Privacy Policy
Treno Facile · Last updated: 23 August 2026
The short version
We never ask who you are, and we have no way of finding out. There is no account, no name, no e-mail address, no
payment. So that we can tell how much the app is being used, each request it makes is recorded next to a random string
your own phone made up for itself. The detail of those requests is kept for six days and then deleted. What
outlives it is a running count next to that same random string — when the app was last opened, how much it was used —
because a service has to know whether the people who try it come back. That count says what an app did; it never says
who you are, and we sell your data to nobody.
The rest of this page says the same thing in the detail the GDPR asks for.
1. Who is responsible for your data
The data controller — the person who decides why and how the data described here is handled — is
Francesco De Martino, a natural person, who can be reached at the e-mail address below for anything in
this policy, including any request under §9.
You can reach us for anything in this policy at trenofacile.app@gmail.com.
We have not appointed a Data Protection Officer: none of the conditions in Article 37 GDPR applies to a service of
this kind and size. Your questions go to the address above.
2. What the app does
Treno Facile is an informational app for Italian rail travel. It searches stations, timetables and journeys, and
reports live departure boards and train status, by asking the public interfaces of Trenitalia, Italo, ViaggiaTreno and
RFI on your behalf and putting their answers together.
It sells nothing. Where a price is shown, the booking link reopens the same search on the operator's own website: from
that moment you are on their site, under their terms and their privacy policy, and whatever you enter there — name,
payment details — is between you and them. We never see it.
3. What we process
3.1 The installation identifier
On first launch the app generates a random string on your device and keeps it there. It is not derived from your
phone's hardware, from any account, or from an advertising identifier; it is not one of those identifiers, and we do not
share it with anyone.
Its only job is arithmetic: it lets us tell one person opening the app ten times from ten people opening it once.
Nothing in it points at you, and we hold nothing anywhere else that could turn it into a name. You can get a fresh one
by uninstalling and reinstalling the app: the old string goes with it, and we have no way of connecting the two, so
from that moment you are a new installation as far as anything here is concerned.
3.2 What each request records
When the app asks our servers something, we record: which feature was asked for, the parameters of the question
(for example the stations, the date and time, or the train number), the moment it was asked, whether it succeeded, how
long it took, the app version and platform, the language requested, and the installation identifier above.
The parameters describe a search, not a person — but a route you look up can say something about where you intend to
be, so we treat these records as personal data and give them the protections below.
3.3 The usage summary kept for each identifier
Once the detail of §3.2 is deleted, a short summary stays behind, attached to the same random string: when that
installation was first seen and last seen, how many requests it made on each day, and which features it used. Nothing
else — no search parameters, no route, no station, no times of travel.
We keep it to answer one question that no single day can: whether people who try the app keep using it, or drop it
after a week. That is the difference between a service worth continuing and one that only looks busy.
Being honest about what this is: it is not anonymous, and we do not call it aggregate. A record that
belongs to one installation singles out one user, even with no name attached, so the GDPR treats it as personal data
(Recital 26) and so do we — it has a retention limit (§5) and your rights reach it (§9). Aggregate is what it becomes
afterwards: totals with no identifier left in them.
3.4 Technical connection data
Like every web server, ours receives the IP address and the user-agent string of whoever connects. An IP address counts
as personal data under the GDPR even when no name is attached to it. It is kept in technical logs for seven days and then
deleted, and it is used to keep the service running and to stop abuse. It is never joined to the installation
identifier of §3.1, and never used for statistics: keeping those two apart is what holds up the word "pseudonymous"
everywhere else in this policy. An address in a technical log stays a technical matter.
3.5 Your position, which never leaves your phone
The app can ask your device roughly where you are, for one purpose: to put the nearest stations at the top of the
list instead of making you scroll. It asks for approximate location, not the precise satellite kind —
a few hundred metres is all it takes to sort stations, and there is no reason to know more. The answer is used on your phone, by the app, to sort a list — and that is where it stops.
It is never sent to our servers, so there is nothing about your position for us to store, to summarise,
to keep for a week or to hand to anyone. We could not tell you where you have been even if you asked us.
