Privacy Notice for the psAico.ai app
Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR)
This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) to users who use the psAico application via the web or via the Apple and Google Play stores. The use of the service is also governed by the Terms and Conditions available on the site.
psAico is a digital service designed to offer psychological help aimed at emotional well-being and personal reflection through a virtual assistant based on artificial intelligence. The service does not constitute a healthcare activity, does not perform diagnostic or therapeutic functions and does not replace the support of a qualified professional.
Data controller:
- psAico srls
- VAT number 02800830222
- Via Pranzelores 87 – 38121 Trento (TN) – Italy
- Email: info@psaico.ai
- PEC: psaico@namirialpec.it
1. Purpose and legal basis of the processing
To allow the operation of the service, the Data Controller may process, based on the functions used:
- account and profile data, such as email, username, protected password, name, surname, nickname, profile image, age, gender, reason for consultation, preferences and registration platform;
- contents inserted in the chat, answers, Technical Summaries, answers and scores of the questionnaires and related history;
- technical and usage data, such as duration and source of sessions, technical counters relating to the use of AI services, access data, IP address, security logs and information relating to cancellation requests;
- installation or registration attribution data, such as source, medium, campaign and ad group name, technical identifier of the ad click, dates and platform, collected only with the consent described in §8;
- data necessary for email verification, two-factor authentication and, if activated, biometric access to the device. The backend can store the device name and its public key, but does not store the user's fingerprint or face;
- notification preferences, device tokens and technical push-notification delivery logs;
- subscription status and technical identifiers of subscriptions managed through payment providers or digital stores;
- messages and any attachments voluntarily sent to support, forwarded to the support mailbox;
- for the newsletter, email, name, surname, date and origin of consent, subscription or unsubscription status and technical data of delivery, non-delivery or complaint.
The user can insert particularly sensitive content relating, for example, to psychological well-being, emotional state or intimate aspects of their life. This information may fall into the special categories of personal data provided for by Article 9 GDPR.
The service applies technical minimisation, scrubbing and context reduction measures to limit the presence of direct identifiers and unnecessary content. However, free text may contain personal information and these measures do not guarantee complete anonymization.
The processing of data belonging to special categories is based on the explicit consent of the user under Article 9(2)(a) GDPR. Consent is requested through a specific declaration during registration; without such consent it is not possible to use the service. The Data Controller records the date and time of acceptance, the version of the notice and the channel through which it was collected.
The other purposes and legal bases are:
- registration, authentication, provision and customisation of the service, profile management, service notifications and assistance: execution of the service requested by the user under Article 6(1)(b) GDPR;
- management of payments, subscriptions and accounting and tax obligations: execution of the contract and fulfillment of legal obligations under Article 6(1)(b) and (c) GDPR;
- security, anti-spam verification, infrastructure protection, prevention of abuse and technical management: legitimate interest of the Data Controller under Article 6(1)(f) GDPR;
- analytics, usage statistics, measurement of the effectiveness of the Data Controller's campaigns, including the recording of the campaign of origin, and unnecessary marketing tools: user consent under Article 6(1)(a) GDPR;
- newsletter and promotional communications: optional and separate consent under Article 6(1)(a) GDPR.
Prevention of free-trial abuse. To prevent the same person from using the free trial more than once, at the time of registration the Data Controller stores a non-reversible identifier (HMAC-SHA256, computed with a key known only to the Data Controller) of the email address provided at registration. The identifier is not computed on the address as written, but on the mailbox to which it corresponds: any suffix after the + sign and, for domains that ignore them, the dots in the part before the @ sign are not taken into account. Different spellings of the same mailbox therefore produce the same identifier.
The identifier is stored separately from the account data: alongside it, only the date on which the trial was granted and, if the same mailbox attempts a new registration, the number and date of the last attempt are stored; neither the email address nor any account data is stored. The address cannot be reconstructed from the identifier: it serves solely to check whether a mailbox has already used the free trial. These are the only data that remain after the account is deleted.
Anyone registering with a mailbox that has already used the trial can still create an account: they do not receive the free trial and can activate a subscription.
