PICA GROUP S.P.A.

PRIVACY CENTRE - GetPica

The following privacy policies, relating to the services that Pica Group S.p.A. offers its Users, are addressed to two categories of subjects:

1) those who access the Platform (as defined below) by taking a picture of their face through their mobile device (“Selfie”), to (i) retrieve the photographic and/or video materials (“Materials”) that portray them (“End Users”) and, if interested, (ii) purchase them later;

2) parties with agreements with Pica Group S.p.A. who, as part of specific events and/or experiences and/or related to the stay at accommodation/tourism/entertainment facilities organised and/or managed by the same (“Events”), make the Platform available to participants in the Events (“Organiser Users”);

Depending on the category of user You belong to, we invite You to read the privacy policy dedicated to You.

Enjoy the reading!

1) PRIVACY POLICY PURSUANT TO ARTICLE 13 OF THE EU REGULATION 2016/679 – END USERS

Pica Group S.p.A., with registered office in Milan, Via dell’Aprica, 12, 20158, VAT No. 02529950392, in its capacity as Data Controller (“Controller”) hereby provides the privacy policy pursuant to Article 13 of the EU Regulation 2016/679 (“Regulation”) and the applicable privacy legislation in force (collectively, “Applicable Law”), to users browsing the getpica.com website and/or the “PICA” application for devices available on Google Play Store or Apple Store (all, collectively, “Platform”).

For more information on how the Platform works, please refer to the Terms and Conditions, accessible within the Platform.

This privacy policy applies exclusively to the processing of data provided by the User or otherwise collected because of using the Platform. Any websites, applications and web pages of third parties that are not directly related to the processing activities carried out by the Controller are subject to the respective third parties’ privacy processing policies.

1. Data Controller’s contact details

The Controller takes into the utmost account the right to privacy and the protection of its Users’ personal data. For any information related to this privacy policy, the End Users may contact the Controller at any time, using the following methods:

• By sending a registered letter with return receipt to the registered office of the Controller in Milan, Italy, via dell’Aprica, 12, 20158;

• By sending an e-mail to the address: privacy@getpica.com.

End Users may also contact the Data Protection Officer (DPO) of the Controller, whose contact details are as follows: dpo@getpica.com.

2. Processing purposes and the nature of data provision

In relation to the activities that may be carried out through the Platform, the Controller collects personal data of End Users.

The Platform and the services that may be offered through it are reserved to subjects over the age of 18 years old. Hereby, the Controller does not collect personal data pertaining to subjects under the age of 18 years old. At request of the End Users, the Controller will promptly delete all the personal data, involuntary collected, pertaining to subjects under the age of 18 years old.

Personal data are collected directly from the User when the User registers with the Platform. The data collected are those that are strictly necessary to achieve the purposes indicated in the following paragraphs and the End User guarantees that, through the Platform, will only provide personal data (including Selfies) concerning himself.

Particularly, the personal data of the End Users will be lawfully processed by the Controller for the following purposes:

a) contractual obligations and provision of the service, to (i) enable navigation of the Platform or to execute the Terms and Conditions of the Platform, which are accepted by the User upon registration on the Platform and creation of an account (the “Account”) and (ii) fulfil specific requests of the User. The User’s data collected by the Controller for the purposes of any registration on the Platform may include: e-mail address, images and videos, billing information, postal address and telephone number, as well as any personal information of the User that may be voluntarily published through the Platform. Unless the User gives to the Controller a specific and voluntary consent for further processing purposes described in the following paragraphs, the User’s personal data will be used by the Controller for the sole purpose of ascertaining the identity of the User (also by validating the e-mail address), thus avoiding possible fraud or abuse, and contacting the User for service reasons only (e.g. sending notifications regarding the services offered on the Platform). Notwithstanding the provisions elsewhere in this privacy policy, under no circumstances the Controller will make End Users’ personal data accessible to other End Users and/or third parties;

b) administrative and accounting purposes, namely, to carry out activities of an organisational, administrative, financial and accounting nature, such as internal organisational activities and activities functional to the fulfilment of contractual and pre-contractual obligations;

c) legal obligations, namely, to comply with obligations imposed by law, an authority, a regulation or European legislation.

d) use of the facial recognition service and retrieval of the Materials through the Platform (“matching”), the User’s data collected by the Controller for this purpose includes the User’s Selfie and biometric data referable to the User, as defined in Article 4, paragraph 1, no.14 of the Regulation. It should be noted that this service also constitutes a security measure to protect the confidentiality of other End Users of the Platform.

