Information on the processing of personal data pursuant to Articles 13–14 of Regulation (EU) 2016/679 (GDPR).
1. Introduction and identity of the Data Controller
This Privacy Policy (hereinafter, "Privacy Policy") is drafted pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, "GDPR"), and applicable national legislation.
This Policy describes how Rumoo collects, uses, stores, protects, and, where applicable, discloses the personal data of users of the Rumoo platform and app (hereinafter, collectively, the "Platform").
Data controller: Mood Global Services B.V.
Registered office: Spinozastraat 47C, 1018 HJ Amsterdam, Netherlands
VAT / Tax ID: NL863644879B01 — registered in the Dutch Companies Register (KvK) under number 85502081
Email: info@moodglobalservices.com
Hereinafter, "Rumoo", "Owner" or "Company".
Data Protection Officer (DPO): Rumoo has not appointed a Data Protection Officer pursuant to Art. 37 of the GDPR, as the mandatory requirements set forth in Art. 37, paragraph 1, letters b) and c), of the GDPR are not met. The Data Controller ensures the presence of an internal contact person responsible for coordinating data protection activities, reachable at info@moodglobalservices.com.
2. Definitions
For the purposes of this Policy, the following definitions apply, consistent with the GDPR and Rumoo's Terms and Conditions:
- Personal data: any information relating to an identified or identifiable natural person ('data subject'), as defined in Art. 4(1) GDPR.
- Processing: any operation or set of operations performed on personal data, whether or not by automated means, pursuant to Art. 4(2) GDPR.
- Data controller: the entity that determines the purposes and means of processing Users' personal data.
- Data processor: a third party that processes data on behalf of the Data Controller pursuant to Art. 28 GDPR.
- Data subject: the natural person whose personal data is being processed, including Platform Users and Creators.
- User: any natural or legal person (through their representatives) who accesses and uses the Rumoo Platform as a Creator, Brand, professional or enterprise.
- Creator: the content creator, influencer or professional who registers on Rumoo to offer their visibility to Brand campaigns.
- Brand: the company, agency, or professional entity that uses Rumoo to discover Creators and manage content marketing campaigns.
- Platform: the set of services, applications, interfaces, APIs, dashboards and digital environments offered under the Rumoo brand, accessible via the web, mobile app and API.
- TikTok/Meta Insights: performance metrics, engagement data, and public indicators obtained through the official TikTok and Meta APIs relating to the Creator's public profile, in compliance with the terms of use of the respective platforms.
- Consent: any free, specific, informed and unambiguous indication of the data subject's wishes, expressed by a declaration or by a clear affirmative action, pursuant to Art. 4(11) GDPR.
3. Scope of application
This Policy applies to all personal data processing carried out by Rumoo in the context of providing the Platform and related services, including:
- access and navigation of the institutional website and the Rumoo web platform;
- registration and account management (Creator, Brand, professional user);
- using the Rumoo mobile app (iOS and Android);
- AI-based analytics, matching, campaign management, prioritization, and decision-making capabilities;
- optional access to TikTok/Meta Insights for algorithmic purposes, subject to obtaining separate explicit consent;
- commercial, support and customer success communications;
- API integrations, enterprise environments, dedicated workspaces, and white-label solutions;
- trial, demo, Pilot or Proof-of-Concept periods.
The Rumoo Platform is intended for professional users and individuals acting in the exercise of their commercial, entrepreneurial, artisanal, or professional activities. Rumoo's services are not intended for minors under 18 years of age. The Data Controller does not knowingly collect personal data from minors; should it become aware of this circumstance, the data will be deleted immediately.
4. Categories of personal data processed
4.1 Professional identification and contact data
During registration, onboarding, and use of the Platform, Rumoo collects the following data:
- name and surname;
- email address (professional or personal);
- professional role and name of the company or organization to which you belong;
- telephone number, if provided voluntarily;
- handles or identifiers of declared social profiles (Instagram, TikTok);
- content of communications sent via contact forms, demo requests, support, or customer success.
4.2 Account data and authentication
- username and login credentials (stored in hashed form);
- roles and permissions assigned within the Platform;
- registration, login, account modification timestamps;
- security and authentication logs;
- tokens, API keys, and session identifiers.