Legal basis: legitimate interest of the Data Controller in preventing abuse of the service, under Article 6(1)(f) GDPR.
The processing concerns pseudonymised and not anonymous data: it does not allow the Data Controller to reconstruct the email address, but it does allow verification of whether a given address corresponds to an identifier already recorded.
The user has the right to object to this processing at any time, under Article 21 GDPR, by writing to info@psaico.ai or by certified email (PEC) to psaico@namirialpec.it: the Data Controller assesses the request by balancing the rights of the data subject against the interest in preventing repeated use of the free trial.
Retention: 24 months from registration of the account, after which the identifier is deleted.
Consent to the processing of special-category data can be revoked at any time. Since this processing is necessary for the essential functions of psAico, revocation involves the cessation of use of the service and can be exercised by deleting the account from the Delete account item, accessible from the profile at the top right, or by contacting the Data Controller.
Marketing consent is optional, separate from the main service and revocable at any time via the unsubscribe link in the newsletters. It may be given when registering for the psAico application, from the profile settings or when registering for the area reserved for healthcare professionals. The Data Controller records the date of consent, any revocation and the origin of the last choice.
The user is invited not to enter personal data relating to third parties or particularly sensitive information when it is not necessary.
Statistical and research purposes on aggregated data. The Data Controller further processes some of the data collected in the provision of the service for statistical and research purposes, with the aim of producing exclusively aggregated and anonymous results. This purpose includes, by way of example: the distribution by age group and gender of registered users; the distribution of the scores of the well-being questionnaires; the duration and frequency of usage sessions; the activation and continuation rates of the service; the number of activations of the responses dedicated to emergency situations.
Pursuant to art. 5(1)(b) GDPR, further processing for statistical purposes or scientific research purposes is not considered incompatible with the original purposes. The processing is carried out in compliance with the safeguards provided for by art. 89(1) GDPR and, for data belonging to special categories, by art. 9(2)(j) GDPR, also taking as a reference standard, insofar as applicable, the ethical rules for processing for statistical or scientific research purposes issued by the Italian Data Protection Authority (decision of the Garante of 19 December 2018, web doc. no. 9069637). In particular:
- the data are used only for the time strictly necessary for the calculation; the results are produced, stored and disseminated exclusively in aggregated form, in such a way that it is not possible to trace, even indirectly, an identified or identifiable person;
- no value referring to small groups is disseminated: each published figure refers to at least 20 observations;
- the contents of the conversations are not used for this purpose, either in full or in part, or in the form of quotations or examples. Only the number of occurrences of the technical events automatically generated by the service's security systems — for example the activation of a response dedicated to emergency situations — may be counted, without the text that triggered them;
- no individual data, personal usage histories or any element allowing re-identification are disseminated;
- the aggregated results may be the subject of scientific or informative publication.
The user may object to this processing at any time, pursuant to art. 21(6) GDPR, by writing to info@psaico.ai or via certified email (PEC) to psaico@namirialpec.it. The exercise of this right does not in any way affect the provision of the service.
2. Processing methods and recipients
The processing takes place using IT and telematic tools, with automated and, where necessary, manual methods, in compliance with the principles of lawfulness, correctness, transparency, minimisation and storage limitation. The Data Controller adopts adequate technical and organizational measures to protect confidentiality, integrity and availability of data and prevent unauthorized access, loss, alteration or unauthorized use.
The data may be processed by authorised personnel and selected service providers, within the limits necessary for their respective functions, belonging to the following categories: AI services, infrastructure and security, payments and digital stores, email and push communications, assistance, analytics and marketing. The updated list of data processors can be requested from the Data Controller.
Some providers may involve processing or transfers of data outside the European Economic Area. In such cases the Data Controller applies the guarantees provided for by Articles 44 et seq. GDPR, including, when applicable, adequacy decisions, Standard Contractual Clauses and additional measures.
3. Processing via third-party services (OpenAI)
To generate virtual assistant responses and Technical Summaries, psAico uses artificial intelligence services provided by OpenAI via API. Before sending, the service applies minimisation and scrubbing measures aimed at reducing direct identifiers and unnecessary information. These measures reduce the risk of identification, but cannot guarantee complete anonymization of the contents freely inserted by the user.
