purpose f).

For processing based on legitimate interest, Trainect carries out a balancing assessment (LIA) and the User has the right to object pursuant to Article 21 of the GDPR and section 11 of this notice.

4. Analysis of Platform Usage (Product Analytics)

To improve the platform's features, usability, and user experience, Trainect analyzes how Users interact with Iris, using product analytics and user experience analysis tools provided by third parties, accessed via instances located within the European Union.

Such tools are sent interaction events, technical data, and internal identifiers of the User. These internal identifiers do not contain the User's name or e-mail address and can be attributed to the individual only by Trainect, by means of additional information stored separately in its own systems. The data transmitted to such tools therefore constitute pseudonymized personal data and remain subject to applicable regulations; in the event of unauthorized access to the data present in such tools alone, that data would not be attributable to a specific person or organization without the additional information held by Trainect.

Such tools are not used to produce assessments of individual survey respondents, nor to return individual respondent data to the client. Their use is limited to the technical and aggregated analysis of usage, service quality, and operational improvement of the platform. The legal basis is Trainect's legitimate interest in the improvement of the product and user experience.

5. Nature of Data Provision

The provision of data required for account creation and management is necessary to allow access to and use of the Iris platform.

Failure to provide the required data may result in the inability to activate the account, access the platform, or properly use the service's features.

6. Marketing Communications

Personal data of Users registered on the Iris platform are not used by Trainect to send newsletters or commercial or promotional communications, except upon a specific and separate request by the data subject.

7. Processing Methods and Security Measures

Personal data are processed by electronic means and, where necessary, also manually, in compliance with the principles of lawfulness, fairness, transparency, minimization, integrity, confidentiality, and storage limitation.

Trainect adopts appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, improper disclosure, or alteration, taking into account the nature of the data processed and the risks associated with the processing. Such measures also include the pseudonymization of data, where applicable; it is understood that pseudonymized data remain personal data.

8. Recipients of Personal Data

Personal data may be processed by authorized Trainect personnel and communicated, within the limits of the purposes indicated above, to providers of technical, infrastructure, hosting, maintenance, support, security, and product analytics services, to providers of e-mail and collaboration services (Google Workspace), as well as to consultants and persons legally entitled to receive them.

Such parties act, depending on the case, as processors, authorized persons, or independent controllers. The distinction between controller and processor depends on the role actually performed with regard to the purposes and means of processing. The updated list of providers and sub-processors is available upon request and in the dedicated documentation made available by Trainect.

9. Transfers of Data outside the EEA

As of the date of this notice, the personal data processed within the Iris platform are hosted on infrastructure located in Italy, and the product analytics tools used operate via instances located within the European Union.

Certain ancillary e-mail and collaboration services, used by Trainect also for managing Users' support requests, are provided via Google Workspace, which may involve the processing of personal data also in the United States. This transfer takes place on the basis of the European Commission's adequacy decision regarding the EU-US Data Privacy Framework, to which the provider adheres.

Any further transfers of personal data to countries outside the European Economic Area will take place in compliance with applicable regulations and following the adoption of the guarantees required by law. Where applicable, such guarantees may include adequacy decisions or standard contractual clauses approved by the European Commission, together with any necessary supplementary measures.

10. Data Retention Period

Personal data of Users are stored for a period no longer than necessary for the purposes for which they are collected and processed. In particular, data relating to Users' accounts and other data processed for service delivery are stored for the entire duration of the contractual relationship or service authorization.

Termination of the relationship, export, and anonymization. Upon termination of the contractual relationship or service authorization, the client has a period of 30 days to request the export of its data. After that period, or once the export has been carried out, Trainect proceeds, within the following 30 days, to irreversibly anonymize the personal data, unless their further storage is necessary to comply with legal obligations or to establish, exercise, or defend a right of the controller.

Anonymization as a means of erasure. Trainect implements the erasure of personal data also by means of irreversible anonymization, carried out using techniques such that the data can no longer be attributed to an identified or identifiable data subject. Data thus rendered anonymous no longer constitute personal data and may be retained and used by Trainect for its own purposes.

Technical and security data and data contained in support requests are stored for the time strictly necessary for the purposes for which they are collected, and in any case according to criteria of proportionality and necessity with respect to platform security, operational continuity, and protection of the controller's rights.

11. Rights of Data Subjects

Users, as data subjects, may exercise the following rights where provided by applicable law:

  • access to personal data;
  • rectification of inaccurate data;
  • erasure of data;
  • restriction of processing;
  • objection to processing, where applicable, including processing based on the controller's legitimate interest;
  • data portability, where provided;
  • withdrawal of consent, where processing is based on consent;
  • complaint to the competent supervisory authority.

Relationship between erasure and anonymization. Trainect may implement the right to erasure also by means of irreversible anonymization of the data, at the end of which the data are no longer attributable to the data subject and cease to constitute personal data.

Requests may be submitted to the contact details indicated in this notice, also for the attention of the Data Protection Officer. The controller will normally respond within one month.

12. Complaint to the Supervisory Authority

Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures provided by applicable regulations.

13. Updates to this Notice

This notice may be updated over time for regulatory, organizational, or technical reasons. The updated version will be made available through appropriate channels, with an indication of the date of last update.