Your phone decides this, not us. The permission is asked by the operating system, and only the first time you use
the feature that needs it — never at launch, and never before you have seen what it is for. You can refuse it, and you
can withdraw it later in the system settings, at which point the app simply stops sorting by distance. Everything else
keeps working: the permission is a convenience, never a condition of use.
One honest detail, so the picture is complete: when you then pick a station and search, that station travels to our
servers like any other search (§3.2). It is your choice of station that reaches us, not your coordinates.
3.6 What we never collect
- Your name, e-mail address, telephone number or postal address.
- Any account: there is none to create.
- Payment or card details: nothing is sold here.
- Your contacts, photos, files, calendar or messages.
- Your position, precise or otherwise: as §3.5 explains, the app only ever asks your device for an approximate
one, and even that never reaches us. We do not track where you are, continuously or otherwise.
- Anything that would follow you across other apps or other websites: nothing described in this policy tracks you
beyond the app itself.
- Special categories of data under Article 9 GDPR — health, beliefs, and the rest.
4. Why we process it, and on what legal basis
- To answer what you ask. Running your search and returning the result. Legal basis: Article
6(1)(b) GDPR — performing the terms under which you use the app; and, for the technical data in §3.4 that arrives
whatever we intend, Article 6(1)(f), our legitimate interest in a service that works at all.
- To understand how the app is used. Which features people use, at what times of day, on which
platforms, how often something fails — and, from the summary of §3.3, whether someone who installs the app is still
using it weeks later. Together they tell us what to build, what to fix and how much capacity to pay for. Legal basis:
Article 6(1)(f), legitimate interest. We weighed it, and these are the limits that made it come out in your favour: the
data is pseudonymous and stays that way, since we hold nothing anywhere that could attach a name to it; the detail of
what you searched for dies within six days and never enters the summary; the summary itself carries counts and dates,
nothing about where you travel; none of it is ever combined with data from another source, sold, or handed to anyone
else; and it has an end date (§5) rather than living forever. You can object at any time, and ask for your own summary
to be deleted (§9).
- To keep the service up and abuse away. Rate limiting, diagnosing faults, investigating attacks.
Legal basis: Article 6(1)(f).
- To comply with the law when we are actually obliged to. Legal basis: Article 6(1)(c).
None of this is compulsory in the sense of a contract you must sign; but the service cannot answer a search without
processing the search.
5. How long we keep it
Three things are kept, for three different lengths of time, and the difference between them matters more than any
single figure.
- The detail of each request (§3.2): six days, after which it is deleted. This is the layer that
knows what you looked up, and it is the shortest-lived on purpose.
- The usage summary per identifier (§3.3): six months. Counts and dates only. It is still personal
data, so it is deleted when those six months run out — and on request before then (§9).
- Aggregate statistics: indefinitely. These are totals with no identifier left in them — how many
searches of which kind on which day, how many installations in a given month kept using the app. They describe no one
in particular, which is what makes them anonymous rather than pseudonymous; it is also why they cannot be traced back
to you, extracted or deleted on request.
- Technical logs of §3.4: seven days.
- Cached operator answers: from seconds to a few hours, depending on how quickly the underlying fact
changes. This cache is keyed by the question — two people asking the same thing share one entry — and never by you.
6. Who else is involved
- Our hosting provider, OVH (OVH SAS, France), whose servers run this service from a data centre
in Strasbourg. It holds the data described above as a processor under Article 28 GDPR, bound by a contract that lets
it act only on our instructions, and it never uses any of it for its own purposes.
- The rail operators. When you search, our servers — not your phone — ask Trenitalia, Italo,
ViaggiaTreno and RFI. They receive the search itself: the stations, the date, the train number. They receive it from
our own network address, not yours, and they never receive your installation identifier or anything else about your
device. If you follow a booking link you leave the app for their website, and from there their privacy policy applies
to everything you do.
- Nobody else. Those above are the whole list. We do not sell personal data. The app carries no
third-party software development kit of any kind — no analytics service, no crash reporter, no advertising or
attribution library — so there is no other company receiving anything from your device without being named here.