The data is transmitted to generate the response requested as part of the provision of the service. The processing may involve a transfer to countries outside the European Economic Area, including the United States, in compliance with the applicable guarantees pursuant to the GDPR.
For end user accounts psAico configures API calls with store=false, without requiring OpenAI to store the prompts and responses in the application. OpenAI can however generate technical and security logs for abuse prevention activities, stored according to the provider's policies and any applicable obligations.
The Data Controller does not use the contents of the conversations to independently train its artificial intelligence models.
4. Data retention
Personal data is stored for the time necessary for the purposes indicated and, in general, as long as the account remains active or until the user's rights are exercised, except for legal obligations or documented security needs.
Complete chat messages are retained by the Data Controller for a maximum period of 30 days and are subject to periodic automatic deletion. After this deadline, the system can keep a Technical Summary useful for the continuity of the service, associated with the account until the conversational memory or the account is deleted.
The memory clear function deletes user messages, summaries and questionnaires from the database. Only the technical logs necessary for operation, security or fulfillment of applicable obligations may remain.
The user can delete the account at any time. Deletion also entails the automatic termination of subscription to the newsletter and the removal of personal data which can be deleted. Only the data required by legal, fiscal and accounting obligations or necessary to document the management of the request can be stored, in a limited form or deprived of unnecessary identifiers.
The only exceptions are the non-reversible identifier described in section 1 (Prevention of free-trial abuse) and the minimal data accompanying it, namely the date on which the trial was granted and any last attempt at a new registration: they do not contain the email address, they do not allow it to be reconstructed and they are retained for 24 months from registration of the account, after which they are deleted. The user may object to this processing at any time by writing to info@psaico.ai or by certified email (PEC) to psaico@namirialpec.it: the Data Controller assesses the request by balancing the rights of the data subject against the interest in preventing repeated use of the free trial.
Any residual data present in the backup copies, which are encrypted and subject to rotation, are overwritten within a maximum of 7 days.
At any time the user can use the functions available in the app to delete the conversational memory or exercise their rights by contacting the Data Controller at the contact details set out in this notice.
5. Nature of the provision of data
The provision of personal data is optional, but necessary to use the service. Without the data required for registration, authentication, security and provision of essential functions it is not possible to use the application correctly.
6. Rights of the data subject
The user can exercise the rights provided for by Articles 15–22 GDPR, including access, rectification, cancellation, limitation, opposition, revocation of consent and portability, when applicable. The revocation of consent does not affect the lawfulness of the processing carried out before the revocation.
The right to lodge a complaint with the Italian Data Protection Authority remains intact.
Requests can be sent to the Data Controller via PEC at the address psaico@namirialpec.it. The Data Controller responds without unjustified delay and within the terms established by Article 12 GDPR, except for the extensions permitted by law.
7. Minors
The application is reserved for people at least 18 years old. A declaration of being of age is required at registration; age is collected with the first questionnaire, without which the Service cannot be used, and it is not permitted to continue when an age under 18 is indicated.
Where an explicit statement of being under age emerges from the interaction, the account is automatically suspended, after a further and independent automated verification of that statement, and notice is given to the associated email address. This is the only case in which an automated decision produces significant effects on the data subject: anyone affected may at any time obtain human intervention from the Data Controller, express their point of view and contest the decision, as provided for in Art. 10 of the Terms and Conditions.
If the Data Controller becomes aware of the involuntary collection of data relating to minors, it will delete them as soon as possible.
8. Cookies and technical operating tools
Web version
The web version uses cookies or equivalent technologies necessary for session management, authentication, security and correct functioning of the service. The necessary tools also include Google reCAPTCHA, used to prevent automated access and abuse based on the technical data necessary for verification.
Only with the user's consent can statistical or marketing tools be activated via Google Tag Manager and Google Analytics 4, used to understand the use of the service and measure campaigns and conversions. Based on the expressed choice, data such as pages visited, URLs, referrers and campaign parameters may be processed.
