Privacy Policy

Privacy Policy of Cali(R)Evolution

This Privacy Policy applies to the “Cali(R)Evolution” application, the website accessible at the address, and its administrative section accessible at the address This document describes how Personal Data of Users who utilize these platforms are collected, processed, and stored.

Data Controller

Cali(R)Evolution by Caruso Manuel Pietro Andrea & C. S.A.S.
Via Caduti di Sabbiuno, 3
40068 San Lazzaro di Savena (BO)
VAT ID: 12347900966

Official PEC Address for Communications:

Email Address for All Other Communications:

Types of Data collected

Among the Personal Data collected by this Application, either independently or through third parties, there are: name; last name; date of birth; email; profile picture; various types of Data; User ID; payment information; billing address; Tracking Tools; Usage Data.
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanatory texts displayed prior to the Data collection. Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.

Unless specified otherwise, all Data requested by this Application is mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate such Data without any consequences on the availability or the functioning of the Service. Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller. The use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that they have the right to communicate or disclose them, thus relieving the Data Controller of any liability towards third parties.

Methods and place of processing the collected Data

Processing methods

The Data Controller processes Users’ Personal Data by taking appropriate security measures to prevent unauthorized access, disclosure, alteration, or destruction of the Personal Data.
The processing is carried out using computers and/or IT-enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Data Controller. The updated list of these parties may be requested from the Data Controller at any time.

Legal Basis of Processing

The Data Controller processes Personal Data relating to the User if one of the following conditions applies:

  • The User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or any other of the legal bases specified below, as long as the User does not object (“opt-out”) to such processing. However, this is not applicable if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • The processing is necessary for the performance of a contract with the User and/or for the performance of pre-contractual measures;
  • The processing is necessary to comply with a legal obligation to which the Data Controller is subject;
  • The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • The processing is necessary for the legitimate interests pursued by the Data Controller or by third parties.

However, it is always possible to request the Data Controller to clarify the specific legal basis for each processing and, in particular, to specify whether the processing is based on law, provided for by a contract, or necessary to conclude a contract.


The Data is processed at the Data Controller’s operating offices and in any other place where the parties involved in the processing are located. For more information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the location of the processing, the User can refer to the section concerning the details of the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or established by two or more countries, such as the United Nations, as well as regarding the security measures adopted by the Data Controller to protect the Data.

The User can verify whether one of the transfers described above takes place by examining the section of this document concerning the details of the processing of Personal Data or by requesting information from the Data Controller using the contact details provided at the beginning.

Retention Period

The Data is processed and stored for the time required for the purposes for which it was collected.

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract has been fully performed.
  • Personal Data collected for purposes related to the legitimate interests of the Data Controller will be retained until such interests are satisfied. The User can obtain further information regarding the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When the processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is revoked. In addition, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or upon order of an authority.
At the end of the retention period, Personal Data will be deleted. Therefore, upon expiration of this term, the right of access, deletion, rectification, and the right to data portability cannot be exercised anymore.

Purpose of Data Processing

User data is collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or perform executive actions, protect their rights and interests (or those of Users or third parties), identify any fraudulent activities, as well as for the following purposes: Contacting the User, Registration and authentication, Payment management, and Statistics.
For detailed information on the purposes of processing and the Personal Data processed for each purpose, Users can refer to the “Details on the processing of Personal Data” section.

Details on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Contacting the User

Contact Form (this Application)

By filling out the contact form with their Data, the User consents to their use to respond to requests for information, quotations, or any other type indicated by the form’s header.

Personal Data processed: surname; email; first name; various types of Data.

Payment management

Unless otherwise specified, this Application processes all payments with credit card, bank transfer, or other means through external payment service providers. In general, and unless otherwise specified, Users are requested to provide payment details and personal information directly to such payment service providers.
This Application is not involved in the collection and processing of such information. Instead, it will only receive a notification from the respective payment service provider about the successful payment.

Stripe (Stripe Technology Europe Ltd)

Stripe is a payment service provided by Stripe Technology Europe Ltd.
Personal Data processed: email; billing address; payment information; name; various types of Data as specified in the privacy policy of the service.

Processing location: European Union – Privacy Policy.

Registration and authentication

By registering or authenticating, Users allow this Application to identify them and give them access to dedicated services.
Depending on the following, registration and authentication services may be provided with the assistance of third parties. If this happens, this Application may access some Data stored by the third-party service used for registration or authentication.

Some of the services listed below may collect Personal Data for targeting and profiling purposes. For more information, Users can refer to the description of each service.

Direct registration and profiling (this Application)

By registering or authenticating, Users allow this Application to identify them and give them access to dedicated services. The Data Controller may process the Data collected at the time of registration or authentication for targeting and profiling purposes. For more information, Users can contact the Data Controller using the contact information provided in this document.
Personal Data processed: last name; date of birth; email; User ID; profile picture; name; various types of Data.

Apple Sign-In (Apple Inc.)

Apple Sign-In è un servizio di registrazione ed autenticazione fornito da Apple Inc. che consente agli Utenti di autenticarsi su questa Applicazione utilizzando il loro ID Apple.