4.3 Technical and usage data
Rumoo automatically collects the following technical data when you access the Platform:
- IP address and network data;
- device type, operating system, browser and version;
- session identifiers and technical cookies;
- application logs, usage events, diagnostics and telemetry;
- pages visited, features used, interaction times;
- Platform performance and availability data.
4.4 Contractual, administrative and commercial data
- billing, license and subscription data;
- order history, renewals and commercial transactions;
- company contacts and contractual data;
- business inquiries, offers, negotiations.
4.5 Data uploaded or provided by the User on the Platform
The User may upload, transmit, or share data, documents, datasets, and materials while using the Platform. The Data Controller processes such data exclusively to provide the Service and in accordance with the User's instructions. The data uploaded by the User remains at the User's disposal and is not used for purposes other than providing the Service, unless specifically agreed to in writing.
4.6 Outputs, inferences and results generated by the Platform
The Platform generates Outputs (reports, rankings, insights, analyses, recommendations) from User and Creator data. These Outputs are intended to support decision-making and do not constitute professional, clinical, legal, tax, or financial advice, nor do they replace qualified human judgment.
4.7 Data from Instagram and TikTok
Data from Instagram:
| Data | Purpose |
|---|---|
| Username, name, profile photo | Creator identification in the profile page |
| Biography (bio) | Thematic relevance to the campaign |
| Follower count, following, and media count | Audience range and engagement rate calculation |
| Post caption and publication date | Thematic relevance, recency, and posting frequency |
| Likes and comments per post | Engagement rate |
| Saves, shares, and views per post | Engagement rate completion |
Data from TikTok:
| Data | Purpose |
|---|---|
| Identifier, username, display name, profile photo | Creator identification |
| Biography (bio) | Thematic relevance to the campaign |
| Follower count, following, and media count | Audience range |
| Video descriptions, date, thumbnail | Thematic relevance and recency |
| Views, likes, comments per video | Content performance |
None of the data listed is used to infer personal characteristics protected under Article 9 of the GDPR (ethnic origin, political opinions, religious beliefs, data concerning health, sexual orientation). No selection, ranking, or campaign matching criteria are based on these characteristics. Rumoo does not knowingly collect special categories of personal data pursuant to Article 9 of the GDPR.
The Creator's biography, if provided, may contain free text written independently by the data subject. Before transmission to processing systems, Rumoo implements technical measures to prevent the processing of any information attributable to special categories incidentally present in the text.
4.8 OAuth connection and access tokens
The connection of Instagram and/or TikTok accounts occurs via the OAuth protocol, through which the Creator authorizes Rumoo to read-only access to their profile data and published content. Rumoo receives and retains OAuth access tokens exclusively for the duration of the active account connection. When the Creator disconnects the account or deletes the Rumoo profile, the tokens are actively revoked on the respective platforms and deleted from Rumoo systems at the same time. Rumoo does not use the tokens for purposes other than the data synchronization described in this section, does not transmit them to third parties, and does not retain them beyond the termination of the connection.
5. Purposes of the processing and legal bases
5.1 Service provision, account management and contractual relationship
The processing of identification, account, contractual, and technical data is necessary to register the User, provide the Service, manage the account, fulfill contractual obligations, provide assistance and support, and manage trials, demos, onboarding, and renewals.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract to which the data subject is party or implementation of pre-contractual measures taken at the request of the data subject.
5.2 Fulfillment of legal obligations
Rumoo processes data to the extent necessary to comply with legal, tax, accounting, and regulatory obligations, or orders from competent authorities.
Legal basis: Art. 6(1)(c) GDPR — fulfillment of a legal obligation to which the Data Controller is subject.
5.3 Security, prevention of abuse and protection of rights
Rumoo processes technical data, security logs, and login information to ensure the security of the Platform, prevent unauthorized access, abuse, fraud, and misuse, and protect its rights and technological assets.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the Data Controller, balanced with the rights and freedoms of data subjects. The legitimate interest consists in protecting the integrity of the Platform, preventing unlawful conduct, and protecting User data.
