This document is generated with Iubenda and published here, on
the RegiaPro website. The original, always up to date and in Italian, is on
iubenda.com.
This English version is a translation: if the two versions differ, the Italian original prevails.
Privacy Policy of regiapro.it
Note: this English translation is provided for your information only. The legally binding text is the Italian version of this privacy policy.
Welcome to the privacy policy of regiapro.it. This policy will help you understand what data we collect, why we collect it and what your rights are in relation to it.
Last updated: 31 August 2026
Owner and Data Controller
Studioweb360 Papini Giovanni
Via casa dell opera 2
51034 Serravalle Pistoiese (PT), Italy
Owner contact email: info@regiapro.it
Types of Data we collect
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
Trackers
Usage Data
number of Users
session statistics
email address
first name
last name
phone number
Data communicated while using the service
answers to questions
User content
message or email content
profile picture
message date
time the message was sent
message sender
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.
Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Any use of Cookies – or of other tracking tools – by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.
Users are responsible for any third-party Personal Data obtained, published or shared through this Application.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located. For further information, please contact the Owner.
The User's Personal Data might be transferred to a country other than the one in which the User is located. To find out more about the place of processing, the User can check the section containing details about the processing of Personal Data.
Retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
Purposes of processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:
Analytics
Displaying content from external platforms
Contacting the User
Interaction with live chat platforms
Advertising
Detailed information on the processing of Personal Data
Contacting the User
Contact form
Personal Data processed: Usage Data +1
By filling in the contact form with their Data, the User authorizes this Application to use these details to reply to requests for information, quotes or any other kind of request.
Personal Data processed:
Usage Data
email address
Legal basis for processing:
Service provided by:
Conditions for the transfer of Data:
Data retention period:
Interaction with live chat platforms
This type of service allows Users to interact with third-party live chat platforms directly from the pages of this Application, in order to contact and be contacted by this Application's support service.
If one of these services is installed, it may collect navigation and Usage Data in the pages where it is installed, even if the Users do not actively use the service. Moreover, live chat conversations may be logged.
WhatsApp Business Chat Widget
Company: Meta Platforms Ireland Limited
Place of processing: Ireland
Personal Data processed: last name +11
The WhatsApp Business Chat Widget is a service for interacting with the WhatsApp live chat platform, provided by Meta Platforms Ireland Limited.
This type of service allows User Data to be utilized for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on this Application, possibly based on User interests.
This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below.
Some of the services listed below may use Trackers for identifying Users, or they may use the behavioral retargeting technique, i.e. displaying ads tailored to the User's interests and behavior, or they may measure ad performance.
For more information, please check the privacy policies of the relevant services.
Services of this kind usually offer the possibility to opt out of such tracking. Users may learn how to opt out of interest-based advertising by visiting the relevant opt-out section in this document.
152 Media
Company: 152 Media LLC
Place of processing: United States
Personal Data processed: Usage Data +1
152 Media is an advertising service provided by 152 Media LLC.
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics 4
Company: Google Ireland Limited
Place of processing: Ireland
Personal Data processed: Usage Data +3
Google Analytics is a web analysis service provided by Google Ireland Limited (“Google”). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
In Google Analytics 4, IP addresses are used at collection time and then discarded before Data is logged in any data center or server. Users can learn more by consulting Google’s official documentation.
This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with it. Such services are often referred to as widgets, which are small elements placed on a website or app. They provide specific information or perform a particular function and often allow for user interaction.
This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Google Maps Widget
Company: Google Ireland Limited
Place of processing: Ireland
Personal Data processed: Usage Data +1
Google Maps is a maps visualization service provided by Google Ireland Limited that allows this Application to incorporate content of this kind on its pages.
Information on opting out of interest-based advertising
In addition to any opt-out feature provided by any of the services listed in this document, Users may learn more on how to opt out of interest-based advertising
within the dedicated section
of the Cookie Policy.
