Up2You

Privacy Policy

An Up2You service

This privacy policy ("Privacy Policy") of the PlaNet service describes the purposes and methods of processing personal data ("Personal Data" or "Data") that Up2You S.r.l. carries out for users who access and use the services of the PlaNet digital platform ("Platform").

The information is provided only for the Up2You S.r.l. Platform and not for other services that may be activated by the user through external links.

Following access and browsing on the Platform, Data related to identified or identifiable persons may be processed. We may receive personal information from users following the creation of a personal profile for carrying out missions and for providing our services.

  1. Who is the Data Controller?

The Data Controller is Up2You S.r.l. ("Up2You" "We" "Company" or "Data Controller") with registered office in Via Pietro Orseolo 12, 20144, Milan, Italy.

  1. What Personal Data do we collect?

We collect and process Personal Data in various ways through our Digital Platform:

  • Personal Data provided voluntarily by the user: we collect personal information about the user when it is actively provided to us, for example when the user registers to create a personal profile and when they upload images and videos on the Platform to finish missions and obtain points, earning ECOins.
  • Personal Data collected through Platform use: we automatically collect certain personal information during the user's browsing and use of the PlaNet service. The Platform is a web app accessible from a browser, both from a desktop and from a smartphone, only by users involved in the initiative. The management of the accounts linked to the service ensures a periodic review thereof and disables all users that are not associated with the business processes or a specific profile. Up2You periodically reviews accounts every month in order to ensure the processing and storage only of the Personal Data which is strictly necessary.
  1. What type of Personal Data do we handle?
  • Information related to the user's account: we collect Personal Data that the user provides for the creation of their personal account (Name, Last name, company email address, company name, and password). We process the Personal Data contained in photographs and videos that users can upload to their profiles to demonstrate that they have completed the assigned missions. We may also process personal information related to Platform use that allows us to improve user experience and, in general, the Platform interface and browsability in order to maximize user friendliness and engagement.
  • Location data: we can approximate the user's location based on their IP address.
  • Data for Platform management: we ensure a periodic review of accounts and disable all users that are not associated with business processes or an identified profile. We periodically review the accounts every month. Up2You records the last login date and disables access for users who have been inactive for more than 90 days since the last login. We regularly check the Platform access system to ensure the safety of our users and automatically log them off after an inactive period. If the data subject would like to continue using our services, they can access the system again following a new identification and authentication procedure. The automatic log off is set to 60 days from the moment the personal profile was created.
  1. Automatically collected information

When the user uses our Platform, interacts with us through a smartphone, a computer, a mobile device, we may automatically collect information about how they access and use the Platform, as well as information about the device used to use the services offered by PlaNet. We use this information to improve user experience and monitor and update our Platform. We generally collect this information through a variety of tracking technologies, including cookies, pixels, web beacons, embedded scripts, location identification technologies, and similar technologies (collectively, “tracking technologies”).

Users can accept and reject these technologies by changing the privacy preference settings in their browser's profile settings.

The information we automatically collect may be combined with other personal information we collect directly from users.

We can automatically collect the following:

  • information related to Platform use (for example if you use the services offered by Up2You, if you complete the missions, if you upload images or videos and if you use the account);
  • Personal Data related to interactions with our Platform (for example, whether or not a user clicks on an image or a link, if they view the blog or if they take the multiple-choice quizzes we provide);
  • information about the devices used to access and interact with the Platform (for example, this allows us to know if you use a computer, tablet or smartphone, screen resolution, operating system, Wi-Fi connection, Internet browser and IP address, information about server log files).
  • behavioral data: information derived from the combination of the device ID and system events that can be used to identify trends and behavioral models in order to improve our service;
  • analytical information: we may collect analytical data, or use third-party analysis tools, to help us better understand the needs our users may have.
  1. What Personal Data do we not collect?

We do not collect or process the following Personal Data regarding users:

  • racial or ethnic origin;
  • political opinions;
  • religion or philosophical beliefs;
  • health or medical conditions;
  • criminal background;
  • trade union membership;
  • genetic or biometric data;
  • life or sexual orientation.