The provision of personal data for the abovementioned processing purposes is optional but necessary, as failure to provide it will result in the User being unable to browse the Platform, register on the Platform and use the services offered by the Controller on the Platform.

Please note that the purchase of photographs portraying the User takes place through Stripe, as autonomous Data Controller, whose Privacy Policy can be found at the following link, and that the User’s credit card details will not be processed by the Controller under any circumstances, nor will be registered on the Platform.

3. Further processing purposes

Marketing (sending advertising material, direct sales and commercial communication)

Some of the User’s personal data (i.e. name, surname and e-mail address) may also be processed by the Controller for marketing purposes (sending advertising material, direct sales and commercial communication), namely so that the Controller can contact the User by e-mail, instant messaging, telephone or ordinary mail, to propose to the User the purchase of products and/or services offered by the Controller itself and/or by third party companies, to present offers, promotions and commercial opportunities.

If consent is not given, the possibility of registering on the Platform will not be affected in any way.

In case of consent, the User may withdraw it at any time by making a request to the Controller in the manner indicated in paragraph 7 below.

The User may also easily object to further promotional e-mail communications by clicking on the appropriate link for the withdrawal of consent, which is in each promotional e-mail. Once consent has been withdrawn, the Controller will send the User an e-mail message confirming that consent has been withdrawn.

The Controller informs that, following the exercise of the right to object to the sending of promotional communications by e-mail, it is possible that, for technical and operational reasons (e.g. formation of contact lists already completed shortly before the receipt by the Controller of the request for objection) the User may continue to receive some further promotional messages. Should the User continue to receive promotional messages after 24 hours have elapsed from the exercise of the right to object, please report the problem to the Controller, using the contact details indicated in paragraph 7 below.

Commercial communication on products and/or services similar to those purchased (so-called soft spam)

To End Users who have purchased products and/or its services, the Controller may send, without requiring their consent, commercial communications, exclusively (i) by e-mail and (ii) in relation to products and/or services similar to those already purchased, namely belonging to the same product category. It will be possible to object at any time, easily and free of charge, to further sending of such communications by means of the automated unsubscribe links in the Controller’s communications, as well as by the ordinary means indicated in paragraph 7 below (in this case this processing purpose will be pursued by the Controller, without the need to obtain the User’s consent, in line with the derogation provided for in Article 130, paragraph 4, of Legislative Decree No. 196/2003, without prejudice to the abovementioned possibility for the User to object easily).

4. Legal Basis

Contractual obligations and provision of the Service (as described in the previous paragraph 2, letter a)): the legal basis is Article 6, paragraph 1, letter b) of the Regulation, as the processing is necessary for the performance of a contract to which the User is party or in order to take measures at the request of the latter prior to entering into a contract.

Administrative and accounting purposes (as described in the previous paragraph. 2, letter b)): the legal basis consists of Article 6, paragraph 1, letter b) of the Regulation, as the processing is necessary for the performance of a contract and/or in order to take measures at the request of the User prior to entering into a contract.

Legal obligations (as described in the previous paragraph 2, letter c)): the legal basis consists of Article 6, paragraph 1, letter c) of the Regulation, as the processing is necessary for compliance with a legal obligation to which the Controller is subject.

To use the facial recognition service and to find personal photos (as described in paragraph. 2, letter. d)): the legal basis is the explicit consent given at the time of uploading the Selfie, in accordance with Article 9, paragraph 2, letter a) of the Regulation. The provision of personal data for this purpose is voluntary. Any refusal to provide such data will make it impossible for the Controller to provide the matching service described in paragraph 2, letter d) to the User.

Further processing purposes: for the processing relating to marketing and soft spam activities (as described in the previous paragraphs 3.1 and 3.2), the legal basis consists in Article 6, paragraph 1, letter a) of the Regulation, namely the provision by the data subject of consent to the processing of his/her personal data for one or more specific purposes. For this reason, the Controller asks the User to provide a specific consent, free and voluntary, in order to pursue such processing purposes (except in the case of the processing described in the previous paragraph 4.2, in which, pursuant to Article 130, paragraph 4 of Legislative Decree No. 196/2003, there is an exemption from the obligation to request consent).