5.4 Product improvement, aggregate analysis and service development
Rumoo uses technical, usage, and aggregated data to analyze Platform performance, identify anomalies, improve functionality, conduct troubleshooting, and develop and validate new features and services. These activities are performed, where possible, on aggregated or pseudonymized data.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the Data Controller in continuously improving the Service, balanced with the rights of data subjects. Where specific analysis activities require consent, this will be collected separately.
5.5 Marketing, commercial communications and follow-up
With the User's consent, Rumoo may send commercial communications, newsletters, product updates, invitations to events or webinars, and follow-up on demo requests or offers. The User may withdraw consent at any time, without prejudice to the lawfulness of the previous processing.
Legal basis: Art. 6(1)(a) GDPR — consent of the data subject.
For existing customers, Rumoo may send communications about products and services similar to those already purchased, pursuant to the 'soft opt-in' procedure and in compliance with applicable ePrivacy legislation, with the right to object at any time.
5.6 Legal basis for TikTok/Meta Insights
The connection of social media accounts and the reading of their data occurs exclusively through the official OAuth flow of the respective platforms (Meta and TikTok), through which the Creator expressly authorizes Rumoo to read-only access to the data indicated in Section 4.7. Rumoo does not use data aggregators, does not perform scraping, and does not access data outside the perimeter authorized by the Creator via OAuth. Access is limited to the permissions and scopes listed in Section 4.7, without further extensions.
6. Artificial intelligence, algorithms and automated decisions
Rumoo uses artificial intelligence and machine learning components to support analytics, prioritization, Creator-Brand matching, insight generation, and Service optimization. The general logic behind this processing is described below, in accordance with Articles 13(2)(f) and 22 of the GDPR.
6.1 General logic of algorithmic processing
Rumoo's algorithmic models process User data (profile metrics, performance data, stated preferences, usage history) to generate outputs such as rankings, matching suggestions, performance analyses, and operational recommendations. The processing logic is based on statistical analysis, machine learning, and optimization techniques, applied to the available data in accordance with the minimization principle.
6.2 Nature of Outputs and system limits
The Outputs generated by the Platform (reports, rankings, analyses, recommendations) are intended to support decision-making and do not constitute binding professional, clinical, legal, tax, financial, or strategic marketing advice, nor do they replace qualified human judgment. The User is and remains solely responsible for interpreting, verifying, validating, and using the Outputs within their operational, regulatory, and organizational context.
6.3 Absence of solely automated decisions pursuant to Art. 22 GDPR
Unless otherwise specifically communicated in relation to specific features, Rumoo does not adopt decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect data subjects, pursuant to Art. 22 GDPR. If such features are introduced in the future, data subjects will be informed and will be able to exercise their rights under the GDPR.
6.4 AI Act
Rumoo monitors the evolution of applicable regulations regarding artificial intelligence, including Regulation (EU) 2024/1689 (AI Act), and is committed to adapting its practices and documentation to the applicable obligations within the deadlines set by the legislation.
7. Access to TikTok/Meta Insights for algorithmic purposes
7.1 Optional nature and explicit consent
Access to TikTok/Meta Insights is an optional feature of the Platform. Creators can freely choose whether or not to activate this feature, without denial affecting access to the basic features of Rumoo. Processing is subject to the acquisition of explicit, freely given, specific, informed, and revocable consent, collected via a separate and non-preselected checkbox in the registration flow or in the account settings.
7.2 Purposes of the processing
Access to TikTok/Meta Insights, if the Creator gives their consent, is permitted exclusively for the following algorithmic and analytical purposes:
- building and updating the Creator profile on the Platform;
- matching between Creators and Brands in content marketing campaigns;
- improving Rumoo's algorithmic models;
- optimization of the analysis and personalization features of the Service;
- generation of aggregated and anonymized insights to support the Platform's functionality.
There is no intention to sell, rent, license, or otherwise directly market Users' personal data to third parties for any purpose.
7.3 Categories of data processed
Through the official TikTok and Meta APIs, or through authorized third-party providers, Rumoo can access only the following categories of data:
- number of followers;
- engagement rate;
- average views per post/video;
- number of recent posts;
- average reach;
- other performance and engagement data publicly available through the official APIs.
Rumoo does not access, collect, or process images, videos, post text, third-party comments, follower identities, contact lists, private messages, sensitive data, or personal data of anyone other than the Creator.