Should another recipient ever become part of the service, it will appear on this list, with what it receives and why,
before it receives anything — see §13.
- Public authorities, only where a law obliges us and only to the extent it obliges us.
7. Transfers outside the European Economic Area
There are none. The servers described in §6 are in France, inside the European Union, and nothing in this policy is
transferred, copied or made accessible outside the European Economic Area. No safeguard under Article 46 GDPR is needed, because no
transfer takes place.
If that ever changes — a different provider, a service in another country — this section will say so, naming the
country and the safeguard, before the change takes effect (§13).
8. Identifiers stored on your device
The installation identifier of §3.1 is stored on your device. Italian law implementing the ePrivacy Directive
(Article 122 of the Codice Privacy, and the Garante's guidelines on cookies and other tracking tools) governs storing
information on someone's terminal equipment, whatever it is called.
We keep this identifier within the narrowest use those rules recognise: it is first-party, it is used only to measure
how the service is used in aggregate, it is never combined with data from anywhere else, never used to build a picture
of you, and never disclosed to a third party.
On that basis we treat it as a first-party measurement rather than as tracking, and we do not ask for your consent
to create it. The reasons, so you can judge them yourself: it never leaves our own service; it feeds counts and nothing
else; it is not combined with any other source, sold, or disclosed; it lasts six months and no longer; and uninstalling
the app ends it, since nothing survives to reconnect an old string to a new one. If you would rather not be counted at
all, §9 tells you how to say so, and we will act on it.
The app uses no cookies: it is not a website. This page you are reading uses none either, and stores nothing on your
device beyond the language you picked for it.
9. Your rights
Your right to object
Stated here on its own, as Article 21(4) GDPR requires. You can object at any time to the usage statistics of
§4 and §3.3, on grounds relating to your particular situation. Write to
trenofacile.app@gmail.com with the identifier below and we will stop
counting your installation and delete what is held under it. We will not argue: measuring how an app is used is not a
ground that outweighs somebody who would rather not be counted.
Beyond that, Articles 15 to 22 GDPR give you the right to obtain access to your data, to have it corrected or erased,
to have its processing restricted, and to receive it in a portable form.
There is a real limitation you should know about, and it works in your favour. Because we hold nothing that identifies
you, we normally cannot find "your" data at all: Article 11 GDPR says we are not obliged to acquire more information
about you just to be able to. In practice:
- If you want a right exercised, send us the installation identifier from §3.1 — you will find it at the bottom of
the app's information screen, where you can copy it. With it we can find, hand over or delete
everything held under it: the request detail if it is still within its six days, and the usage summary of §3.3, which
is the part that lasts. Note the flip side: anybody holding that string could ask the same, which is one more reason we
keep so little behind it.
- Without it we cannot act, and Article 11 does not require us to go looking: there is no name, no e-mail and no
account here to search by.
- Once the periods in §5 have run out there is nothing left to access, correct or erase.
- Aggregate statistics are anonymous. They cannot be traced back to any identifier, so they cannot be extracted or
deleted for one person — which is the point of aggregating them.
Write to trenofacile.app@gmail.com. We answer within one month, as
Article 12(3) requires.
You also have the right to lodge a complaint with a supervisory authority — in Italy the Garante per la protezione dei
dati personali, Piazza Venezia 11, 00187 Roma, garante@gpdp.it,
www.garanteprivacy.it — or with the authority of the EU country where you
live or work.
10. Security
Traffic between the app and our servers travels over TLS. Access to the servers is restricted to those who operate
them. The strongest measure here is how little there is to protect: no names, no addresses, no payment data, and records
that delete themselves within the week.
No system is perfectly secure. If a breach ever puts your rights and freedoms at risk we will notify the Garante
within 72 hours and, where Article 34 requires it, tell users directly.
11. Children
The app is for the general public and is not directed at children. Under Italian law the age for consenting to
information-society services on one's own is 14 (Article 8 GDPR as implemented by Article 2-quinquies of the Codice
Privacy). We do not knowingly process data of anyone below that age — and since we collect nothing that identifies a
person, no data here reveals anyone's age either.