5. Processing methods and data retention period

The Data Controller will process the End Users’ personal data using manual and IT tools, with logic strictly related to the purposes themselves and, in any case, in order to guarantee the security and confidentiality of the data.

With reference to the facial recognition service in order to facilitate the retrieval of its photos, the Controller uses an AI technology with facial recognition.

In particular, the Selfie and the User’s related biometric data, processed for the purposes set out in the previous paragraph 2, letter d) shall be kept only for the time necessary to finalise the delivery of the photos to the participant.

The personal data of the End Users collected for the purposes set out in the previous paragraph 2 shall be kept for as long as the End User keeps his Account active, or in any case (i) as long as necessary for the civil law protection of the interests of both the End Users and the Controller and (ii) for as long as required by the applicable tax, fiscal and civil law.

In the cases referred to in the previous paragraphs 3.1 and 3.2, the End User’s personal data will be kept for the time strictly necessary to fulfil the purposes set out in the same and, in any case:

• for the cases referred to in paragraph 3.1, for the entire duration of the User’s registration on the Platform and, thereafter, up to a maximum of 10 (ten) years, unless consent is renewed;

• for the cases referred to in paragraph 3.2, until the End User opts out.

6. Transmission and dissemination of data

The Users’ personal data may be transferred outside the European Union, and, in this case, the Controller will ensure that the transfer takes place in accordance with the Applicable Law and, in particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision) and 46 (Transfer subject to adequate guarantees) of the Regulation.

The personal data of the End Users may be disclosed to the employees and/or collaborators of the Controller in charge of managing the Platform and the End Users’ requests. These subjects, who have been instructed to do so by the Controller pursuant to Article 29 of the Regulation, will process the End Users’ data exclusively for the purposes indicated in this privacy policy and in compliance with the provisions of the Applicable Law.

Third parties who may process personal data on behalf of the Controller as Data Processors may also become aware of End Users’ personal data, such as, but not limited to, IT and logistics service providers functional to the operation of the Platform, outsourcing or cloud computing service providers, professionals and consultants.

End Users have the right to obtain a list of any Data Processors appointed by the Controller, making a request to the Controller in the manner indicated in paragraph 7 below.

7. Rights of data subjects

Pursuant to the Applicable Law, the Controller informs that the End Users have the right to obtain information on (i) the origin of the personal data; (ii) the purposes and methods of processing; (iii) the logic applied in the case of processing carried out with the aid of electronic instruments; (iv) the identification details of controllers and processors; (v) the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them in their capacity as processors or persons in charge of processing.

Furthermore, End Users have the right to obtain:

a) the access, update, rectification or, where interested therein, integration of the data;

b) the cancellation, transformation into anonymous form or limitation of data processed in violation of the law, including data whose storage is not necessary in relation to the purposes for which the data was collected or subsequently processed;

c) certification that the operations referred to in letters a) and b) have been notified, also as regards their content, to the entities to whom or which the data have been communicated or disseminated, unless this fulfilment is impossible or involves a manifestly disproportionate effort compared with the right protected.

In addition, End Users have:

a) the right to withdraw the consent at any time, if the processing is based on consent;

b) the right (where applicable) to data portability (the right to receive all personal data concerning them in a structured, commonly used and machine-readable format);

c) the right to object:

(i) in whole or in part, for legitimate reasons to the processing of personal data concerning them, even if relevant to the purpose of collection;

(ii) in whole or in part, to the processing of personal data concerning them for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication;

(iii) whether personal data are processed for the purpose of direct marketing, at any time, the processing of their data for that purpose, including profiling insofar as it relates to this direct marketing.

d) if they consider that the processing of their personal data is in violation of the Regulation, the right to lodge a complaint (in the Member State in which they have their habitual residence, in the Member State in which they work or in the Member State in which the alleged breach has occurred). The Italian Supervisory Authority is the Garante per la protezione dei dati personali, located in Piazza Venezia n. 11, 00187 - Rome (RM) (http://www.garanteprivacy.it/).

End Users may exercise their rights granted by the Applicable Law, contacting the Controller with the following methods:

• By sending a registered letter with return receipt to the registered office of the Controller, located in Milan, Italy, – Via dell’Aprica, 12, 20158;

• By sending an e-mail to the following address: privacy@getpica.com.

End Users may also contact the Data Protection Officer (DPO) of the Controller, whose contact details are as follows: dpo@getpica.com.

8. Registration through Social Network

Registration through “Connect with Facebook”

The Controller informs End Users registered with Facebook that they can register to the Platform though “Connect with Facebook” service or its equivalent, where this option is available through the appropriate button. The data that may be communicated by Facebook to the Controller through “Connect with Facebook” service are as follows: first name, last name, profile picture, email address on which the User can be contacted by Facebook (with “real” address or address on the proxymail.facebook.com domain), address and date of birth. The Controller will process this data exclusively for the purposes indicated in this privacy policy, in compliance with the consent given by the User from time to time. By subscribing to the “Connect with Facebook” service and clicking on the “Allow” button, the User agrees to the previous data being transferred from the Facebook platform to the Controller. The Controller will use this data to facilitate the registration process by pre-filling the fields of the User’s registration form with the data communicated by Facebook. The End Users using the Facebook Connect service will be able to access the Platform using the credentials normally used to access Facebook. For further information on the “Connect with Facebook” service and to change your privacy settings for this service, please refer to the following links:

http://www.facebook.com/help/405977429438260/

https://www.facebook.com/about/privacy/your-info-on-other

Registration through “Sign in with Google”

The Controller informs that End Users who have a Google account can register within the Platform through “Sign in with Google” service or equivalent, where this option is available through the appropriate button. The data that may be communicated by Google to the Controller through “Continue with Google” service is as follows: first name, last name, e-mail. The Controller will process this data exclusively for the purposes indicated in this privacy policy, in compliance with the consents that the User decides to express.

By clicking on the “Continue with Google” button followed by the Google logo, the User consents to the transfer of the previous data to the Controller by Google. The Controller will use this data to facilitate the registration process by pre-filling certain fields on the registration form with the data provided by Google.

For further information on the “Continue with Google” service and to change your privacy settings relating to this service, you can consult the following links:

www.google.com/intl/it_ALL/policies/privacy/

https://support.google.com/accounts/answer/112802?hl=it&ref_topic=7188760

Registration through “Sign in with Apple”

The Controller informs that End Users who have an Apple account can register within the Platform through “Sign in with Apple” service or equivalent, in cases where this option is available through the appropriate button. The data that may be communicated by Apple to the Controller through the “Continue with Apple” service is as follows: first name, last name, e-mail. The Controller will process this data exclusively for the purposes indicated in this privacy policy, in compliance with the consents that the User decides to express. By clicking on the “Continue with Apple” button followed by the Apple logo, the User consents to Apple transferring the previous data to the Controller. The Controller will use this data to facilitate the registration process by pre-filling certain fields of the registration form with the data communicated by Apple. For more information about the “Continue with Apple” service and to change your privacy settings related to this service, please refer to the following link:

apple.com/privacy/

9. Amendments to this Privacy Policy concerning the processing of personal data

The Controller reserves the right to make any amendments and updates to this privacy policy regarding the processing of personal data, that are deemed appropriate or required by current legislation, at its sole discretion and at any time. On such occasions, End Users will be duly informed of the changes made.

The Controller is not responsible for updating all the links displayed in this privacy policy. Therefore, whenever a link is not functional and/or updated, End Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by such link.


2) PRIVACY POLICY PURSUANT TO ARTICLE 13 OF THE EU REGULATION 2016/679 – ORGANISER USERS

Pica Group S.p.A., with registered office in Milan, Via dell’Aprica, 12, 20158, VAT No. 02529950392, in its capacity as Data Controller (“Controller”) hereby provides the privacy policy pursuant to Article 13 of the EU Regulation 2016/679 (“Regulation”) and the applicable privacy legislation in force (collectively, “Applicable Law”), to users browsing the getpica.com website and/or the “PICA” application for devices available on Google Play Store or Apple Store (all, collectively, “Platform”).

For more information on how the Platform works, please refer to the Terms and Conditions, accessible within the Platform.

This privacy policy applies exclusively to the processing of data provided by the User or otherwise collected because of using the Platform. Any websites, applications and web pages of third parties that are not directly related to the processing activities carried out by the Controller are subject to the respective third parties’ privacy processing policies.

1. Data Controller’s contact details

The Controller takes into the utmost account the right to privacy and the protection of its Users’ personal data. For any information related to this privacy policy, the Organiser Users may contact the Controller at any time, using the following methods:

• By sending a registered letter with return receipt to the registered office of the Controller in Milan, Italy, via dell’Aprica, 12, 20158;

• By sending an e-mail to the address: privacy@getpica.com.

