Privacy Notice

Roundabout platform · Version 1.0 · effective from 21/09/2026

This notice explains how Roundabout S.r.l. processes the personal data of people who register for and use the Roundabout platform, under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).

1. Data controller

The controller is Roundabout S.r.l., registered office at Corso Castelfidardo 30/a, 10129 Turin, Italy, VAT no. 12027720015.

For any request concerning your data, including the rights described in section 9, write to [email protected].

2. Who this notice applies to

It applies to:

The platform also analyses public creator profiles on Instagram, TikTok and YouTube. That processing is described in a separate notice.

The platform is a professional service for businesses and professionals. It is not intended for consumers or for anyone under 18.

3. What data we process

CategoryDataWhere it comes from
Accountemail, name, role, company, company website, language, notification preferences, the workspaces and brands you have access tofrom you, at registration and in settings
Authenticationemail, user identifier, credentials and sign-in times, handled by Firebase Authentication (Google). Roundabout does not store your passwordFirebase
Invoicingcompany name, address, VAT number, SDI code or certified emailfrom you or your business contact
Paymentcustomer and subscription identifiers in Stripe. We neither see nor store card details: Stripe handles themStripe
Usageusage counters, cost logs, notifications, a record of significant actions (audit log)generated by the platform as you use it
Content you entercampaign briefs, quotes, campaigns, approvals, comments, notesfrom you
Integrations you enableyour brand’s Google Analytics 4 property ID and the aggregated traffic data read from it; the screenshots held in the Google Drive folders shared with usfrom the services you connect
Commercial demosname, role, company and a transcript of what was said during the demo, to derive needs and next stepsfrom the demo recording, which participants are told about at the start

How the Google integrations work. We do not ask you to sign in with your Google account and we do not store personal tokens. You grant read-only access to a service account of ours. From Google Analytics 4 we read only aggregated data, never data about individual visitors to your site, and we install no code on your site.

We do not process special categories of data (Article 9 GDPR). Please do not enter any in free-text fields.

4. Why we process data, and on what legal basis

PurposeLegal basis (Article 6 GDPR)
Creating and managing your account, signing you in, providing the platform’s featuresperformance of a contract — (b)
Processing briefs and content with artificial intelligence tools, as a feature of the serviceperformance of a contract — (b)
Reading data from the integrations you enable (Google Analytics 4, Google Drive)performance of a contract — (b)
Managing subscriptions and paymentsperformance of a contract — (b)
Issuing invoices and keeping accounting and tax recordslegal obligation — (c)
Service communications (team invitations, notifications, email verification)performance of a contract — (b)
Security, abuse prevention, the record of significant actionslegitimate interest in protecting the platform and its customers — (f)
Defending against claimslegitimate interest — (f)
Sending you the newsletter and updates about Roundabout’s news and servicesconsent, optional and withdrawable at any time — (a). For existing customers, for services similar to those purchased: legitimate interest, Article 130(4) of the Italian Privacy Code — (f)
Analysing commercial demos to prepare proposals suited to the prospective customer’s needspre-contractual measures taken at the data subject’s request — (b); for other participants, legitimate interest — (f)

Consent to the newsletter is given through an unticked box at registration and is not required to use the platform. Every email contains an unsubscribe link.

If you do not provide account and invoicing data we cannot activate the service.

The platform does not take decisions based solely on automated processing that produce legal effects concerning you, or similarly significantly affect you as a user (Article 22 GDPR). In particular, prices, quotes and forecasts are calculated by rules defined by Roundabout, not generated by artificial intelligence models.

5. When we process data on the customer’s behalf

For some data Roundabout does not decide the purposes and means: it follows the customer’s instructions. This is the case for third-party data that the customer enters into the platform, for example the names of its own contacts or collaborators.

For that data the customer is the controller and Roundabout acts as processor (Article 28 GDPR). The relationship is governed by the Data Processing Agreement (DPA), which forms part of the Terms of Service. Anyone affected by that data may contact the customer or us, and we will forward the request.

6. Who we share data with

We do not sell personal data. We share it only with the suppliers needed to run the service, appointed as processors, or with parties acting as independent controllers.

