Nymia · Privacy Policy
Privacy Policy
Notice provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). It describes how Bull Marketing S.r.l.s. processes the personal data of Users and Voice Pros of the Nymia platform.
1. Introduction
This Privacy Policy ("Policy") explains how Bull Marketing S.r.l.s. ("Bull Marketing", "we", "Controller") collects, uses, shares and protects your personal data when you access or use the Nymia platform ("Platform"), available via web and mobile application.
This Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), Italian Legislative Decree No. 196 of 30 June 2003 as amended by Legislative Decree No. 101 of 10 August 2018 ("Privacy Code"), and the general measures of the Italian Data Protection Authority (Garante per la protezione dei dati personali).
Bull Marketing is committed to processing your data in a transparent, lawful, proportionate and secure manner, applying the principles of minimisation, accuracy, storage limitation, integrity and confidentiality (Art. 5 GDPR).
We invite you to read this Policy carefully before using the Platform. If you have any questions, you can write to us at any time at privacy@nymia.me.
This English version is published as a courtesy translation; in the event of any interpretative divergence, the Italian version shall prevail.
2. Data Controller
The Controller of your personal data is:
- Bull Marketing S.r.l.s.
- Via Minelli 23, 44042 Cento (FE), Italy
- Tax code and VAT number: IT02178200388
- REA registration: FE-257774
- Dedicated privacy email: privacy@nymia.me
- General support email: support@nymia.me
As of the date of publication of this Policy, Bull Marketing has not appointed a Data Protection Officer ("DPO") pursuant to Art. 37 GDPR, as the conditions making such appointment mandatory do not apply. Should the Controller appoint a DPO in the future, the relevant contact details will be made available in this Section and communicated to data subjects with adequate notice through the Platform's official channels.
Any communication, request or complaint relating to the processing of your personal data may be addressed to privacy@nymia.me or to the postal address of the registered office indicated above.
3. Definitions
For the purposes of this Policy, the following definitions apply:
- "Personal data": any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
- "Processing": any operation or set of operations performed on personal data, whether or not by automated means (Art. 4(2) GDPR).
- "Data Controller": Bull Marketing S.r.l.s., as indicated above.
- "Data Processor": the natural or legal person that processes personal data on behalf of the Controller (Art. 4(8) GDPR); in this Policy, the technical providers that process data on behalf of Nymia are qualified as Processors.
- "Data subject": the natural person to whom the data relate (User, Voice Pro, visitor).
- "Profiling": any form of automated processing of personal data to evaluate certain personal aspects (Art. 4(4) GDPR).
- "Consent": any freely given, specific, informed and unambiguous indication of wishes (Art. 4(11) GDPR).
- "Special categories of data": sensitive data referred to in Art. 9 GDPR (origin, opinions, health, sexual orientation, etc.).
- "Platform" or "Nymia": the online service accessible at www.nymia.me and through the related apps.
- "Voice Pro": a User who uses the Platform to publish content and monetise their activity.
- "User": any person who accesses or registers on the Platform.
4. Personal data we collect
Bull Marketing processes the following categories of personal data:
- Identification data (username, date of birth, country of residence, avatar).
- Contact data (email address, telephone number if provided).
- Login credentials (passwords stored in hashed form using secure cryptographic algorithms; the Controller has no access to the plain-text password).
- Public profile data (biography, personal website, published content).
- Data relating to activity on the Platform (posts, likes, follows, comments, chat messages, internal browsing history, Live/Call bookings, purchased tickets).
- Payment and billing data (within the limits described in Section 7).
- Technical and browsing data (IP address, browser type, operating system, device identifiers, timestamps, access logs).
- Data from communications with customer support.
- Data required for KYC/AML compliance (for Voice Pros only, managed through Stripe — Section 8).
- Data arising from reports or disputes submitted by or against you.
Bull Marketing does NOT intentionally collect special categories of data (Art. 9 GDPR) and we invite you not to voluntarily share sensitive data in published content, chat messages or communications with support, unless strictly necessary. Where, due to the nature of the service (e.g. autobiographical content), you decide to publish special categories of data, the related processing will be limited to making the content available and may be subject to specific protective measures.
5. Data you provide directly
You provide us directly with the following data:
- At registration: email address, password (which we store only in hashed form), public username, date of birth, country.
- When completing your profile: display name, profile photo (avatar), biography, website, communication preferences (including interface language).
- Through the content you publish: posts, images, videos, audio, chat messages, comments, content transmitted during Lives and Calls.
