This notice is written in Italian; this English version is a translation provided for convenience. If the two differ, the Italian version prevails, except where the discrepancy would operate to the detriment of someone who read the English version, in which case the version they read applies.
Privacy notice
Version 2026-10-10.1 — in effect since 10 October 2026. Also read our terms of use.
The rule we set ourselves: we collect only the data strictly needed to run your campaign, and we keep it for the shortest time possible. We don't sell data, we don't hand it over for third-party marketing, we don't do advertising profiling, and we don't use your content to train models. Where the law requires us to keep something longer, we say so openly below.
In this notice, the project creator is whoever proposes a project and the backer is whoever supports a project.
1. Who processes your data
Data controller: KIJO DIGITAL SRLS, Viale Beatrice d'Este 43, 20122 Milan, Italy — VAT 10031630964. To exercise your rights or ask us anything: info@kijodigital.com.
2. What we process, why and for how long
| What it does | Where | Safeguard | |
|---|---|---|---|
| Email and password (stored encrypted) | Let you log in and protect your account | Performance of the contract | For as long as you keep the account, then 30 days |
| Name, bio, profile photo (if you write them) | Show who is behind the campaign | Performance of the contract | For as long as you keep the account, then 30 days |
| Campaign text and materials | Produce and publish your page | Performance of the contract | For as long as the campaign exists, then 90 days |
| Posts on the platform's social pages: the approved text, the campaign image and, if you give them to us and we check them, your Instagram name or your Facebook Page ID | Publish the campaign on Campagna Crowdfunding's social pages, if you turn the feature on | Performance of the contract | For as long as the campaign exists, then 90 days; published posts stay on our pages until we remove them |
| Activation payment data | Collect the €59 fee and issue tax documents | Legal obligation | 10 years (tax obligation): we cannot keep it for less |
| Invoice details of campaign creators (name or company name, tax code, VAT number, address, e-invoicing recipient code or PEC address) | To issue the invoices for the €59 and for our commission | Legal obligation | 10 years from the last invoice (tax obligation). If we never issued an invoice, we delete them together with the account |
| Backer email address (never passed on to the project creator) | Confirm the pledge and service communications | Performance of the contract | Campaign duration + 12 months |
| Reward shipping address (physical rewards only: for digital rewards we neither ask for it nor keep it) | Let you ship what you promised | Performance of the contract | 12 months from delivery, then deleted |
| A backer's confirmation: their address goes to the creator (with the creator's country) | Be able to show that whoever gave the address knew who it was going to, and where | Legitimate interest (defence in court) | 5 years |
| Country where the creator is based (public on the campaign page) | Let backers know who they are dealing with, and where | Legitimate interest | For as long as you keep the account, then 30 days |
| Creator type (private person, organisation, business or professional) and the «personal capacity» declaration | Tell backers whether they are dealing with a professional, and prove what the creator declared | Performance of the contract and legal obligation (art. 49-bis of the Italian Consumer Code) | 5 years |
| Request for immediate performance when paying the €59 | Prove that you asked for work to start straight away, knowing you would lose the right of withdrawal (art. 59 of the Italian Consumer Code) | Legal obligation and legitimate interest (defence in court) | 5 years |
| Contacts you upload (lists) | Send the messages you decide to send | You are the controller, we are the processor | For as long as you keep them: you delete them whenever you want |
| Log of the declarations made at launch | Prove who declared what and when | Legitimate interest (defence in court) | 5 years |
| Log of social post approvals (who approved what, when, from where) | Prove who approved each item published under our name | Legitimate interest (defence in court) | 5 years |
| Declaration that the people shown in photos have consented | Be able to show that the published photos could be published | Legitimate interest (defence in court) | 5 years |
| International sanctions alerts (from Stripe or from our own checks) | Block accounts and campaigns of people subject to restrictive measures | Legal obligation | 5 years from the block |
| Essential technical logs | Security and troubleshooting | Legitimate interest | As short as possible, normally 30 days |
If you back a campaign. We ask for a shipping address only if you choose a reward that has to be shipped; for digital rewards we don't ask for it. Your email address stays with us: the creator sees your name, the amount, any rewards you chose and, if something has to be shipped, your address — never your email. Who receives your address, and under which rules, is explained in section 6.
