Privacy Policy
Effective Date: 10/08/2026
Chamelix ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our software-as-a-service (SaaS) platform ("Platform"). This notice is provided under Arts. 13 and 14 GDPR: it does not require any acceptance — we invite you to read it carefully.
The Short Version
The full policy is below; these are the essentials.
- The organization you register or book with (sports centre, gym, salon) is the data controller of your membership and certificate data; we process it on its behalf (Art. 28 GDPR). We are the controller only of your account and website data.
- We do not sell your data. Providers processing it on our behalf may not use it for their own purposes or marketing; the few cases where a provider acts as an independent controller are noted on the Subprocessors page.
- We collect the minimum needed: name, email, phone, and what the organization records to manage your membership or bookings.
- Medical certificates, where the module is active, live in private EU storage and are visible only to you and your organization's authorized staff. No automated reading of their contents.
- AI-assisted features are off by default and never make decisions about you.
- Data resides on servers in the European Union; US providers are covered by the SCC / Data Privacy Framework safeguards listed on the Subprocessors page.
- We keep data for defined periods, listed below: account data for the life of the account, certificates until expiry + 90 days, technical logs 60 days to 24 months, accounting records up to 10 years.
- Optional cookies stay off until you consent; "Reject" carries the same weight as "Accept".
- You can export and delete your data yourself from the Platform; we answer requests within one month.
Data Controller
The Chamelix Platform is operated by ArizenLab S.r.l.s., registered office at Via Padova 20, 36010 Zanè (VI), Italia, VAT 04578500243.
ArizenLab S.r.l.s. acts as the data controller for Platform-account data and for the purposes described in this policy. For data managed on behalf of a client organization — for example a sports centre, a gym or a salon — such as membership registrations, bookings and, where the relevant module is active, medical/fitness certificates, the organization is the data controller and ArizenLab S.r.l.s. acts as a data processor (Art. 28 GDPR; see the DPA page).
Data Protection Officer (DPO). ArizenLab S.r.l.s. has not currently designated a DPO. The reference channel for any matter concerning the processing of personal data remains the address below, monitored by the controller.
For any request regarding your personal data, contact us at app@chamelix.it.
Information We Collect
We collect information from you in two primary ways: information you provide to us and information we collect automatically.
Information You Provide
- Account Information: When you create an account, we collect your name and email address. During onboarding we also require a phone number to send appointment reminders and operational notices. Profile picture remains optional.
- User Content: This includes any information you choose to share on the Platform, such as reviews, posts, and messages.
- Additional Information: Depending on the features you use, you may provide other details related to your activities or services on the Platform.
Information We Collect Automatically
- Usage Data: We may automatically collect information about how you access and use the Platform, including your IP address, browser type and version, device type and operating system, pages visited, time spent on each page, search queries, and preferences.
- Cookies and Tracking Technologies: We use cookies and similar tracking technologies to collect and store information about your usage of the Platform. This helps us improve your experience, analyze how the Platform is used, and personalize content.
How We Use Your Information
We use the collected information for various purposes, including:
- Providing and Maintaining the Platform: To operate and maintain the Platform, create and manage user accounts, facilitate interactions and communication, and provide customer support.
- Personalizing Your Experience: To tailor the Platform to your preferences and provide relevant content and recommendations.
- Improving the Platform: To analyze usage trends, identify areas for improvement, and develop new features.
- Marketing and Communications: To send you updates, newsletters, and promotional content, if you have opted in to receive them.
- Legal Compliance: To comply with applicable laws and regulations, and to respond to legal requests.
Legal Bases for Processing
Each purpose rests on a specific legal basis (GDPR Art. 6, and Art. 9 for special categories). Where the basis is consent, processing does not start until you give it and stops if you withdraw it.
| Purpose | Legal basis | Retention | | --- | --- | --- | | Account creation, authentication, delivering the service | Performance of a contract — Art. 6(1)(b) | For the life of the account | | Bookings, service management, operational messages (confirmations, reminders) | Performance of a contract — Art. 6(1)(b) | Duration of the relationship and subsequent limitation periods | | Sports membership and health certificates | Processed on behalf of the client organization, on its documented instructions; for health data the basis is the one the organization identifies in its own flow (Art. 9) | Certificates deleted as a rule within about 90 days of expiry | | Platform security, abuse prevention, audit logs | Legitimate interest — Art. 6(1)(f) | Retention windows configured per log | | Application error monitoring | Legitimate interest — Art. 6(1)(f) | Per the provider's retention | | Usage analytics, third-party maps, session replay | Consent — Art. 6(1)(a) | Until withdrawal; durations in the Cookie Policy | | Marketing messages and newsletters | Consent — Art. 6(1)(a) | Until withdrawal | | Accounting, tax and other statutory obligations | Legal obligation — Art. 6(1)(c) | For the periods required by law |
Where we rely on legitimate interest, the interest pursued is keeping the service available, secure and working; you still have the right to object on grounds relating to your particular situation (see below).