Organiser Users may also contact the Data Protection Officer (DPO) of the Controller, whose contact details are as follows: dpo@getpica.com.

2. Processing purposes and the nature of data provision

In relation to the activities that may be carried out through the Platform, the Controller collects personal data of Organiser Users.

The Platform and the services that may be offered through it are reserved to subjects over the age of 18 years old. Hereby, the Controller does not collect personal data pertaining to subjects under the age of 18 years old. At request of the Organiser Users, the Controller will promptly delete all the personal data, involuntary collected, pertaining to subjects under the age of 18 years old.

Personal data are collected directly from the User when the User registers with the Platform. The data collected are those that are strictly necessary to achieve the purposes indicated in the following paragraphs and the User guarantees that, through the Platform, will only provide personal data concerning himself.

Particularly, the personal data of the Organisers Users will be lawfully processed by the Controller for the following purposes:

a) contractual obligations and provision of the service, to (i) enable navigation of the Platform or to execute the Terms and Conditions of the Platform, which are accepted by the User upon registration on the Platform and creation of an account (the “Account”) and (ii) fulfil specific requests of the User. The User’s data collected by the Controller for the purposes of any registration on the Platform includes: e-mail address, billing information, postal address and telephone number, as well as any personal information of the User that may be voluntarily published through the Platform. Unless the User gives to the Controller a specific and voluntary consent for further processing purposes described in the following paragraphs, the User’s personal data will be used by the Controller for the sole purpose of ascertaining the identity of the User (also by validating the e-mail address), thus avoiding possible fraud or abuse, and contacting the User for service reasons only (e.g. sending notifications regarding the services offered on the Platform). Notwithstanding the provisions elsewhere in this privacy policy, under no circumstances the Controller will make Organiser Users’ personal data accessible to other Organiser Users and/or third parties;

b) administrative and accounting purposes, namely, to carry out activities of an organisational, administrative, financial and accounting nature, such as internal organisational activities and activities functional to the fulfilment of contractual and pre-contractual obligations;

c) legal obligations, namely, to comply with obligations imposed by law, an authority, a regulation or European legislation.

The provision of personal data for the abovementioned processing purposes is optional but necessary, as failure to provide it will result in the User being unable to browse the Platform, register on the Platform and use the services offered by the Controller on the Platform.

3. Further processing purposes

Marketing (sending advertising material, direct sales and commercial communication)

Some of the User’s personal data (i.e. name, surname and e-mail address) may also be processed by the Controller for marketing purposes (sending advertising material, direct sales and commercial communication), namely so that the Controller can contact the User by e-mail, instant messaging, telephone or ordinary mail, to propose to the User the purchase of products and/or services offered by the Controller itself and/or by third party companies, to present offers, promotions and commercial opportunities.

If consent is not given, the possibility of registering on the Platform will not be affected in any way.

In case of consent, the User may withdraw it at any time by making a request to the Controller in the manner indicated in paragraph 7 below.

The User may also easily object to further promotional e-mail communications by clicking on the appropriate link for the withdrawal of consent, which is in each promotional e-mail. Once consent has been withdrawn, the Controller will send the User an e-mail message confirming that consent has been withdrawn.

The Controller informs that, following the exercise of the right to object to the sending of promotional communications by e-mail, it is possible that, for technical and operational reasons (e.g. formation of contact lists already completed shortly before the receipt by the Controller of the request for objection) the User may continue to receive some further promotional messages. Should the User continue to receive promotional messages after 24 hours have elapsed from the exercise of the right to object, please report the problem to the Controller, using the contact details indicated in paragraph 7 below.

Commercial communication on products and/or services similar to those purchased (so-called soft spam)

To Organiser Users who have purchased products and/or its services, the Controller may send, without requiring their consent, commercial communications, exclusively (i) by e-mail and (ii) in relation to products and/or services similar to those already purchased, namely belonging to the same product category. It will be possible to object at any time, easily and free of charge, to further sending of such communications by means of the automated unsubscribe links in the Controller’s communications, as well as by the ordinary means indicated in paragraph 7 below (in this case this processing purpose will be pursued by the Controller, without the need to obtain the User’s consent, in line with the derogation provided for in Article 130, paragraph 4, of Legislative Decree No. 196/2003, without prejudice to the abovementioned possibility for the User to object easily).