Dati Personali trattati: varie tipologie di Dati secondo quanto specificato dalla privacy policy del servizio.

Google OAuth (Google Ireland Limited)

Google OAuth is a registration and authentication service provided by Google Ireland Limited and connected to the Google network.
Personal Data processed: various types of Data as specified in the privacy policy of the service.

Processing location: Ireland – Privacy Policy.


The services included in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.

Google Analytics (Google Ireland Limited)

Google Analytics is a web analytics service provided by Google Ireland Limited (“Google”). Google uses Personal Data collected for the purpose of tracking and examining the use of this Application, compiling reports, and sharing them with other Google services.
Google may use Personal Data to contextualize and personalize the ads of its advertising network.

Processed Personal Data: Usage Data; Tracking Tools.

Location of processing: Ireland – Privacy PolicyOpt Out.

Use of Push Notifications

This Application sends push notifications to Users through the Firebase service by Google LLC. The notifications sent are intended to provide updates, promotions, or other communications we believe may be of interest to Users. These notifications are not personalized based on the individual data of the User or the device but are sent uniformly to all Users who have activated notifications.

Personal Data collected: No Personal Data from the User is collected through the push notification service provided by Firebase. Notifications are managed and sent using anonymous identifiers that do not allow Cali(R)Evolution to personally identify the service’s users.

Purpose of processing: Push notifications are used to enhance the user experience by providing relevant and timely information regarding the service offered by this Application.

Users can manage their push notification preferences directly from the device or application settings, where they can decide whether to activate or deactivate this feature.

Additional information about Personal Data processing

Online sale of goods and services

The Personal Data collected is used for the provision of services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected for the purpose of completing the payment may include credit card details, the bank account used for the transfer, or any other payment instrument provided. The payment data collected by this Application depends on the payment system used.

User rights

Users may exercise certain rights regarding their Data processed by the Data Controller.
In particular, Users have the right to:

  • withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
  • object to the processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
  • access their Data. Users have the right to learn if Data is being processed by the Data Controller, obtain disclosure regarding certain aspects of the processing, and obtain a copy of the Data undergoing processing.
  • verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
  • restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Data Controller will not process their Data for any purpose other than storing it.
  • obtain the erasure or removal of their Personal Data. Users have the right to obtain the erasure of their Data from the Data Controller.
  • receive their Data. Users have the right to receive their Data in a structured, commonly used, and machine-readable forma.
  • lodge a complaint. Users have the right to bring a claim before their competent data protection authority or seek remedies in court.

Details on the right to object

When Personal Data is processed in the public interest, in the exercise of public authority vested in the Data Controller, or for the legitimate interests pursued by the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are hereby informed that if their Data is processed for direct marketing purposes, they can object to the processing at any time, free of charge and without providing any justification. If Users object to the processing for direct marketing purposes, their Personal Data will no longer be processed for such purposes. To find out if the Data Controller processes Data for direct marketing purposes, Users can refer to the respective sections of this document.

Exercising your rights

To exercise their rights, Users can submit a request to the contact details of the Data Controller indicated in this document. The request can be made free of charge, and the Data Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectifications, deletions, or restrictions of processing will be communicated by the Data Controller to each of the recipients, if any, to whom the Personal Data have been disclosed, unless this proves impossible or involves a disproportionate effort. The Data Controller will provide the User with such recipients if requested.

Cookie Policy

This Application uses Tracking Tools. To learn more, Users can consult the Cookie Policy.

Further information on processing

Legal defense

The User’s Personal Data may be used by the Data Controller in court or in the stages leading to possible legal action arising from improper use of this Application or the related Services by the User.

The User declares to be aware that the Data Controller may be required to reveal Personal Data upon request of public authorities.

Specific information

Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User’s IP address.

Information not contained in this policy

Additional information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Response to “Do Not Track” requests

This Application does not support “Do Not Track” requests. To determine if any third-party services used support them, Users are advised to check the respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if technically and legally feasible, by sending a notification to Users through one of the contact details held. Therefore, please check this page frequently, referring to the date of the last modification indicated at the bottom.

If the changes affect processing activities based on consent, the Data Controller will collect the User’s consent again, if necessary.

Definitions and legal references

Personal Data

Personal Data means any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic,

mental, economic, cultural, or social identity of that natural person.

Usage Data

Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.


The individual using this Application, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refers.

Data Subject

The natural person to whom the Personal Data refers.

Data Controller (or Owner)

The natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.

This Application

The hardware or software tool by which the Personal Data of the User is collected and processed.


The service provided by this Application as described in the relative terms (if available) and on this site/application.

European Union (or EU)

Unless otherwise specified, all references made within this document to the European Union (EU) include all current member states of the European Union and the European Economic Area.


Small sets of data stored in the User’s device.

Tracking Tool

Any technology – such as Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting – that enables the tracking of Users, for example by collecting or saving information on the User’s device.

Legal references

This privacy statement is drafted based on multiple legislative systems, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy exclusively concerns this Application.

Last modified: March 13, 2024