We ask our users not to send and/or upload or disclose any Personal Data among those mentioned above through the Platform or directly to our contacts.


  1. Why do we process users' Personal Data?

Users' Personal Data are processed on our Platform to:

  1. Allow users to register on the Platform and create their own account

We may process users' Data to allow them to access the Platform and register, creating a personal account. By creating their personal profile, users can access the services, carry out missions and increase their points and ECOins. We may request the following personal information for the purposes of activating the profile:

  • User name and last name;
  • Company email address;
  • Name of the company you work for;
  • Reference password.

In addition, we may process Personal Data related to the images contained in the photographs and videos related to the missions carried out. Each mission, if completed, enables users to benefit from two types of bonuses:

  • ECOins: a sort of "currency" that allows redeeming rewards;
  • points, which allow climbing the internal leaderboard of the system and earning rewards.

There are no options for modifying the "mechanics of the game," for example by excluding one of these bonuses, modifying them, or adding a third. Up2You defines the allocation of these bonuses for each mission.

For the purposes of account security, we hereby ask users to choose "strong" passwords with at least 8 alphanumeric characters and the presence of symbols.


Legal basis of the processing: providing the service to users who decide to register on the PlaNet platform.


  1. Answering questions and processing user requests

In order to respond to requests and questions sent by users related to missions, points, and the ECOin system using the Contact Data indicated by Up2You.  We can respond to requests by email to help you manage your account.

Legal basis of the processing: to manage user requests in an adequate and timely manner, and guarantee the service offered by Up2You.

  1. Send update emails to our users

To keep our users up-to-date on the PlaNet service and missions, send automatic emails ("transactional emails") that each user is free to accept or avoid receiving, based on their preferences set within the Platform. We hereby specify that the emails are addressed only to subscribers and can relate to the addition of new missions in the Platform with "calls to action" or can refer to updates on the classification or notifications regarding missions that have been completed/not completed or Notifications regarding redeemed prizes.

Legal basis of the processing: the user's explicit prior consent to receive such communications.

Please note that users can always refuse to receive updating communications, even if they have already given their consent, simply by unsubscribing from the service or by communicating the same to us via email.

  1. Provide news on the Platform

The Platform includes a "news" section with training news (including for example news related to completed missions), updates, and advice for using the Platform. If users have given us authorization to share a photo or video in the news section, we may upload the image or video and make it accessible to the individual community that has access to the Platform.

Legal basis of the processing: our legitimate interest in keeping our users updated on the services provided and the missions completed. Where videos and/or images are shared, we will request the data subject's prior consent.

  1. Ensuring the technical functioning of the Platform

We collect and use users' Personal Data to technically manage the Platform and ensure that it works properly. We may use the personal information provided by users to respond to reports or complaints about the proper functioning of PlaNet.

Legal basis of the processing: our legitimate interests in ensuring the proper functioning of the Platform from a technical/IT point of view.

  1. Informing users about changes to the Platform terms and conditions of use and providing this Privacy Policy

To send information about changes to the Platform terms and conditions of use and provide this Privacy Policy.

Legal basis of the processing: our legitimate interest in informing the user of the entry into force of such changes well in advance.

  1. Compliance with legal obligations

To comply with our legal obligations, upon orders of government authorities which may also include measures from authorities outside the users' country of residence, when we reasonably believe we are obliged to such communications and when the disclosure of Personal Data is strictly necessary to comply with the aforementioned legal obligations or government orders.

Legal basis of the processing: compliance with our legal obligations.

  1. Carry out market and approval surveys following the provision of the service

To carry out market and/or approval surveys regarding the service provided by Up2You. Such research will be used to provide useful statistical samples for improving the activities promoted by the Company.

Legal basis of the processing: our legitimate interest in collecting information on the quality of the intervention provided for the purposes of improving Up2You services.

  1. Knowing the preferences and tastes of Up2You Platform users

We collect users' Personal Data to better understand the tastes and preferences of Platform users, so as to adapt our offers to our users' characteristics.