- When you contact us: the content of your support request, any attachments and contextual information.
- When you take part in optional promotions or surveys: the answers provided.
- When you give consent to the use of non-essential cookies: preferences recorded in the cookie banner.
The provision of certain data (email, password, date of birth) is mandatory for access to the Platform; failure to provide it prevents registration. The provision of other data (photo, biography, etc.) is optional and its absence does not affect the use of the essential services.
We collect the date of birth provided by the user in order to determine whether the minimum age requirement for accessing Nymia (18 years) is met. The date of birth is not displayed publicly to other users. Age is self-declared by the user and, for ordinary users, is not verified through identity documents, selfies, or biometric systems. The verification procedures and obligations (including tax and KYC obligations) separately provided for Voice Pros and for payout enablement remain unaffected.
6. Data collected automatically
When you use the Platform, certain data are collected automatically, including for IT security, fraud prevention and service continuity purposes:
- IP address of the device accessing the Platform.
- Browser type, version, language and time zone.
- Information about the device used (model, operating system, screen resolution, session identifiers).
- URL of the referring page (referrer).
- Date and time of access, actions performed within the Platform, open sessions.
- Technical and security logs (successful and failed logins, authentication attempts, brute-force events, API requests).
- Data from cookies and tracking technologies (Section 16), including identification via Meta Pixel and Google Analytics (Sections 17-18) where you have given your consent.
These data are used to ensure the proper functioning of the Platform, prevent abuse, calculate aggregate metrics on service performance and — where you have consented — measure the effectiveness of our communication activities.
7. Payment data
Bull Marketing does NOT store the full payment card number, the CVV, the expiry date or any other authentication data of your payment instruments. The collection, processing and storage of such information are managed exclusively by Stripe Payments Europe, Limited ("Stripe"), a PCI DSS Level 1 certified payment service provider, acting as an independent Data Controller for such purposes.
Bull Marketing receives and stores only the transaction metadata necessary for the performance of the contract and to comply with accounting and tax obligations:
- transaction identifier (Stripe payment intent ID);
- amount and currency;
- last four digits of the card and/or network (VISA, MasterCard, etc.);
- country of issue of the instrument;
- transaction status (authorised, declined, refunded);
- decline reason code in the event of an error;
- date and time of the transaction.
For more information on the processing carried out by Stripe, you can consult Stripe's Privacy Policy at https://stripe.com/it/privacy.
Where a tax invoice needs to be issued, we may also collect and process billing data (name, address, tax code/VAT number, recipient code or certified email address).
8. Voice Pro data
Voice Pros who intend to monetise their activity on the Platform are subject to additional processing aimed at ensuring compliance with anti-money laundering, counter-terrorism financing and tax regulations:
- Identification data provided to Stripe for the Know Your Customer (KYC) procedure: valid identity document, proof of residence, tax code/VAT number, bank details of the payout beneficiary account.
- Information on professional capacity (sector of activity, nature of the content offered, type of services).
- Beneficial ownership data (for Voice Pros operating through companies or entities other than natural persons).
- History of accrued earnings, commissions applied, payouts received and any reversals/refunds.
- Statistical and analytical data visible in the Voice Pro Dashboard (number of followers, conversion rate, gross/net revenue, trends over time).
- Tax and billing data transmitted by or to the Voice Pro, where necessary.
VERIFICATION FOR VOICE PRO PAYMENTS. Voice Pros may use the Platform's monetisation features without first completing the payment provider's KYC verification.
KYC verification becomes necessary before Nymia can transfer accrued earnings to the Voice Pro. For this purpose, the Voice Pro may be directed to the payment provider used by the Platform, currently Stripe Connect Express, which may request identification, tax and banking data and any further information necessary for its own regulatory and verification obligations.
As described in Section 19, the KYC procedure is managed directly by Stripe. Nymia receives from the provider the information necessary to know the status of the verification and the Voice Pro's eligibility to receive transfers, as described in this Privacy Policy.
9. Purposes of processing
Your data are processed exclusively for the following purposes:
- To provide, maintain and improve the Platform and the services requested (registration, login, profile management, content publication, purchase of Digital Content, Lives, Calls, chat, wallet).
- To process payments in favour of Voice Pros and Wallet transactions, in cooperation with Stripe.
- To comply with the accounting, tax and anti-money laundering obligations provided for by the applicable legislation (in particular, Italian Legislative Decree 231/2007).
