Privacy notice
How we handle your data
Provided under Articles 12 and 13 of Regulation (EU) 2016/679 (GDPR) and Law of the Republic of San Marino no. 171/2018. It is written to be read: if any part isn't clear, ask us and we'll rewrite it.
Who processes your data
Data Controller is Migastone International S.r.l., a company under the law of San Marino, which runs this site and the Segnalazione Vincente brand.
- Migastone International S.r.l.
- Via 28 Luglio, 212 — 47893 Borgo Maggiore, Republic of San Marino
Economic Operator Code SM28583 - Privacy requests
- privacy@migamatch.com — the Controller's dedicated inbox, shared between this site and the MigaMATCH platform
- General contact
- support@migastone.com · 0549 888808 · PEC (certified email) migawin@pec.it
The Data Protection Officer
The Controller has appointed a Data Protection Officer (DPO) under Art. 37 GDPR. You can address him directly, without going through us, for any matter concerning your data.
- Ing. Antonio Mirizzi
- Via Tommaso Fiore, 82 — 70019 Triggiano (BA), Italy · VAT No.
MRZNTN76D19A662U
rpd@invictusaziende.it
The EU Representative: why a San Marino company has a contact person in Italy
San Marino is a third country relative to the European Union. A controller established outside the EU that processes data of people located in the EU must designate a Representative under Art. 27 GDPR: a person on European territory that you and the Supervisory Authorities can address directly, as if they were the Controller. We have designated one.
Walter Coslop — Via Ugo Bassi, 11 — 47822 Santarcangelo di Romagna (RN), Italy · VAT No. 04640000404 · Tax Code CSLWTR76P03F187N · w.coslop@migastone.com
If you reside in the European Union you can exercise all your rights by writing to him. You are not required to write to San Marino.
What data we collect
We only collect the data you give us, plus what measurement cookies collect if you authorise us to. We don't buy lists and don't collect data from third-party sources.
Data you provide through the site's forms
- First and last name, email address, phone number
- Company, role, industry and the information you choose to write in the form's free-text fields
- The content of the request you send us
Data collected automatically
- IP address, browser and device type, pages viewed, source of the visit — through the cookies and measurement tools described in the cookie policy, and only to the extent you gave consent
- Date, time, notice version and the choice expressed on cookies, which we keep so we can demonstrate how and when consent was given (Art. 5.2 GDPR)
Special categories of data (Art. 9 GDPR)
We do not ask for or intentionally collect data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, or data concerning health or sex life. The free-text fields in our forms do, however, let you write anything: we ask you not to enter data of this kind. If you do so on your own initiative, the processing is based on the explicit consent you express by voluntarily entering it (Art. 9.2.a GDPR) and you can request its deletion at any time.
Why we process it, and on what legal basis
For each purpose we state the legal basis that legitimises it under Art. 6 GDPR. Where the basis is consent, consent is optional and revocable.
| Purpose | What it involves | Legal basis |
|---|---|---|
| Responding to your request | Handling the contact or information request, including by phone, and the contacts that follow from it | Art. 6.1.b — pre-contractual steps taken at your request |
| Providing the requested service | AIRA-DX© Stoic Analysis, AIRA-SCAN©, access to the MigaMATCH platform, participation in events | Art. 6.1.b — performance of a contract |
| Newsletter | Sending the discipline's numbers and communications on activities, events and news | Art. 6.1.a — consent, revocable with one click from every message |
| Measuring the site and campaigns | Browsing statistics, measurement and personalisation of ads — see the cookie policy | Art. 6.1.a — consent given via the banner, revocable |
| Site security | Prevention of abuse, unauthorised access attempts and automated form submissions | Art. 6.1.f — legitimate interest |
| Legal obligations | Accounting and tax compliance, responses to lawful requests from authorities, retention of proof of consent | Art. 6.1.c — legal obligation |
| Defence in legal proceedings | Establishment, exercise or defence of a right in judicial proceedings | Art. 6.1.f — legitimate interest |
For the legitimate-interest basis we have carried out a balancing test (Legitimate Interest Assessment), available on request. You can object at any time on grounds relating to your particular situation (Art. 21 GDPR).
Profiling and automated decisions
This is the part the previous notice stated the opposite of, and it has to be said in full.
Yes, some of our services profile — and they do it with an algorithm
If you request the AIRA-DX© Stoic Analysis, use AIRA-SCAN© or sign up to the MigaMATCH platform, the data you give us is processed automatically by AIRA© to compute a score and generate a report. This is profiling, and it is the service itself: without the algorithm there is nothing to deliver to you.
How it works is described in a verifiable way — the five components of the score, the three modifiers, the effects on you and the safeguards you're entitled to — in sections 7 and 9 of the MigaMATCH notice, which is the document that governs this part of the processing.
Read the MigaMATCH notice on profiling and AI-generated reports
What you should know without opening the other document
- Profile data is turned into numeric vectors by Google Vertex AI and compared by the AIRA© algorithm, which computes an affinity score.
- Reports are generated by an artificial-intelligence model (Anthropic Claude). Anthropic acts as a Data Processor, is contractually committed to not using the data to train the models and to deleting input and output within 7 days.
- You always have the right to obtain human intervention, to express your point of view and to contest the automated decision (Art. 22.3 GDPR). Write to privacy@migamatch.com or to the DPO.
For these services you are asked for a specific, separate consent from the simple contact one: its own checkbox, never pre-ticked, with a direct link to the sections cited above.
The simple contact form and the newsletter sign-up do not profile. If you write to us to ask for information, no algorithm assigns you a score.
Who we share data with
Your data is not sold or transferred to third parties for their own purposes. It may be shared with:
- Authorised internal staff trained in data processing.
- Data Processors appointed under Art. 28 GDPR, who process data on our behalf and under our instructions. The site's forms feed into the MigaMATCH platform: its providers — Supabase (database, EU), Google Cloud (semantic processing and geocoding), Anthropic (report generation), Twilio/SendGrid (transactional email), n8n self-hosted on the Controller's own EU servers — are listed with role, data location and safeguards in section 10 of the MigaMATCH notice.
- Measurement-tool providers — Google, Meta, LinkedIn — within the limits of the consent you gave and with the detail set out in the cookie policy.
- Tax, legal and business consultants of the Controller, bound by professional secrecy.
- Judicial, administrative and supervisory authorities, when required by law.
The updated list of Data Processors is kept by the Controller and can be requested at any time by writing to privacy@migamatch.com or to the DPO.
Where the data goes
San Marino
The Controller is based in the Republic of San Marino, a third country relative to the European Union, for which the European Commission has not adopted a formal adequacy decision under Art. 45 GDPR. Because of this:
- San Marino has adopted Law no. 171/2018, which substantially transposes GDPR principles;
- form data is stored on servers located in the Netherlands, i.e. within EU territory;
- we have designated an EU Representative under Art. 27 GDPR (section 1), who is the point of contact on European territory.
United States
Some providers are based in the United States. Transfers take place in compliance with Arts. 44-49 GDPR, with cumulative safeguards: EU-US Data Privacy Framework (Google and Twilio are certified), Standard Contractual Clauses approved by EU Decision 2021/914, Binding Corporate Rules where the provider has them, and supplementary encryption and security measures. You have the right to obtain a copy of these safeguards: request it from privacy@migamatch.com.
How long we keep it
We keep data for the time strictly necessary for the purposes it was collected for (Art. 5.1.e GDPR), and no longer.
Personal data provided is kept for the time strictly necessary to handle contact requests, support networking opportunities and develop the relational-engineering programme requested by the data subject. In particular, where no contract or active collaboration is finalised, the data is kept for a maximum of 24 months from the last contact or qualified interaction (for example, participation in events, opening of communications, interaction with our platforms), unless consent is withdrawn earlier or the right to object is exercised. Once that period has passed without further interest being shown or an active relationship existing, the data is deleted or irreversibly anonymised.
| Data | For how long |
|---|---|
| Contact requests | Up to 24 months from the last contact or qualified interaction (for example, participation in an event or interaction with our platforms), if no contract or active collaboration is finalised in the meantime — unless consent is withdrawn earlier. |
| Newsletter subscription | Until unsubscription, which you can do with the link at the bottom of every message |
| Data processed on the MigaMATCH platform | For the whole duration of the relationship; on unsubscription, immediate anonymisation of the profile and deletion of vectors and reports |
| Data sent to the AI service to generate a report | Maximum 7 days in the provider's systems. No use for model training |
| Proof of cookie consent | The sv_consent cookie lasts 180 days; the consent log is kept for accountability purposes (Art. 5.2 GDPR) |
| Accounting and tax data | 10 years from the close of the relevant financial year |
| Data subject to litigation | Duration of the dispute plus 10 years, for defence in legal proceedings |
Once these periods expire, data is deleted, irreversibly anonymised or — where an audit trail needs to be kept — pseudonymised.