7.4 Legal basis
Main legal basis: explicit consent of the Creator pursuant to Art. 6(1)(a) GDPR. Supplementary legal basis: performance of the contract pursuant to Art. 6(1)(b) GDPR, limited to the data strictly necessary for the provision of the matching service.
The processing is carried out in compliance with the principles set forth in Article 5 of the GDPR: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
7.5 Data acquisition methods
Rumoo acquires TikTok/Meta Insights through:
- Official TikTok and Meta APIs: in compliance with the respective terms of use, existing authorization agreements and the technical limits imposed by the platforms.
- Specialized third-party providers (aggregators): entities such as Phyllo, Modash, HypeAuditor or equivalent, which operate based on direct agreements with Meta and TikTok and act as data processors pursuant to Art. 28 GDPR.
Rumoo does not perform unauthorized scraping, does not access data outside the perimeter authorized by the platforms, and does not collect data from Creators who have not completed registration on Rumoo and given consent.
7.6 Retention
Metrics acquired through TikTok/Meta Insights are retained for the duration of the Creator's Rumoo account and for a period no longer than 30 days after account deletion or withdrawal of consent. Rumoo periodically updates the metrics with the frequency indicated in the Platform settings and communicated to the Creator at the time of consent.
7.7 Withdrawal of consent
The Creator may withdraw consent to access TikTok/Meta Insights at any time, without prejudice to the lawfulness of the processing carried out prior to the withdrawal, by:
- account settings (Settings > Privacy > Manage metrics);
- written request to info@moodglobalservices.com.
After withdrawal, Rumoo will no longer access and update the Creator's TikTok/Meta Insights. Already collected metrics will be deleted within 30 days of withdrawal. The Creator will receive confirmation of the withdrawal and the deletion.
7.8 Prohibition on the sale of data
Rumoo does not sell, rent, license, or market Users' personal data, including TikTok/Meta Insights, to third parties for their own commercial purposes. The data is processed exclusively for the algorithmic and analytical purposes described in this section.
8. Identity verification via bio-code challenge
Upon registration, Rumoo may require the Creator to verify their declared Instagram and/or TikTok profile through a bio-code challenge system. Rumoo generates a unique code that the Creator temporarily inserts into their public bio; Rumoo performs a single automated scan of the public profile to detect the code and verify account ownership. The Creator can remove the code immediately after verification.
During this process, Rumoo only reads the profile bio and does not acquire or store any other profile data. The unique code is deleted upon completion of the verification; the verification log (declared handle, outcome, timestamp) is retained for a period not exceeding 12 months.
10. Recipients and communication of data
Users' personal data may be communicated or made accessible, within the limits strictly necessary for the purposes indicated in this Policy, to the following categories of recipients:
10.1 IT service providers, infrastructure and support
The following entities process Creators' personal data on behalf of Rumoo, acting as data processors pursuant to Article 28 of the GDPR, based on specific Data Processing Agreements:
- OpenAI (OpenAI, LLC, San Francisco, USA): receives the Creator's bio text and captions of published content to generate vector representations (embeddings) used by the ranking engine to calculate thematic affinity between creators and campaigns. The transfer to the US is based on the Standard Contractual Clauses (SCCs) adopted by the European Commission.
- Supabase (Supabase Inc., USA): database provider that hosts the entire Platform data store, including creator profile data synchronized from Instagram and TikTok. The transfer, where applicable, is based on the Standard Contractual Clauses (SCCs).
- Vercel (Vercel Inc., San Francisco, USA): application hosting provider. It processes data to the extent technically necessary to provide the Service. The transfer to the USA is based on the Standard Contractual Clauses (SCCs).
None of the above-mentioned parties is authorized to use the data received for their own purposes or for purposes other than those indicated. Rumoo does not sell, rent, or license the data obtained from Meta or TikTok to third parties.
10.2 Creator data aggregators
Third-party providers specializing in the collection and provision of social profile metrics (e.g., Phyllo, Modash, HypeAuditor, or equivalent), who act as data processors pursuant to Art. 28 GDPR based on direct agreements with Meta and TikTok. These parties receive data only to the extent necessary to provide the Service and for the purposes indicated in Section 7.