Automated Decision-Making and Profiling
- Skill level. Some sports features include a skill level, computed automatically from the match results recorded on the platform. It exists to build balanced matches and, where the organization allows it in its visibility settings, may appear on match cards.
- It produces no legal or similarly significant effects: it does not govern access to the service, pricing, or any contractual decision. You can ask for human intervention on the computed value, express your point of view, or contest it using the contact details at the end.
- AI-assisted features. They are off by default and can only be enabled by the client organization for its own users. We do not use them to make automated decisions about you within the meaning of GDPR Art. 22.
How We Share Your Information
We may share your information with the following third parties:
- Service Providers: We may share your information with third-party service providers who assist us in providing and maintaining the Platform, such as payment processors, data analytics providers, and customer support platforms. We have contracts with these providers requiring them to protect your information and forbidding them from using it for their own purposes, selling it, or using it for their own marketing. Some services (for example Google for social sign-in and maps, Meta for WhatsApp) act as independent controllers for certain processing, under their own privacy notices. The full list, with the data each one receives and its role, is on the Subprocessors page.
- Other Users: Depending on the Platform's functionality, other users may view your public profile or interact with you.
- Legal Authorities: We may disclose your information to legal authorities if required by law or in response to valid legal requests.
- Business Transfers: In the event of a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your information is transferred and becomes subject to a different Privacy Policy.
WhatsApp and Email Communications
For transparency about communication channels:
- WhatsApp (only where your organization enables it): Meta (WhatsApp Cloud API) receives the phone number, the template message content and delivery metadata — not the rest of your profile. Send logs are kept for 180 days.
- Transactional email: our email provider receives the address and the message content, solely for delivery.
You can ask your organization to use a different reminder channel at any time.
Roles and Data Protection Responsibilities
Depending on the context, data protection roles are distributed as follows:
- Client organization (for example a sports centre, gym or salon): data controller for membership registration (tesseramento) data handled for that organization, including certificate checks and organization-specific acceptance records.
- Chamelix: data processor for those organization-managed processing activities, acting on documented instructions.
- Chamelix as independent controller: for account management, authentication, platform security, platform operations, service reliability, and Chamelix direct communications/marketing (where applicable).
Sports Membership and Health Certificate Data
For sports organizations, the platform can manage health certificate data as special category data under applicable law. The certification is required by Italian sports-medicine law (Ministerial Decree of 18 February 1982 for competitive activity; Ministerial Decree of 24 April 2013 for non-competitive activity) and the controller organization is responsible for verifying its validity and expiry.
When this module is used, we process:
- the certificate file, stored in private storage;
- the certificate type (for example competitive or non-competitive);
- the certificate expiry date;
- minimal technical information needed for management and traceability (for example who uploaded the document and a record of relevant operations).
What we do not do on certificate files:
- no OCR extraction of medical content;
- no automated medical analysis or profiling;
- no enrichment of medical data beyond what is needed for compliance workflow.
Who can see a certificate:
| Who | What they see | | --- | --- | | You (the data subject) | Your certificate and its status | | Your organization's authorized staff | File and status, solely to manage the membership | | Other users and members | Nothing | | Chamelix personnel | No routine access; any technical intervention is limited and logged |
Technical and Organizational Security Measures
We take appropriate technical and organizational measures to protect your information from unauthorized access, use, or disclosure. These include:
- Role-based access control: access to data is restricted based on role and organization membership.
- Private document storage: certificates are kept in non-public areas that cannot be accessed without authorization.
- Time-limited file access: documents are downloaded through time-limited links, not permanent public addresses.
- Logging of relevant operations: significant activities on membership and certificates are recorded for accountability purposes.
- Deletion and retention procedures: we apply defined procedures for the deletion and retention of data.
Data Retention
We retain personal data for the time needed to provide the service and to comply with legal obligations. In summary:
- Account data: kept for as long as the account exists. When the account is deleted we remove the profile and the data linked to it, subject to the technical backup windows described in the next section and to anything we are required to keep by law.
- Membership data: processed on behalf of the client organization and kept while the membership is active; on revocation or deletion, identifying data is removed. The retention period is set by the organization as data controller.