12. Automated decision-making
There is none. We take no decision about you by automated means, and there is no profiling producing legal effects
or similarly significant effects on you within the meaning of Article 22 GDPR. The app ranks train journeys, not
people.
13. Changes to this policy
The date at the top of this page is the date of the version you are reading. If we change something that matters — a
new purpose, a new recipient, a longer retention — the app will tell you the next time you open it, with a notice that
brings you here, and it will do so before the change takes effect rather than after. Where the law
requires your consent, we will ask for it rather than assume it.
14. Contact
trenofacile.app@gmail.com
Any request under this policy, any question about it, any correction to it: that address.
Informativa sulla privacy
Treno Facile · Ultimo aggiornamento: 23 agosto 2026
In breve
Non ti chiediamo mai chi sei e non abbiamo modo di scoprirlo. Non c'è un account, non c'è un nome, non c'è un
indirizzo e-mail, non c'è un pagamento. Per capire quanto l'app viene usata registriamo ogni richiesta che fa, accanto a
una stringa casuale che il tuo telefono si è generato da solo. Il dettaglio di quelle richieste resta sei giorni e poi
viene cancellato. Quel che gli sopravvive è un conteggio accanto alla stessa stringa casuale — quando
l'app è stata aperta l'ultima volta, quanto è stata usata — perché un servizio deve pur sapere se chi lo prova poi
torna. Quel conteggio dice cosa ha fatto un'app; non dice mai chi sei, e i tuoi dati non li vendiamo a nessuno.
Il resto della pagina dice la stessa cosa nel dettaglio che il GDPR richiede.
1. Chi è responsabile dei tuoi dati
Il titolare del trattamento — la persona che decide perché e come vengono trattati i dati descritti qui — è
Francesco De Martino, persona fisica, raggiungibile all'indirizzo e-mail qui sotto per qualsiasi cosa
riguardi questa informativa, comprese le richieste ai sensi del §9.
Per qualsiasi cosa riguardi questa informativa puoi scrivere a
trenofacile.app@gmail.com.
Non abbiamo nominato un Responsabile della protezione dei dati: per un servizio di questo tipo e di queste dimensioni
non ricorre nessuna delle condizioni dell'articolo 37 del GDPR. Le domande vanno all'indirizzo qui sopra.
2. Cosa fa l'app
Treno Facile è un'app informativa sul trasporto ferroviario italiano. Cerca stazioni, orari e soluzioni di viaggio e
mostra i tabelloni di partenza e lo stato dei treni in tempo reale, interrogando per tuo conto le interfacce pubbliche di
Trenitalia, Italo, ViaggiaTreno e RFI e mettendo insieme le loro risposte.
Non vende nulla. Dove compare un prezzo, il link di acquisto riapre la stessa ricerca sul sito dell'operatore: da quel
momento sei sul loro sito, con i loro termini e la loro informativa, e tutto ciò che inserisci lì — nome, dati di
pagamento — riguarda te e loro. Noi non lo vediamo mai.
3. Quali dati trattiamo
3.1 L'identificativo di installazione
Al primo avvio l'app genera sul tuo dispositivo una stringa casuale e la conserva lì. Non deriva dall'hardware del
telefono, da alcun account né da un identificativo pubblicitario; non è uno di quegli identificativi e non lo
condividiamo con nessuno.
Serve solo a fare i conti: permette di distinguere una persona che apre l'app dieci volte da dieci persone che la
aprono una volta. Non contiene nulla che rimandi a te, e non conserviamo altrove niente che possa trasformarlo in un
nome. Se ne vuoi uno nuovo, disinstalla e reinstalla l'app: la vecchia stringa se ne va con essa e non abbiamo modo di
collegare le due, quindi da quel momento sei un'installazione nuova a tutti gli effetti.
3.2 Cosa registra ogni richiesta
Quando l'app chiede qualcosa ai nostri server, registriamo: quale funzione è stata richiesta, i parametri della
domanda (per esempio le stazioni, la data e l'ora, o il numero del treno), il momento in cui è arrivata, se è andata a
buon fine, quanto ci ha messo, la versione dell'app e la piattaforma, la lingua richiesta e l'identificativo di
installazione di cui sopra.