Further information about the processing of Personal Data
Google Calendar synchronisation
Google Calendar synchronisation
This Application allows the User to connect, optionally, their own Google account in order to synchronise the appointments managed in the management tool with their own Google calendar.
The connection takes place only at the User's explicit request: the User authorises access through Google's consent screen and can revoke it at any time, both from the settings of this Application and from the security page of their own Google account.
Personal Data processed: the list of calendars associated with the account, and calendar event data (title, date, time, place, description, participants).
Purpose of processing: creating, reading, updating and deleting in the User's calendar the appointments corresponding to the events managed in the management tool, and showing the User their own availability. Calendar data is not used for any other purpose.
Method of processing: event data is exchanged with Google's servers solely to carry out the synchronisation requested by the User. The access credentials issued by Google are stored in encrypted form and used only on the User's behalf.
Disclosure to third parties: calendar data is not transferred, sold or disclosed to third parties, and is not used for profiled advertising or to train artificial intelligence models.
Retention: data stays synchronised as long as the connection is active. When the connection is revoked or the account is closed, the access credentials are deleted and synchronisation stops.
This Application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Place of processing: Germany (European Union) and United States - Google Privacy Policy: https://policies.google.com/privacy
Connection with Instagram (Meta)
This Application allows the User to connect, optionally, their own Instagram professional account, in order to publish on Instagram the content that the User has prepared in this Application.
The connection takes place only at the User's explicit request: the User authorises access through Meta's consent screen and can revoke it at any time, both from the settings of this Application and from the «Apps and websites» section of their own Instagram account.
Permissions requested: instagram_business_basic, to read the basic data of the connected profile, and instagram_business_content_publish, to publish content on behalf of that account. This Application does not request, and does not receive, permission to read direct messages or comments.
Personal Data processed: username and identifier of the connected Instagram account; the access credentials issued by Meta and their expiry date; the photos and texts (caption and hashtags) that the User chooses to publish. This Application does not download or store content already on the User's Instagram profile: no posts, photos, comments or messages.
Purpose of processing: publishing on Instagram, at the time chosen by the User, the content the User has prepared in this Application, and showing the User which account it goes out from. The data is not used for any other purpose.
Method of processing: at the time of publication this Application sends Meta's servers the text of the post and the public address from which to download the photo; it is Meta that downloads the photo from that address. The access credentials issued by Meta are stored in encrypted form, are used only on the User's behalf, last sixty days and are renewed automatically as long as the connection stays active.
When the content portrays a person, this Application checks that the related consent to publication is recorded, and checks it again at the very moment of publication: without that consent the content is not published.
Disclosure to third parties: the data is not transferred, sold or disclosed to anyone other than Meta, and is not used for profiled advertising or to train artificial intelligence models.
Retention: the connection data remains as long as the connection is active. When the connection is revoked, or the account is closed, the access credentials are deleted and publishing stops. How to ask for your data to be deleted is described on the Data deletion page.
This Application allows the User to connect, optionally, a Facebook Page that the User administers, in order to publish on that Page the content the User has prepared in this Application. The Facebook Page connection is separate from the Instagram account connection described above: it is switched on separately, removed separately, and may not exist at all.
The connection takes place only at the User's explicit request: the User presses «Connect the Facebook Page» in the Social section of this Application and authorises access through Meta's consent screen. The User can revoke it at any time, both from this Application (Social, Settings tab, «Scollega» / Disconnect button) and from the «Apps and websites» section of their own Facebook account settings.