SupplierFor whatData involvedWhere processedRole
Amazon Web Services EMEA SARL (Luxembourg, Italian branch in Milan)database, file storage, sending service emailsall platform dataItaly — AWS Milan regionprocessor
Google Ireland Limited — Firebase Authenticationsign-in and authenticationemail, user identifier, credentials, sign-in timesUnited Statesprocessor
OpenAI Ireland Limitedtext analysis and generation, via APIbrief texts, company websites, content enteredincluding outside the EU, the United States among themprocessor
Anthropic, PBC (United States)text analysis, via APIcommercial demo transcripts. Receives neither account nor invoicing dataUnited Statesprocessor
Stripe Payments Europe, Limited (Italian branch, Milan)payments and subscriptionsinvoicing and payment dataEUindependent controller for payment data
Google (Analytics 4, Drive)only if you enable these integrationsaggregated traffic data, screenshots in shared foldersEU and United Statesprocessor on your behalf

Data we send to OpenAI through the API is not used to train their models and is retained by OpenAI for a maximum of 30 days for abuse monitoring.

Apify, the supplier we use to collect public data from social networks, does not process platform users’ data: it is described in the creator notice.

We may also share data with advisers (accountants, lawyers) bound by confidentiality, and with authorities where the law requires it.

Transfers outside the European Economic Area

Platform data is stored in Italy. Three suppliers also process it outside the European Economic Area:

You can request a copy of the safeguards by writing to [email protected].

7. How long we keep data

We keep data for as long as is necessary for the purposes for which we collect it, according to these criteria:

DataFor how long
Account datafor the duration of the relationship; if you delete your account it is anonymised immediately (section 9)
Quotes, campaigns and content enteredfor the duration of the relationship and for as long as is needed to respond to any claims
Screenshots and insights read from Google Drivefor the duration of the campaign and as long as needed for subsequent reports
Notificationsfor as long as needed for the purpose for which they were sent
Usage cost logs30 days
Commercial demo transcriptsfor as long as needed to assess and prepare the commercial proposal
Invoices and accounting records10 years, as required by Article 2220 of the Italian Civil Code
The archive of your data generated on request7 days, after which it can no longer be downloaded
Record of significant actions (audit log)for as long as needed for security purposes and to demonstrate compliance with legal obligations
Data needed to defend against a claimuntil it is resolved and for the applicable limitation periods
Newsletter subscriptionuntil consent is withdrawn or you unsubscribe

8. Security

Platform data is stored in Italy, in the AWS Milan region. Access is enforced server-side: each user sees only the workspaces and brands they have been granted, according to their role. Significant actions are recorded. Authentication is handled by Firebase and payment cards by Stripe.

No system is free of risk. If a data breach affecting you occurs, we handle it as required by Articles 33 and 34 GDPR.

9. Your rights

You may ask at any time to:

Downloading your data. From the Account page you can generate an archive of your data at any time: profile, access, notifications and references to the quotes and campaigns you worked on. The archive is ready immediately and remains downloadable for 7 days. The full content of shared documents is not included, because it contains other people’s data and commercial information (Articles 15(4) and 20(4) GDPR). If you need more, write to us.

Deleting your account. From the Account page you can delete your account. Deletion is immediate: access is revoked on all devices, your email address is removed from all our records and from the authentication system, and your identifying data (name, company, role, preferences) is irreversibly anonymised. We keep only a technical identifier, needed so that quotes, campaigns and comments remain coherent for the other people who worked on them (“Removed person” appears in place of your name), and the record that the deletion took place. Invoices remain, as the law requires. If you are the sole owner of a workspace shared with other people, you must first appoint another owner.

After deletion you can register again with the same email address. The new account starts from scratch: data from the previous one cannot be recovered.

Unsubscribing from the newsletter. Use the link in any email or write to us. Unsubscribing does not affect your account.

Entries in the security record written before the deletion keep the email address of whoever performed the actions, for the period given in section 7. They serve to protect the platform and to demonstrate compliance with legal obligations (Article 5(2) GDPR), and for that reason they are not altered.

For all other requests write to [email protected]. We reply within one month, extendable by two further months in complex cases, as Article 12 GDPR provides.

You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

10. Cookies and tracking tools

This section serves as the platform’s cookie policy, at app.roundabout.pro.

ToolTypeWhat it doesDuration
Firebase Authentication (Google)browser storage, technicalkeeping your sign-in session and recognising you from page to pageif you choose “remember me” it lasts until you sign out; otherwise it is cleared when the browser closes

The platform uses no profiling or advertising cookies and no third-party analytics tools. Strictly necessary technical tools do not require consent (Article 122 of the Italian Privacy Code), which is why we show no banner. If we add different tools in future, we will update this section and ask for consent where needed.

The roundabout.pro marketing site is separate from the platform. As at the date of this version it uses no analytics tools and no advertising tags.

11. Minors

The platform is reserved for professionals and businesses and is not intended for anyone under 18.

12. Changes to this notice

We may update this notice when the service or the law changes. Each version carries a number and a date. If the changes are significant, we will tell you by email or in the platform before they take effect.