International sanctions screening. Screening against the lists of persons and organisations subject to restrictive measures is carried out by Stripe, as a payment institution. We block accounts and campaigns when we receive its alerts or when our own checks require it. The legal basis is a legal obligation.
Automated decisions. We do not take decisions based solely on automated processing: the automated check flags the sentences to look at, and a person decides.
We don't collect special-category data (health, opinions, orientation) and we ask you not to enter any. What stays in your browser is listed below, item by item.
We do not process special category data. Art. 9 of the Regulation gives stricter protection to some data: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a person's sex life or sexual orientation. This platform does not host campaigns that would reveal such data about the creator or about those who back them (see the Terms), and we never ask you for it. This is not a ban on subjects: it covers only those categories, in those words.
3. What we keep in your browser
We use no profiling, marketing or analytics cookies. There is no Google Analytics, no Facebook pixel, we don't measure how many of you there are or where you come from. That is why we don't ask you to consent to cookies. What stays in your browser is purely technical — without it the site doesn't work:
| What | Purpose | How long |
|---|---|---|
| NEXT_LOCALE (cookie) | Remember whether you read the site in Italian or English | 1 year |
| ccf_token | Keep you signed in after login | Until the session expires or you sign out |
| ccf_uid | Know which profile is yours | Until you sign out |
| ccf_email | Show you which address we write to | Until you sign out |
| ccf_verified | Remember whether your email is already confirmed | Until you sign out |
| ccf_dispositivo | Avoid asking for the emailed code at every sign-in from this device | 30 days |
| ccf_sfida_accesso | If the page reloads while you finish signing in, remember which email address we're waiting for a code for and the temporary sign-in reference (never the password or the code) | 10 minutes at most, and it's gone when you close the tab |
| ccf_avviso_privacy | Remember that you have read the notice at the bottom of the page | Until you clear your browser |
| ccf_bozza_campagna | Keep what you write in the creation form before signing in | Until you create the campaign or empty the fields |
| ccf_bozza_studio | Keep what you write in the campaign Studio, including suggestions you haven't used yet, if you reload the page or leave without saving | Until you save, cancel or sign out |
Except for the first one, these aren't cookies: they are entries in your browser's storage (local or per tab) and they stay on your device — they never reach us. You can delete them at any time by clearing the site data in your browser; if you do, you'll be asked to sign in again. The only case where a third party can write anything to your device is a campaign's video: that is why we don't load it on its own, only if you click.
A campaign's video is hosted by YouTube or Vimeo. Until you press ▶ nothing loads and no data goes to the provider. By pressing ▶ you agree that the provider receives your IP address and your browser's data and uses its own cookies, under its privacy policy: YouTube (Google Ireland) — policies.google.com/privacy; Vimeo — vimeo.com/privacy. For that loading we and the provider are joint controllers; the provider alone is responsible for what it does afterwards. You can withdraw your consent by deleting the provider's cookies from your browser.
4. The photos you upload
A photo taken with a phone carries far more than what you see: where it was taken (GPS location), with which phone, when, and sometimes the name of whoever took it. When you upload an image, our servers re-encode it (converted to JPG, longest side 2400 pixels) and that data is removed: it never reaches the published page. The original file is not kept, and we hold no backup copies of it. Before an image is published the system checks again that nothing is left: if it finds the location or the phone model, the image is refused and deleted instead of published.
When you upload a photo in which someone can be recognised, we ask you to confirm that you have their written permission. We record that confirmation with the date and the image it refers to: it protects you as much as it protects us.