Legal basis of the processing: the explicit prior consent of the data subject to profiling.

  1. Preventing fraud and abuse

We will use information about fraudulent or criminal activities related to the use of our services for the purpose of detecting and preventing fraud or abuse.

Legal basis of the processing: our legitimate interests in protecting our organization from fraudulent activities.

  1. Legal protection of our interests

To enforce our service terms and conditions, protect our business operations, protect our rights, privacy, security or property, and/or those of our affiliates, and allow us to pursue available legal remedies or limit any damages against us.

Legal basis of the processing: our legitimate interests in protecting our organization in accordance with the law.

  1. To whom are users' Personal Data communicated?

In addition to the personnel duly authorized by Up2You to process the Personal Data of our Platform users, the information provided by data subjects may be communicated to the company promoting the initiative, after obtaining the data subject's consent.

The Personal Data of our Platform users may also be processed by some of our service providers who deal with the technical maintenance of the systems.

If necessary, Personal Data may be transmitted to the competent public and judicial authorities in order to prevent any fraud or illegal acts.

  1. What are the user's rights in relation to the processing of Personal Data, how can they be exercised?

The subjects to whom the Personal Data refers have the right at any time to obtain confirmation of the existence or non-existence of such Data and to know the content and origin, verify its accuracy or request its integration, updating or rectification (Articles 15 and 16 of the Regulation), namely:

  • Right to access.The right to obtain access to personal information about the user together with some related information;
  • Right to Data portability.The right to receive personal information in a common format and to have it transferred to another data controller;
  • Right to rectification.The right to obtain the rectification of Personal Data without undue delay if the Personal Data is inaccurate or incomplete;

Pursuant to Articles 17, 18, and 21 of the Regulation, you have the right to request the cancellation, limitation of processing, transformation into anonymous form, or blocking of the Data processed in violation of the law, as well as to oppose in any case, for legitimate reasons, their processing, and more precisely:

  • Right to erasure.The right to obtain the erasure of your Personal Data without undue delay in certain circumstances, such as if the Personal Data is no longer necessary in relation to the purposes for which it was collected or processed;
  • Right to restrict processing.The right to obtain, in specific circumstances identified by the applicable law, a restriction of the processing of your Data for a certain period of time, for example when you dispute the accuracy of Personal Data, for the time needed to verify the accuracy and correctness of such Data.
  • Right to object. The right to object, for reasons relating to your particular situation, to the processing of Personal Data, and to object to the processing of Personal Data for direct marketing purposes, insofar as this is linked to such direct marketing.

As a data subject, the user also has the right to revoke the consent given at any time, without prejudice to the validity of the processing carried out prior to such revocation.

The rights can be exercised by contacting the Data Controller and/or the Data Protection Officer at the following addresses:

  • e-mail: privacy@u2y.io
  • by mail to Via Orseolo 12, 20144, Milano (MI)


  1. How long do we keep Personal Data?

The management of the profiles linked to the service ensures a periodic review of the accounts by the Company which disables all users that are not associated with business processes or a specific profile. We periodically review the accounts every month. Up2You records the last login date and disables access for users who have been inactive for more than 90 days since the last login. In the event of contract termination, there is a procedure that deletes all the accounts and information connected with them. We monitor the correct use of accounts and automatically log users off after an inactive period of 60 days.

In accordance with the conditions of service indicated on our Site, Up2You undertakes to protect the Data entered by the user and to make them available for processing through the tools offered by our services. Up2You reserves the right to store anonymized or aggregated customer information for statistical use, aimed at improving the services provided on the basis of a legitimate interest.

What transfers can we carry out?

We may communicate certain user Data and personal information to our suppliers for the activities related to the use of the services offered through the Platform and to the company promoting the initiative. We do not currently transfer Personal Data outside the European Economic Area. In the future, for some of the processing mentioned above, we could use providers and suppliers that are located outside the territory of the European Union. In these circumstances, we guarantee that we will undertake to comply with the applicable legal provisions on data transfer by signing, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses envisaged by the European Commission.