4. Legal Basis

Contractual obligations and provision of the Service (as described in the previous paragraph 2, letter a)): the legal basis is Article 6, paragraph 1, letter b) of the Regulation, as the processing is necessary for the performance of a contract to which the User is party or in order to take measures at the request of the latter prior to entering into a contract.

Administrative and accounting purposes (as described in the previous paragraph. 2, letter b)): the legal basis consists of Article 6, paragraph 1, letter b) of the Regulation, as the processing is necessary for the performance of a contract and/or in order to take measures at the request of the User prior to entering into a contract.

Legal obligations (as described in the previous paragraph 2, letter c)): the legal basis consists of Article 6, paragraph 1, letter c) of the Regulation, as the processing is necessary for compliance with a legal obligation to which the Controller is subject.

Further processing purposes: for the processing relating to marketing and soft spam activities (as described in the previous paragraphs 3.1 and 3.2), the legal basis consists in Article 6, paragraph 1, letter a) of the Regulation, namely the provision by the data subject of consent to the processing of his/her personal data for one or more specific purposes. For this reason, the Controller asks the User to provide a specific consent, free and voluntary, in order to pursue such processing purposes (except in the case of the processing described in the previous paragraph 4.2, in which, pursuant to Article 130, paragraph 4 of Legislative Decree No. 196/2003, there is an exemption from the obligation to request consent).

5. Processing methods and data retention period

The Controller will process the Organiser Users’ personal data using manual and IT tools, with logic strictly related to the purposes themselves and, in any case, in order to guarantee the security and confidentiality of the data.

The personal data of the Organiser Users collected for the purposes set out in the previous paragraph 2 shall be kept for as long as the Organiser User keeps his Account active, or in any case (i) as long as necessary for the civil law protection of the interests of both the Organisers Users and the Controller and (ii) for as long as required by the applicable tax, fiscal and civil law.

In the cases referred to in the previous paragraphs 3.1 and 3.2, the Organiser User’s personal data will be kept for the time strictly necessary to fulfil the purposes set out in the same and, in any case:

• for the cases referred to in paragraph 3.1, for the entire duration of the User’s registration on the Platform and, thereafter, up to a maximum of 10 (ten) years, unless consent is renewed;

• for the cases referred to in paragraph 3.2, until the Organiser User opts out.

6. Transmission and dissemination of data

The Users’ personal data may be transferred outside the European Union, and, in this case, the Controller will ensure that the transfer takes place in accordance with the Applicable Law and, in particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision) and 46 (Transfer subject to adequate guarantees) of the Regulation.

The personal data of the Organiser Users may be disclosed to the employees and/or collaborators of the Controller in charge of managing the Platform and the Organiser Users’ requests. These subjects, who have been instructed to do so by the Controller pursuant to Article 29 of the Regulation, will process the Organiser Users’ data exclusively for the purposes indicated in this privacy policy and in compliance with the provisions of the Applicable Law.

Third parties who may process personal data on behalf of the Controller as Data Processors may also become aware of Organiser Users’ personal data, such as, but not limited to, IT and logistics service providers functional to the operation of the Platform, outsourcing or cloud computing service providers, professionals and consultants.

Organiser Users have the right to obtain a list of any Data Processors appointed by the Controller, making a request to the Controller in the manner indicated in paragraph 7 below.

7. Rights of data subjects

Pursuant to the Applicable Law, the Controller informs that the Organiser Users have the right to obtain information on (i) the origin of the personal data; (ii) the purposes and methods of processing; (iii) the logic applied in the case of processing carried out with the aid of electronic instruments; (iv) the identification details of controllers and processors; (v) the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them in their capacity as processors or persons in charge of processing.

Furthermore, Organiser Users have the right to obtain:

a) the access, update, rectification or, where interested therein, integration of the data;

b) the cancellation, transformation into anonymous form or limitation of data processed in violation of the law, including data whose storage is not necessary in relation to the purposes for which the data was collected or subsequently processed;

c) certification that the operations referred to in letters a) and b) have been notified, also as regards their content, to the entities to whom or which the data have been communicated or disseminated, unless this fulfilment is impossible or involves a manifestly disproportionate effort compared with the right protected.