With consent to statistics, at the time of payment and of any refund psAico sends to Google Analytics 4 — directly from its own servers and not from the browser — a purchase or refund event relating to the subscription. The event contains the pseudonymous identifier assigned by the Google Analytics cookie, the invoice number, the amount and the tax, the currency, the name of the plan purchased, the reason for the charge (first purchase or renewal) and any discount code; it also carries the choice expressed on the Marketing category, so that in its absence Google does not use the event for personalised advertising purposes. No name, email address or account identifier is transmitted. The technical data needed to link the payment to the browsing session is kept by psAico for 7 days, extended to 90 in the event of a successful payment, and then deleted.
With consent to statistics, at registration psAico stores on its own servers, associated with the account, the campaign parameters contained in the address used to reach the web app (source, medium, campaign and ad group name, technical identifier of the click), in order to measure which of the Data Controller's campaigns bring sign-ups and subscriptions. The same parameters may be carried over into the link to Google Play, so that the app receives them at installation. Only the first origin is recorded; the data are not disclosed to Google or to other advertisers, are not used to display ads, are not combined with the content of conversations and are deleted together with the account; the technical identifier of the click is deleted after 90 days.
The choice is stored in the technical cookie cc_cookie, shared on the .psaico.ai domain for a maximum of 182 days. The user can accept or reject the Statistics and Marketing categories separately and modify or revoke the choice at any time via the Cookie Preferences item of the web app.
The public site may provide further details in its cookie policy. This information does not replace this section: the preference is shared between psAico domains and the web app can also directly carry out the statistical and marketing treatments described above.
iOS and Android app
The iOS and Android app does not use cookies or advertising identifiers (IDFA/AAID) and does not carry out any tracking across third-party apps or websites. In addition to the technical tools necessary for its operation (session and authentication, security, Google reCAPTCHA at the access points, push notifications via the device token, technical logs), the app may collect aggregate usage statistics through Google Analytics for Firebase (Google Ireland Limited, acting as data processor), exclusively with the prior consent of the user, given on first launch on the Rispettiamo la tua privacy (We respect your privacy) screen. For this purpose a pseudonymous identifier of the installation (app instance ID) is generated and usage events are recorded, such as opening the app, completing the registration and the first questionnaire, starting and completing the purchase — the latter accompanied by the amount, the currency, the plan purchased and the transaction identifier assigned by the store — together with technical data of the device (model, operating system, language, country). Name, email address and the content of conversations are never transmitted; Google Signals and advertising signals are disabled. Consent may be refused without any consequence for the use of the service, is stored on the device for 182 days and can be modified or revoked at any time from the app, under Privacy e termini → Preferenze privacy (Privacy and terms → Privacy preferences), item Statistiche d’uso (Usage statistics): upon revocation the collection stops and the statistical data and the identifier already present on the device are deleted. If the tools or the purposes change substantially, the choice is requested again. The statistical data is kept by Google for a maximum of 14 months. Legal basis: consent pursuant to art. 6(1)(a) GDPR. Google may also process the data on servers located in the United States, on the basis of the EU-U.S. Data Privacy Framework and the standard contractual clauses.
With the same consent, the app detects which campaign of the Data Controller the installation comes from. On Android it reads, through Google Play services, the campaign parameters recorded by the store at the time of download (source, medium, campaign and ad group name, technical identifier of the click, date of the click and of the installation) and transmits them to the psAico servers on the first authenticated session. On iOS the app requests from the operating system the Apple Search Ads attribution token (AdServices framework) and sends it to the psAico servers together with a random installation identifier generated by the app, which is neither a device identifier nor an advertising identifier; the Data Controller presents the token to Apple, which responds only with the campaign and ad group identifiers, without receiving any user data. The result is associated with the account at the time of registration. Only the first origin is recorded; the data are not disclosed to Google, to Apple or to other advertisers, are not used to display ads, are not combined with the content of conversations and are deleted together with the account; the installation identifier and the click identifier are deleted after 90 days. No advertising identifier is read and no iOS tracking authorisation is requested.
