Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how personal data is collected and processed through the Junction® mobile app and the dojunction.online website (together, "the Service"). It is drafted under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
Marco Tribuzio — data controller, a natural person
Controller's email address: privacy@dojunction.online
2. Personal data we collect
In the Junction® app
The app is also covered by its own, more detailed notice: Junction® App Privacy Policy.
- Account data — name, email address and the account identifier returned by Google Sign-In or Sign in with Apple.
- Scan data — the JCode™ or NFC tag read, the result of the check (valid, activated, blocked, reported), the timestamp and the product the code belongs to.
- Approximate or precise location, non-continuous — collected only if you grant the permission on your device, only at the moment of a scan or of a location-based action. Junction® does not track your position in the background or continuously.
- Camera — used only to read QR codes. The camera output is never stored, recorded or transmitted.
- NFC reader — used only to read contact-less tags.
- Device identifier and push token — a unique identifier of your installation, used to keep your preferences and to deliver notifications.
- Usage and diagnostic data — app version, device model, operating system, crash and error logs.
On the dojunction.online website
- Contact and demo requests — name, company, business email, message.
- Navigation data — IP address, browser and OS, pages visited, referrer and timestamps, recorded in server logs.
- Cookies and similar technologies — see the Cookie Policy.
Unless stated otherwise, the data requested by the Service is necessary to provide it. Refusing to provide it may make the Service partly or wholly unavailable.
3. Purposes and legal bases
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating the account, signing you in, authenticating products | Account data, scan data | Performance of a contract — Art. 6(1)(b) |
| Location-based features (where a scan happened, nearby services) | Location, non-continuous | Consent — Art. 6(1)(a), given through the device permission |
| Push notifications on your items | Push token | Consent — Art. 6(1)(a), given through the OS permission |
| Security, abuse and fraud prevention, system logs, service maintenance | Usage data, logs, device identifier | Legitimate interest — Art. 6(1)(f) |
| Answering contact and demo requests | Contact data | Pre-contractual measures — Art. 6(1)(b) |
| Website analytics, measurement and session replay | Cookies, usage data | Consent — Art. 6(1)(a) |
| Accounting, tax and answering lawful requests from authorities | As required by law | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | The data strictly needed | Legitimate interest — Art. 6(1)(f) |
4. Device permissions
Depending on your device, the app asks for permissions before any related data can be processed: camera (read QR codes, no recording), NFC reader, approximate location, precise location, notifications.
You may revoke any permission at any time from your device settings. Revoking a permission does not affect the lawfulness of processing carried out before. Revoking the camera or NFC permission stops the app from scanning codes, which is its core function.
5. Third parties involved
| Service | Role | Place of processing |
|---|---|---|
| Google Sign-In — Google Ireland Ltd | Registration and authentication | Ireland / EU |
| Sign in with Apple — Apple Distribution International Ltd | Registration and authentication | Ireland / EU |
| Google Cloud Platform — Google Ireland Ltd | Hosting, storage and backend infrastructure | EU regions |
| Google Analytics 4 and Google Tag Manager — Google Ireland Ltd | Website measurement, loaded only after consent | Ireland / EU, with transfers to the US |
| Microsoft Clarity — Microsoft Ireland Operations Ltd | Anonymised session replays and heatmaps, loaded only after consent | Ireland / EU, with transfers to the US |
| Apple App Store — Apple Distribution International Ltd | App distribution, aggregate usage statistics | Ireland / EU |
| Google Play Store — Google Ireland Ltd | App distribution, aggregate usage and diagnostics | Ireland / EU |
These providers act as processors under Article 28 GDPR, except where they determine their own purposes as independent controllers. An up-to-date list of processors is available on request at privacy@dojunction.online.
6. Transfers outside the EU
Data is processed in the European Union wherever possible. Where a provider transfers data to a third country, the transfer relies on an adequacy decision — including the EU-US Data Privacy Framework for certified US recipients — or on the Standard Contractual Clauses adopted by the European Commission, together with supplementary measures.
The EU-US Privacy Shield referred to in previous versions of this policy was invalidated by the Court of Justice in 2020 and is no longer relied upon.
7. Retention
- Account data — for as long as the account exists, then deleted within 30 days of a deletion request (see Delete user data).
- Scan and product data — for the life of the product record, since it evidences authenticity and ownership; anonymised afterwards.
- Server and security logs — up to 12 months.
- Analytics data — up to 14 months from collection.
- Contact and demo requests — up to 24 months from the last exchange.
- Data kept for legal obligations — for the period imposed by law.
8. Security
Appropriate technical and organisational measures are in place to prevent unauthorised access, disclosure, alteration or destruction of personal data: encryption in transit, access control on a need-to-know basis, and logging of administrative access.
9. Your rights
Under Articles 15 to 22 GDPR you may:
- access your data and obtain a copy of it;
- have inaccurate data rectified;
- have your data erased;
- obtain restriction of processing;
- receive your data in a portable format, or have it transmitted to another controller;
- object to processing based on legitimate interest, for reasons relating to your situation, and object to direct marketing at any time without giving reasons;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before.
Send any request to privacy@dojunction.online. Requests are free of charge and answered within one month. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the authority of your country of residence.
10. Children
The Service is not directed to children. Minors may use Junction® only with the assistance of a parent or guardian, and in no case may it be used by children under 14, the age set for consent to information society services in Italy under Article 8 GDPR.
11. Push notifications
The app may send push notifications for the purposes described here. You can disable them at any time in your device notification settings. Disabling them may affect alerts about your products.
12. Do Not Track and Global Privacy Control
The website does not respond to the "Do Not Track" browser header. It does honour the Global Privacy Control signal (GPC): when a browser sends GPC, analytics and marketing cookies are treated as refused unless you later opt in yourself.
13. Changes to this policy
This policy may be updated at any time. Changes are published on this page with a new "last updated" date and, where the change concerns processing based on consent, consent is collected again.
14. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Usage data — information collected automatically by the Service, such as IP address, URIs requested, request time and method, response size and status, country, browser and OS characteristics, time spent on each page and navigation path.
- User / data subject — the natural person using the Service, to whom the personal data relates.
- Processor — the party processing personal data on behalf of the Controller.
- Controller — the party determining the purposes and means of processing.
- Cookie — a small piece of data stored on the user's device.
This policy concerns the Junction® app and the dojunction.online website only.