Permissions requested: pages_show_list, to show the User the list of Pages they administer, so that they can choose one; pages_read_engagement, to read, in read-only mode, the name and picture of the chosen Page and, only for the posts the User published from this Application on that Page, the link to the post and the number of reactions, comments and shares, which this Application shows to the User under the post; pages_manage_posts, to publish content on the chosen Page on the User's behalf; business_management, to read, in read-only mode, the identifier and name of the Meta business portfolios the User administers: the name is shown under each Page in the list and, if Facebook returns no Page, it is used to look for the Pages owned by those portfolios, which would otherwise not be shown. This Application does not create, change or delete anything in the business portfolio. This Application does not request, and does not receive, permission to read direct messages, Page insights or advertising account data; of comments it reads neither the text nor the authors, only the number.
Personal Data processed: identifier and name of the Facebook Pages the User administers, received to build the list to choose from; identifier and name of the User's business portfolios, read to show the name under the Pages in the list and to find those Pages; identifier and name of the chosen Page, and the username of the Instagram account linked to that Page, if any; the Page access credential issued by Meta; the photos, videos and texts the User chooses to publish. This Application does not download and does not store content already on the Page: no posts, photos, comments, messages or insights. Only for the posts published from this Application, and using the access credential of that Page, it reads from Facebook, in read-only mode and without storing it: the picture of the chosen Page, the address (permalink) of each such post, and the number of reactions, comments and shares of that post. The text of comments and who wrote them are not read. This data is shown only to the User, inside their own account, and is not shared with anyone: it stays in the server's memory for at most five minutes, to avoid repeating requests to Facebook, and is not saved in the database.
Purpose of processing: publishing on the chosen Facebook Page, at the time chosen by the User, the content the User has prepared in this Application, and showing the User which Page it goes out from, how it went and how the posts published from this Application are doing (link to the post, reactions, comments and shares). The data is not used for any other purpose.
Method of processing: at the time of publication this Application sends Meta's servers the text of the post and the public address from which to download the photo or video; it is Meta that downloads them from that address. The Page access credential is stored in encrypted form, never appears in the pages of this Application and is never written to logs; it is used only on the User's behalf. A Page credential obtained from a long-lived access does not expire: it stops working when the User changes their Facebook password, removes this Application's permission or is no longer an administrator of that Page. In that case publishing on that Page stops and this Application tells the User.
When the content portrays a person, this Application checks that the related consent to publication is recorded, and checks it again at the very moment of publication: without that consent the content is not published.
Disclosure to third parties: the data is not transferred, sold or disclosed to anyone other than Meta, and is not used for profiled advertising or to train artificial intelligence models.
Retention: the Page connection — identifier and name of the Page, encrypted credential, connection date — remains as long as the connection is active. When the User presses «Scollega» (Disconnect), that record is deleted, credential included. The list of the other Pages shown during the choice is not kept: it exists only for the duration of the choice. Also not kept: the names of the business portfolios, the Page picture, the address of the posts and the numbers of reactions, comments and shares read from Facebook. The result of each publication (successful or not, Page name, date) stays in the User's post history inside this Application as long as the User has an account, and is deleted with it. Posts already published stay on the Facebook Page: they are on Facebook, not here. How to ask for your data to be deleted is described on the Data deletion page.
This chapter was added on 28 September 2026 and updated on 5 October 2026.
Meta Platforms data – summary
This section summarises the two chapters above.
RegiaPro is a management tool sold as a service to independent professionals – mostly photographers and videographers. Each customer runs their own workspace at their own address. The social module is optional: a customer may connect their own Instagram professional account, their own Facebook Page, both, or neither.
Instagram. Permissions requested: instagram_business_basic (basic data of the connected profile) and instagram_business_content_publish (publishing on behalf of that account). Data processed: the username and identifier of the connected account, the access credential issued by Meta and its expiry, and the photos and texts the customer chooses to publish. We do not download or store existing posts, photos, comments or direct messages.