- Technical and security logs: have defined retention windows, from 60 days to 24 months depending on the log; once the window has passed they are deleted or anonymised.
- Records with accounting or tax relevance: kept for the periods required by law (up to 10 years, art. 2220 of the Italian Civil Code); where possible, identifying data that is no longer needed is removed or anonymised before that term.
For medical sports certificates:
- we keep only the most recent certificates needed to manage the membership;
- expired or no longer necessary certificates are deleted through periodic procedures, typically within about 90 days of expiry;
- limited technical backup or disaster-recovery windows may still apply, as described in the following section.
Backups and Deletion Recovery
When you or your organization delete a document or account, we remove the corresponding records from the active system and the associated files from our storage. However, you should be aware that:
- Cloud storage soft-delete: our file storage provider keeps a deleted object recoverable for a limited soft-delete / object-recovery window (for certificate files this window may be up to 7 days, subject to provider configuration) before it is permanently purged. During this window the file is not accessible through the Platform, but it could be restored by the storage provider in a recovery scenario.
- Database backups: our database provider retains point-in-time backups for a bounded period. Deleted personal data may persist inside those backups until the backup window rolls over, after which it is no longer recoverable.
These windows exist for security, accountability, and disaster-recovery purposes. After they elapse, the data is no longer recoverable. If you need the exact, currently-configured windows for a data-subject request, contact us using the details below.
Your Privacy Rights and Request Routing
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal information:
- Right of Access: You have the right to request access to your personal information.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal information.
- Right to Erasure: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Restriction of Processing: You have the right to request restriction of processing of your personal information.
- Right to Data Portability: You have the right to receive your personal information in a structured, commonly used, and machine-readable format.
- Right to Object: You have the right to object to the processing of your personal information for certain purposes, including processing based on our legitimate interest.
- Right to Withdraw Consent: Where processing relies on consent, you may withdraw it at any time and as easily as you gave it, without affecting the lawfulness of processing carried out before the withdrawal (GDPR Art. 7(3)). For cookie preferences use the Cookie Preferences button in the footer of every page; for marketing messages, the unsubscribe link in each message or a request to the contact details below.
- Right to Lodge a Complaint: If you believe the processing of your data infringes the law, you may lodge a complaint with the Italian Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garanteprivacy.it, protocollo@gpdp.it) or with the supervisory authority of the Member State where you live or work (GDPR Art. 77). Your right to a judicial remedy is unaffected.
To exercise these rights, contact us using the details below. To speed up handling, requests should be routed as follows:
- Requests about an organization's membership registration data (including certificate data and organization-specific acceptance events): route to the relevant organization (controller).
- Requests about platform account data and Chamelix services (login, profile, platform security/operations, and Chamelix direct marketing): route to Chamelix.
If a request is sent to the wrong party, we will support correct routing where possible.
We answer requests within one month of receipt (Art. 12(3) GDPR); for complex cases the period may be extended by two further months, in which case we notify you within the first month with the reason.
Data Deletion
We provide several ways for you to manage and delete your data:
- Platform Deletion: You can manage your account settings to delete specific data or disconnect integrations, if applicable.
- Automatic Deletion: We support automated mechanisms to handle data deletion requests when permissions are revoked through third-party tools.
- Manual Requests: You can request data deletion by contacting us via our support channels or email.
Legal Compliance
We operate in compliance with the General Data Protection Regulation (GDPR). We process your data based on your consent or other legal bases where applicable. We inform all users of their rights under the GDPR and provide mechanisms for exercising those rights.
To ensure the lawful and secure processing of personal data, we have implemented the following measures:
- Data Processing Addendum (DPA): We have signed agreements with our data processors to ensure compliance with GDPR requirements.
- Transfer Impact Assessment (TIA): We conduct assessments to mitigate risks associated with data transfers, ensuring compliance with GDPR requirements.
Children's Privacy
Personal data of minors can be processed only when entered by a parent or legal guardian acting for the minor. Direct self-registration by users under 18 is not allowed under our terms.
At sign-up we require a declaration that the person registering is either an adult or a parent/legal guardian. The controller organization remains responsible for verifying eligibility and legal basis in its own registration workflows.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the Effective Date; for material changes we also give notice through the Platform. Previous versions of this policy are available on request via the contact details below.
Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
Email: app@chamelix.it
Address: Chamelix, Via Padova 20, 36010 Zanè (VI), Italia
By using our Platform, you acknowledge that you have read and understood this Privacy Policy.