Effective Date: 02.06.2025
This Privacy Policy describes how MyNewsly ("we", "us", "our") collects, uses, and shares the personal data of users ("you", "your") who use our website www.mynewsly.com (the "Site").
1. Data Controller
Cristoforo Decaro
Dubsstrasse 34, Zurich
editor@mynewsly.com
2. Personal Data Collected
We collect the following personal data voluntarily provided by users through the preference collection form:
- Email: User's email address.
- Topic: The topic of interest specified by the user.
- Frequency: How often the user wants to receive updates (daily, weekly, monthly).
- Language: The preferred language for content (Italian, English, Spanish, French, German).
- Country: The user's country.
- Newsletter Subscription: Preference regarding subscription to our newsletter.
- Submission Date and Time (created_at): We automatically record the date and time the form is submitted.
- Interaction Data: Information about whether you open our emails, click on links, or interact with specific content.
3. Purposes of Processing
We use the collected personal data for the following purposes:
- Providing personalized updates: Sending newsletters and content based on the specified preferences (topic, frequency, language, country).
- Displaying targeted advertisements within the newsletters, which may be selected based on your preferences, interactions, or other profile data you provide us.
- Managing newsletter subscription: Registering and managing your subscription to our newsletter.
- Improving our services: Analyzing user preferences to improve our content and website offerings.
4. Legal Basis for Processing
The legal basis for processing your personal data is:
- Consent (Art. 6(1)(a) GDPR): For newsletter subscription and profiling for personalized advertising, we obtain your explicit consent via checkboxes or other affirmative actions.
- Legitimate Interest (Art. 6(1)(f) GDPR): For sending personalized updates based on expressed preferences, we believe we have a legitimate interest in providing you with relevant content. You can object to this processing at any time.
- Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) (if applicable).
5. Recipients of Personal Data
Your personal data may be disclosed to:
- Service providers: We may use third-party service providers (e.g., email sending platforms) who act as data processors on our behalf.
- Supabase: Your data is stored in the database provided by Supabase.
- Competent authorities (if required by law).
We do not sell, trade, or rent your personal data to third-party companies. Your data is only used for the purposes described in this policy and will not be shared with third parties for their own marketing or commercial purposes.
6. Transfer of Data Outside the EU
The personal data collected is stored on servers located within the European Union, specifically in Frankfurt, Germany, as provided by Supabase. Therefore, we do not transfer your personal data outside the European Union.
7. Data Retention Period
We retain your personal data for the period necessary to achieve the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Generally:
- Data related to preferences will be retained until the user requests deletion or withdraws consent (for the newsletter).
- Newsletter subscription data will be retained as long as the user remains subscribed.
8. Your Rights
Under the GDPR, you have the following rights:
- Right of access: You can request to know what personal data we hold about you.
- Right to rectification: You can request the correction of inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten"): You can request the deletion of your personal data under certain circumstances.
- Right to restriction of processing: You can request the restriction of the processing of your personal data under certain circumstances.
- Right to data portability: You can receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another data controller.
- Right to object: You can object to the processing of your personal data, especially in the case of profiling for targeted advertisements. If you do not wish to be subject to such processing, you may exercise your right to object by withdrawing your consent or renouncing the service altogether.
- Right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Right to withdraw consent: You can withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
To exercise your rights, please contact us using the contact details provided in section 1.
9. Security Measures
We take appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, destruction, or alteration. Your data is securely stored in the Supabase database, which implements industry-standard security measures, including encryption of data in transit and at rest. Access to the database is limited through authentication and authorization controls.
10. Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. Changes will be posted on our Site with an indication of the update date. We encourage you to review this page regularly for any changes.
11. Contact Us
If you have any questions or requests regarding this Privacy Policy or the processing of your personal data, please contact us using the contact details provided in section 1.