The app also uses Firebase Crashlytics (Google) to collect, in the event of an error or a crash, technical reports (type of error, state of the app, device model and operating system version) necessary to ensure the stability and security of the service (legitimate interest pursuant to art. 6(1)(f) GDPR). The reports do not contain identifying data or the content of conversations and are retained by Google for 90 days.
9. Sharing with a trusted healthcare professional
At the user’s exclusive initiative, the application allows a trusted healthcare professional to be authorised to access, on a read-only basis, the answers and scores of the questionnaires, the technical summaries and the chat content retained at the time of consultation, in accordance with the retention periods set out in §4. Together with that content, the professional sees the identifying data of the account (first and last name or, failing that, the nickname) and the email address, which are needed to recognise the User among the people who have authorised them. The feature requires an active subscription and is not available during the free trial. It is also available in Italy only and is reserved to professionals registered with Italian professional boards.
The feature is optional: not using it does not affect the use of the service in any way. The sharing concerns data that may fall within the special categories provided for by Art. 9 GDPR and is based on explicit consent, specific and separate from the consent required to use the service, pursuant to Art. 6(1)(a) and Art. 9(2)(a) GDPR. Consent is collected at the time of the invitation, with the professional’s email address entered twice and confirmation through the second authentication factor; the Data Controller records the date, time, recipient and version of the notice.
The user may revoke the authorisation at any time from their personal area, with immediate effect and without prejudice to the lawfulness of processing carried out before revocation. Deleting the conversation memory or the account makes the content no longer visible to the professional. No copies are created for the professional that survive revocation or deletion. Technical records of the authorisation, of its revocation and of the consultations carried out by the professional remain, kept for 24 months to document the choices made by the user and to ensure the traceability of accesses.
The professional who gains access processes the consulted data within their own activity, as an independent data controller, in compliance with their own regulatory and ethical obligations and their own privacy notice. The Data Controller is not liable for subsequent processing carried out by the professional.
The professional’s personal data is processed in accordance with the dedicated notice available at the bottom of this page.
International addendum to the psAico Privacy Policy
1. Purpose, scope and precedence
This Addendum supplements the psAico Privacy Policy and applies to the processing of personal data of users located outside the European Union and the European Economic Area, when the law of the place where the user is located is applicable to the Service.
The general Privacy Policy and this Addendum must be read together. This Addendum does not limit the rights recognized by the general Privacy Policy.
In case of conflict, the mandatory provisions of the law applicable to the user prevail. To the extent compatible with this law, the provision that ensures the highest protection for the data subject applies.
The availability of the application in a digital store does not exclude the application of local legislation and does not replace any registrations, authorizations, impact assessments, local representatives or other preliminary obligations required in the country concerned.
2. Data Controller and contact details
The Data Controller is:
- psAico S.r.l.s. single shareholder
- Via Pranzelores 87 – 38121 Trento (TN) – Italy
- VAT number 02800830222
- Email: info@psaico.ai
- PEC: psaico@namirialpec.it
Requests relating to privacy can be sent to the contact details indicated above or via the assistance tools available in the application.
When local law requires the designation of a representative, privacy officer or contact person located in your country, their contact details must be made available before the Service is offered in that country and published in the Policy or through an easily accessible local notice.
3. Data processed and purposes
The categories of personal data processed, the purposes, methods of processing, recipients and storage times are described in the general Privacy Policy.
Depending on the features used, the processing may include account and profile data, Chat contents, Technical Summaries, questionnaires, technical and security data, data relating to authentication, notifications, subscriptions, assistance and newsletters.
Content freely inserted by the user may reveal information about psychological well-being, emotional state, health or intimate life. This information is treated as sensitive data or data belonging to special categories when applicable law requires it.
psAico invites the user not to enter personal data of third parties, direct identifiers or information that is not necessary for the provision of the Service.
4. Legal bases and consent
When the GDPR is applicable, the legal bases remain those indicated in the general Privacy Policy.
In other countries, psAico processes data on the basis of consent, the execution of the contract requested by the user, the fulfillment of legal obligations, the protection of security and other prerequisites recognized by local legislation.
