Technology Licence Agreement
These general licence terms (the "General Terms" or the "Agreement") govern the use of the "Vitality+" software, accessible through a mobile application (the "App") and a web application (the "Web App"), which allows companies to monitor and improve the physical and psycho-social wellbeing of their employees by collecting, analysing and displaying indicators relating to stress, health and quality of life (collectively, the "Software").
The software is provided by Vitality Plus SA, with registered office at Via Emilio Maraini 27, 6942 Savosa, CHE-169.816.147 (the "Licensor" and/or "Vitality Plus"), and is accessible through the Google Play and Apple Store stores or through the Website.
To use the Software and its services it is necessary to complete the purchase procedure, register as a customer (the "Licensee") and accept these General Terms.
The Licensee acknowledges that the annexes to these General Terms, namely the Data Processing Agreement (the "DPA" – Annex A) and the privacy notice (the "Privacy Notice" – Annex B), are a substantial and integral part of these General Terms, and undertakes to sign them by way of acknowledgement and to send them, signed, to Vitality Plus SA.
In order to facilitate the Licensee's legal and privacy compliance of the Service towards its own Users, the Licensor provides specific documentation in "template" form which may be used by the Customer Company as a supporting tool to govern its relationship with End Users (End User General Terms and Conditions – Annex C) and the privacy notice (the "End User Privacy Notice" – Annex D1/D2).
The documentation provided in Annexes C and D must first be customised by the Licensee and then uploaded.
By accepting these General Terms, the Licensee declares that it has carefully read their content and undertakes to observe and comply with the provisions contained therein.
1. Definitions
1.1. In addition to the terms and expressions defined elsewhere in these General Terms, the terms and expressions listed below have, for the purposes of these General Terms, the meaning indicated for each of them:
"Software" (or, generically, the "Platform"): the program developed by Vitality Plus SA which, through a digital service, allows licensees to improve the corporate wellbeing of their employees and/or collaborators through an APP and Web APP named "Vitality+", designed to promote physical, mental, spiritual and relational health.
"Customers" (or, generically, "Users"): all parties who purchase a licence to the Software in order to integrate it into their own business processes.
"End Users": the employees, collaborators or persons associated with the Customer who use the Software licensed by the Licensee.
"Account": the access credentials (username and password) required to use the Software.
"Intellectual Property Rights": any right relating to patentable and non-patentable inventions, patent rights, database rights, copyright and related rights including copyright in the Software, in the source code and algorithms, in databases, as well as trade secrets pursuant to Articles 98-99 of the Italian Industrial Property Code (i.e., Legislative Decree no. 30 of 10 February 2005), design rights, rights in drawings and models, trademarks, domain names and any other right relating to any industrial and/or intellectual property, whether registered or not, including all rights to apply for such rights.
"Third-Party Content": materials, videos, texts, audio, articles or other contributions produced by external professionals and made available within the Software.
"Services": the Software, its documentation, maintenance, technical support, updates and agreed optional services.
"Documentation": user manuals, guides, technical specifications and any other information provided by the Licensor relating to the Software.
"AI or Recommendation Algorithm": artificial intelligence systems integrated into the Software which analyse personal and behavioural data in order to provide personalised suggestions or programmes.
2. Subject matter of the Agreement
2.1. Under these General Terms and against payment of the subscription purchased by the Licensee, the Licensor undertakes to provide the Licensee with the following Services: a) access to and use of the Software, on the basis of a non-exclusive, non-sub-licensable (except as expressly authorised by the Licensor), non-assignable and non-transferable licence, valid worldwide and for the entire term of these General Terms (the "Licence"); b) maintenance and updating of the Software; c) integration of the Software with the Licensee's Domains for the management of End User support; d) reporting and analysis of Software activity; e) technical support managed directly by the Licensor's tech team; f) periodic updates of the underlying AI model, to ensure optimal performance of the recommendation algorithm; g) customisation of the "Challenges" and of the reward system connected to the activities carried out by the End User.
The Licensee may grant use of the Software to End Users who: (a) are at least 18 years old; (b) are employees, collaborators or associated persons operating within its corporate organisation; (c) accept a set of general terms and conditions whose content complies with the template attached to the Agreement as Annex C ("End User General Terms and Conditions"); and (d) read and, consequently, accept the processing of personal data as set out in the privacy notice attached as Annex D ("User Privacy Notice").
2.2. Depending on the subscription to the Services purchased, the Licensee may have a limited or unlimited number of accounts available according to the plan chosen. The Licensee may purchase additional licences to create further accounts, subject to agreement with the Licensor.
2.3. The Licensee acknowledges that the Software uses recommendation intelligence systems and that the data processed through the Software is managed in accordance with the DPA and the Privacy Notice annexed to this Agreement.
2.3-bis The Licensee acknowledges that, for the purposes of Regulation (EU) 2024/1689 (the "AI Act"), the Licensor qualifies as the provider of the artificial intelligence systems integrated into the Software, while the Licensee qualifies as the deployer of such systems in the course of its professional activity. Should one or more artificial intelligence systems integrated into the Software be classified as "high-risk" pursuant to Annex III of the AI Act, the obligations under Article 26 of that Regulation (including, by way of example, human oversight, monitoring of operation, retention of automatically generated logs for an appropriate period, informing workers' representatives and affected workers before putting the system into service in the workplace and, where applicable, the fundamental rights impact assessment pursuant to Article 27) shall rest with the Licensee as deployer, without prejudice to the Licensor's obligation, as provider, to supply the information and technical documentation necessary for the Licensee to comply, including an impact assessment template made available on request.
The Licensor declares that the Software does not currently integrate artificial intelligence systems intended to infer the emotions or state of mind of natural persons in the workplace, nor any other artificial intelligence practice prohibited under Article 5 of the AI Act. It is understood that the aggregate analysis features intended for managers and human resources staff operate exclusively on aggregated data subject to minimum group thresholds, as further described in the technical documentation made available by the Licensor on request.
Pursuant to Article 50 of the AI Act, the Licensor ensures that End Users are informed, through appropriate notices within the Software, that they are interacting with an artificial intelligence system. The Licensee undertakes not to remove, alter or conceal such notices within any customisations of the Software it may make, where permitted.
2.3-ter It remains understood that the use of the Software features that integrate artificial intelligence systems (including, by way of example, the Recommendation Algorithm) may be subject to usage limits (by way of example, as to the number of interactions allowed, the frequency of updates to suggestions or access to advanced features), differentiated according to the type of subscription plan purchased by the Licensee under Article 2.2 above, as detailed in the order form and/or commercial proposal signed by the Licensee.
2.4. The Licensee expressly acknowledges that, in order to use the Services, it must first register on the Platform in accordance with Article 3 "Registration" below, after accepting these General Terms.
3. Log-in
3.1. To access the Software and use the Services, the Licensee must: (i) create an account on the App or Web App (the "Account"); and (ii) access the Software with its own authentication credentials after creating the Account; (iii) receive accreditation/authorisation from the Licensor.
3.2. To create the Account, the Licensee must: (i) correctly fill in the fields of the log-in form, entering all the data requested (by way of example and without limitation, company name, e-mail address, username and password); (ii) confirm that it has read the Privacy Notice; (iii) accept these General Terms; and (iv) confirm the access procedure.
3.3. When the Account is created, a one-time code will be sent, which will be renewed at each new log-in. The Licensee is solely responsible for maintaining the confidentiality and security of the Account access credentials, which must not be transmitted or otherwise disclosed, even partially, to unauthorised third parties.
3.4. The Licensee undertakes to promptly notify the Licensor of any breach of Account security and/or loss of access credentials, and/or any unauthorised use of the Account, by sending a communication to the addresses set out in Article 19.5 of these General Terms.
3.5. Indemnity for unauthorised use of the Account
The Licensee undertakes to hold the Licensor harmless from any loss or damage arising from the Licensee's failure to keep its Account access credentials secure or to promptly notify the Licensor of the unauthorised use, loss or theft of the Account access credentials.
4. Term of the Agreement
4.1. Automatic renewal
These General Terms are concluded at the moment they are accepted by the Licensee, remain in force for a period of 12 months from the date of signature (the "Expiry Date") and shall be deemed automatically renewed on the Expiry Date for successive periods of one year each, unless the Licensee cancels the subscription in the manner described in Article 5.3 below.
4.2. In the case of multi-year or customised subscriptions, the term shall be that specifically agreed between the Parties.
5. Subscription, invoicing and cancellation
5.1. Subscription
5.1.1. To purchase a subscription and use the Services, the Licensee must sign a written order form with the Licensor and make payment by bank transfer payable to "Vitality Plus". The Licensee acknowledges and accepts that, unless the subscription is cancelled, it will automatically renew on the Expiry Date and the Licensor will be entitled to payment of a further annual fee.
5.2. Invoicing
5.2.1. Billing cycle. The Licensee acknowledges and accepts that the subscription fee for the Services shall be paid by bank transfer according to the timing agreed with the Licensor in the order form (the "Invoicing Date"). The billing cycle is annual.
5.2.2. Unpaid amounts. The Licensee acknowledges and accepts that, in the case of payment in instalments (e.g. quarterly) of the subscription, should a subscription payment fail or not be made for any reason not attributable to the Licensor, the Licensor reserves the right to suspend access to the Services until the outstanding amount has been paid. Suspension of the Services does not release the Licensee from the obligation to pay the fees due for the period of suspension.
5.2.3. In the event of non-payment for more than 15 days after the due date, default interest shall apply pursuant to Italian Legislative Decree 231/2002 for B2B relationships, and the Licensor may, in addition to suspending access to the Services, terminate the agreement after 30 days of persistent default pursuant to Article 13 of these General Terms.
5.3. Cancellation of the Subscription
5.3.1. The Licensee may cancel the subscription by sending written notice to the Licensor with a minimum notice period of 30 days before the Expiry Date, unless otherwise provided in the Order Form. Cancellation takes effect at the end of the current subscription period.
5.3.2. Non-refundable fee. The Licensee acknowledges and accepts that the subscription fee purchased is non-refundable, unless otherwise agreed in writing between the Parties. In the event of withdrawal from these General Terms through cancellation by the Licensee of its subscription to the Services, the Account will be closed automatically at the end of the current billing cycle.
6. Amendments to the General Terms
6.1. The Licensor reserves the right to amend these General Terms, including the cost of the subscription, where there are justified reasons, including: (a) reasons of public interest and/or security; (b) reasons connected with proper compliance with legislative and/or regulatory obligations; (c) reasons related to legislative and/or regulatory changes; (d) reasons related to the implementation of updates and technical improvements to the Services, including any technical update of the Software; (e) reasons related to the improvement and/or modification of the Services, as well as the design of new services by the Licensor; (f) technical, organisational and/or commercial reasons requiring changes without which the Licensor would be unable to continue providing the Services covered by these General Terms.
6.2. Amendments to these General Terms shall be communicated in writing to the Licensee by publication on its account or by communication to the e-mail address provided by the Licensee at registration, with 14 days' notice before the date on which the amendment actually takes effect (the "Notice Period").
6.3. If the Licensee does not intend to accept the amendments to these General Terms, including any changes to the subscription fee, it shall have the right to withdraw from these General Terms within the Notice Period, by cancelling the subscription to the Services in the manner set out in Article 5.3 above.
6.4. If the Licensee does not exercise its right of withdrawal within the Notice Period, the amendments to these General Terms shall be deemed definitively known and accepted by the Licensee and shall become definitively effective and binding.
7. Use of the Software demo
7.1. The Licensee – at the Licensor's discretion – may access a reduced or simplified version of the Software (the "Demo"). While the demo is being used, these General Terms shall apply insofar as relevant. The Licensor may at any time revoke access to the reduced or simplified version of the Software.
8. Obligations of the Licensee
8.1. The Licensee undertakes to refrain, directly and/or indirectly (for example through third parties), from: (i) circumventing or attempting to circumvent the technical protection measures and technical restrictions applied to the Software for the purpose of identifying codes and/or algorithms of any kind and nature; (ii) analysing, decrypting, decompiling, disassembling and/or reverse engineering the Software or attempting to carry out such activities; (iii) altering, modifying and/or processing the Software in any way; (iv) reproducing, modifying, adapting, customising the Software and/or developing, or having developed, derivative products; (v) making or having made copies of the Software; and (vi) commercialising the Services in any way, including the Software, without the Licensor's written authorisation.
8.2. The Licensee undertakes to use the Services in compliance with and within the limits of the conditions provided for by the subscription purchased, and also undertakes to comply with the limitation on the number of accounts, unless otherwise agreed with the Licensor.
8.3. The Licensee remains solely responsible for the use of the Services and for any data, information, video, image, photograph and/or content of any nature uploaded, sent, published, displayed and/or otherwise transmitted through the use of the Services, including by End Users.
8.4. The Licensee must use the Services exclusively for lawful purposes and in compliance with applicable laws, including those on intellectual property, the protection of personal data and electronic communications.
8.5. By accepting these General Terms, the Licensee acknowledges and accepts that: (i) any use of the Software, the Platform and the Services that is improper or otherwise different from that permitted under these General Terms is prohibited; (ii) these General Terms and/or any provision contained therein may under no circumstances be interpreted as granting the Licensee express or implied rights of any kind and nature in the Software other than and in addition to those expressly granted under these General Terms; (iii) the adoption of the Software within its corporate context may not prejudice workers' rights or constitute a monitoring and/or surveillance tool; and (iv) the personal data provided by the Licensee's employees/collaborators shall be processed by default in aggregated and anonymous form both by the Licensor and by the Licensee, unless expressly requested otherwise by the latter.
8.6. Content warranties and indemnity
The Licensor expressly warrants that it holds all rights in the Third-Party Content present within the Service and undertakes to indemnify and hold the Licensee harmless from any third-party claim relating to such Content, including any infringement of intellectual property rights, copyright, privacy rights or other applicable rules.
9. Intellectual property
9.1. The Licensee must use the Services in full compliance with the Intellectual Property Rights owned by the Licensor and/or third parties. The Licensor is and shall remain the sole and exclusive owner and holder of all Intellectual Property Rights in the Software (including the source code) and in every content, information, trademark, logo and/or other distinctive sign present within the Software. The Licensor shall also own any Intellectual Property Right in any customisation and/or parameterisation implemented with reference to the Software at the Licensee's express request.
9.2. The Licensee undertakes not to contest the Licensor's exclusive ownership of the Intellectual Property Rights in the Software and/or the Platform and any subsequent customisations thereof, and undertakes not to take any action that could compromise or otherwise prejudice the Licensor's ownership of such Intellectual Property Rights, including in the event of expiry, termination, withdrawal and/or cessation, for any reason, of these General Terms.
9.3. The Licensee undertakes to use the Software in full compliance with the conditions and limitations provided for by the Licence, as detailed in Article 2 of these General Terms.
9.4. The Licensee authorises the Licensor to use the Licensee's trade name, trademark and logo as a customer reference for marketing purposes, unless otherwise agreed in writing between the Parties.
9.5. Ownership of improvements resulting from machine learning
All improvements, optimisations and adaptations of the AI model and of the Software, even if resulting from use with the Licensee's Content or from learning based on End Users' interactions, remain the exclusive property of the Licensor. The Licensee acknowledges and accepts that the machine learning process may lead to improvements of the AI model that transcend the individual Content provided and represent an evolution of the Technology owned by the Licensor.
10. Acknowledgements
10.1. The Licensee expressly accepts and authorises that, in response to End Users' questions as to who owns and/or developed the Technology and/or the Chatbot (and/or similar questions), the Chatbot shall indicate the Licensor as the owner of the Technology.
10.2. The Licensee undertakes to state in all press releases relating to the Software that the Technology was developed by and is owned by the Licensor; in this regard, the Licensee shall, at its own choice, refer to the Licensor as Vitality Plus SA.
10.3. The Licensee acknowledges: (i) that the Software is a system for improving the corporate wellbeing of employees and/or collaborators; (ii) that the assessments made by the Software may not reflect the positions and/or views of the Licensor and/or the Licensee; (iii) that the Software uses constantly evolving AI technologies and that the answers generated may not always be accurate, truthful, up to date or otherwise relevant; (iv) that no interaction may constitute a binding commitment for the Licensee and/or the Licensor; (v) that the parameters provided must always be subject to "human" review; (vi) that the Software cannot replace medical and/or professional advice and/or therapeutic indications.
11. Premium Services, management of the rewards budget and redemption
11.1. The Licensee may request specific customisations of the Software and/or additional services not included in the standard subscription (the "Premium Services").
11.2. The Premium Services, where available and always subject to the Licensor's availability, shall be the subject of a specific quotation by the Licensor and shall be governed by agreements supplementing the General Terms.
11.3. The Licensee may set up a rewards budget in order to reward its employees and/or collaborators who achieve the wellbeing objectives set by the Platform.
11.4. The Licensee may decide to entrust the entire management of the rewards budget, including the delivery of the related prizes, to the Licensor by means of written consent given when subscribing to the Service.
11.5. The management of Rewards is quantified on the basis of the Budget set by the Licensee which, in agreement with the Licensor, shall establish the timing and manner of delivery of each Reward. Rewards earned may be redeemed through the application by the expiry date of the current annual contractual period and within the limits of the Budget allocated. Vouchers must be used at partner merchants by the same deadline. Once these deadlines have passed, rewards not redeemed or not used shall definitively lapse without any right to a refund.
11.6. The redemption and use of rewards are subject to the licence agreement between the Licensor and the Licensee being in force at the same time and to the continuation of the employment relationship between the employee and the company. If either relationship ends, the employee/collaborator immediately loses all rights to rewards earned but not redeemed and may not use rewards already redeemed.
12. Warranties and service levels
12.1. The Licensor warrants that the Services shall be provided with reasonable care and skill and shall substantially comply with the specifications published on the App or Web App or otherwise agreed in writing between the Parties.
12.2. The Licensor undertakes to maintain Software availability of at least 99.5% on a monthly basis, excluding scheduled maintenance periods, which shall be communicated to the Licensee with adequate notice.
12.3. The Licensor undertakes to respond to technical support requests within 14 days of receipt of the request.
12.4. No warranty on the AI recommendation process
The Software integrates artificial intelligence (AI) and personalised recommendation algorithms which process the personal data provided by End Users (e.g. level of physical activity, stress parameters, sleep quality, individual preferences, blood tests, etc.) in order to suggest content, wellbeing programmes, physical exercises and other activities aimed at improving general psycho-physical condition; the Licensor provides no warranty that the recommendations generated are free from errors. It is further specified that the recommendations are automatic, probabilistic and not free from errors, and therefore do not constitute medical prescriptions or individual health advice.
12.5. Medical disclaimer and disclaimer of liability for content
The suggestions, recommendations, programmes and multimedia content available in the Software – including those generated by artificial intelligence algorithms or provided by third parties – do not in any way constitute a diagnosis, treatment or medical prescription, nor should they be used as a substitute for professional medical consultations, clinical examinations or treatment plans. End Users are invited to consult a doctor or a qualified professional before undertaking any exercise, nutrition or stress-management programme or suggestion provided by the Software. The Licensor does not guarantee the accuracy, completeness or reliability of such content and disclaims all liability for any damage arising from its use.
13. Termination
13.1. The Licensor shall be entitled to terminate these General Terms with immediate effect pursuant to Article 1456 of the Italian Civil Code where the Licensee uses the Services in breach of these General Terms and/or in breach of applicable laws and regulations and/or for unlawful purposes and, in particular, for breach of Articles 2.2, 3.4, 5.2.2, 5.2.3, 8 and 9.
13.2. The foregoing is without prejudice to the right of the Parties, where the circumstances so require and it is deemed appropriate, to take any suitable action for the termination of these General Terms pursuant to and for the purposes of Articles 1453 and 1454 of the Italian Civil Code.
13.3. In the event of termination of the Agreement for any reason: (i) the Licensee must immediately cease using the Services and inform the Users; (ii) the Licensor may deactivate the Licensee's Account; and (iii) each Party must return or destroy (at the disclosing Party's discretion) all confidential information of the other Party.
14. Processing of personal data
14.1. The Licensee acknowledges that the acceptance and performance of these General Terms involve the processing by the Licensor of personal data relating to the Licensee or to its employees and collaborators. The Licensor undertakes to process the so-called "special category" personal data of End Users in aggregated and anonymous form.
14.2. The Licensor shall act as data processor for the Service provided, in accordance with the purposes and in the manner described in the documents annexed to these General Terms, namely the Data Processing Agreement (the "DPA" – Annex A) and the Privacy Notice (the "Privacy Policy" – Annex B), which are a substantial and integral part of these General Terms. By accepting these General Terms, the Customer declares that it has carefully read their content and undertakes to observe and comply with the provisions contained therein.
14.3. It is understood that the Licensee is the data controller under the GDPR with respect to the personal data of third parties, including the personal data of End Users, which it processes by means of or through the use of the Services. For the purpose of providing the Services, the Licensor may access and process on behalf of the Licensee the personal data of End Users as data processor pursuant to Article 28 of the GDPR. Processing carried out by the Licensor as data processor shall take place on the basis of and in accordance with the DPA annexed to these General Terms.
14.4. The Licensor expressly declares, and the Licensee accepts without reservation, that the data collected on behalf of the latter shall be subject to an aggregation process, following an anonymisation procedure, including for the purpose of being used for the Licensor's own purposes. The data referred to above cannot be defined as "personal data" as it consists of information which does not relate to an identified or identifiable natural person, in light of Recital 26 of the GDPR.
14.5. The Licensee acknowledges and accepts that, following the termination, for any reason, of the employment or collaboration relationship between the Licensee and one of its End Users, the Licensor shall be entitled to contact the data subject directly, by e-mail or by any other means of communication provided by the End User, in order to offer them the possibility of continuing to use the Software, as a consumer, by taking out a personal subscription through the dedicated channel made available by the Licensor at www.vitalityplus.app. It is understood that, should the End User accept such an offer, the Licensor shall act, with reference to the personal data processed in the context of such direct subscription, as an independent data controller under the GDPR and the FADP, and no longer as data processor on behalf of the Licensee pursuant to Article 14.3 above and the DPA (Annex A).
15. Confidentiality
15.1. Each Party undertakes to treat as strictly confidential and not to disclose to third parties (a) all commercial, technical, financial, operational or other information relating to the other Party, (b) the existence and content of these General Terms, (c) information relating to the technology and operating methods of the other Party. In particular, the Licensee undertakes to keep strictly confidential all technical, commercial and operational information relating to the Software and the Platform.
15.2. The confidentiality obligations under this Article do not apply to information which is or becomes public knowledge for reasons other than a breach of the obligations under this Article.
15.3. The confidentiality obligations under this Article do not apply to information which: (a) is or becomes public knowledge for reasons other than a breach of the obligations under this Article; (b) was already lawfully in the possession of the receiving Party before disclosure; (c) is lawfully obtained by the receiving Party from third parties entitled to disclose it; (d) is developed independently by the receiving Party without using the confidential information of the other Party.
15.4. Each Party may disclose the confidential information of the other Party to the extent that such disclosure is required by law or by a judicial or administrative authority, provided that the Party subject to such obligation gives the other Party prompt notice, where legally possible.
15.5. The confidentiality obligations under this Article shall remain in force for the entire term of the Agreement and for a period of 2 (two) years after its termination for any reason.
16. Force majeure
16.1. For the purposes of these General Terms, force majeure means all circumstances beyond the Licensor's control which, temporarily or permanently, prevent it from fulfilling the obligations under these General Terms; such as, by way of example and without limitation, war or the risk of war, riots, total or partial social mobilisation, strikes, shortage of raw materials, delays in the supply of products and services (including digital ones) and/or in suppliers' performance, transport difficulties, difficulties or delays in the transmission of data over networks, restrictions of any kind on imports and/or exports, frost, fire, epidemics, pandemics, natural disasters and any other unforeseen impediment which makes the provision of the Services wholly or partly impossible ("Force Majeure").
16.2. In the event of Force Majeure, the Licensor has the right to: (i) suspend/interrupt the provision of the Services; or (ii) withdraw from the relationship with the Licensee, without any form of liability being attributable to the Licensor as a result.
16.3. The Licensor undertakes to promptly inform the Licensee of the occurrence of Force Majeure events and to restore the Services as soon as such events have ceased.
17. Limitation of liability
17.1. The Licensee acknowledges and accepts that the Services are provided "as is" and are characterised by constantly evolving technologies. Therefore, the technical characteristics of the Software may be modified where this is made necessary by technological evolution and/or by supply and/or organisational requirements.
17.2. The Licensee acknowledges that under no circumstances may the Licensor be held liable for damage suffered by the Licensee itself or by third parties as a result of the use of the Services, or of the content generated by the Software, for amounts exceeding the fees actually paid by the Licensee in the 12 months preceding the harmful event.
17.3. Under no circumstances shall the Licensor be liable to the Licensee for indirect damage, loss of profit, loss of business opportunities, reputational damage, loss of data or other economic loss, even if the Licensor has been previously informed of the possibility of such damage.
17.4. The Licensor shall not be liable for damage arising from improper use of the Software by the Licensee or by End Users, nor for damage arising from causes not attributable to the Licensor, such as malfunctions of telecommunication networks or problems relating to the devices used by the Licensee or by End Users.
17.5. With regard to any management and delivery of Rewards by the Licensor, the Licensor is not liable for malfunctions attributable to third-party gift card providers or for unilateral changes to their terms. Furthermore, the Licensor does not assume any tax or employment-law advisory role and reserves the right to change the types of rewards, providers and allocation criteria with thirty days' notice.
17.6. The Licensor is not responsible for the documentation provided in template form under Annexes C and D of these Terms and Conditions, which must necessarily be adapted and customised according to the relationship between the Licensee and the End Users.
17.7. The limitations of liability provided for in this Article apply to the fullest extent permitted by law and survive termination of the Agreement.
18. Governing law and jurisdiction
18.1. Jurisdiction. This agreement is governed by Italian law. Any dispute relating to the interpretation, performance and termination of these General Terms shall be subject to the exclusive jurisdiction of the Court of Milan.
19. Final provisions
19.1. These General Terms, together with the Annexes, constitute the entire agreement between the Parties in relation to the subject matter of the agreement and supersede any previous agreement, understanding or communication, whether written or oral, relating to the same subject matter.
19.2. Should one or more clauses of these General Terms be declared null, voidable or otherwise ineffective by the competent judicial authority, such nullity, voidability or ineffectiveness shall not extend to the remaining clauses, which shall continue to have full effect.
19.3. Any tolerance by one of the Parties of conduct by the other Party in breach of the provisions of these General Terms shall not constitute a waiver of the rights arising from the provisions breached or of the right to demand exact performance of all the terms and conditions provided for herein.
19.3-bis The official version of these General Terms and their Annexes is the Italian version. At the Licensee's express request, a translated text may be provided, but it remains understood that in the event of discrepancies the Italian-language text shall apply.
19.4. Assignment of the Agreement
The Licensee may not assign this Agreement, in whole or in part, without the Licensor's prior written consent. The Licensor may assign this Agreement to subsidiaries, parent companies or affiliated companies pursuant to Article 2359 of the Italian Civil Code, as well as to third parties, upon written notice to the Licensee.
19.5. All communications relating to this Agreement must be made in writing and sent to the following addresses:
- For the Licensor: Email: info@vitalityplus.app.
- For the Licensee: to the address indicated at registration or subsequently communicated to the Licensor.
19.6. Any amendment to these General Terms must be made in writing, except as provided for in Article 6.
Pursuant to and for the purposes of Articles 1341 and 1342 of the Italian Civil Code, the Licensee declares that it has carefully read and specifically approves the following clauses: Art. 2.2 (Limitation of available accounts); Art. 3.5 (Indemnity for unauthorised use of the Account); Art. 4.1 (Automatic renewal); Art. 5.2.2 (Unpaid amounts); Art. 5.3.2 (Non-refundable fee); Art. 6 (Amendments to the General Terms); Art. 8.6 (Content warranties and indemnity); Art. 9.5 (Ownership of improvements resulting from machine learning); Art. 12.4 (No warranty on the AI recommendation process); Art. 13 (Termination); Art. 17 (Limitation of liability); Art. 18.1 (Jurisdiction); Art. 19.4 (Assignment of the Agreement).
