Privacy statement.
Last updated: April 15, 2026
Dear Customer, datteco s.r.l. hereby provides you with information on the nature and purposes of the processing of personal data, in accordance with applicable data protection regulations—in particular Regulation (EU) 2016/679 and Italian Legislative Decree No. 196/2003 as amended.
This Privacy Policy applies to personal data collected and/or provided by you in connection with the use of the Profitize platform, the associated website www.profitize.io, and the app. This Privacy Policy applies exclusively to Profitize, the corresponding website, and the app, and does not apply to third-party websites or web platforms—including social networks—that are accessible in any way through them, in particular via hyperlinks.
If you have any questions about this Privacy Policy, you can contact us:
By email: hello@profitize.io
1. Definitions
1.1. For the purposes of this Privacy Policy and in accordance with applicable data protection provisions, the following terms shall have the meanings defined below, whether used in the singular or plural:
- PROFITIZE: AI-powered platform for financial planning and analysis in the hotel industry, offered by datteco S.r.l. and provided as Software-as-a-Service (SaaS) via the web portal (hereinafter "WEBSITE") and via apps for Android and iOS (hereinafter "APP");
- DATA CONTROLLER: datteco s.r.l., VAT No. 03119520215, based in 39100 Bolzano (BZ), Italy;
- CUSTOMER: any person using PROFITIZE via the WEBSITE and/or the APP and using the associated services, providing personal data as defined below.
- PERSONAL DATA: any information relating to the CUSTOMER as an identified or identifiable natural person. Where the CUSTOMER is a legal entity, personal data refers to the identified or identifiable natural persons acting on behalf of the CUSTOMER (e.g., legal representatives, contact persons, employees).
- IDENTIFYING DATA: data allowing the direct identification of the data subject, in particular information such as name, identification number, residential address, email address, date of birth, place of birth, location and movement data (GPS), online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- USAGE DATA: data collected automatically through the use of PROFITIZE or from its technical infrastructure, such as information on access, duration of use, or interactions with the WEBSITE and/or the APP (e.g., the duration of a page visit), IP addresses, date and time of access, pages viewed, device and browser information, as well as error messages.
- DEVICE DATA: information about the device used by the CUSTOMER, such as device type, operating system, unique device identifiers, and language settings.
- DEVICE: Any device capable of accessing the PROFITIZE platform, such as a computer, mobile phone, or digital tablet;
- COOKIES: Small text files stored on the CUSTOMER's DEVICE that enable the analysis of service usage. Cookies can be used as persistent cookies or session cookies:
- Persistent cookies: remain on the CUSTOMER's DEVICE even when the CUSTOMER goes offline.
- Session cookies: are automatically deleted as soon as the CUSTOMER closes the browser.
The cookies used by the DATA CONTROLLER on its WEBSITE and/or APP may include, among others, the following types: - Necessary Cookies: Technical cookies required to provide functions and ensure the proper operation of PROFITIZE;
- Functional Cookies: Cookies that allow the CUSTOMER to use certain features of PROFITIZE beyond purely necessary functions, enhancing user-friendliness and CUSTOMER interaction with PROFITIZE;
- Cookie Policy Consent Cookies (see Art. 10 of this Privacy Policy);
- Measurement/Analytics Cookies: Cookies that analyze CUSTOMER behavior to improve PROFITIZE;
- Marketing Cookies: Cookies used to tailor advertising and marketing content to the CUSTOMER's interests;
- Flash Cookies: Locally stored objects used to store information about CUSTOMER preferences or the use of PROFITIZE.
- SIMILAR TRACKING TECHNOLOGIES: Beacons, tags, and scripts that collect, process, and contribute to analyzing and improving PROFITIZE. The tracking technologies used by the DATA CONTROLLER on its WEBSITE and/or APP include, in particular, web beacons (also known as clear gifs, pixel tags, or single-pixel gifs), which enable the DATA CONTROLLER to record the use of certain pages or content, track email opens, and collect other related website statistics, such as the popularity of certain sections and system/server integrity verification.
