1. Data Controller
The Data Controller of your data is:
Contact email for privacy issues: soshelmetproject@gmail.com
Effective Date: September 10, 2025
This policy describes what personal data we collect, why we collect it, and how we use it when you use our S.O.S. Helmet service. Your privacy is of utmost importance to us, and we are committed to protecting your data in compliance with Regulation (EU) 2016/679 (GDPR).
The Data Controller of your data is:
We collect various categories of data for specific purposes described below.
Data collected: Email address, Password (stored as cryptographic hash, never in plain text).
Purpose: Create and manage your account, allow you access to the reserved area, recover password, and send essential service communications (e.g., registration confirmation).
Legal Basis: Performance of a contract (Art. 6.1.b GDPR), to which you are a party at the time of registration to our service.
Data collected: First and Last Name, Date and place of birth, Place of residence, Blood type, Allergies, Relevant conditions, Notes for rescuers, Emergency contacts.
Purpose: The main and sole purpose of this data is to make it quickly accessible to rescuers or anyone scanning your NFC/QR tag in an emergency, to provide more effective and safer first aid.
Legal Basis: Explicit consent (Art. 9.2.a GDPR). We collect and process this health data only after obtaining your free, specific, informed, and unambiguous consent during the registration phase. You are aware and accept that this data will be displayed on a public web page, accessible to anyone possessing the unique URL associated with your tag.
Data collected: IP addresses, system logs.
Purpose: Ensure the security of our infrastructure, protect the service from cyber attacks (e.g., brute-force attempts), and diagnose technical problems.
Legal Basis: Our legitimate interest (Art. 6.1.f GDPR) to keep the service secure and functioning.
Your data is not sold or transferred to third parties for marketing purposes. It is shared only with:
Some of our service providers may have their servers outside the European Economic Area (EEA). In this case, the transfer of your data is carried out in compliance with applicable regulations, ensuring an adequate level of protection (for example, through the signing of Standard Contractual Clauses approved by the European Commission).
At any time, you can exercise the following rights by sending a request to the email address soshelmetproject@gmail.com:
You also have the right to lodge a complaint with the competent Supervisory Authority (for Italy, the Garante per la Protezione dei Dati Personali).
We reserve the right to update this Privacy Policy. Any changes will be communicated via our website or via email.