Facebook Pages. Permissions requested: pages_show_list (to show the customer the list of Pages they administer, so that they can pick one), pages_read_engagement (read-only: the name and picture of the chosen Page and, only for the posts the customer published from RegiaPro on it, the post link and the number of reactions, comments and shares, shown under the post), pages_manage_posts (to publish on the chosen Page on the customer's behalf) and business_management (read-only: the names of the business portfolios the customer administers, shown under the Pages in the list and, when Facebook returns no Page, used to find the Pages owned by those portfolios; nothing is created, changed or deleted in the portfolio). Data processed: the identifiers and names of the Pages the customer administers, the identifiers and names of their business portfolios (read to show the name in the list and to find those Pages), the identifier and name of the chosen Page, the username of the Instagram account linked to it if any, the Page access credential, and the photos, videos and texts the customer chooses to publish. We do not request, receive or store direct messages, Page insights or advertising data, and we do not download or store existing Page content; of comments we never read the text or the authors, only their number. For the posts published from RegiaPro only, we read from Facebook, read-only and without storing them, the Page picture, the post link and the numbers of reactions, comments and shares: they are shown only to the customer, are kept in server memory for at most five minutes, are not saved in the database and are not shared with anyone.
Purpose. Publishing, at the time chosen by the customer, the content the customer prepared inside RegiaPro, and showing them which account or Page it went out from and whether it succeeded. The data is not used for anything else, is never sold or passed to anyone other than Meta, is never used for profiled advertising, and is never used to train artificial intelligence models.
Storage and retention. Access credentials are stored encrypted and are never shown in the interface or written to logs. The connection record lasts as long as the connection is active. When the customer disconnects – from RegiaPro (Social, Settings tab, «Scollega» / Disconnect) or from Facebook or Instagram settings, under «Apps and websites» – the credential is deleted and publishing stops. Posts already published stay on Instagram or on the Facebook Page: they are on Meta's platforms, not here, and only the customer can remove them.
Deletion. How to have data deleted, including step by step how to disconnect Instagram and the Facebook Page, is described on the Data deletion page. Requests can also be sent to info@regiapro.it; we answer within thirty days at the latest.
Data controller. Studioweb360 Papini Giovanni, Via casa dell'opera 2, 51034 Serravalle Pistoiese (PT), Italy – info@regiapro.it. Processing takes place in the European Union and in the United States. Meta's own privacy policy: privacycenter.instagram.com/policy.
Connection with TikTok
This Application allows the User to connect, optionally, their own TikTok account, in order to send to TikTok the videos and photos that the User has prepared in this Application: into the drafts of the TikTok app, where the User reviews them and posts them personally, or, only when the User chooses so for that piece of content, posted directly to their profile. The TikTok connection is separate from the Instagram and Facebook Page connections described above: it is switched on separately, removed separately, and may not exist at all.
The connection takes place only at the User's explicit request: the User presses «Collega TikTok» (Connect TikTok) in the Social section of this Application (Settings tab) and authorises access through TikTok's consent screen. The User can revoke it at any time, both from this Application (Social, Settings tab, TikTok box, «Scollega» / Disconnect button) and from the settings of their own TikTok account, in the section about connected apps and services.
Permissions requested: user.info.basic, to receive the identifier of the connected profile and its display name; user.info.profile, to receive the profile's username (@); video.upload, to send content to the drafts of the User's TikTok app; video.publish, to post it directly to the profile when the User chooses so. This Application does not request, and does not receive, permission to read profile or video statistics (user.info.stats, video.list), direct messages, comments or the list of followers.
Personal Data processed: the identifier of the connected TikTok profile (open_id), its display name and its username; the access credentials issued by TikTok, with their expiry dates, and the list of permissions actually granted; the connection date; for each piece of content sent to TikTok, the text, videos or photos chosen by the User, the settings that TikTok asks to be chosen for each piece of content (who can view it, comments, duet, stitch, commercial content disclosure), the publish identifier returned by TikTok and the result (in drafts, posted or failed, with the reason). The TikTok profile picture is not downloaded or stored. Before a direct post, this Application asks TikTok for the information that TikTok itself requires to be shown to the User (profile name, allowed visibility options, whether comments, duet and stitch are turned off on the profile): it is kept in memory for a few minutes and is not saved. This Application does not download and does not store content already on the TikTok profile: no videos, photos, comments, messages or statistics.