- To verify the identity of Voice Pros for KYC/AML purposes.
- To send transactional communications (e.g. purchase confirmations, reminders of booked sessions, security alerts, important updates on the Terms).
- To provide customer assistance and respond to support requests.
- To enable content moderation and the handling of reports pursuant to the Digital Services Act (EU Reg. 2022/2065).
- To prevent, detect and combat fraud, abuse, money laundering, security breaches, misuse of the Platform and conduct contrary to the Terms.
- To protect the rights, safety and property of Bull Marketing, Users, Voice Pros and third parties.
- To manage disputes, refund requests and no-shows.
- To analyse the use of the Platform in aggregate form in order to improve its features, usability and security.
- To send promotional communications and commercial proposals for Bull Marketing products or services, only with your specific consent (Art. 130 of Legislative Decree 196/2003).
- To measure the effectiveness of communication campaigns through third-party tools such as Meta Pixel and Google Analytics, only if you have consented to the related cookies.
- To comply with legal obligations, orders of judicial or administrative authorities and law enforcement requests.
10. Legal basis
The processing of your personal data is based on the following legal bases provided for by Art. 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — for Account management, the provision of Platform services, the processing of purchases, bookings, payments and transactional communications.
- Compliance with legal obligations (Art. 6(1)(c)) — for the retention of accounting and tax documentation, anti-money laundering obligations, cooperation with the competent authorities and transparency obligations under the DSA.
- Legitimate interest of the Controller (Art. 6(1)(f)) — to ensure the security of the Platform, prevent fraud and abuse, protect the rights of Bull Marketing and third parties, improve the service and conduct internal statistical analyses in aggregate form. In these cases, Bull Marketing has carried out a prior assessment of the balance between its own interest and the rights of data subjects (Legitimate Interest Assessment), available upon written request to privacy@nymia.me.
- Consent (Art. 6(1)(a); Art. 7) — for the installation of non-technical cookies (analytics and marketing), the sending of promotional communications and the further uses indicated in the cookie banner. Consent is always optional, granular and revocable at any time without affecting the lawfulness of processing carried out before withdrawal.
- Protection of a vital interest (Art. 6(1)(d)) — in exceptional cases where processing is necessary to protect a person's life or physical safety.
For any special categories of data provided by the User pursuant to Art. 9 GDPR, processing is based on the data subject's explicit consent or on the data being manifestly made public by the data subject (Art. 9(2)(a) and (e) GDPR).
11. Data retention
Bull Marketing retains personal data only for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the principle of storage limitation (Art. 5(1)(e) GDPR):
- Account data (email, password, profile, public content): for the entire duration of the contractual relationship, i.e. as long as the Account remains active.
- Account closure: within 30 days of the closure request, identification data are anonymised or deleted, except for data whose retention is required by law or necessary for the protection of rights in legal proceedings.
- Published content (posts, images, videos, audio, chat): until the User deletes it or the Account is closed; in the event of pending reports, deletion may be suspended until the conclusion of the relevant procedure.
- Payment data and tax documentation: 10 years pursuant to Art. 2220 of the Italian Civil Code and Italian tax legislation.
- Technical, security and anti-fraud logs: up to 12 months, unless an extension is necessary for ongoing investigations or to protect the Controller's rights.
- Automatic technical recordings of Calls for security and dispute management purposes: 90 days, unless extended in the presence of disputes or reports.
- Data relating to reports, disputes and disciplinary measures: up to 5 years from their resolution, or for the longest limitation period provided for by the applicable law.
- Communications with customer support: up to 24 months.
- Consents given (cookies, marketing): at least for the period of validity of the consent and for a further period necessary to document compliance with GDPR obligations (min. 12 months).
Upon expiry of the indicated periods, the data are deleted or permanently anonymised so that they can no longer be traced back to the data subject.
13. International transfers
Some providers we work with are based or have servers located in countries outside the European Economic Area. In particular:
- Stripe: the Stripe group is based in Ireland for the European entity (Stripe Payments Europe Ltd, Data Controller), with affiliated companies in the United States of America; transfers to the USA are covered by the EU-US Data Privacy Framework (EU Adequacy Decision 2023/1795) and/or Standard Contractual Clauses approved by the European Commission.
- LiveKit Inc.: a company based in the United States of America; the transfer is governed by Standard Contractual Clauses (EU Decision 2021/914) and, where applicable, by the EU-US Data Privacy Framework, with supplementary security measures (encryption in transit and at rest).
- MongoDB Atlas: the Platform uses clusters hosted in European regions; transfers to the US entity remain governed by Standard Contractual Clauses.
- Wasabi Technologies: the Platform uses European regions (in particular Wasabi EU); transfers are covered by Standard Contractual Clauses.
- Meta Platforms Ireland Limited: an entity based in Ireland; any transfers to the Meta group in the USA are covered by the EU-US Data Privacy Framework.
- Google Ireland Limited: similar safeguards through the EU-US Data Privacy Framework and Standard Contractual Clauses.
Upon written request to privacy@nymia.me, the Controller can provide you with a copy of the safeguards adopted for each transfer (in particular, the Standard Contractual Clauses signed).
14. Data security
Bull Marketing adopts technical and organisational measures appropriate to the risk, pursuant to Art. 32 GDPR, to protect your personal data from loss, destruction, unauthorised access, alteration or unlawful disclosure, including:
- encryption of data in transit via TLS (HTTPS) on all communication channels;
- encryption at rest of media content stored on Wasabi Storage;
- storage of passwords exclusively in hashed form using resistant cryptographic algorithms (e.g. bcrypt) with a random salt for each user;
- role-based access controls (RBAC) to the internal infrastructure, with the principle of least privilege;
- audit logs of administrative access and critical operations;
- regular backups and data integrity monitoring;
- vulnerability and security incident management procedures;
- periodic testing of security measures and continuous updating of the tools used;
- separation of development, test and production environments;
- periodic staff training on privacy and IT security topics.
In the event of a personal data breach involving a risk to the rights and freedoms of data subjects, Bull Marketing will notify the Italian Data Protection Authority within 72 hours of becoming aware of it (Art. 33 GDPR) and, where applicable, will communicate the breach directly to the data subjects pursuant to Art. 34 GDPR.
Despite the adoption of appropriate measures, no IT system can be considered absolutely secure: the User is required to cooperate by adopting prudent behaviour (strong passwords, safekeeping of credentials, keeping their device up to date, prompt notification of suspected unauthorised access).
15. Profiling and automated decisions
Bull Marketing uses certain automated processes and artificial intelligence tools, in particular:
- Automated content moderation (Sightengine or equivalent tools): content uploaded to the Platform is automatically analysed to detect potential violations of the community rules (prohibited nudity, illegal content, hate speech, spam, etc.). The outcome of the analysis may lead to the automatic removal of content with a high probability of violation; in such cases, the User can always request the intervention of a human moderator through the internal appeal mechanism referred to in the Terms and Conditions and Art. 20 of the DSA.
- Anti-fraud systems: automatic analysis of transactions to detect anomalous patterns (unusual purchase velocity, geographical discrepancies, previous chargebacks). Stripe in turn uses its own anti-fraud engine "Stripe Radar", with potential profiling of payment instruments.
- Abuse and brute-force detection: automatic analysis of authentication logs and API requests to prevent attacks.
- Recommendation systems: the Platform may suggest content or Voice Pros based on your interests and previous interaction, in a non-profiling form within the meaning of Art. 22 GDPR and transparently pursuant to Art. 27 of the DSA.
PURSUANT TO ART. 22 GDPR, no decisions are taken based solely on automated processing that produce significant legal effects on the data subject, unless authorised by law or by the data subject's consent. In any case, you have the right to:
- obtain human intervention by the Controller;
- express your opinion;
- contest the automated decision.
To exercise these rights, you can write to privacy@nymia.me.
17. Meta Pixel
If you have given the relevant consent, the Platform uses the Meta Pixel provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, to measure the effectiveness of communication campaigns conducted through Meta platforms (Facebook, Instagram) and for advertising targeting and re-targeting activities.
In accordance with the ruling of the Court of Justice of the European Union in case C-40/17 (Fashion ID) and the Guidelines of the European Data Protection Board, the processing carried out through the Meta Pixel takes place under a joint controllership arrangement between Bull Marketing and Meta Platforms Ireland Limited, limited to the collection and transmission phase of the data. A joint controllership agreement is available at https://www.facebook.com/legal/controller_addendum.
Meta Platforms Ireland Limited subsequently processes the data received as an independent Data Controller, in accordance with its own policies available at https://www.facebook.com/privacy/policy/.
Bull Marketing configures the Meta Pixel by adopting reasonable minimisation measures: IP address anonymisation, deactivation of the automatic collection of advanced browsing data and transmission of only essential events (for example: page view, registration, purchase). The User may object to the processing at any time by withdrawing consent from the cookie banner or from the Meta Settings of their social Account.