I parametri descrivono una ricerca, non una persona — ma un percorso che consulti può dire qualcosa su dove hai
intenzione di essere, perciò trattiamo queste registrazioni come dati personali e diamo loro le tutele descritte
sotto.
3.3 Il riepilogo d'uso conservato per ciascun identificativo
Una volta cancellato il dettaglio del §3.2, resta un breve riepilogo, legato alla stessa stringa casuale: quando
quell'installazione è stata vista la prima e l'ultima volta, quante richieste ha fatto in ciascun giorno e quali funzioni
ha usato. Nient'altro — nessun parametro di ricerca, nessun percorso, nessuna stazione, nessun orario di viaggio.
Lo conserviamo per rispondere a una domanda che nessun singolo giorno può soddisfare: se chi prova l'app continua a
usarla oppure la abbandona dopo una settimana. È la differenza tra un servizio che vale la pena portare avanti e uno che
sembra soltanto molto frequentato.
Diciamolo con chiarezza: non è un dato anonimo e non lo chiamiamo aggregato. Un record che appartiene
a una singola installazione individua un singolo utente, anche senza alcun nome accanto: il GDPR lo considera dato
personale (considerando 26) e così lo consideriamo noi — ha un limite di conservazione (§5) e i tuoi diritti lo
raggiungono (§9). Aggregato è ciò che diventa dopo: totali in cui non è rimasto alcun identificativo.
3.4 Dati tecnici di connessione
Come ogni server web, il nostro riceve l'indirizzo IP e la stringa user-agent di chi si collega. Un indirizzo IP è un
dato personale ai sensi del GDPR anche quando non ha alcun nome accanto. Resta nei log tecnici per sette giorni e poi
viene cancellato, e serve a tenere in piedi il servizio e a impedirne gli abusi. Non viene mai associato
all'identificativo di installazione del §3.1 né usato per le statistiche: tenere separate quelle due cose è ciò che
regge la parola "pseudonimo" in tutto il resto dell'informativa. Un indirizzo in un log tecnico resta una questione
tecnica.
3.5 La tua posizione, che non esce mai dal telefono
L'app può chiedere al tuo dispositivo all'incirca dove ti trovi, per una sola finalità: mettere in cima all'elenco le
stazioni più vicine invece di farti scorrere. Chiede la posizione approssimata, non quella satellitare
puntuale: per ordinare delle stazioni bastano qualche centinaio di metri, e non c'è ragione di sapere di più. La risposta viene usata sul tuo telefono, dall'app, per ordinare un elenco — e lì si
ferma. Non viene mai inviata ai nostri server, quindi della tua posizione non c'è nulla che possiamo
conservare, riepilogare, tenere per una settimana o consegnare a qualcuno. Non potremmo dirti dove sei stato nemmeno se
ce lo chiedessi tu.
A deciderlo è il tuo telefono, non noi. Il permesso lo chiede il sistema operativo, e soltanto la prima volta che usi
la funzione che ne ha bisogno — mai all'avvio, mai prima che tu abbia visto a cosa serve. Puoi rifiutarlo e puoi
revocarlo in seguito dalle impostazioni di sistema, e a quel punto l'app smette semplicemente di ordinare per distanza.
Tutto il resto continua a funzionare: il permesso è una comodità, mai una condizione per usare l'app.
Un dettaglio, per onestà, così il quadro è completo: quando poi scegli una stazione e fai una ricerca, quella stazione
arriva ai nostri server come qualsiasi altra ricerca (§3.2). Ciò che ci raggiunge è la stazione che hai scelto, non le
tue coordinate.
3.6 Cosa non raccogliamo mai
- Il tuo nome, l'indirizzo e-mail, il numero di telefono o l'indirizzo postale.
- Nessun account: non ce n'è uno da creare.
- Dati di pagamento o della carta: qui non si vende nulla.
- La tua rubrica, le foto, i file, il calendario o i messaggi.