5. Who we share the data with
Only with suppliers necessary to run the service, bound by contract and with no freedom to use it for themselves, except where the table says otherwise. Application, servers, database, website, domain, email and DNS are in Europe: in Italy, the Netherlands and Germany. Some services are based in or process data in the United States: image storage, sending service emails, payments (in part) and the AI we use. For each, below, the safeguard under which the data travels.
| Who | What it does | Where | Safeguard |
|---|---|---|---|
| Application server and database | European Union (Netherlands) | Standard contractual clauses for support and technical logs | |
| Website | European Union (Germany) | Standard contractual clauses for support and technical logs | |
| Email, domain and DNS | Italy | No transfer | |
| Image storage | United States | Data Privacy Framework | |
| Sending service emails | Sent from Ireland; account data and logs in the United States | Standard contractual clauses | |
| Payments and identity checks of people raising funds | European Union (Ireland) and United States | Standard contractual clauses. For identity checks the payment provider is an independent controller | |
| Artificial intelligence for texts and images | United States | Standard contractual clauses | |
| Publishing posts on the platform's social pages (Facebook and Instagram) | European Union (Ireland) and United States | For what appears on its platforms the provider is an independent controller; for transfers to the United States, Data Privacy Framework |
The model providers do not use your content to train their systems. The images we generate for you carry a visible «AI-generated» label. The texts are written by a model, but before they go online a person reads them and takes responsibility for them.
If you turn social on. We publish the posts you approve on our own Facebook and Instagram pages. We send the social provider the text of the post, and it fetches the image from the public address of our storage at the moment of publishing. If you give us your Instagram name or your Page, after our check the post mentions you. What happens to posts once published — comments, shares, statistics — is handled by the social provider under its own privacy notice. No advertising profiling: paid ads, if they ever come, will have a separate consent.
If a campaign has a video, the player belongs to YouTube or Vimeo: it loads only if you click, and only from that moment does the video provider know you are watching.
6. The creator of the campaign you back
If you choose a reward that has to be shipped, your name and address are passed on to whoever launched the campaign, so that they can deliver it to you. Before you give us your address we ask you to confirm that you understand who it goes to and in which country. We pass it on to the creator, who undertakes to use it only to provide you with the reward: from that moment the creator is an independent controller of that data and answers for how they use it. Our Terms require them to use it only for shipping, not to reuse it, to delete it after delivery, and to give you their own privacy notice. Your email address is not passed on to them, and for digital rewards they receive no address at all.
This does not contradict what we promised you at the top: we don't sell your data and we don't hand it over for anyone's marketing. The address goes to the creator only so they can deliver what you chose, and using it for marketing is exactly what our Terms forbid them to do.
If the creator is based outside the European Economic Area, your address leaves the EEA. If their country is covered by an adequacy decision of the European Commission — as the United Kingdom and Switzerland are — no further safeguards are needed. Otherwise the transfer relies on the standard contractual clauses approved by the European Commission, which the creator accepts with our Terms; as an ancillary basis, it is necessary to perform the contract you entered into for the reward (Art. 49(1)(b) and (c) GDPR).
7. Contacts you upload
For addresses you import into our systems you are the controller: you must have collected them lawfully and be able to demonstrate the basis on which you write to them. We process them as a processor, only to carry out your sends, and we delete them when you delete them or when you close your account.
8. Your rights
You can ask at any time to access your data, correct it, delete it, restrict its processing, port it elsewhere, and object to processing based on legitimate interest. Write to info@kijodigital.com: we reply within 30 days. If you believe something is wrong, you can complain to the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
9. Security
Passwords stored only in encrypted form, protected traffic, access limited to those who need it, payments handled by Stripe so that card numbers never pass through our systems, images stripped of hidden data before publication. No system is invulnerable: if a breach occurred that put your rights at risk, we would tell you and notify the Data Protection Authority within the terms set by law.
10. Changes and language
If we change this notice we update the version number and the date at the top. Material changes are communicated to you.
This notice is written in Italian; the English version is a translation. If the two differ, the Italian version prevails, except where the discrepancy would operate to the detriment of someone who read the English version, in which case the version they read applies.