18. Google Analytics
Where activated and subject to your consent, the Platform uses the Google Analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to analyse the use of the site in aggregate form and improve its features.
Google Analytics processes the data collected as a Data Processor on behalf of Bull Marketing. The service is configured by adopting the following measures to ensure compliance with Italian and European legislation, taking into account the measures of the Italian Data Protection Authority of 9 June 2022 (No. 224) and subsequent ones:
- activation of IP address anonymisation;
- deactivation of Google Signals and advanced demographic reporting features;
- deactivation of data sharing with other Google services for marketing purposes;
- adoption of Standard Contractual Clauses for any transfers outside the EEA;
- limitation of data retention to the minimum strictly necessary period.
For further information on the processing carried out by Google, you can consult the relevant Privacy Policy at https://policies.google.com/privacy. You can object to the processing at any time by withdrawing your consent from the cookie banner or by installing the browser add-on for deactivating Google Analytics available at https://tools.google.com/dlpage/gaoptout.
19. Stripe and payments
All payments made on the Platform (purchase of Digital Content, Live tickets, Call bookings, tips, Wallet top-ups) are processed by Stripe Payments Europe, Limited, with registered office at 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and by the affiliated companies of the Stripe group, acting as an independent Data Controller for its own purposes (execution of payments, KYC/AML compliance, fraud management through Stripe Radar).
Stripe collects and stores the full data of payment instruments (card numbers, CVV, banking information, biometric data in the case of strong authentication), in an environment compliant with the PCI DSS Level 1 standard. Such data are NOT accessible to Bull Marketing.
Bull Marketing receives from Stripe only:
- transaction metadata (transaction ID, amount, currency, status);
- last four digits of the card and network;
- country of issue of the instrument;
- result of anti-fraud and/or authentication checks;
- for Voice Pros: status of the KYC procedure and essential information on the ability to receive payments.
For further details on the processing carried out by Stripe, you can consult Stripe's Privacy Policy (https://stripe.com/it/privacy) and the specific terms of the Stripe Connect Express service (https://stripe.com/it/legal/connect-account).
20. LiveKit
The real-time transmission infrastructure (audio and video) for Lives and Calls is provided by LiveKit Inc., a company based in the United States of America, acting as a Data Processor on behalf of Bull Marketing (Art. 28 GDPR).
LiveKit processes the following data for the sole purpose of providing the streaming services:
- audio/video streams of the participants in the Live or Call;
- participant authentication tokens and session metadata;
- technical connection indicators (latency, transmission quality, participants' IP addresses for selecting the nearest server).
Unless both parties consent (for Calls) or the Voice Pro consents (for Lives), the streams are neither recorded nor stored. Bull Marketing may arrange automatic technical recordings of limited duration for security, moderation and dispute management purposes, as indicated in the Terms and Conditions and in this Policy.
Data transfers to LiveKit are covered by Standard Contractual Clauses (EU Decision 2021/914) and, where applicable, by the EU-US Data Privacy Framework. Additional technical security measures are ensured through encryption in transit.
21. Wasabi Storage
The media content you publish on the Platform (photos, videos, audio, avatars, Live covers) is stored on the servers of Wasabi Technologies, Inc. through the Wasabi S3 Cloud Storage service, acting as a Data Processor designated pursuant to Art. 28 GDPR.
Nymia uses Wasabi's European regions (Wasabi EU) for content storage, in order to minimise the use of transfers outside the EEA. Any replications or backups to additional regions are governed by Standard Contractual Clauses.
Content is stored with encryption at rest. Access to content requires the User's authentication on the Platform and the generation of temporary signed URLs; Wasabi does not process the content for its own purposes other than the mere provision of the storage service.
22. Your rights (arts. 15-22 GDPR)
As a data subject, you have the right to exercise, at any time, the rights provided for by Articles 15-22 of the GDPR and by the applicable Italian legislation:
- Right of access (Art. 15 GDPR): to obtain confirmation as to whether or not your data are being processed and, if so, to receive a copy of the data processed and information on the categories of data, purposes, recipients and retention periods.
- Right to rectification (Art. 16 GDPR): to obtain the rectification of inaccurate data concerning you or the completion of incomplete data.
- Right to erasure — "right to be forgotten" (Art. 17 GDPR): to obtain the erasure of your data in the cases provided for by law, without prejudice to the exceptions set out in Art. 17(3) GDPR (legal obligations, defence in legal proceedings, etc.).
