Roundabout platform · Version 1.0 · effective from 21/09/2026
This notice explains how Roundabout S.r.l. processes the personal data of people who register for and use the Roundabout platform, under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).
The controller is Roundabout S.r.l., registered office at Corso Castelfidardo 30/a, 10129 Turin, Italy, VAT no. 12027720015.
For any request concerning your data, including the rights described in section 9, write to [email protected].
It applies to:
The platform also analyses public creator profiles on Instagram, TikTok and YouTube. That processing is described in a separate notice.
The platform is a professional service for businesses and professionals. It is not intended for consumers or for anyone under 18.
| Category | Data | Where it comes from |
|---|---|---|
| Account | email, name, role, company, company website, language, notification preferences, the workspaces and brands you have access to | from you, at registration and in settings |
| Authentication | email, user identifier, credentials and sign-in times, handled by Firebase Authentication (Google). Roundabout does not store your password | Firebase |
| Invoicing | company name, address, VAT number, SDI code or certified email | from you or your business contact |
| Payment | customer and subscription identifiers in Stripe. We neither see nor store card details: Stripe handles them | Stripe |
| Usage | usage counters, cost logs, notifications, a record of significant actions (audit log) | generated by the platform as you use it |
| Content you enter | campaign briefs, quotes, campaigns, approvals, comments, notes | from you |
| Integrations you enable | your brand’s Google Analytics 4 property ID and the aggregated traffic data read from it; the screenshots held in the Google Drive folders shared with us | from the services you connect |
| Commercial demos | name, role, company and a transcript of what was said during the demo, to derive needs and next steps | from the demo recording, which participants are told about at the start |
How the Google integrations work. We do not ask you to sign in with your Google account and we do not store personal tokens. You grant read-only access to a service account of ours. From Google Analytics 4 we read only aggregated data, never data about individual visitors to your site, and we install no code on your site.
We do not process special categories of data (Article 9 GDPR). Please do not enter any in free-text fields.
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Creating and managing your account, signing you in, providing the platform’s features | performance of a contract — (b) |
| Processing briefs and content with artificial intelligence tools, as a feature of the service | performance of a contract — (b) |
| Reading data from the integrations you enable (Google Analytics 4, Google Drive) | performance of a contract — (b) |
| Managing subscriptions and payments | performance of a contract — (b) |
| Issuing invoices and keeping accounting and tax records | legal obligation — (c) |
| Service communications (team invitations, notifications, email verification) | performance of a contract — (b) |
| Security, abuse prevention, the record of significant actions | legitimate interest in protecting the platform and its customers — (f) |
| Defending against claims | legitimate interest — (f) |
| Sending you the newsletter and updates about Roundabout’s news and services | consent, optional and withdrawable at any time — (a). For existing customers, for services similar to those purchased: legitimate interest, Article 130(4) of the Italian Privacy Code — (f) |
| Analysing commercial demos to prepare proposals suited to the prospective customer’s needs | pre-contractual measures taken at the data subject’s request — (b); for other participants, legitimate interest — (f) |
Consent to the newsletter is given through an unticked box at registration and is not required to use the platform. Every email contains an unsubscribe link.
If you do not provide account and invoicing data we cannot activate the service.
The platform does not take decisions based solely on automated processing that produce legal effects concerning you, or similarly significantly affect you as a user (Article 22 GDPR). In particular, prices, quotes and forecasts are calculated by rules defined by Roundabout, not generated by artificial intelligence models.
For some data Roundabout does not decide the purposes and means: it follows the customer’s instructions. This is the case for third-party data that the customer enters into the platform, for example the names of its own contacts or collaborators.
For that data the customer is the controller and Roundabout acts as processor (Article 28 GDPR). The relationship is governed by the Data Processing Agreement (DPA), which forms part of the Terms of Service. Anyone affected by that data may contact the customer or us, and we will forward the request.
We do not sell personal data. We share it only with the suppliers needed to run the service, appointed as processors, or with parties acting as independent controllers.
| Supplier | For what | Data involved | Where processed | Role |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg, Italian branch in Milan) | database, file storage, sending service emails | all platform data | Italy — AWS Milan region | processor |
| Google Ireland Limited — Firebase Authentication | sign-in and authentication | email, user identifier, credentials, sign-in times | United States | processor |
| OpenAI Ireland Limited | text analysis and generation, via API | brief texts, company websites, content entered | including outside the EU, the United States among them | processor |
| Anthropic, PBC (United States) | text analysis, via API | commercial demo transcripts. Receives neither account nor invoicing data | United States | processor |
| Stripe Payments Europe, Limited (Italian branch, Milan) | payments and subscriptions | invoicing and payment data | EU | independent controller for payment data |
| Google (Analytics 4, Drive) | only if you enable these integrations | aggregated traffic data, screenshots in shared folders | EU and United States | processor on your behalf |
Data we send to OpenAI through the API is not used to train their models and is retained by OpenAI for a maximum of 30 days for abuse monitoring.
Apify, the supplier we use to collect public data from social networks, does not process platform users’ data: it is described in the creator notice.
We may also share data with advisers (accountants, lawyers) bound by confidentiality, and with authorities where the law requires it.
Platform data is stored in Italy. Three suppliers also process it outside the European Economic Area:
You can request a copy of the safeguards by writing to [email protected].
We keep data for as long as is necessary for the purposes for which we collect it, according to these criteria:
| Data | For how long |
|---|---|
| Account data | for the duration of the relationship; if you delete your account it is anonymised immediately (section 9) |
| Quotes, campaigns and content entered | for the duration of the relationship and for as long as is needed to respond to any claims |
| Screenshots and insights read from Google Drive | for the duration of the campaign and as long as needed for subsequent reports |
| Notifications | for as long as needed for the purpose for which they were sent |
| Usage cost logs | 30 days |
| Commercial demo transcripts | for as long as needed to assess and prepare the commercial proposal |
| Invoices and accounting records | 10 years, as required by Article 2220 of the Italian Civil Code |
| The archive of your data generated on request | 7 days, after which it can no longer be downloaded |
| Record of significant actions (audit log) | for as long as needed for security purposes and to demonstrate compliance with legal obligations |
| Data needed to defend against a claim | until it is resolved and for the applicable limitation periods |
| Newsletter subscription | until consent is withdrawn or you unsubscribe |
Platform data is stored in Italy, in the AWS Milan region. Access is enforced server-side: each user sees only the workspaces and brands they have been granted, according to their role. Significant actions are recorded. Authentication is handled by Firebase and payment cards by Stripe.
No system is free of risk. If a data breach affecting you occurs, we handle it as required by Articles 33 and 34 GDPR.
You may ask at any time to:
Downloading your data. From the Account page you can generate an archive of your data at any time: profile, access, notifications and references to the quotes and campaigns you worked on. The archive is ready immediately and remains downloadable for 7 days. The full content of shared documents is not included, because it contains other people’s data and commercial information (Articles 15(4) and 20(4) GDPR). If you need more, write to us.
Deleting your account. From the Account page you can delete your account. Deletion is immediate: access is revoked on all devices, your email address is removed from all our records and from the authentication system, and your identifying data (name, company, role, preferences) is irreversibly anonymised. We keep only a technical identifier, needed so that quotes, campaigns and comments remain coherent for the other people who worked on them (“Removed person” appears in place of your name), and the record that the deletion took place. Invoices remain, as the law requires. If you are the sole owner of a workspace shared with other people, you must first appoint another owner.
After deletion you can register again with the same email address. The new account starts from scratch: data from the previous one cannot be recovered.
Unsubscribing from the newsletter. Use the link in any email or write to us. Unsubscribing does not affect your account.
Entries in the security record written before the deletion keep the email address of whoever performed the actions, for the period given in section 7. They serve to protect the platform and to demonstrate compliance with legal obligations (Article 5(2) GDPR), and for that reason they are not altered.
For all other requests write to [email protected]. We reply within one month, extendable by two further months in complex cases, as Article 12 GDPR provides.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
This section serves as the platform’s cookie policy, at app.roundabout.pro.
| Tool | Type | What it does | Duration |
|---|---|---|---|
| Firebase Authentication (Google) | browser storage, technical | keeping your sign-in session and recognising you from page to page | if you choose “remember me” it lasts until you sign out; otherwise it is cleared when the browser closes |
The platform uses no profiling or advertising cookies and no third-party analytics tools. Strictly necessary technical tools do not require consent (Article 122 of the Italian Privacy Code), which is why we show no banner. If we add different tools in future, we will update this section and ask for consent where needed.
The roundabout.pro marketing site is separate from the platform. As at the date of this version it uses no analytics tools and no advertising tags.
The platform is reserved for professionals and businesses and is not intended for anyone under 18.
We may update this notice when the service or the law changes. Each version carries a number and a date. If the changes are significant, we will tell you by email or in the platform before they take effect.