Acceptance of this agreement by clicking the "I accept" button is equivalent to an electronic signature pursuant to Article 21 of Italian Legislative Decree no. 82 of 7 March 2005 (Digital Administration Code).
Annex A – Data Processing Agreement
Deed of appointment and data processing agreement
pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and Article 9 of the Swiss Federal Act on Data Protection of 25/09/2020 (FADP)
This agreement is entered into between:
The "Licensee", i.e. the legal or natural person who, in order to access the Software and use the Services, has taken out a subscription (hereinafter the "Licensee" or the "Controller")
and
The "Licensor", i.e. the company Vitality Plus SA, with registered office in Savosa at Via Emilio Maraini 27, 6942 Savosa, UID CHE-169.816.147 (hereinafter "Vitality Plus" or the "Licensor" or the "Processor")
hereinafter also referred to individually as a "Party" and jointly as the "Parties".
Whereas:
- The Parties acknowledge and accept that they have entered into a technology licence and services agreement for access to the "Vitality+" Software and the related "B2B" Services (the "Agreement").
- In performing the Agreement, Vitality Plus SA will process personal data on behalf of the Licensee and will therefore be the data Processor.
- The role of the Processor is governed by Article 28 of the GDPR and Article 9 of the FADP; the two sets of rules therefore apply to Licensees located in the territory of the European Union and of the Swiss Confederation respectively.
- In this regard, it is specified that, depending on where the Licensee is established, in performing the Agreement Vitality Plus will process personal data on behalf of the Licensee as Processor under one of the two provisions referred to above.
- By virtue of such processing, and in order to enable the Controller to comply with the regulatory obligations referred to above and with any other Applicable Law, the Parties have agreed to enter into this Agreement.
The Parties agree as follows:
1. Definitions
In this Agreement, depending on where the Licensee is established, the FADP or the GDPR shall apply respectively.
| For Controllers established in Switzerland | For Controllers established in the EU | Definition |
|---|---|---|
| "Agreement" | "Agreement" | the Agreement signed under which the Processor takes on the engagement assigned by the Controller |
| "Privacy Authority" | "Privacy Authority" | the supervisory authority responsible for the protection of personal data in the jurisdiction to which the Controller is subject |
| "Controller" | "Controller" | the natural or legal person who determines the Purposes and means of the Processing of Personal Data |
| "Processing" | "Processing" | For Swiss Controllers: any operation relating to personal data, irrespective of the means and procedures used, in particular the collection, recording, storage, use, modification, disclosure, archiving, deletion or destruction of data. For EU Controllers: any operation or set of operations performed on Personal Data, whether or not by automated means, including the collection, recording, organisation, storage, adaptation, alteration, retrieval, consultation, use, disclosure, making available, updating, combination, blocking, erasure and destruction of Personal Data under the Applicable Law |
| "Personal Data" | "Personal Data" | any information relating to an identified or identifiable natural person as defined by the Applicable Law |
| "Sensitive personal data" | "Special Category Data and Criminal Convictions" | For Swiss Controllers – Sensitive personal data: data on religious, philosophical, political or trade-union opinions or activities, health, the intimate sphere or racial or ethnic origin, genetic data, biometric data uniquely identifying a natural person, data on administrative and criminal proceedings and sanctions, and data on social assistance measures. For EU Controllers – Special category data: racial/ethnic origin, political opinions, religion, trade-union membership, genetic, biometric and health data and data concerning sex life/sexual orientation. Data relating to criminal convictions and offences: data relating to criminal convictions and offences or related security measures on the basis of Article 6(1) |
| Applicable Law: FADP and DPO | Applicable Law: GDPR | the set of rules relevant to the protection of personal data to which the Controller is subject, and any guideline, Code or measure issued by the Privacy Authority(ies). For Swiss Controllers: the Federal Act on Data Protection of 25 September 2020, applicable from 1 September 2023 (hereinafter also the FADP); the Data Protection Ordinance of 31.08.2022 (hereinafter also the DPO). For EU Controllers: Regulation (EU) 2016/679 (hereinafter also the GDPR or the Regulation) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), applicable from 25 May 2018 |
| "Purpose" | "Purpose" | the specific and legitimate reason for which personal data is collected and processed |
| "Justification" | "Legal Basis" | the lawfulness of the processing, i.e. the legal provision that lawfully authorises the processing of personal data, making it lawful |
| "Technical and organisational measures" | "Appropriate Security Measures" | the security measures that the Controller and the Processor implement to ensure a level of security appropriate to the risk |
2. Processing of data in accordance with the Controller's instructions
The Processor, with respect to all Personal Data it processes on behalf of the Controller, guarantees that it:
- will process such Personal Data only for the purposes of performing this Agreement and only in accordance with what is expressly provided by the Parties in the technology licence and services agreement, therefore acting exclusively on the basis of what is expressly provided;
- will not process Personal Data for its own Purposes, except for the training of the Platform's algorithms;
- will inform the Controller, before starting any processing and, where necessary, at any other time, if, in its opinion, any instruction given by the Controller is in breach of the law;
- is subject to legal provisions which could make it wholly or partly impossible or unlawful for it to act in accordance with the instructions given by the Controller or in compliance with the Applicable Law.
In order to ensure compliance with the instructions given by the Controller, as provided for in this Article, the Processor shall use appropriate processes and any other suitable technical measure to implement the instructions given by the Controller, including:
- procedures suitable to ensure respect for the rights and requests made to the Controller by data subjects in relation to their Personal Data;
- procedures suitable to ensure the updating, modification and correction, at the Controller's request, of the Personal Data of each data subject;
- procedures suitable to ensure the deletion or blocking of access to Personal Data at the Controller's request;
- measures allowing Personal Data or accounts to be flagged, to enable the Controller to apply specific rules to the Personal Data of individual data subjects;
- procedures suitable to ensure the right of Data Subjects to restriction of processing, at the Controller's request.
The Processor must comply with the Applicable Law and fulfil the obligations under this Agreement so as to prevent the Controller from breaching any obligation under the Applicable Law.
The Processor must guarantee and provide the Controller with the cooperation, assistance and information that may reasonably be requested by the Controller, to enable it to fulfil its obligations under the Applicable Law.
The Processor also undertakes to comply with the instructions or decisions of a Privacy Authority within a time that allows the Controller to meet the deadline imposed by that Privacy Authority.
The Controller acknowledges the Processor's right, as provided for in the licence agreement, to process conversational data, previously anonymised, for its own purposes.
The Parties acknowledge and agree that the Processor shall not be entitled to reimbursement of any expenses it may incur in complying with the instructions given by the Controller, for the performance of the Agreement, and/or of any other obligation of the Processor under the Agreement or under any other Applicable Law.