- Right to restriction of processing (Art. 18 GDPR): to obtain the restriction of processing in the cases provided for by law.
- Right to data portability (Art. 20 GDPR): to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit them to another controller without hindrance.
- Right to object (Art. 21 GDPR): to object at any time to processing based on legitimate interest or for direct marketing purposes.
- Right not to be subject to automated decisions (Art. 22 GDPR): as specified in Section 15.
- Right to withdraw consent (Art. 7(3) GDPR): to withdraw at any time the consents given for specific purposes, without affecting the lawfulness of the processing carried out before withdrawal.
HOW TO EXERCISE YOUR RIGHTS. To exercise one or more of these rights you can:
- use the self-service features available in the "Settings" section of your Account (profile editing, email change, password change, data export, Account closure);
- write an email to privacy@nymia.me, clearly indicating the right you intend to exercise and attaching (where necessary to verify your identity) a copy of an identity document;
- send a written communication to the postal address of the Controller's registered office.
Bull Marketing handles requests diligently and in any case within one month of receipt, subject to justified extensions pursuant to Art. 12(3) GDPR. The exercise of rights is free of charge; however, in the case of manifestly unfounded or excessive requests, in particular because of their repetitive nature, the Controller reserves the right to charge a reasonable fee or to refuse the request, giving reasons to the data subject.
DATA EXPORT. For the purposes of the right to portability, you can request the export of your data (in structured JSON or CSV format) by writing to privacy@nymia.me. The request will be handled within one month and the copy of the data will be made available via a temporary downloadable link.
23. Right to lodge a complaint
If you believe that the processing of your personal data by Bull Marketing violates the GDPR or the applicable Italian legislation, you have the right to lodge a complaint with the competent supervisory authority, namely:
- Garante per la protezione dei dati personali (Italian Data Protection Authority)
- Piazza Venezia n. 11 — 00187 Rome, Italy
- Telephone: +39 06.696771
- Email: garante@gpdp.it
- Certified email (PEC): protocollo@pec.gpdp.it
- Website: www.gpdp.it
Alternatively, you may bring proceedings before the competent judicial authority pursuant to Art. 79 GDPR.
In any case, we invite you to contact Bull Marketing in advance at privacy@nymia.me: we will try to resolve any concern as quickly and effectively as possible.
24. Minors
The Nymia Platform is intended exclusively for adults (18 years of age or older). Bull Marketing does NOT knowingly collect personal data of minors under 18.
Should Bull Marketing become aware that an Account has been created or used by a minor, it will promptly proceed with:
- the immediate suspension of the Account;
- the deletion of the minor's personal data, except where otherwise required by law (e.g. reporting obligations to the competent bodies in the event of a suspected criminal offence);
- communication to the reporting person and, where appropriate, to the competent authorities.
If you are a parent or guardian and suspect that a minor has created an Account on Nymia, please write immediately to privacy@nymia.me: we will intervene with the highest priority.
25. Changes to this Privacy Policy
Bull Marketing may amend this Policy at any time to reflect regulatory changes, technological developments, changes in the service providers used or new features of the Platform.
Substantial changes will be communicated to Users by means of a notice published on the Platform and, where appropriate, by email, with reasonable notice before their entry into force. Non-substantial changes (typographical corrections, formal clarifications, updates of regulatory references) will be published without any obligation of prior notice.
The date of the last revision of the Policy is indicated at the beginning of the document. Bull Marketing keeps previous versions of the Policy for a minimum period of twelve months; upon written request to privacy@nymia.me, it is possible to obtain a copy of the version in force at the time of your registration or of a specific transaction.
26. Privacy contacts
For any question, request or observation relating to the processing of your personal data, you can contact the Data Controller at the following addresses:
- Bull Marketing S.r.l.s.
- Registered office: Via Minelli 23, 44042 Cento (FE), Italy
- VAT number and tax code: IT02178200388
- REA registration: FE-257774
- Dedicated privacy email: privacy@nymia.me
- General support email: support@nymia.me
- Dedicated DSA reports email: report@nymia.me
DPO (Data Protection Officer): not appointed as of the date of this Policy. Should Bull Marketing appoint a DPO in the future, their contact details will be published in this Section and communicated to data subjects with adequate notice.
Competent supervisory authority: Garante per la protezione dei dati personali (www.gpdp.it), as indicated in Section 23.