The processing of content that reveals sensitive data is based on explicit consent when this is required by applicable law. The revocation of consent does not affect the lawfulness of the processing carried out before the revocation. If the processing of sensitive data is necessary for the essential functions of psAico, the revocation makes it impossible to continue using these functions and can be exercised by deleting the account or contacting the Data Controller.
Consent to the newsletter and promotional communications is optional, separate from the main Service and revocable at any time.
5. Processing using artificial intelligence
To generate virtual assistant responses and Technical Summaries, psAico uses artificial intelligence services provided by OpenAI via API.
Before sending, the Service applies minimisation, scrubbing and context reduction measures aimed at limiting the presence of direct identifiers and unnecessary information. Since free text may contain specific or identifying information, these measures reduce the risk of identification but do not guarantee complete or irreversible anonymization of the contents.
For end-user accounts, API calls are configured with store=false, without requiring OpenAI to store the prompts and responses. OpenAI can however generate technical and security logs for the prevention of abuse, stored according to the provider's policies and applicable obligations.
The Data Controller does not use conversations to independently train its artificial intelligence models.
6. No sale of data or behavioural advertising
psAico:
- does not sell users' personal data;
- does not license personal data to data brokers;
- does not use the content of conversations for behavioural advertising;
- does not share the content of conversations with advertisers;
- does not use sensitive data to create advertising segments;
- does not authorize OpenAI to use inputs or outputs sent via API to train its models.
The data may be communicated to technical service providers who operate on behalf of psAico, within the limits necessary for the provision, security and management of the Service, or when communication is required by law.
Any use of unnecessary analytics or marketing tools occurs within the limits and on the basis of consent described in the general Privacy Policy.
7. International transfers
Some providers may process data outside the country in which the user is located. These service providers may include, depending on the features used, artificial intelligence, infrastructure and security services, digital stores, email and push communications, assistance, analytics and marketing.
When an international transfer of personal data occurs, psAico adopts the guarantees required by applicable law, which may include:
- adequacy decisions or equivalent mechanisms;
- Standard Contractual Clauses or model clauses recognized by local law;
- data processing agreements;
- impact or transfer risk assessments;
- explicit consent, only when it constitutes a valid mechanism for the transfer concerned;
- additional technical and organizational measures;
- authorizations from the competent authority, when mandatory.
A description of the applicable guarantees may be requested from the Data Controller, to the extent permitted by law and without prejudice to confidential or security-related elements.
8. Retention and deletion
The data is stored for the periods indicated in the general Privacy Policy. In particular:
- the complete Chat messages are kept by the Data Controller for a maximum period of 30 days and are subject to periodic automatic deletion;
- after this deadline, the system may retain a Technical Summary associated with the account until the conversational memory or the account is deleted;
- clearing the memory eliminates messages, Technical Summaries and user questionnaires from the database;
- administrative, accounting and fiscal data may be retained for the periods required by law;
- technical and security logs are retained to the extent necessary for operation, security and management of applicable obligations;
- any residual data present in the backup copies, encrypted and subject to rotation, are overwritten within a maximum of 7 days;
- the non-reversible identifier described in section 1 of the general Privacy Policy, the date on which the trial was granted and any last attempt at a new registration are retained for 24 months from registration of the account and are the only data that remain after the account is deleted.
Deletion of the account also involves the automatic termination of the newsletter subscription and the removal of personal data which can be deleted. Only data that must be retained for legal, fiscal and accounting obligations, to document the management of the request or for security and legal protection requirements permitted by law are excluded. The non-reversible identifier indicated above and the minimal data accompanying it are also retained.
9. User rights
Regardless of the country of residence and within the technically and legally applicable limits, the user can request:
- confirmation of the existence of personal data concerning them;
- access to your data and information on processing;
- correcting or updating inaccurate or incomplete data;
- data deletion;
- limitation or suspension of treatment;
- opposition to certain treatments;
- portability of the data provided by the user;
- revocation of consent previously given;
- information on recipients and international transfers;
- human intervention or review when the law recognizes rights relating to automated processes;
- review of a previously rejected privacy request;
- complaint to the competent authority.
psAico may request information reasonably necessary to verify the applicant's identity and prevent unauthorized access. Requests are handled free of charge and within the terms established by applicable law, except in cases of manifestly unfounded, excessive or repetitive requests in which the law allows a refusal or the charging of a reasonable cost.