- La tua posizione, puntuale o meno: come spiega il §3.5, l'app chiede al dispositivo soltanto quella
approssimata, e nemmeno quella ci arriva mai. Non tracciamo dove ti trovi, né in modo continuo né altrimenti.
- Qualsiasi cosa che ti segua su altre app o su altri siti: nulla di ciò che questa informativa descrive ti traccia
al di fuori dell'app.
- Categorie particolari di dati ai sensi dell'articolo 9 del GDPR — salute, convinzioni e via dicendo.
4. Perché li trattiamo e su quale base giuridica
- Per rispondere a ciò che chiedi. Eseguire la ricerca e restituirti il risultato. Base giuridica:
articolo 6(1)(b) del GDPR — esecuzione delle condizioni alle quali usi l'app; e, per i dati tecnici del §3.4 che
arrivano comunque, articolo 6(1)(f), il nostro legittimo interesse ad avere un servizio funzionante.
- Per capire come viene usata l'app. Quali funzioni si usano, in che ore, su quali piattaforme,
quanto spesso qualcosa fallisce — e, grazie al riepilogo del §3.3, se chi installa l'app la sta ancora usando qualche
settimana dopo. Insieme ci dicono cosa costruire, cosa correggere e quanta capacità pagare. Base giuridica: articolo
6(1)(f), legittimo interesse. Il bilanciamento l'abbiamo fatto, e questi sono i limiti che lo fanno pendere dalla tua
parte: i dati sono pseudonimi e tali restano, perché non conserviamo da nessuna parte qualcosa che possa attaccarvi un
nome; il dettaglio di ciò che hai cercato muore entro sei giorni e non entra mai nel riepilogo; il riepilogo porta
conteggi e date, nulla su dove viaggi; niente di tutto ciò viene mai combinato con altre fonti, venduto o consegnato a
terzi; e ha una scadenza (§5) invece di restare per sempre. Puoi opporti in qualsiasi momento e chiedere la
cancellazione del tuo riepilogo (§9).
- Per tenere in piedi il servizio e tenerne lontani gli abusi. Limitazione delle richieste, diagnosi
dei guasti, analisi degli attacchi. Base giuridica: articolo 6(1)(f).
- Per adempiere a obblighi di legge, quando ce ne sono davvero. Base giuridica: articolo
6(1)(c).
Niente di tutto questo è obbligatorio nel senso di un contratto da firmare; ma il servizio non può rispondere a una
ricerca senza trattare la ricerca.
5. Per quanto tempo li conserviamo
Le cose conservate sono tre, per tre durate diverse, e la differenza tra loro conta più di qualsiasi singola cifra.
- Il dettaglio di ogni richiesta (§3.2): sei giorni, dopodiché viene cancellato. È lo strato che
sa cosa hai consultato, ed è il più effimero apposta.
- Il riepilogo d'uso per identificativo (§3.3): sei mesi. Solo conteggi e date. Resta un dato
personale, quindi viene cancellato allo scadere dei sei mesi — e prima, su richiesta (§9).
- Le statistiche aggregate: a tempo indeterminato. Sono totali in cui non è rimasto alcun
identificativo — quante ricerche di che tipo in quale giorno, quante installazioni di un certo mese hanno continuato a
usare l'app. Non descrivono nessuno in particolare, ed è ciò che le rende anonime anziché pseudonime; è anche il motivo
per cui non possono essere ricondotte a te, estratte o cancellate su richiesta.
- I log tecnici del §3.4: sette giorni.
- Le risposte degli operatori in cache: da pochi secondi a qualche ora, a seconda della velocità con
cui cambia il dato sottostante. La cache è indicizzata sulla domanda — due persone che chiedono la stessa cosa
condividono la stessa voce — e mai su di te.
6. Chi altro è coinvolto
- Il nostro fornitore di hosting, OVH (OVH SAS, Francia), i cui server ospitano il servizio in un
datacenter di Strasburgo. Conserva i dati descritti sopra in qualità di responsabile del trattamento ai sensi
dell'articolo 28 del GDPR, vincolato da un contratto che gli consente di agire solo su nostra istruzione, e non li usa
mai per finalità proprie.