- DATA PROCESSING: Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
- DATA PROCESSOR: Any natural or legal person processing data on behalf of the DATA CONTROLLER. This includes, in particular, third-party companies or individuals engaged to enable the operation of PROFITIZE, provide PROFITIZE on behalf of the DATA CONTROLLER, perform related services, or assist the DATA CONTROLLER in analyzing the usage of PROFITIZE;
2. Types of Data Collected
2.1. When using PROFITIZE via the WEBSITE and/or the APP as well as the associated services, the DATA CONTROLLER or the DATA PROCESSOR processes the following PERSONAL DATA of the CUSTOMER:
- IDENTIFYING DATA;
- USAGE DATA;
- DEVICE DATA.
2.2. The DATA CONTROLLER, acting as controller, does not process any special categories of PERSONAL DATA pursuant to Art. 9 GDPR for the purposes described in this Privacy Policy.
3. Use of Personal Data
3.1. The DATA CONTROLLER will use the CUSTOMER's PERSONAL DATA for the following purposes, in accordance with applicable data protection regulations, in particular Art. 6 of Regulation (EU) 2016/679:
- Provision and operation of PROFITIZE and related services;
- Account management: Registration and administration of the customer account, and enabling access to features of PROFITIZE and related services for registered CUSTOMERS;
- Contract performance: Conclusion, execution, and management of contracts concerning PROFITIZE and related services, as well as other contractual relationships between the CUSTOMER and the DATA CONTROLLER;
- Communication: Contacting the CUSTOMER via electronic communication means (e.g., email, phone, SMS, push notifications) regarding PROFITIZE, its features, and related services including security updates, where necessary or appropriate for implementation;
- Information and Marketing: Sending information, offers, newsletters, marketing or promotional materials, and other communications regarding products, services, or events of PROFITIZE that may be of interest to the CUSTOMER, subject to prior written consent. The DATA CONTROLLER is entitled to use the CUSTOMER's email address collected in connection with the sale of products or services for direct advertising of its own similar products or services related to PROFITIZE, provided the CUSTOMER has not objected to such use;
- Request management: Processing and handling of CUSTOMER inquiries;
- Corporate transactions: Use of PERSONAL DATA in the context of mergers, divestitures, financing, or acquisition of PROFITIZE or parts of the business;
- Analysis and improvement: Data analysis, identification of usage trends, evaluation of marketing campaign effectiveness, and improvement of PROFITIZE, services, and user experience;
- Public interactions: Processing PERSONAL DATA voluntarily disclosed by the CUSTOMER in public areas of PROFITIZE, which may be visible to other users;
- Consent-based purposes: Processing PERSONAL DATA for additional purposes based on the CUSTOMER's explicit consent (e.g., CUSTOMER profiling, transfer of PERSONAL DATA to third parties for commercial purposes, etc.).
Furthermore, in addition to the purposes described above, the DATA CONTROLLER may process the CUSTOMER's PERSONAL DATA:
- to comply with legal obligations or to implement orders, decisions, and measures issued by competent authorities, including the Data Protection Authority;
- based on its legitimate interest in establishing, exercising, or defending its legal claims in judicial proceedings.
3.2. The DATA CONTROLLER processes PERSONAL DATA in compliance with the principles of the Regulation and exclusively for the purpose of carrying out its activities as well as fulfilling existing contracts or pre-contractual measures requested by the data subjects.
3.3. Data is accessible solely to employees and contractors of the DATA CONTROLLER acting on its behalf, who have received appropriate training and possess knowledge of their tasks and permitted data handling activities.
3.4. The CUSTOMER's PERSONAL DATA will be processed by the DATA CONTROLLER in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using suitable technical and organizational measures.
4. Use of Sensitive Data in Special Cases
4.1. In the context of using PROFITIZE, the DATA CONTROLLER ensures that PERSONAL DATA of the CUSTOMER in special processing contexts will be processed exclusively to the necessary extent and in compliance with the principle of data minimization, insofar as this is strictly necessary to guarantee proper operation and to deliver the contractually agreed services of PROFITIZE.
4.2. In particular, the following applies:
- PERSONAL DATA relating to user management (in particular name and email address) is processed exclusively for customer account management and is under no circumstances transmitted to AI systems integrated into PROFITIZE (in particular Large Language Models – LLMs). The CUSTOMER also has the option to create additional PROFITIZE users without transferring any PERSONAL DATA to such systems.