10. Regional protections
Switzerland
The Federal Data Protection Act applies to users in Switzerland. The user can contact the Federal Data Protection and Information Commissioner.
When the processing connected to the offering of the Service is regular, on a large scale and presents a high risk, psAico must designate and publish the contact details of a representative in Switzerland.
Australia and New Zealand
Users in Australia can exercise their rights under the Privacy Act 1988 and complain to the Office of the Australian Information Commissioner.
Users in New Zealand can exercise their rights under the Privacy Act 2020 and complain to the Office of the Privacy Commissioner.
Latin America
Users in Latin American countries in which the Service is available are entitled to the rights provided for by the respective national legislation, including, when applicable, access, information, rectification, updating, cancellation, opposition, portability and revocation of consent.
Requests can be addressed to psAico and, in case of failure to resolve, to the competent national authority. Local obligations regarding the registration of databases, designation of representatives or delegates, impact assessment and regulation of international transfers remain unchanged. In Chile, law no. 21.719 and the related new regime apply from the date of entry into force established by law.
Asia and the Pacific
Users in the countries of Asia and the Pacific area in which the Service is available are entitled to the rights recognized by the respective national legislation.
Where applicable, psAico must designate a data protection officer or local representative, register processing systems, document impact assessments, adopt safeguards for cross-border transfers and comply with local requirements relating to consent for sensitive data.
Middle East
Users in the Middle Eastern countries where the Service is available are entitled to the rights provided by local law.
In some of these countries, the processing of information freely entered by the user that reveals data relating to health or psychological condition and the transfer of data abroad require registrations, permits or prior authorizations. This Addendum does not replace these obligations.
Other countries
If the legislation of the user's country recognizes additional rights, guarantees, limitations or mandatory complaint tools, these provisions apply and integrate this Addendum.
11. Minors
The Service is intended exclusively for persons who are 18 years of age or older.
psAico does not knowingly collect personal data from minors. If it is ascertained that a minor has created an account or provided personal data, psAico will suspend the account and delete the data as soon as possible, without prejudice to legal obligations and the protection needs of the person concerned.
12. Territorial availability
The Service is offered exclusively in countries and territories selected by psAico in digital stores, supported by essential technology providers and in which applicable obligations can be respected.
For users residing outside Italy, any subscription to the Service is offered exclusively through the Apple App Store or Google Play. The website does not constitute a channel for selling subscriptions to such users.
The Service is not offered:
- in the United States of America;
- in Brazil;
- in countries or territories not supported by essential technology providers;
- in territories subject to sanctions, embargoes or legal restrictions incompatible with the provision of the Service;
- in countries in which a mandatory mandatory preliminary requirement has not been completed.
The mere technical possibility of downloading the application does not guarantee that registration, purchase or use of the Service is permitted in all places. psAico may prevent registration, purchase, or access from an unsupported or suspended territory, even if the application was previously downloaded in another country.
The feature that shares data with a trusted healthcare professional, described in §9, is available in Italy only and is reserved to professionals registered with Italian professional boards: it is not offered to users located outside Italy.
13. Complaints
The user is invited to initially contact psAico using the contact details indicated in this Addendum.
This remains without prejudice to the right to lodge a complaint with the competent authority in the country of residence, in the place where the user is located or in the place where the alleged infringement occurred, in accordance with the applicable law.
14. Changes and languages
Substantial changes to this Addendum are communicated in an appropriate manner, for example by email, notice in the application or request for new acceptance, when required by law.
The translations of this Addendum are prepared to facilitate understanding. In case of interpretative differences, the Italian version prevails exclusively within the limits permitted by applicable law. The mandatory rights recognized to the user in their own country remain at all times unaffected.