Privacy policy
Last updated: 3 September 2026
This notice explains which personal data we collect through the supplyone.app website and the SupplyONE platform, why we use it and which rights you can exercise. It is written under the European data protection regulation of 2016.
1. Data controller
The data controller is Investfood SRL, Via Riva di Trento 11/A, Milan, Italy, VAT number 12925600962.
For any request about personal data write to info@investfood.it.
2. Data processed on the public website
When you visit the public pages of supplyone.app we process:
- browsing data collected by the systems that serve the site, such as IP address, browser type, requested page, date and time of the request
- data you send us on your own initiative by email, such as name, email address, company and message
- the cookie choice you express, stored in your browser
We do not use advertising cookies and we do not sell data to third parties.
3. Data processed inside the platform
The SupplyONE platform processes data of the users who sign in, such as name, email address, role, assigned location and log of the actions performed. It also processes the business data entered by the client, such as supplier and customer records, documents, orders and HACCP entries.
For that data Investfood SRL acts as processor on behalf of the client company, which remains the controller. The relationship is governed by the service contract and by the related data processing agreement.
4. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Running the site and information security | Legitimate interest in keeping the service available and protected | Technical logs for 12 months |
| Answering contact requests | Pre contractual measures at your request | 24 months from the last contact |
| Providing the platform to authorised users | Performance of the contract with the client company | Contract duration and legal terms |
| Anonymous statistics on page views | Consent, which can be withdrawn at any time | 14 months |
| Accounting and tax duties | Legal obligation | 10 years |
5. Recipients and providers
Data may be processed by providers acting as processors, chosen for their guarantees and compliance:
- Google Cloud and Firebase for infrastructure, database and site delivery, with resources located in the European Union
- email providers used to send orders and service messages
- support and electronic document storage providers
We do not disclose personal data publicly. Any transfer outside the European Economic Area happens only towards countries with an adequacy decision or under standard contractual clauses approved by the European Commission.
6. Retention
We keep data for the time needed for the purposes above and never beyond legal terms. When a contract ends, business data is returned or deleted according to the instructions of the client controller.
7. Your rights
You can exercise the rights set out in articles 15 and following of the regulation at any time:
- access to your data and a copy of it
- rectification of inaccurate data and completion of incomplete data
- erasure in the cases provided for
- restriction of processing
- portability of the data you provided
- objection to processing based on legitimate interest
- withdrawal of consent, without affecting processing already carried out
Requests can be sent to info@investfood.it. We answer within one month, extendable by two months for complex requests.
If you believe the processing breaks the rules you can lodge a complaint with the Italian data protection authority, Piazza Venezia 11, Rome.
8. Providing data and what happens if you do not
Browsing data is needed for the technical operation of the site. The data you send us to get in touch is optional: without it we cannot answer your request.
For platform users, name, email address and role are needed to create the access foreseen by the contract with the client company. Without them the account cannot be activated.
9. Where the data comes from
Data about platform users does not reach us directly from the person but from the client company that asks for the account. The categories of data are the ones listed in the previous section.
10. Automated decisions
We do not take automated decisions producing legal effects on people. Reorder suggestions, document reading and forecasting work on business data and always stay editable by the person using them.
11. Cookies
The site uses only technical cookies and local storage needed to run it. The full list, with purpose and duration, is in the cookie policy, where you can also change your choice.
12. Security
We apply appropriate technical and organisational measures: encrypted connections, personal credentials, permissions per role, separation between client companies verified on every request, a log of sensitive actions, automatic backups and application secrets kept in a dedicated vault.
13. Minors
The site and the platform address professionals and companies. We do not knowingly collect data of people under sixteen.
14. Changes
This notice may be updated to follow legal changes or new features of the service. The date at the top of the page always shows the latest revision.
