Document version 2026-07-24

Privacy Policy

This Policy explains how personal data are collected, used, protected and retained when individuals visit or use JoinIOI.

Data controller

Gama group SRL · VAT No. IT04818360408 · Province of Rimini, Italy · support@joinioi.com

1. Data Controller

The controller responsible for the processing of personal data through JoinIOI is Gama group SRL, VAT No. IT04818360408, Province of Rimini, Italy.

Questions, privacy requests and communications concerning personal data may be sent to support@joinioi.com.

2. Scope of This Privacy Policy

This Privacy Policy applies to visitors, registered members, invited members, staff applicants and other individuals who interact with JoinIOI through its website, registration procedures, protected communication tools, publication services, payment functions and support channels.

External services and websites linked from JoinIOI may operate under their own privacy policies and are responsible for their own processing activities.

3. Personal Data We May Process

The categories of personal data processed depend on how a person uses the platform.

  • Identity and profile information, such as name, surname, company name, country, city and account type.
  • Contact information, including email address and information voluntarily submitted through Contact or Support forms.
  • Account and authentication information, including password hashes, verification status, account identifiers and security records.
  • Publication information, images, documents, commercial proposals and other material submitted by members.
  • Protected communication records, investor requests, permissions, support tickets and related action history.
  • Payment and invoice information required to administer publication and visibility services. Payment card or account credentials may be processed directly by the relevant payment provider.
  • Technical and security information, such as user agent, timestamps, authentication events and protected hashes derived from IP addresses.
  • Consent and acceptance records, including document version, date, time and technical evidence associated with the acceptance.

4. Purposes of Processing

Personal data may be processed for the following purposes:

  • Creating, verifying, reviewing and administering user accounts.
  • Providing publication, visibility, discovery and protected-contact services.
  • Reviewing publications, documents, member requests and potential platform violations.
  • Enabling protected communication between members.
  • Processing publication-plan payments, payment authorisations, refunds and invoices.
  • Responding to Contact requests, Support tickets, complaints and administrative questions.
  • Sending operational messages concerning verification, approval, security, publications, payments and account activity.
  • Protecting users, preventing fraud, enforcing platform rules and maintaining audit evidence.
  • Complying with legal, accounting, tax, regulatory and dispute-resolution obligations.
  • Improving the reliability, accessibility and security of JoinIOI.

5. Legal Bases

Depending on the activity, JoinIOI processes personal data on one or more of the following legal bases:

  • Performance of a contract or steps requested before entering into a contract, including registration, publication services, support and payment administration.
  • Compliance with legal obligations applicable to Gama group SRL.
  • Legitimate interests in operating and securing the platform, preventing misuse, maintaining historical evidence, responding to requests and protecting legal rights.
  • Consent where JoinIOI specifically requests optional consent for a particular processing activity. Consent may be withdrawn at any time without affecting earlier lawful processing.

6. Required and Optional Information

Fields marked as required are necessary to provide the requested service, evaluate an account or publication, respond to a request, or comply with security and legal requirements.

Optional fields may be left blank. Failure to provide required information may prevent JoinIOI from creating an account, processing a publication, completing a payment-related procedure or responding effectively to a request.

7. Contact and Support Requests

Information submitted through the public Contact form is used to record, review and respond to the request. Each request receives a unique reference number.

For abuse prevention, JoinIOI may store a protected one-way hash derived from the sender's IP address rather than the plain IP address, together with limited browser information and submission timestamps.

Registered members should use the protected Support module when they need the request and its history to remain connected to their verified account.

8. Recipients and Service Providers

Personal data may be accessed only by authorised JoinIOI personnel and by service providers that support platform operation, hosting, email delivery, authentication, security, payment processing, accounting or technical maintenance.

Information may also be disclosed to professional advisers, competent authorities, courts or other parties where required by law or reasonably necessary to establish, exercise or defend legal rights.

JoinIOI does not sell personal data to advertisers.

9. International Data Transfers

Some technical or payment providers may process information outside the country in which the user is located.

Where personal data are transferred outside the European Economic Area, JoinIOI will rely on an applicable legal transfer mechanism, such as an adequacy decision, contractual safeguards or another mechanism permitted by data-protection law.

10. Data Retention

Personal data are retained for the period necessary to provide the relevant service, fulfil the purposes described in this Policy and comply with legal, tax, accounting, security and dispute-related obligations.

Public Contact requests are ordinarily retained for up to 24 months after they are resolved, unless a longer period is reasonably required for security, legal claims or regulatory compliance.

Account, consent, publication, payment, protected communication and audit records may be retained for extended periods where necessary to preserve platform integrity, document accepted rules, investigate misuse, resolve disputes or protect legal rights.

Certain historical records are designed to be immutable. Restriction, anonymisation or access limitation may be used where deletion would conflict with legitimate legal, security or evidentiary requirements.

11. Security

JoinIOI applies technical and organisational measures intended to protect personal data against unauthorised access, alteration, loss, misuse and disclosure.

These measures include access controls, password hashing, account verification, protected communication, administrative review, security logging, restricted document access and historical action records.

No internet-based service can guarantee absolute security. Users must protect their passwords, devices and account access.

12. User Rights

Subject to the conditions and limitations established by applicable law, individuals may request:

  • Confirmation of whether their personal data are being processed and access to those data.
  • Correction of inaccurate or incomplete personal data.
  • Deletion of personal data where the legal conditions for erasure are satisfied.
  • Restriction of processing in applicable circumstances.
  • Objection to processing based on legitimate interests.
  • Portability of data where the processing is based on consent or contract and carried out by automated means.
  • Withdrawal of consent where processing relies on consent.
  • Information about safeguards used for applicable international transfers.

13. Exercising Privacy Rights

Privacy requests may be sent to support@joinioi.com. JoinIOI may request reasonable information to confirm the identity of the person making the request and to protect accounts from unauthorised disclosure.

A request may be refused or limited where an exception applies, including where information must be retained for legal obligations, fraud prevention, security, dispute evidence or the rights of other persons.

14. Complaints

Individuals have the right to lodge a complaint with the competent data-protection supervisory authority.

In Italy, the competent authority is the Garante per la protezione dei dati personali. Individuals may also contact the supervisory authority in the European Union country where they habitually reside, work or believe an infringement occurred.

15. Automated Decisions

JoinIOI may use automated technical checks to support security, spam prevention, validation and platform administration.

JoinIOI does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects for users.

16. Children

JoinIOI is a professional platform intended for adults and persons legally authorised to act for themselves or an organisation.

The platform is not intended for children, and children should not submit personal data through JoinIOI.

17. Technical Technologies and Cookies

JoinIOI may use technical cookies or similar technologies that are necessary for authentication, security, session continuity and essential platform operation.

Any future non-essential analytics, advertising or profiling technology will be introduced only with the notices and choices required by applicable law.

18. Policy Updates

This Privacy Policy may be updated to reflect changes in platform functionality, service providers, legal requirements or data-processing practices.

The current version and effective date will remain available on this page. Where required, registered users may be asked to review or accept a new document version.

Privacy and data requests

Send privacy questions or requests to support@joinioi.com. Registered members may also use the protected Support module.