MyBoletus
EN IT
Your data

Privacy Policy.

Notice on the processing of personal data pursuant to Art. 13 of EU Regulation 2016/679 (GDPR).

1. Data controller

MyBoletus.com, registered address: Via Vivaldi 5, Genova, Italy. Email: [email protected]

2. Data we collect

We collect the following personal data:

  • Registration data: name, surname, email address, password (encrypted);
  • GPS location data: only with explicit prior consent, to personalise predictive maps;
  • Browsing data: IP address, browser type, pages visited, access times (collected automatically);
  • App usage data: map interactions, reports and sightings submitted by the user.

3. Purposes of processing

Data is processed for the following purposes:

  • Service delivery: creating and managing user accounts, generating personalised predictive maps;
  • Service improvement: aggregate and anonymous analysis of usage patterns to improve predictive algorithms;
  • Service communications: technical notifications, account updates, optional newsletters (only with separate consent).

4. Legal basis for processing

Processing is based on the following legal grounds:

  • Registration data: performance of a contract (Art. 6(1)(b) GDPR);
  • Location data: explicit user consent (Art. 6(1)(a) GDPR);
  • Browsing and analytics data: legitimate interest in service improvement (Art. 6(1)(f) GDPR).

5. Data retention

Data is retained for the following periods:

  • Account data: for the duration of the contractual relationship and up to 12 months after account deletion;
  • Location data: 24 months, unless the user chooses otherwise;
  • Navigation logs: 90 days;
  • Aggregated and anonymised analytics data: retained indefinitely.

6. Sharing with third parties

Personal data is NOT sold, transferred or shared with third parties for commercial or advertising purposes. Data may be shared exclusively with technical service providers (hosting, cloud) bound by GDPR-compliant data processing agreements, with analytics services in aggregate and anonymised form only, and with competent authorities where required by law. No personal data is transferred outside the European Economic Area, except to countries with an adequate decision by the European Commission.

7. Your rights

You have the right to:

  • Access your personal data (Art. 15 GDPR);
  • Rectify inaccurate data (Art. 16 GDPR);
  • Request erasure of your data — right to be forgotten (Art. 17 GDPR);
  • Request restriction of processing (Art. 18 GDPR);
  • Receive your data in a portable format (Art. 20 GDPR);
  • Object to processing (Art. 21 GDPR);
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

8. How to exercise your rights

To exercise your rights, write to us at: [email protected]

9. Right to lodge a complaint

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali — www.garanteprivacy.it) if you believe the processing of your data infringes the GDPR. We will respond to your requests within 30 days of receipt.

10. Cookies

We use technical cookies required for the site to function. For further details, see the Cookie Policy.

11. Updates to this notice

This notice may be updated from time to time. We will notify you of any significant changes via email or a prominent notice on the site. The date of the last revision is shown below.

Last updated: June 4, 2026