The Processor, also in compliance with Article 30 of the Regulation, must maintain and complete, on its own and/or on the basis of the instructions to be provided by the Controller, and make available at the Controller's request, a record of the personal data processing activities it carries out, where such processing is not otherwise documented. Such record must include:
- the name and contact details of the Processor; of each Controller on whose behalf the Processor acts and of the Data Protection Officer, where present;
- the categories of processing carried out on behalf of each controller;
- where applicable, transfers of Personal Data to a third country or an international organisation, including the identification and indication of such third country or international organisation.
In order to enable the Controller to carry out a data protection impact assessment, which is required whenever a given processing operation is likely to result in a high risk to the rights and freedoms of natural persons, and to comply with Article 22 FADP and Article 35 of the Regulation, the Processor undertakes to support and show the utmost cooperation at the Controller's request, in order to carry out such activity.
3. Protection of personal data
The Processor must adopt and maintain appropriate security measures, both technical and organisational, to protect Personal Data against unlawful or accidental destruction or loss, damage, alteration, unauthorised disclosure or access and, in particular, where the processing involves the transmission of data over a network, against any other unlawful form of processing, such as:
- a) pseudonymisation and encryption of the personal data covered;
- b) measures to ensure the confidentiality, integrity, availability and ongoing resilience of the systems and services used for processing;
- c) measures to restore the availability of and access to the personal data covered within an appropriate time in the event of a physical or technical incident;
- d) a procedure for regularly testing, analysing and evaluating the effectiveness of the technical and organisational security implemented to ensure the security of processing.
The Processor must store Personal Data ensuring its logical separation from Personal Data processed on behalf of third parties or on its own behalf.
The Processor undertakes to follow the measures of the Federal Data Protection and Information Commissioner or of the Italian Data Protection Authority (Garante), without prejudice to any adjustments that may be necessary following the application of the Applicable Laws and any implementing measures.
4. Security of communications
The Processor must adopt appropriate technical and organisational measures to safeguard the security of any electronic communication network or of the services provided to the Controller or used to transfer or transmit Personal Data (including, for example, measures intended to guarantee the secrecy of communications so as to prevent the interception of communications or unauthorised access to any computer or system), thereby ensuring the security of communications.
5. Persons authorised to process data – Confidentiality
The Processor guarantees the reliability of any employee and Sub-Processor or Sub-Supplier who accesses the Controller's Personal Data and also ensures that they have received adequate training with regard to the protection and management of Personal Data, and that they are bound by confidentiality obligations no less onerous than those provided for in this Agreement in relation to the Processing of Personal Data.
6. Processing of personal data outside the European Economic Area
The Processor specifies that the personal data subject to processing through the Software may also be processed outside the European Economic Area, by the Processor itself or by other Sub-Processors or Sub-Suppliers.
The Processor guarantees, however, that processing always takes place in compliance with an adequate level of personal data protection pursuant to Articles 16 – 18 of the FADP and Articles 45 – 47 of the GDPR.
7. Sub-processors of personal data
The Controller authorises the Processor to appoint sub-processors for the performance of the activities covered by the Agreement, pursuant to Article 7 of the DPO and Article 28(2) of the GDPR.
The Processor undertakes to select its sub-processors carefully, taking care to assess the following parameters: a) reliability with regard to personal data protection; b) security measures adopted; c) location of the sub-processor and of its servers (Switzerland or EU preferred); d) in the case of a location outside the EU, verification of compliance with the applicable rules, the FADP and the GDPR respectively.
The Processor makes itself available to provide the Controller with an up-to-date list of sub-processors.
8. Personal data breach and notification obligations
The Processor, pursuant to Article 24(3) FADP and Article 33 of the Regulation, and in compliance with decision no. 97 of 4 April 2013 of the Italian Privacy Authority, must notify the Controller as soon as possible, and in any event no later than 72 hours after becoming aware of it, of any destruction, loss, alteration, disclosure of or unauthorised access to Personal Data (a "Security Breach"), including those involving its own sub-Suppliers and/or sub-Processors.
Such notification must contain:
- a detailed description of the Security Breach;
- the type of data affected by the Security Breach;
- the identity of each data subject (or, where this is not possible, the approximate number of persons concerned and the personal data involved).
The Processor must then communicate to the Controller:
- the name and contact details of its Data Protection Officer, or of another contact point from which further information can be obtained;
- a description of the likely consequences of the Security Breach;
- a description of the measures taken or proposed to be taken to address the Security Breach, including, where appropriate, measures to mitigate its possible adverse effects;
- as soon as possible, any other information collected or made available, as well as any other information that may reasonably be requested by the Controller in relation to the Security Breach.
Where the Processor is unable to provide the above information with the notification, for reasons beyond its control, the information must be provided as soon as possible.
The Processor must take immediate action to investigate the Security Breach and to identify, prevent and limit the adverse effects of such breach, in accordance with its obligations under this Article and, with the Controller's agreement, to take any action necessary to remedy the breach.
Should the Security Breach have a greater impact on the Processor's own data, the Processor must nevertheless give priority to the Controller in providing its support and implementing the remedies and actions deemed necessary.
9. Risk analysis, privacy by design and privacy by default
Where requested by the Controller, the Processor must make available all the information necessary to demonstrate the Controller's compliance with the Applicable Law and must assist it in impact assessment activities and related data processing, as well as cooperate in giving effect to the mitigation actions envisaged and agreed to address any risks identified.
The Processor must do everything possible to enable the Controller to comply with Article 7 of the FADP and Article 25 of the Regulation regarding data protection by design and data protection by default.
In particular, in line with the principles of privacy by design:
If the Licensee is established in Switzerland: adopt the technical and organisational measures necessary to ensure that the processing of personal data complies with the data protection provisions, in particular with the principles set out in Article 6 FADP. Such measures must be adopted from the design stage. The technical and organisational measures must be appropriate in particular to the state of the art, to the type and extent of the processing of personal data and to the risks that the processing poses to the personality or fundamental rights of the persons concerned. It must be ensured, by means of appropriate default settings, that the processing of personal data is limited to the minimum required for the purpose pursued, unless the person concerned specifies otherwise.
If the Licensee is established in the EU: every new processing operation must be designed so as to guarantee security appropriate to the risks relating to the specific processing. Furthermore, the Processor must enable the Controller, taking into account the state of the art, the costs, the nature, scope and purpose of the relevant processing, to adopt, both at the initial stage of determining the means of processing and during the processing itself, any technical and organisational measure deemed appropriate to guarantee and implement the data protection principles and to protect the rights of data subjects.
In line with the principles of privacy by default, only the personal data necessary for each specific purpose of the processing must be processed by default.
10. Deletion of personal data
Where the Processor keeps a copy of the Personal Data processed, it shall delete it at the end of the established retention period and in any circumstance in which the Controller so requests, including where deletion must take place further to the exercise of the relevant right by the Data Subject, without prejudice to the Processor's right to anonymise the personal data processed in order to continue training its own artificial intelligence systems.
11. Requests for disclosure of personal data for investigative and defence purposes from third parties
Unless prohibited by the Applicable Law, the Processor or any Sub-Supplier and/or Sub-Processor shall promptly inform the Controller, and in any event within two working days, of any request, communication or complaint received from any regulatory or supervisory authority or from any data subject relating to any Personal Data or to any obligation under the Applicable Law, and shall provide free of charge all due assistance to the Controller to ensure that the Controller can respond to such communications or complaints and comply with the time limits laid down by applicable law and regulations.