In addition, Organiser Users have:

a) the right to withdraw the consent at any time, if the processing is based on consent;

b) the right (where applicable) to data portability (the right to receive all personal data concerning them in a structured, commonly used and machine-readable format);

c) the right to object:

(i) in whole or in part, for legitimate reasons to the processing of personal data concerning them, even if relevant to the purpose of collection;

(ii) in whole or in part, to the processing of personal data concerning them for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication;

(iii) whether personal data are processed for the purpose of direct marketing, at any time, the processing of their data for that purpose, including profiling insofar as it relates to this direct marketing.

d) if they consider that the processing of their personal data is in violation of the Regulation, the right to lodge a complaint (in the Member State in which they have their habitual residence, in the Member State in which they work or in the Member State in which the alleged breach has occurred). The Italian Supervisory Authority is the Garante per la protezione dei dati personali, located in Piazza Venezia n. 11, 00187 - Rome (RM) (http://www.garanteprivacy.it/).

Organiser Users may exercise their rights granted by the Applicable Law, contacting the Controller with the following methods:

• By sending a registered letter with return receipt to the registered office of the Controller, located in Milan, Italy, – Via dell’Aprica, 12, 20158;

• By sending an e-mail to the following address: privacy@getpica.com.

Organiser Users may also contact the Data Protection Officer (DPO) of the Controller, whose contact details are as follows: dpo@getpica.com.

8. Registration through Social Network

Registration through “Connect with Facebook”

The Controller informs Organiser Users registered with Facebook that they can register to the Platform though “Connect with Facebook” service or its equivalent, where this option is available through the appropriate button. The data that may be communicated by Facebook to the Controller through “Connect with Facebook” service are as follows: first name, last name, profile picture, email address on which the User can be contacted by Facebook (with “real” address or address on the proxymail.facebook.com domain), address and date of birth. The Controller will process this data exclusively for the purposes indicated in this privacy policy, in compliance with the consent given by the User from time to time. By subscribing to the “Connect with Facebook” service and clicking on the “Allow” button, the User agrees to the previous data being transferred from the Facebook platform to the Controller. The Controller will use this data to facilitate the registration process by pre-filling the fields of the User’s registration form with the data communicated by Facebook. The Organiser Users using the Facebook Connect service will be able to access the Platform using the credentials normally used to access Facebook. For further information on the “Connect with Facebook” service and to change your privacy settings for this service, please refer to the following links:

http://www.facebook.com/help/405977429438260/

https://www.facebook.com/about/privacy/your-info-on-other

Registration through “Sign in with Google”

The Controller informs that Organiser Users who have a Google account can register within the Platform through “Sign in with Google” service or equivalent, where this option is available through the appropriate button. The data that may be communicated by Google to the Controller through “Continue with Google” service is as follows: first name, last name, e-mail. The Controller will process this data exclusively for the purposes indicated in this privacy policy, in compliance with the consents that the User decides to express.

By clicking on the “Continue with Google” button followed by the Google logo, the User consents to the transfer of the previous data to the Controller by Google. The Controller will use this data to facilitate the registration process by pre-filling certain fields on the registration form with the data provided by Google.

For further information on the “Continue with Google” service and to change your privacy settings relating to this service, you can consult the following links:

www.google.com/intl/it_ALL/policies/privacy/

https://support.google.com/accounts/answer/112802?hl=it&ref_topic=7188760

Registration through “Sign in with Apple”

The Controller informs that Organiser Users who have an Apple account can register within the Platform through “Sign in with Apple” service or equivalent, in cases where this option is available through the appropriate button. The data that may be communicated by Apple to the Controller through the “Continue with Apple” service is as follows: first name, last name, e-mail. The Controller will process this data exclusively for the purposes indicated in this privacy policy, in compliance with the consents that the User decides to express. By clicking on the “Continue with Apple” button followed by the Apple logo, the User consents to Apple transferring the previous data to the Controller. The Controller will use this data to facilitate the registration process by pre-filling certain fields of the registration form with the data communicated by Apple. For more information about the “Continue with Apple” service and to change your privacy settings related to this service, please refer to the following link:

apple.com/privacy/

9. Amendments to this Privacy Policy concerning the processing of personal data

The Controller reserves the right to make any amendments and updates to this privacy policy regarding the processing of personal data, that are deemed appropriate or required by current legislation, at its sole discretion and at any time. On such occasions, Organiser Users will be duly informed of the changes made.

The Controller is not responsible for updating all the links displayed in this privacy policy. Therefore, whenever a link is not functional and/or updated, Organiser Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by such link.