10.3 Consultants and professionals
Legal, tax, accounting, or technical consultants who assist Rumoo in carrying out its business, who act as independent data controllers or, where applicable, as data processors.
10.4 Public authorities and authorized entities
Judicial, administrative, control, or supervisory authorities, to the extent that disclosure is required by law, by order of the authority, or necessary to protect the Data Controller's rights.
Personal data will not be transferred, sold, or disclosed to third parties for their own commercial purposes. No systematic disclosure of data to parties not listed in this Policy is foreseen, unless the data subject has expressly consented or it is required by law.
11. Data transfers to third countries
Users' personal data is processed primarily within the European Economic Area (EEA). Some of Rumoo's technical providers or partners may be located in countries outside the EEA, including the United States.
In such cases, Rumoo guarantees that the transfer takes place in compliance with the provisions of Chapter V of the GDPR, through one or more of the following tools:
- European Commission adequacy decision, where available (e.g., EU-US Data Privacy Framework for certified providers);
- Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR;
- other appropriate guarantees pursuant to Art. 46 GDPR.
Detailed information on transfers to third countries and the guarantees adopted is available upon request by contacting the Data Controller at the address indicated in Section 1.
12. Retention periods
12.1 Retention
Personal data is retained for the time strictly necessary for the purposes for which it was collected, in compliance with the storage limitation principle pursuant to Art. 5(1)(e) of the GDPR, and in any case no longer than the terms imposed by applicable legal obligations.
- Account and contractual data: retained for the entire duration of the contractual relationship and, subsequently, for the period necessary to fulfill legal obligations (tax, accounting, regulatory) and to protect the rights of the Data Controller, in any case no longer than 10 years from the termination of the relationship, unless otherwise provided by law.
- Technical data and security logs: retained for a limited period of time proportionate to security and diagnostic purposes, generally no longer than 12 months, except for the need to investigate security incidents or to comply with requests from the authorities.
- Data for marketing and commercial communications: retained until the data subject withdraws consent or exercises the right to object.
- TikTok/Meta Insights — data synchronized from Instagram and TikTok (profile, metrics, content, embeddings): retained for the duration of the Creator's active account on Rumoo and for a period of 30 days following the disconnection of the social media account, the deletion of the Rumoo profile, or the data subject's deletion request. After this period, the data is permanently and irreversibly deleted, including vector representations generated by OpenAI.
- OAuth tokens: retained exclusively for the duration of the active connection. Upon disconnection, they are revoked on the originating platform and deleted from Rumoo systems simultaneously, without a grace period.
- Deletion requests: completed within 30 days of receiving the request. Within 72 hours of receipt, the Creator receives written confirmation indicating the expected deletion date and the status of the request. A status page in the Creator's profile indicates the updated status (in progress/completed).
- Bio-code verification log: declared handle, outcome, and timestamp retained for no more than 12 months.
- Browsing data and technical cookies: for the time strictly necessary for the session or, for persistent cookies, for the duration indicated in the Cookie Policy.
Upon expiration of the retention periods, the data is securely deleted or anonymized, so that the data subject can no longer be identified.
12.2 Disconnecting your social media account and deleting your data
The Creator may disconnect their Instagram and/or TikTok account from the Rumoo Platform at any time by accessing Settings > Account > Linked Accounts > Disconnect. Disconnecting will immediately revoke the OAuth token and initiate the process of deleting synchronized data, which takes 30 days to complete.
The Creator may request the complete deletion of their Rumoo profile and all associated data by accessing Settings > Account > Delete Account, or by sending a written request to info@moodglobalservices.com. Following the request, the Creator will receive confirmation within 72 hours with the expected effective date of deletion. The status of the request can be viewed in the profile until deletion is completed.
Rumoo does not transfer the data obtained from Meta or TikTok to third parties for their own purposes, nor does it sell it or use it for purposes other than those indicated in this Policy.
13. Security measures
Rumoo adopts appropriate technical and organizational measures to ensure a level of security appropriate to the risk, pursuant to Art. 32 GDPR, to protect Users' personal data from unauthorized access, loss, destruction, alteration, disclosure, or any other form of unlawful processing.