- PERSONAL DATA of the CUSTOMER's employees—where possible—is processed in a reduced or pseudonymized form; in particular, sensitive details such as position, department, compensation, or working hours remain exclusively within the internal area and are never transmitted to external AI systems used by PROFITIZE.
- In accounting, any PERSONAL DATA regarding employees contained in raw files provided by the CUSTOMER will be anonymized prior to further DATA PROCESSING, specifically by removing identifying characteristics; subsequent DATA PROCESSING within the application takes place using internal, non-traceable employee numbers only.
- Data from external systems (such as Property Management Systems – PMS) is processed exclusively in aggregated or non-identifiable form, limited to statistical information (e.g., country of origin or age groups), while all other PERSONAL DATA is neither processed further nor stored.
- In connection with Point-of-Sale (POS) systems, no guest data is generally processed, with the exception of purely technical references (e.g., table or room numbers); any service staff data (e.g., name or ID) is processed exclusively internally and never transmitted to AI systems integrated into PROFITIZE.
- In the context of bank transactions, the following PERSONAL DATA in particular is processed:
- Sender and recipient IBAN
- Payment reference/purpose of transaction
In individual cases, the payment reference may contain PERSONAL DATA (e.g., guest or company names). The payment reference is transmitted to AI systems integrated into PROFITIZE for categorization purposes, processed—where possible—without PERSONAL DATA.
5. Storage of Personal Data
5.1. The CUSTOMER's PERSONAL DATA will be stored by the DATA CONTROLLER only for the duration required to achieve the purposes outlined under Section 3.1, as well as to comply with legal obligations, resolve disputes, protect legitimate interests, and enforce contractual agreements and internal policies: specifically for the duration of the contractual relationship + 10 years (statutory retention requirements); Marketing data: until consent is revoked; Usage data (non-anonymized): maximum 12 months; Technical log data: maximum 6 months.
5.2. Furthermore, USAGE DATA is stored in anonymized form for internal analysis purposes.
6. Transfer of Personal Data
6.1. The CUSTOMER's PERSONAL DATA may be disclosed to third parties, in particular to employees, contractors, DATA PROCESSORS, commercial advisors for administrative and accounting purposes, and legal counsel for handling potential disputes. Such transfer may also take place outside the state, province, country, or other governmental jurisdiction.
6.2. The processing of this data by the aforementioned third parties takes place exclusively for purposes related to the use of PROFITIZE and associated services and is governed by Regulation (EU) 2016/679 as well as the Italian Data Protection Code.
6.3. The CUSTOMER's PERSONAL DATA may also be transmitted to police or judicial authorities, provided this is necessary for the detection or prosecution of criminal offenses committed by the CUSTOMER in connection with the online services.
7. Data Processors
7.1. Personal data may be transferred to countries outside the European Economic Area (e.g., USA). Such transfers are carried out in compliance with the GDPR based on: Standard Contractual Clauses (SCCs) and additional appropriate safeguards. The DATA CONTROLLER uses Mailchimp, an email marketing distribution service provided by The Rocket Science Group LLC. Therefore, The Rocket Science Group LLC acts as a DATA PROCESSOR regarding this service.
For more information on Mailchimp's privacy practices, please refer to their Privacy Policy.
7.2. In addition, the DATA CONTROLLER uses Webflow for hosting, rendering, providing functionality, and ensuring the security of the WEBSITE. In this context, Webflow stores COOKIES or other SIMILAR TRACKING TECHNOLOGIES necessary for the rendering, functionality, and security of the WEBSITE. Webflow acts as a DATA PROCESSOR. Further information on Webflow's privacy practices is available at: https://webflow.com/legal/eu-privacy-policy.
8. Purpose and Legal Basis for Processing Personal Data
|
Purpose |
Legal Basis |
Requirement |
|
Provision of services and account management |
Performance of a contract (Art. 6(1)(b) GDPR) |
Required |
|
Customer communication and support |
Performance of a contract (Art. 6(1)(b) GDPR) |
Required |
|
Compliance with legal obligations |
Legal obligation (Art. 6(1)(c) GDPR) |
Required |
|
Security and fraud prevention |
Legitimate interest (Art. 6(1)(f) GDPR) |
Required |
|
Service analysis and improvement |
Legitimate interest (Art. 6(1)(f) GDPR) |
Optional |
|
Marketing communications |
Consent (Art. 6(1)(a) GDPR) |
Optional |
|
Direct marketing for similar products ("Soft Spam") |
Legitimate interest (Art. 130 Italian Data Protection Code) |
Optional |
8.1. The CUSTOMER's consent to the processing of their PERSONAL DATA is a prerequisite for carrying out all activities under Articles 3, 4, and 5, unless applicable data protection laws permit processing without consent.