Purpose of processing: sending to TikTok, at the time chosen by the User, the content the User has prepared in this Application, and showing the User which TikTok profile is connected, which profile the content goes out from and how it went. The data is not used for any other purpose.
Method of processing: for a video, this Application uploads the file directly to TikTok's servers; for photos, it sends TikTok the public address from which to download a reduced copy (at most 1080 pixels per side), and it is TikTok that downloads it. The text of the post and the settings chosen by the User are sent together with the content. The access credentials issued by TikTok are stored in encrypted form, never appear in the pages of this Application and are never written to logs; they are used only on the User's behalf. The access credential lasts 24 hours and is renewed automatically, as long as the connection stays active, with the refresh credential, which lasts up to one year. If TikTok reports that the connection is no longer valid, sending to that profile stops and this Application tells the User.
When the content portrays a person, this Application checks that the related consent to publication is recorded before sending it to TikTok: without that consent the content is not sent.
Disclosure to third parties: the data is not transferred, sold or disclosed to anyone other than TikTok, and is not used for advertising, profiled or of any other kind, or to train artificial intelligence models.
Retention: the connection — identifier and names of the profile, encrypted credentials, dates, granted permissions — remains as long as the connection is active. When the User presses «Scollega» (Disconnect), that record is deleted, credentials included, and this Application also asks TikTok to revoke the authorisation on its side. The result of each submission stays in the User's post history inside this Application as long as the User has an account, and is deleted with it. Content already posted on TikTok stays on TikTok: it is on the User's profile, not here, and only the User can remove it. How to ask for your data to be deleted is described on the Data deletion page.
Place of processing: TikTok's servers; for users in the European Economic Area the controller on TikTok's side is TikTok Technology Limited (Ireland) – TikTok Privacy Policy: tiktok.com/legal/privacy-policy-eea
This chapter was added on 30 September 2026.
TikTok data – summary
This section summarises the chapter above.
What it is. RegiaPro customers may, optionally, connect their own TikTok account to send the videos and photos they prepared inside RegiaPro to TikTok: into the drafts of their TikTok app, where they review and post them themselves, or, only when they choose so for that piece of content, posted directly to their profile. The connection starts only when the customer presses «Collega TikTok» (Connect TikTok) and approves TikTok's consent screen.
Permissions requested.user.info.basic (identifier and display name of the connected profile), user.info.profile (the @username), video.upload (sending content to the TikTok drafts) and video.publish (direct posting, when the customer chooses it). We do not request or receive profile or video statistics (user.info.stats, video.list), direct messages, comments or follower lists.
Data we keep. The open_id, display name and username of the connected profile; the access and refresh credentials issued by TikTok, encrypted, with their expiry dates and the granted scopes; the connection date; for each post sent to TikTok, the settings the customer chose for it (who can view it, comments, duet, stitch, commercial content disclosure), the publish identifier returned by TikTok and the result. The profile picture is not downloaded or stored. We do not download or store existing TikTok videos, photos, comments, messages or statistics.
Purpose. Sending to TikTok, at the time chosen by the customer, the content the customer prepared inside RegiaPro, and showing which TikTok profile is connected and how each post went. The data is not used for anything else, is never sold or passed to anyone other than TikTok, is never used for advertising of any kind, and is never used to train artificial intelligence models.
Retention and disconnection. The connection record lasts as long as the connection is active. When the customer presses «Scollega» (Disconnect) in RegiaPro (Social, Settings tab, TikTok box), the record and its credentials are deleted and RegiaPro also asks TikTok to revoke the authorisation. Access can also be removed at any time from the TikTok account settings, in the section about connected apps and services. Content already posted stays on TikTok, on the customer's profile, and only the customer can remove it. How to have all data deleted is described on the Data deletion page; requests can also be sent to info@regiapro.it.