Your rights
At any time, and free of charge, you can exercise against us the rights recognised by Arts. 15-22 GDPR and by San Marino Law no. 171/2018.
- Access (Art. 15)
- Find out whether we process data concerning you, what it is, and obtain a copy of it.
- Rectification (Art. 16)
- Correct inaccurate data and complete incomplete data.
- Erasure — "the right to be forgotten" (Art. 17)
- Obtain erasure of the data in the cases provided by law.
- Restriction (Art. 18)
- Freeze processing in the cases provided by law, without deleting the data.
- Portability (Art. 20)
- Receive the data you provided us with in a structured, machine-readable format, and transmit it to another controller.
- Objection (Art. 21)
- Object to processing based on legitimate interest for reasons relating to your situation, and to direct marketing at any time and without needing to give a reason.
- Automated decisions (Art. 22)
- Obtain human intervention, express your point of view and contest a decision made by an algorithm.
- Withdrawal of consent (Art. 7)
- Withdraw at any time a consent you gave, without affecting the lawfulness of processing carried out before the withdrawal.
How to exercise them
Choose whichever channel you prefer. No special form is needed: just say which right you want to exercise.
- Email to the Controller: privacy@migamatch.com
- Email to the DPO: rpd@invictusaziende.it
- Email to the EU Representative: w.coslop@migastone.com — recommended if you reside in the European Union
- PEC (certified email): migawin@pec.it
- Post: Migastone International S.r.l., Via 28 Luglio 212, 47893 Borgo Maggiore, Republic of San Marino
We respond within 30 days of receipt. In complex cases the deadline may be extended by a further 60 days, with reasoned notice given to you. To verify your identity we may ask you for a copy of a valid identity document.
Complaints to the Supervisory Authority
If you believe the processing of your data breaches the GDPR or San Marino Law no. 171/2018, you have the right to lodge a complaint with the Supervisory Authority, in addition to any other administrative or judicial remedy.
- If you reside in Italy — Garante per la Protezione dei Dati Personali
- Piazza Venezia, 11 — 00187 Rome · protocollo@gpdp.it · PEC protocollo@pec.gpdp.it · garanteprivacy.it
- If you reside in another EU Member State
- The Supervisory Authority of your State of residence.
- If you reside in the Republic of San Marino
- Garante per la Protezione dei Dati Personali — Contrada Omerelli, 6 — 47890 Città di San Marino · info.privacy@pa.sm
How we protect your data
We adopt technical and organisational measures proportionate to the risk, under Art. 32 GDPR. Among the main ones:
- encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256);
- row-level access control on the database, denying every anonymous access to profiles;
- separation of roles and the principle of least privilege for staff;
- immutable audit logs and monitoring of unauthorised access attempts;
- automatic backups and periodic staff training.
The detail of the measures adopted on the platform is in section 16 of the MigaMATCH notice.
Whether providing data is mandatory
Providing data is always optional. But some data is necessary for the service to exist:
- without contact details we cannot respond to your request;
- without the company's data the algorithm has nothing to analyse, and the Stoic Analysis or AIRA-SCAN© cannot be delivered;
- consent to marketing and the newsletter is instead entirely optional: declining it takes nothing away from the service, and does not authorise us to treat you any differently.
Changes to this notice
We may amend this notice to adapt it to regulatory changes, new services or guidance from Supervisory Authorities. Every substantial change involves publishing the new version on this page with an updated date and number and, where the change requires a fresh expression of consent, the banner reappearing on the next visit.
Previous versions are kept by the Controller: you can request a copy of the version in force on a given date by writing to privacy@migamatch.com.