12. Liability and indemnities
The Controller shall indemnify the Processor for any Claim brought against the latter for any breach of the Applicable Law arising exclusively from having carried out the instructions given by the Controller under the provisions of this Agreement, provided however that the Processor has notified the Controller, in advance and in writing, that the Controller's instructions could result in a breach of the Applicable Law and that the Controller, notwithstanding the Processor's notification, has nevertheless ratified its instructions in writing.
Upon receipt of a Claim relating to the activities covered by this Agreement, the Processor shall promptly notify the Controller of the Claim in writing once it becomes aware of it and shall provide the Controller with all the assistance it may reasonably require in handling the Claim.
13. Term
This Agreement takes effect from the date of its signature and shall remain in full force and effect until the termination or expiry of the Agreement.
Place and date ………………………
Controller's signature ……………………… — Processor's signature ………………………
Appendix on the processing of personal data
This Appendix describes the types of personal data and the purposes for which they may be processed by the Processor.
Personal data processing activities
| Purpose of processing | Category of data processed | Data subjects | Retention period of personal data | Processing operations |
|---|---|---|---|---|
| Provision and management of the "Vitality+" Software supplied as App or Web App | Ordinary personal data of the Controller. Ordinary and special category personal data of Third Parties (i.e. "End Users") | Controller and its authorised persons. Third Parties | Data will be retained for the entire term of the agreement. | Collection; Recording; Organisation; Structuring; Storage; Consultation; Use; Comparison/Interconnection; Erasure/Destruction. |
Technical and organisational measures adopted
User policies and rules – Vitality Plus SA applies detailed policies and rules with which all users with access to information systems are required to comply and which are aimed at ensuring conduct suitable to guarantee respect for the principles of confidentiality, availability and integrity of data in the use of IT resources.
Logical access authorisation – Vitality Plus SA defines access profiles in accordance with the least privilege principle, as necessary for the performance of the tasks assigned. Authorisation profiles are identified and configured before the start of processing, so as to limit access to only the data necessary to carry out the processing operations. Such profiles are subject to periodic checks aimed at verifying that the conditions for retaining the profiles assigned still apply.
Data Breach – Vitality Plus SA has implemented a specific procedure for managing events and incidents with a potential impact on personal data, which defines roles and responsibilities, the detection process (suspected or confirmed), the application of countermeasures, the response to and containment of the incident/breach, as well as the manner in which personal data breaches are communicated to the Customer.
Training – Vitality Plus SA periodically provides its employees involved in processing activities with training courses on the correct management of personal data.
Technical security measures adopted by Vitality Plus SA
Firewall – Personal data is protected against the risk of intrusion referred to in Article 615-quinquies of the Italian Criminal Code by means of Intrusion Detection & Prevention systems, kept up to date in line with the best technologies available.
Security of communication lines – Within its area of responsibility, Vitality Plus SA adopts secure communication protocols in line with what technology makes available.
Protection from malware – Systems are protected against the risk of intrusion and the action of programs through the activation of suitable electronic tools updated periodically. Antivirus tools are in use and kept constantly up to date.
Authentication credentials – Systems are configured in a manner suitable to allow access only to persons holding authentication credentials that allow their unique identification. These include a code associated with a password, confidential and known only to the person concerned; an authentication device in the exclusive possession and use of the user, possibly associated with an identification code or a password.
Passwords – With regard to the basic characteristics, i.e. mandatory change at first access, minimum length, absence of elements easily traceable to the person, complexity rules, expiry, history, contextual assessment of strength, display and storage, passwords are managed in accordance with best practice. Persons to whom credentials are assigned are given specific instructions on how to ensure their secrecy.
Logging – Systems can be configured to allow the tracking of access and, where appropriate, of the activities carried out by the different types of users (Administrator, Super User, etc.), protected by adequate security measures guaranteeing their integrity.
Backup & Restore – Suitable measures are adopted to ensure the restoration of access to data in the event of damage to the data or to the electronic tools, within set times compatible with the rights of data subjects. Where contractual agreements so provide, a business continuity plan is in place, integrated where necessary with the disaster recovery plan; these guarantee the availability of and access to systems even in the event of significant adverse events that persist over time.
System Administrators – With regard to all users acting as System Administrators, whose list is kept up to date and whose assigned functions are appropriately defined in specific deeds of appointment, a log management system is operated for the precise tracking of the activities carried out and the retention of such data in unalterable form suitable to allow ex post monitoring. The work of System Administrators is subject to verification activities to check its compliance with the organisational, technical and security measures for the processing of personal data provided for by the rules in force.
Annex B – Customer Privacy Notice
Notice on the processing of personal data pursuant to Article 13 of Regulation (EU) 2016/679 and Article 19 of the Swiss Federal Act on Data Protection of 25/09/2020
Dear Customer,
this notice on the processing of personal data governs the processing of the personal data of Customers who enter into a technology licence agreement with Vitality Plus SA for the APP and Web APP software named "Vitality+".
The rules indicated above apply to Customers located in the territory of the European Union and of the Swiss Confederation respectively.
In this regard, please note that, depending on where you or the company you represent are located, your personal data will be processed under one of the two sets of provisions referred to above.
1. Data subject
You, i.e. the person to whom this notice is addressed, also referred to as the Customer.
2. Data Controller
The Controller of your personal data is Vitality Plus SA (hereinafter also the "Controller" or "Vitality Plus"), with registered office at Via Emilio Maraini 27, 6942 Savosa, which can be contacted at the following e-mail address: info@vitalityplus.app.
3. Representative in the European Union
For Users established in EU countries, pursuant to Article 27 of Regulation (EU) 2016/679, the Controller has appointed as its representative in the European Union INDO SRLS, Viale Giacomo Mancini, 156 – 87100 Cosenza (CS), Italy, VAT no. 03510180783, Tel. +39 02 87366082, Email dpo@indoconsulting.it.
4. Purpose of processing, justification/legal basis, retention period of your personal data
Your data is processed for the following purposes.
4.1. Legal obligation
To comply with any obligation provided for by the federal or cantonal laws in force, ordinances, related regulations and commercial practices, in particular in tax and fiscal matters.
Justification: (for Users in Switzerland) Art. 31(1) FADP, processing justified by law. Legal basis: (for Users in the EU) Art. 6(1)(c) GDPR, legal obligation. Retention period: data will be retained for as long as the Controller is subject by law to retention obligations.
4.2. Taking pre-contractual measures
Where you contact Vitality Plus to request information about the services or products we offer, including for the purpose of taking pre-contractual measures aimed at issuing a quotation. Provision of the data is necessary; without it, it will not be possible to follow up requests or issue quotations.
Justification: (for Users in Switzerland) Art. 31(2)(a) FADP, overriding interest of the Controller, namely the processing of data relating to the Data Subject in direct connection with pre-contractual measures. Legal basis: (for Users in the EU) Art. 6(1)(b) GDPR, performance of pre-contractual measures taken at the Data Subject's request. Retention period: data will be retained for the time necessary to process the request or for the period of validity of the quotation.