This Application also exists as an app for iPhone and Android, called «RegiaPro». It is used by the studio that subscribes to RegiaPro and, when the studio offers it, by the studio's clients, for example to view their galleries and save the photos they bought. The app is not a separate service: it is another way into the same workspace of the studio, and it processes the data described in this policy.
Who decides about the data: for the data of the studio's clients that goes through the app (names, contacts, appointments, galleries, photos, orders) the data controller is the studio; RegiaPro processes that data on the studio's behalf, as data processor, only to run the service, as stated in the Terms of use. For the data of the studio's own account the data controller is the one named at the top of this page.
Advertising and tracking: the app shows no ads, contains no analytics or behavioural analysis tools, contains no third-party code that tracks the User across different apps and websites, and does not read the phone's advertising identifier. The data processed by the app is not sold and is not used for profiled advertising.
Camera: the app uses it only when the User presses the button that opens it, for two things: scanning the QR code that links the phone to their studio, and taking photos or videos during a job, to upload to the chosen gallery. The app does not use the microphone and does not ask for permission to use it.
Photos on the phone: the app opens the phone's photos only when the User chooses to upload some of them to a gallery, and receives only the ones the User selects. When a client asks to save the photos they bought on the phone, the app adds them to the phone's photo library, asking only for permission to add; the temporary copy used to download them is deleted right afterwards.
Notifications: they are optional, and the app offers them only when the User taps the dedicated box or the switch in the settings, never at first launch. If the User turns them on, the phone receives a notification code from the system, which the app sends to the studio's server; the management software uses it only to tell the User what is happening in their work, for example a new contact, an appointment, a payment, a gallery or a post to approve. Notifications leave from the studio's server and go through Expo's notification service (650 Industries, Inc., United States), which delivers them through Apple (iPhone) or Google (Android): these services receive the phone's code and the text of the notification. The User can turn them off at any time from the app settings, and the code is then removed from the studio's server, or from the phone settings.
Sign-in: the User signs in with the email and password of their account or, if they prefer, with «Sign in with Apple» or «Sign in with Google»; the studio can also link the phone by scanning the QR code shown by the management software. With Apple or Google, it is they who confirm the User's identity: the app receives a token that the studio's server verifies, and from which it takes the email address and, when the service provides it, the name. These two services are used only to sign in. At each sign-in the app tells the studio's server the name and model of the phone, the system (iPhone or Android) and the app version: they are used to show the list of phones connected to the account, from which any phone can be disconnected.
Where the data is kept: the contacts, appointments, galleries, photos and the other data the User enters or views in the app are kept on the studio's server, that is in its RegiaPro workspace, on servers in Europe, just like the data used from the computer. On the phone the app keeps, in the system's protected storage (Keychain on iPhone, Keystore on Android), the sign-in code that keeps it connected and a few preferences (theme, language, notifications); that code is not included in backups to other phones. Images already viewed may stay for a while in the app's temporary memory, to show them faster.
Updates and technical reports: to know whether an updated version is available, the app asks Expo's update service, which receives only technical data (the system, the app version and a random installation code, not linked to the person). Apple and Google may collect on their own, if the User has allowed it in the phone settings, technical reports about app crashes, under their own policies.
Permissions: camera, photos and notifications can be revoked at any time from the phone settings; the app keeps working, without the parts that need them.
Deleting the account: a studio's client can delete their account directly from the app, by tapping the person icon at the top right and then «Delete my account». Before deleting, the app explains what is deleted (the account and password, the sign-ins from all phones, the events followed and the download history) and what is kept (purchase receipts, without the name, because tax rules require it; the photos already saved on the phone, which remain the User's), and asks to confirm with the password or with a code sent by email. A studio's account is deleted on request, as described on the Data deletion page. Uninstalling the app does not delete the account.