The main measures adopted include:
- encryption of data in transit (TLS/HTTPS) and, where appropriate, at rest;
- hashing of login credentials;
- need-to-know access control;
- multi-factor authentication for privileged access;
- segregation of environments and data of different customers (multi-tenant);
- continuous security monitoring, vulnerability assessment, and periodic penetration testing;
- security incident management and data breach notification procedures pursuant to Article 33 of the GDPR;
- training of personnel authorized to carry out the processing.
Despite the adoption of these measures, no IT system can guarantee absolute security. In the event of a personal data breach that may pose a high risk to the rights and freedoms of data subjects, Rumoo will notify the data subjects without undue delay, pursuant to Art. 34 GDPR.
14. Rights of the data subject
Data subjects have the right to exercise, against Rumoo as Data Controller, the following rights provided for by Articles 15–22 of the GDPR:
- Right of access (Art. 15 GDPR): obtain confirmation as to whether personal data concerning them is being processed and, if so, access to such data and information on the processing.
- Right to rectification (Art. 16 GDPR): obtain the correction of inaccurate personal data or the completion of incomplete personal data.
- Right to erasure ('right to be forgotten', Art. 17 GDPR): obtain the erasure of your personal data, in the cases provided for by law.
- Right to restriction of processing (Art. 18 GDPR): obtain the limitation of processing in the cases provided for by the legislation.
- Right to data portability (Art. 20 GDPR): receive your personal data in a structured, commonly used, and machine-readable format and transmit that data to another controller, where the processing is based on consent or a contract and is carried out by automated means.
- Right to object (Art. 21 GDPR): object to the processing of your personal data when this is based on the legitimate interest of the Data Controller.
- Right to withdraw consent (Art. 7(3) GDPR): withdraw the consent given at any time, without prejudice to the lawfulness of the processing based on consent before its withdrawal.
- Right to lodge a complaint (Art. 77 GDPR): lodge a complaint with the competent supervisory authority: Autoriteit Persoonsgegevens (AP), Netherlands (www.autoriteitpersoonsgegevens.nl), or, for users residing in Italy, with the Italian Data Protection Authority (www.gpdp.it).
To exercise their rights, the data subject can send a written request to the email address info@moodglobalservices.com, or through the features available in the Rumoo Dashboard (Settings > Privacy). Rumoo responds to requests within 30 days of receipt, unless an additional two-month extension is required in cases of particular complexity, and will notify the data subject accordingly.
15. Minors
The Rumoo Platform is intended exclusively for professional users and individuals acting in the exercise of their commercial, entrepreneurial, or professional activities. Rumoo's services are not intended for persons under the age of 18.
The Data Controller does not knowingly collect personal data from minors. If the Data Controller becomes aware that it has received personal data from a minor without the consent of the parent or guardian, it will delete such data immediately. Anyone aware of any inappropriate processing is encouraged to contact the Data Controller at the address indicated in Section 1.
16. Changes to this Policy
Rumoo reserves the right to modify this Policy at any time due to regulatory, technological, or operational developments. Substantial changes will be communicated to registered Users via email or in-app notification with reasonable notice.
The updated version of the Privacy Policy is always available on the Platform. The date of the last update is indicated at the top of this Policy. Users are encouraged to consult this page periodically.
Your continued use of the Platform following the posting of changes constitutes acceptance of the updated Privacy Policy, to the extent permitted by applicable law.
17. Contacts and complaints
For any requests regarding the processing of personal data, the exercise of the rights set forth in Section 14, or to report alleged violations of this Policy, data subjects may contact the Data Controller at the following addresses:
Data controller: Mood Global Services B.V.
Registered office: Spinozastraat 47C, 1018 HJ Amsterdam, Netherlands
General email / support: info@moodglobalservices.com
Privacy / GDPR: info@moodglobalservices.com
Platform: rumoo.app
To lodge a complaint with the competent supervisory authority: Autoriteit Persoonsgegevens (AP), Huis te Landelaan 492, 2283 SZ Rijswijk, Netherlands — www.autoriteitpersoonsgegevens.nl. Users residing in Italy may also contact the Italian Data Protection Authority, Piazza Venezia 11, 00187 Rome — www.gpdp.it.