8.2. This consent is given by the CUSTOMER at the time of signing any agreement with the DATA CONTROLLER.
8.3. The CUSTOMER has the right to withdraw given consent at any time, resulting in a corresponding restriction of services relying on DATA PROCESSING.
9. Rights of the Customer
9.1. THE CUSTOMER has the right to:
- Obtain access to their data (Art. 15 GDPR)
- Have inaccurate data rectified (Art. 16 GDPR)
- Have data erased (Art. 17 GDPR)
- Restrict processing (Art. 18 GDPR)
- Request data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent at any time.
9.2. To exercise these rights, the CUSTOMER must send a written request to the designated email address. The DATA CONTROLLER reserves the right to request identity verification prior to responding to the CUSTOMER's request.
9.3. THE CUSTOMER also has the right to lodge a complaint with the competent data protection supervisory authority.
10. Personal Data of Minors Under 14
10.1. The services offered by the DATA CONTROLLER and the PROFITIZE platform are not directed at minors under 14 years of age. Accordingly, no PERSONAL DATA of individuals under 14 is processed by the DATA CONTROLLER.
10.2. In any event, where consent is required for handling PERSONAL DATA, the processing of PERSONAL DATA of children who have not reached 14 years of age is lawful pursuant to Art. 8 GDPR and Art. 2-quinquies of Legislative Decree No. 196/2003 only if consent is given by the holder of parental responsibility over the child.
11. Use of Cookies and Similar Tracking Technologies
11.1. The DATA CONTROLLER uses COOKIES and SIMILAR TRACKING TECHNOLOGIES to analyze the CUSTOMER's usage of PROFITIZE, the WEBSITE, and the APP, track CUSTOMER activities on PROFITIZE, and store certain information.
11.2. When the CUSTOMER visits the PROFITIZE platform, WEBSITE, and/or APP for the first time, returns after a certain period, or accesses the WEBSITE in private browsing mode (incognito window), a cookie banner will be displayed.
11.3. The CUSTOMER can accept all COOKIES or manage preferences by selecting the types of COOKIES to be stored on their DEVICE.
11.4. Furthermore, the CUSTOMER can change these settings at any time.
11.5. The CUSTOMER can also configure their browser to reject individual or all COOKIES, or to require consent prior to accepting cookies.
11.6. Please note that rejecting, deleting, or disabling COOKIES may restrict or prevent access to certain areas or features of PROFITIZE.
12. Hyperlinks on profitize
12.1. PROFITIZE may contain hyperlinks to other websites that are neither owned nor controlled by the DATA CONTROLLER.
12.2. The DATA CONTROLLER assumes no liability for the content or other data processing activities associated with these third-party websites.
13. Changes to this Privacy Policy
13.1. The DATA CONTROLLER may update this Privacy Policy from time to time. Changes will be published on the WEBSITE.
13.2. THE CUSTOMER will be notified prior to material changes taking effect via email and/or through a prominent notice on the PROFITIZE platform.
13.3. Changes to this Privacy Policy become effective upon publication on the WEBSITE.
HubSpot
The provider is HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA (hereinafter "HubSpot"). When you visit our website, HubSpot processes various technical data (e.g., IP address, browser information, time of page view) and stores log files.
HubSpot is a tool for building, managing, and hosting websites, as well as providing marketing and analytics features. HubSpot uses cookies and similar recognition technologies that are necessary for displaying the website, providing certain functionalities, and ensuring security (necessary cookies).
Details can be found in HubSpot's Privacy Policy: https://legal.hubspot.com/privacy-policy
The use of HubSpot is based on Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably, securely, and efficiently as possible. Where appropriate consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TTDSG (or applicable national legislation), insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting). Consent can be revoked at any time.
Data transfer to the USA is based on the European Commission's Standard Contractual Clauses (SCCs). Details can be found here: https://legal.hubspot.com/privacy-policy