Place of processing: European Union for the studio's server; United States and other countries for the Expo, Apple and Google services used for notifications, updates and sign-in.
This chapter was added on 5 October 2026.
RegiaPro mobile app – summary
This section summarises, in English, the chapter above. The Italian text is the binding one.
What it is. The RegiaPro app for iPhone and Android is another way into the same RegiaPro workspace of a studio. It is used by the studio that subscribes to RegiaPro and, when the studio offers it, by the studio's clients (for example to view their galleries and save the photos they bought). For the clients' data the studio is the data controller and RegiaPro processes that data on the studio's behalf, as data processor, only to run the service.
No ads, no tracking. The app shows no ads, contains no analytics or behavioural tracking tools, contains no third-party code that tracks users across apps and websites, and does not read the device advertising identifier. Data is never sold and never used for profiled advertising.
Camera. Used only when the user presses the button that opens it: to scan the QR code that links the phone to the studio, and to take photos or videos during a job for the chosen gallery. The microphone is not used and its permission is not requested.
Photos. The app receives only the photos the user picks for upload. When a client asks to save purchased photos, the app adds them to the photo library with add-only permission; the temporary download copy is deleted right away.
Notifications. Optional, and never requested at first launch. If the user turns them on, the device push token is sent to the studio's server and used only for work notifications (new contact, appointment, payment, gallery, post to approve). Notifications are relayed by Expo's push service (650 Industries, Inc., United States) through Apple or Google, which receive the token and the notification text. They can be turned off in the app settings (the token is then removed from the studio's server) or in the phone settings.
Sign-in. Email and password, or Sign in with Apple / Sign in with Google, used only to sign in: the studio's server verifies the token issued by Apple or Google and takes the email address and, when provided, the name. At each sign-in the app sends the phone name and model, the system and the app version, shown in the list of connected phones, from which any phone can be disconnected.
Storage. Contacts, appointments, galleries and other data stay on the studio's server, in the European Union. On the phone the app keeps only its sign-in token and a few preferences in the system's secure storage (Keychain / Keystore), not included in backups to other devices, plus a temporary cache of images already viewed. Update checks go to Expo's update service with technical data only (system, app version, a random installation code).
Account deletion. A studio's client can delete their account inside the app: the person icon at the top right, then «Delete my account» («Cancella il mio account» in Italian). Purchase receipts are kept without the name, as tax rules require. A studio account is deleted on request, as described on the Data deletion page. Uninstalling the app does not delete the account.
Data controller. Studioweb360 Papini Giovanni, Via casa dell'opera 2, 51034 Serravalle Pistoiese (PT), Italy – info@regiapro.it.
Cookie Policy
This Application uses Trackers. To learn more, Users may consult the Cookie Policy.
Further information for Users in the European Union
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
Users have given their consent for one or more specific purposes.
provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
processing is necessary for compliance with a legal obligation to which the Owner is subject;
processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Further information about retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
Pertanto:
Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
Personal Data collected for the purposes of the Owner's legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
The rights of Users based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Owner.
In particular, Users have the right to do the following, to the extent permitted by law:
Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
Restrict the processing of their Data. Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Owner.
Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
Lodge a complaint. Users have the right to bring a claim before their competent data protection authority or to take legal action.
Users are also entitled to learn about the legal basis for Data transfers abroad including to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
Details about the right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users' request, the Owner will inform them about those recipients.
Additional information about Data collection and processing
Legal action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
Additional information about User's Personal Data
In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data (such as the IP Address) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time using the contact information.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User's browser.
Tracker
Tracker indicates any technology - e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that enables the tracking of Users, for example by accessing or storing information on the User’s device.
Legal information
Unless otherwise stated, this privacy policy relates solely to this Application.
Although we strive to create a positive user experience, we know that problems between us and our users can occasionally arise.
If that happens, do not hesitate to contact us.