  1. How do we protect users' Personal Data?

Information security is very important to us, and we have established safeguards to preserve the integrity and security of the information we collect and process through the Platform.

However, no security system is impenetrable and we cannot guarantee the security of our systems at 100%. If any information under our control is compromised due to a security breach, we will take reasonable steps to investigate the situation and, where appropriate, notify persons whose information may have been compromised and take other measures, in accordance with applicable laws and regulations.

  1. Applicable law

This Privacy Policy is governed by and will be interpreted in accordance with provisions and any other mandatory legislation applicable in the European Union.

  1. Complaint to the Authority  

The Data Subject may lodge a complaint with the Authority for the Protection of Personal Data, which can be contacted at the Website https://www.garanteprivacy.it/.

PLANET COOKIE POLICY

An Up2You service


  1. Introduction 

The Cookie Policy ("Cookie Policy") of the PlaNet digital platform ("Platform") owned by Up2You S.r.l. describes the different types of cookies that are used in relation to the Platform that can be accessed and browsed by users.

Up2You S.r.l. ("Up2You", "We" or "Company") is the Data Controller of Personal Data described in this Cookie Policy and determines the purposes and means pursuant to (EU) Regulation 2016/679 ("GDPR").

What are cookies?

Cookies are small text files that can be used by websites and platforms to make the user experience more efficient. Cookies allow us to store small amounts of information about a user's computer or mobile application related to visits made to our Platform.

Why do we use cookies?

We use cookies for different purposes. The necessary cookies are used to ensure the proper functioning of the Platform.

We may also collect information on the use of the Platform by users in anonymous form such as: pages visited, time spent, traffic source, geographical origin, age, gender, and interests. These cookies are sent from third-party domains outside our Platform.

How do we use cookies?

We may store cookies on the user's device if they are strictly necessary for the functioning of the Platform. For all other types of cookies, we need the user's consent.

What types of cookies do we use?

This Platform uses different types of cookies. Some cookies are placed by third-party services that appear on our pages.

At any time, the user can change the cookie settings in their browser that allow using all the functions without restrictions when browsing the Platform. We invite users to read the Privacy Policy of the PlaNet service containing all the information about who we are, how we process Personal Data, and how users can contact us.

The types of cookies that we use when users browse our Platform are indicated below.

  • Necessary cookies

Necessary cookies help make the Platform usable by enabling basic functions, like page browsing and access to secure areas. Our Platform and our services cannot function properly without these cookies.

  • Preference cookies

Preference cookies allow us to remember the information that influences the way the Platform behaves or presents itself, such as the preferred language or the place where the user is located.

  • Statistical cookies

Statistical cookies help us understand how visitors interact with us by collecting and transmitting information in anonymous form.

  • Marketing cookies

Marketing cookies are used to monitor the Platform's visitors. The intent is to display relevant and engaging ads for the individual user.

  • Unclassified cookies

Unclassified cookies are the cookies that are being classified, together with the providers of individual cookies.

Links are listed below to the respective information on the use of cookies, accessing the consent forms provided:

Cookie settings and preferences.

Users can decide whether to accept cookies or otherwise via their browser settings. The total or partial disabling of technical cookies could compromise the optimal use of the Platform. If third-party cookies are disabled, your browsing experience will not be affected in any way. The browsers allow specifying different settings for first party and third party cookies.

For example, in Firefox, using the menu Tools > Options > Privacy, a user can access a control panel where it is possible to define whether or not to accept different types of cookies and to remove them. Documentation on how to set the cookie management rules for your browser can be easily found online. For example, some addresses relating to the main browsers are listed below:

Chrome: https://support.google.com/chrome/answer/95647?hl=it 

Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie 

Internet Explorer: http://windows.microsoft.com/it-it/windows7/how-to-manage-cookies-in-internet-explorer-9 

Safari: http://support.apple.com/kb/HT1677?viewlocale=it_IT