- Gli operatori ferroviari. Quando cerchi, sono i nostri server — non il tuo telefono — a
interrogare Trenitalia, Italo, ViaggiaTreno e RFI. Ricevono la ricerca in sé: le stazioni, la data, il numero del
treno. La ricevono dal nostro indirizzo di rete, non dal tuo, e non ricevono mai il tuo identificativo di installazione
né altro sul tuo dispositivo. Se segui un link di acquisto esci dall'app verso il loro sito e da lì vale la loro
informativa per tutto ciò che fai.
- Nessun altro. Quelli sopra sono l'elenco completo. Non vendiamo dati personali. L'app non
incorpora alcun SDK di terze parti — nessun servizio di analytics, nessun raccoglitore di crash, nessuna libreria
pubblicitaria o di attribuzione — quindi non c'è nessun'altra società che riceva qualcosa dal tuo dispositivo senza
essere indicata qui. Se un altro destinatario dovesse mai entrare a far parte del servizio, comparirà in questo elenco,
con ciò che riceve e perché, prima che riceva qualsiasi cosa — vedi §13.
- Le autorità pubbliche, solo quando una legge ce lo impone e solo nei limiti in cui lo impone.
7. Trasferimenti fuori dallo Spazio economico europeo
Non ce ne sono. I server descritti nel §6 si trovano in Francia, all'interno dell'Unione europea, e nulla di quanto
questa informativa descrive viene trasferito, copiato o reso accessibile fuori dallo Spazio economico europeo. Non serve alcuna garanzia ai
sensi dell'articolo 46 del GDPR, perché non avviene alcun trasferimento.
Se un giorno dovesse cambiare — un fornitore diverso, un servizio in un altro paese — questa sezione lo dirà,
indicando il paese e la garanzia adottata, prima che il cambiamento abbia effetto (§13).
8. Identificativi memorizzati sul tuo dispositivo
L'identificativo di installazione del §3.1 è memorizzato sul tuo dispositivo. La normativa italiana che attua la
direttiva ePrivacy (l'articolo 122 del Codice privacy e le linee guida del Garante su cookie e altri strumenti di
tracciamento) disciplina la memorizzazione di informazioni nel dispositivo di un utente, comunque la si chiami.
Manteniamo questo identificativo entro l'uso più ristretto che quelle regole riconoscono: è di prima parte, serve
soltanto a misurare in forma aggregata l'uso del servizio, non viene mai combinato con dati di altra provenienza, non
viene mai usato per farsi un'idea di chi sei e non viene mai comunicato a terzi.
Su questa base lo consideriamo una misurazione di prima parte e non un tracciamento, e non ti chiediamo il consenso
per generarlo. Le ragioni, così puoi giudicarle tu: non esce mai dal nostro servizio; alimenta conteggi e nient'altro;
non viene combinato con alcuna altra fonte, venduto o comunicato; dura sei mesi e non di più; e disinstallando l'app
finisce lì, perché non resta nulla che possa ricollegare una vecchia stringa a una nuova. Se preferisci non essere
conteggiato affatto, il §9 ti dice come dirlo, e noi vi daremo seguito.
L'app non usa cookie: non è un sito web. Nemmeno questa pagina ne usa, e sul tuo dispositivo non memorizza altro che
la lingua che hai scelto per leggerla.
9. I tuoi diritti
Il tuo diritto di opposizione
Lo indichiamo qui separatamente, come richiede l'articolo 21(4) del GDPR. Puoi opporti in qualsiasi momento
alle statistiche d'uso dei §4 e §3.3, per motivi connessi alla tua situazione particolare. Scrivi a
trenofacile.app@gmail.com indicando l'identificativo di cui sotto e
smetteremo di conteggiare la tua installazione, cancellando quanto è conservato sotto di essa. Non staremo a discutere:
misurare come viene usata un'app non è un motivo che prevalga su chi preferisce non essere conteggiato.
