Privacy Policy

Last updated: 23 July 2026

INTERNAL DRAFT — to be validated by a privacy lawyer before publication. Highlighted items like this one require confirmation.

1. Introduction

Rise Against Hunger Italia ("we", "Controller") respects the privacy of its users. This notice, provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), explains which personal data we process through the Rise Against Hunger Italia mobile application, why we process it, who we share it with, and what rights you have.

2. What data we process

The app can be browsed without registration: informational content (projects, figures, news) is visible to everyone. If you choose to create an account for the donor area, we process the following data.

CategoryDataWhen
Account data Email address and password (the latter stored only in irreversibly encrypted form) Registration with email
Social sign-in Identifier and email address provided by Google or Apple. With Apple you may use "Hide My Email": in that case we receive an anonymous relay address and you may optionally provide a real contact email Sign-in with Google or Apple
Profile data First name, last name, phone number, city, province, country, date of birth (used to verify adult age) Completion of the donor profile
Consents Date and version of the accepted notice, marketing consent choice and its changes over time (consent log kept for evidentiary purposes) Registration and later changes
Technical diagnostics Error and crash reports of the app, associated with the technical identifier of your account (never email, password or profile content) Use of the app

The app does not access the device's GPS location, shows no advertising, uses no advertising identifiers and runs no commercial analytics or behavioural tracking. Your sign-in session is stored only on your device, in a protected area.

3. Purposes and legal bases

PurposeLegal basis (Art. 6 GDPR)
Creation and management of the account and donor areaPerformance of a contract or pre-contractual measures (Art. 6.1.b)
Promotional communications and updates about the association's activitiesConsent, optional and revocable at any time (Art. 6.1.a)
Keeping the consent logLegal accountability obligation (Art. 6.1.c and Art. 7)
Technical diagnostics and application securityLegitimate interest in a working, secure service (Art. 6.1.f)

4. Recipients and data processors

Data is processed through providers acting on our behalf:

If you sign in with Google or Apple, those companies process the sign-in data as independent controllers, under their own privacy notices.

Data is neither sold nor transferred to third parties for commercial purposes.

5. Transfers outside the EU

Account data resides in the European Union. Some providers are US companies: for processing that involves a transfer outside the EU we rely on appropriate safeguards under Chapter V of the GDPR (standard contractual clauses and, where available, certification under the EU-US Data Privacy Framework). List here the individual confirmed transfers after verifying the DPAs (Sentry, email provider).

6. Data retention

7. Your rights (Arts. 15-22 GDPR)

You have the right to access your data, to rectification, erasure, restriction of processing, portability, and to object to processing based on legitimate interest. You may withdraw marketing consent at any time, without affecting the lawfulness of prior processing.

Directly from the app you can: export your data in a readable format (profile and consent history) and delete your account (immediately, or as a scheduled request in 30 days, see section 6). For any other request write to the contacts in section 12: we will reply within 30 days.

If you believe the processing infringes the GDPR, you may lodge a complaint with the Italian supervisory authority, Garante per la protezione dei dati personali (www.garanteprivacy.it).

8. Over-The-Air (OTA) updates

The app uses the Expo Updates service to receive updates to its own code. The update request transmits only technical information about the installed app version, with no data from your account.

9. Donations, shop and events on external platforms

Money donations and solidarity purchases happen outside the app, on partner platforms acting as independent controllers:

When you open these links, the app takes you to the device browser. If form pre-filling (name/email in the web address) or a donation-source reference code is activated, this section must be updated BEFORE activation, describing the data transmitted.

10. Security

We adopt appropriate technical and organisational measures: encryption of data in transit and at rest, access rules under which each user can read and modify only their own data (row-level security), passwords stored exclusively in irreversibly encrypted form, session kept in the device's secure storage.

11. Minors and automated decision-making

The donor area is restricted to adults: the date of birth is used to verify this. The app uses no automated decision-making or profiling.

12. Data controller and contacts

Rise Against Hunger Italia
Email: info@riseagainsthunger.it
Certified email (PEC) and registered office address to be added.
Website: https://italy.riseagainsthunger.org

Data Protection Officer (DPO): not appointed. Confirm with legal counsel that appointment is not required (Art. 37 GDPR).

13. Changes to this notice

This notice may be updated. Substantial changes will be communicated in the app, which will ask for renewed acknowledgement; every accepted version remains tracked in the consent log.