4.3. Performance of a contract
Where you are entering into the Technology Licence Agreement with Vitality Plus. Provision of the data is necessary; without it, it will not be possible to perform the contract and the services concluded.
Justification: (for Users in Switzerland) Art. 31(2)(a) FADP, overriding interest of the Controller, namely the processing of data relating to the Customer in direct connection with the performance of the contract. Legal basis: (for Users in the EU) Art. 6(1)(b) GDPR, performance of the contract. Retention period: data will be retained for the entire term of the contract and, consequently, for 10 years from the end of the financial year, in accordance with the Swiss Code of Obligations (CO).
4.4. Assessing creditworthiness
To assess the Customer's creditworthiness where the type of contract entered into makes this necessary, except in the case of advance payments. Provision of the data is necessary; without it, it will not be possible to allow deferred payments or payment in instalments.
Justification: (for Users in Switzerland) Art. 31(2)(c) FADP, overriding interest of the Controller, namely assessing the Customer's creditworthiness; however, we do not collect sensitive personal data and do not carry out high-risk profiling, the data is disclosed only to third parties who need it for the conclusion or performance of the contract with the person concerned, the data is not more than ten years old and the person concerned is of legal age. Legal basis: (for Users in the EU) Art. 6(1)(f) GDPR, legitimate interest of the Controller. Retention period: data will be retained for the entire term of the contract.
4.5. Direct marketing to Customers (Soft Spam)
Where you have already purchased a product or service from Vitality Plus, we will send you promotional communications concerning services and products similar to those already purchased. Provision of the data is authorised by law. Your contact details will therefore be used for direct marketing purposes.
Justification: (for Users in Switzerland) processing justified by law, namely by Art. 3(1)(o) of the Federal Act against Unfair Competition (UCA). Legal basis: (for Users in the EU) Art. 6(1)(f) GDPR, legitimate interest of the Controller. Retention period: until you object or unsubscribe via the "opt-out" system at the bottom of our e-mails.
4.6. Direct marketing
To send you commercial and informational communications of various kinds concerning the sector in which the Controller operates, to send newsletters, commercial proposals, invitations to workshops or events promoted by us and notices of advertising events, through traditional channels such as telephone operators and mailing, or more innovative systems such as SMS, social media including WhatsApp, and e-mail, for services and products other than those you may already have purchased. Provision of the data is therefore optional; without it, we will not be able to keep you updated on our services and promotional activities or invite you to our events.
Justification: (for Users in Switzerland) Art. 3(1)(o) UCA and Art. 31(1) FADP, through the Data Subject's consent expressly given at the bottom of this notice or elsewhere (for example following your explicit request to subscribe received by us via e-mail, SMS or social media). Legal basis: (for Users in the EU) Art. 6(1)(a) GDPR, consent of the Data Subject. Retention period: until you object or unsubscribe via the "opt-out" system at the bottom of our e-mails.
5. Categories of recipients of personal data, disclosure and dissemination
Your data will not be disseminated to unspecified parties by being made available or consultable. We disclose your data to the following categories of recipients:
5.1. Collaborators or other staff authorised to process data (by way of example: administrative, sales and accounting staff, system administrators), within the limits necessary to carry out their duties for the Controller, subject to a letter of appointment imposing the duty of confidentiality and security.
5.2. Consultants or suppliers acting as data processors (by way of example: IT companies, communication agencies or other parties carrying out outsourced activities on behalf of the Controller), within the limits necessary to carry out their duties for the Controller, subject to the signing of a contract imposing the duty of confidentiality and security.
5.3. Bodies and, in general, any public or private party to which we are obliged (or entitled under primary, secondary or EU legislation) or need to disclose data, within their respective and specific areas of competence, such as, for example: i) the cantonal and federal authorities (e.g. for accounting or tax reasons) where a legal notification obligation applies; ii) other recipients (e.g. banks); iii) the offices responsible for collecting unpaid debts.
The Controller uses exclusively certified and secure service providers which: (i) are established in Switzerland; (ii) are established in the EEA; (iii) are established outside the EEA, in particular in Colombia. This takes place only after verifying that the safeguards provided for by Federal – European laws have been adopted, in particular:
- for Users in the EU, in accordance with adequacy decision 2003/490/EC;
- for Users in Switzerland, in accordance with Annex 1 of the DPO, which contains the list of States providing an adequate level of data protection.
Disclosure of personal data to providers that do not adequately protect data under Swiss and European law is therefore excluded.
Data Subjects established in Switzerland may request further information by writing to the following e-mail address: info@vitalityplus.app.
Data Subjects established in an EU country may request further information by writing to our EU representative at the following e-mail address: dpo@indoconsulting.it.
6. Processing methods
Data is processed by means of technical and organisational measures suitable to ensure that the security of personal data is appropriate to the risk. Processing may be carried out both on paper and with the aid of automated IT tools capable of storing, managing and transmitting the data.
7. Rights of Data Subjects
7.1. If you are domiciled in Switzerland
Articles 25 to 32 of the FADP grant you the following rights and claims, within the limits of the prescribed legal framework:
- the right of access, to request information on the processing of your personal data;
- the right to request the updating and rectification of your personal data;
- the right to request the restriction of processing and of disclosure to third parties;
- the right to request erasure or destruction;
- the right to request a ban on processing or on disclosure to third parties;
- the right to request that the disputed nature of the data or the court decision be noted.
If you have a complaint about how we handle your data, we would like to hear from you, but you also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner.
7.2. If you are domiciled in the EU
Articles 15 to 21 of the GDPR grant you the following rights, within the limits of the prescribed legal framework:
- the right of access under Article 15 GDPR and the right to rectification (to amend your data) under Article 16 GDPR;
- the right to erasure under Article 17 GDPR and the right to restriction of processing (i.e. that such data is not subject to further processing and can no longer be modified) under Article 18 GDPR;
- the right to data portability (i.e. to receive the personal data concerning you, which is processed by automated means, in a structured, commonly used and machine-readable format, and to transmit it to another controller, or to have it transmitted directly) under Article 20 GDPR;
- the right to object to processing (i.e. to object to the processing of data concerning you and to the sending of advertising material, direct sales and market research) under Article 21 GDPR.
If you have a complaint about how we handle your data, we would like to hear from you, but you also have the right to lodge a complaint with the supervisory authority competent for the country in which you habitually reside, without prejudice to any other administrative or judicial remedy.
8. How to exercise your rights
To exercise your rights and claims, in the manner and within the time limits prescribed by the FADP or the GDPR, you may proceed as follows:
- If you are established in Switzerland, by writing to the following e-mail address: info@vitalityplus.app.
- If you are established in an EU country, by writing to our EU representative at the following e-mail address: dpo@indoconsulting.it.
We kindly ask you to promptly inform the Controller, or its representative in the European Union appointed by us, of any change to your personal data so that we can comply with Article 6 of the FADP and/or Article 16 of the GDPR, which require that the data collected be accurate and, therefore, up to date.
Prevailing language version
These terms and conditions are available in several languages. Translations are provided for ease of understanding only: in the event of any divergence, doubt of interpretation or conflict between versions, only the Italian version prevails and is legally binding.