Oltre a questo, gli articoli da 15 a 22 del GDPR ti danno il diritto di accedere ai tuoi dati, di farli rettificare o
cancellare, di limitarne il trattamento e di riceverli in un formato portabile.
C'è un limite concreto che è bene tu conosca, e gioca a tuo favore. Poiché non conserviamo nulla che ti identifichi,
di norma non siamo proprio in grado di trovare i "tuoi" dati: l'articolo 11 del GDPR stabilisce che non siamo tenuti ad
acquisire ulteriori informazioni su di te al solo scopo di riuscirci. In concreto:
- Se vuoi esercitare un diritto, inviaci l'identificativo di installazione del §3.1 — lo trovi in fondo alla
schermata delle informazioni dell'app, da dove puoi copiarlo. Con quello possiamo trovare,
consegnare o cancellare tutto ciò che è conservato sotto di esso: il dettaglio delle richieste, se siamo ancora entro
i suoi sei giorni, e il riepilogo d'uso del §3.3, che è la parte che dura. Il rovescio della medaglia: chiunque disponga di
quella stringa potrebbe chiedere lo stesso, ed è un motivo in più per cui dietro di essa teniamo così poco.
- Senza di esso non possiamo agire, e l'articolo 11 non ci obbliga a cercare: qui non c'è un nome, un'e-mail o un
account su cui fare una ricerca.
- Scaduti i periodi del §5 non resta nulla a cui accedere, da rettificare o da cancellare.
- Le statistiche aggregate sono anonime. Non sono riconducibili ad alcun identificativo, quindi non possono essere
estratte né cancellate per una singola persona — che è precisamente lo scopo dell'aggregazione.
Scrivi a trenofacile.app@gmail.com. Rispondiamo entro un mese, come
richiede l'articolo 12(3).
Hai inoltre il diritto di proporre reclamo a un'autorità di controllo — in Italia il Garante per la protezione dei
dati personali, Piazza Venezia 11, 00187 Roma, garante@gpdp.it,
www.garanteprivacy.it — oppure all'autorità del paese dell'Unione in cui
risiedi o lavori.
10. Sicurezza
Il traffico tra l'app e i nostri server viaggia su TLS. L'accesso ai server è riservato a chi li gestisce. La misura
più efficace, qui, è quanto poco ci sia da proteggere: nessun nome, nessun indirizzo, nessun dato di pagamento e
registrazioni che si cancellano da sole entro la settimana.
Nessun sistema è perfettamente sicuro. Se una violazione dovesse mai mettere a rischio i tuoi diritti e le tue
libertà, lo notificheremo al Garante entro 72 ore e, dove l'articolo 34 lo richiede, lo comunicheremo direttamente agli
utenti.
11. Minori
L'app si rivolge al pubblico generale e non è destinata ai bambini. In Italia l'età per consentire da soli ai servizi
della società dell'informazione è 14 anni (articolo 8 del GDPR, attuato dall'articolo 2-quinquies del Codice privacy).
Non trattiamo consapevolmente dati di persone al di sotto di quell'età — e poiché non raccogliamo nulla che identifichi
una persona, nessun dato qui rivela nemmeno l'età di qualcuno.
12. Decisioni automatizzate
Non ne prendiamo. Non assumiamo alcuna decisione su di te con mezzi automatizzati e non esiste alcuna profilazione
che produca effetti giuridici o incida in modo analogamente significativo su di te ai sensi dell'articolo 22 del GDPR.
L'app ordina i viaggi in treno, non le persone.
13. Modifiche a questa informativa
La data in cima alla pagina è quella della versione che stai leggendo. Se cambiamo qualcosa che conta — una nuova
finalità, un nuovo destinatario, una conservazione più lunga — te lo dirà l'app stessa alla prima apertura utile, con un
avviso che rimanda a questa pagina, e lo farà prima che la modifica abbia effetto, non dopo. Dove la
legge richiede il tuo consenso, lo chiederemo invece di darlo per scontato.
14. Contatti
trenofacile.app@gmail.com
Qualsiasi richiesta ai sensi di questa informativa, qualsiasi domanda su di essa, qualsiasi correzione: quell'indirizzo.