Privacy Policy Mobility Connect Web App
Table of Contents
Mobility Connect Web App
Information on personal data processing
(Art. 13 Regulation (EU) 679/2016 “GDPR”)
Wiseair S.r.l. is committed to protecting your personal data. This privacy notice describes how we process your data when you use our “Mobility Connect Web App”.
Important note about your relationship with your employer
This privacy notice describes the personal data processing carried out by Wiseair S.r.l., as Data Controller (hereinafter also the “Controller”), with reference to the optional services you choose to use through the “Mobility Connect Web App”.
Your employer may be required by law to adopt a Home-Work Travel Plan (“PSCL”). Limited to this purpose, your employer acts as Data Controller, while Wiseair operates as Data Processor pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR), processing strictly necessary personal data under the employer’s instruction. For information on this specific processing, please consult the privacy notice provided directly by your employer.
1. Data Controller
Wiseair S.r.l. IT10700370967
Contacts for exercising rights: Requests to exercise the rights provided by GDPR or any withdrawal of consent can be addressed to the Data Controller at the following contacts:
- Address: Via Andrea Costa 8 - 20131, Milano (MI) - Italy
- Contacts: +393490566225, privacy@wiseair.vision, wiseair.srl@legalmail.it
Categories of data subjects: Mobility Connect Web App Users
2. What data do we process and for what purposes?
Wiseair processes different categories of personal data for the purposes described below. The provision of some data is necessary to use the Web App, while for others it is optional and based on your consent.
| Processing purpose | Description | Legal basis (GDPR) | Categories of data processed |
|---|---|---|---|
| A. Account creation and provision of essential “Mobility Connect Web App” services | Allow you to use the basic features of the Web App (such as creating and managing your “mobility profile”, estimating emissions and accessing incentives). | Performance of a contract to which you are party (Art. 6.1.b) | Personal and contact data (Name, Surname, email), User ID, Mobility profile data*. |
| B. Profiling of your mobility profile* | Analyze your travel habits and the information you provide to enable personalized features. | Your specific consent (Art. 6.1.a) | Personal data, User ID, Mobility profile data*, data derived from mobility profile*. |
| C. Sending personalized mobility information | Provide you, through the Web App or via email, with personalized suggestions and information to optimize your trips. | Your specific consent (Art. 6.1.a) | Personal and contact data (email), User ID, Mobility profile data*, data derived from mobility profile*. |
| D. Sharing complete mobility data with your employer | Communicate your complete mobility profile* data (including data from purpose B, if you have given consent) to your employer (as independent Controller) for mobility management purposes (e.g. incentives, reporting). | Your specific consent (Art. 6.1.a) | Personal and contact data, User ID, Mobility profile data*, data derived from mobility profile*. |
| E. Security, maintenance and technical management of the platform | Ensure data and system security, perform maintenance, prevent fraud and manage incidents. | Legal obligation and Legitimate interest (Art. 6.1.c and 6.1.f) | Browsing data, technical logs, IP addresses (in addition to remaining user personal data based on specific preferences expressed in relation to purposes A to D) |
* “Mobility profile” refers to information about your travel habits (e.g. municipality of residence, age, gender, type of contract, travel distance, main means of transport, preferences, schedules, smart working frequency), in line with the Ministerial Guidelines for PSCL.
More specifically, the personal data processed are those that can be inferred from - and connected to - Province of residence, Municipality of residence, Age, Gender, Type of employment contract, Travel distance, Main means of transport, Travel preferences, Remote working frequency, Home-work travel frequency, Working days, Travel conditions, Transport means preferences, Company of belonging, Name (natural person), Surname (natural person), Company email address.
The required information (personal data) detailed above includes both those defined by regulations as “minimum”, and additional ones deemed necessary by the employer to pursue their mobility management purposes. Therefore, less personal data than indicated may be processed.
3. Is the provision of data mandatory? What data is necessary?
The provision of data necessary for Purpose A (Provision of Web App services) is an essential contractual requirement to use the platform. Failure to provide it will prevent you from creating an account and using our basic services.
The provision of data for Purposes B (Profiling), C (Sending personalized information) and D (Sharing with employer) is optional and based on your consent. Lack of consent will not prevent you from using the basic Web App services, but you will not be able to receive personalized suggestions nor allow your employer to access your mobility profile* for specific initiatives.
4. Who do we communicate your data to? (Recipients)
Your data may be communicated to:
- your employer and/or designated Mobility Manager, only with your specific consent (Purpose D);
- service providers, entities acting as our Data Processors (Art. 28 GDPR) to provide us with instrumental services (e.g. hosting, maintenance, technical support).
- competent authorities, when required to comply with legal obligations
5. Do we transfer your data to third countries or international organizations?
Yes, for the provision of our services we use suppliers who process your personal data in the United States of America. This transfer is legitimized by the European Commission Adequacy Decision 2023/1795 (EU-U.S. Data Privacy Framework) or, failing that, relationships with such suppliers are governed by Standard Contractual Clauses (SCC).
The main suppliers are: Typeform S.L, Retool Inc, Postman Inc., Notion Labs Inc., WorkOs Inc., Intercom Inc.
6. How long do we keep your data?
We retain your personal data for different periods of time depending on the purposes for which it was collected, in compliance with the principle of storage limitation:
- Personal and contact data (name, surname, email): Until deletion of your account.
- Data processed based on your consent (e.g. for purposes B, C and D): until withdrawal of your consent and in any case until deletion of your account if earlier.
- Data relating to mobility profile* (trips, preferences, etc.): For a maximum period of 10 years* from their collection, for aggregate statistical analysis and service improvement purposes.
- Browsing data and technical logs: For the time strictly necessary to ensure platform security (usually no more than 12 months).
* The 10-year retention period is established to allow historical and longitudinal analyses on the evolution of sustainable mobility. At the end of this period, data will be deleted or made irreversibly anonymous.
7. What are your rights?
Right of access
The data subject has the right, according to Art. 15 of GDPR, to request from the controller access to their personal data.
Right to rectification
The data subject has the right, according to Art. 16 of GDPR, to request from the controller rectification of their personal data.
Right to erasure
The data subject has the right, according to Art. 17 of GDPR, to request from the controller erasure of their personal data.
Right to restriction of processing
The data subject has the right, according to Art. 18 of GDPR, to request from the controller restriction of processing of data concerning them.
Right to object
The data subject has the right, according to Art. 21 of GDPR, to object to their processing.
Right to data portability
The data subject has the right, according to Art. 20 of GDPR, to exercise their right to data portability.
Right to withdraw consent
The data subject has the right, according to Art. 7 of GDPR, to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
How to exercise your rights
Subject to identification, preferably by sending an email to privacy@wiseair.vision and including in the subject line EXERCISE OF PRIVACY RIGHTS.
Additional notes
The data subject may also lodge a complaint with a supervisory authority (for example, the Italian Data Protection Authority).
8. Profiling and automated decision-making processes
To provide you with our full services, we carry out profiling, that is, we analyze your mobility habits derived from your mobility profile* (this activity is not carried out with reference to purposes A and E and, in any case, is carried out exclusively with your consent for one or more of purposes B to D). However, we do not use decision-making processes based solely on automated processing that produce legal effects or similarly significantly affect you (pursuant to Art. 22 GDPR).
For any questions about these terms, contact us at:
privacy@wiseair.vision +39 349 0566225
Via Andrea Costa 8, 20131, Milan (MI)
For any questions about these terms, please contact us at: