Data controller
The controller is Tenet System di Fabrizio Cerulli, with registered address at via Pietro Nenni 5, 20128 Milano, Italia. VAT number 14595820961. This notice covers the website and applications; using the app will be covered by its own privacy notice.
Early access application
We ask for your name, email, country, device, participation modes and arenas of interest. You may add a social profile link. We record your language, confirmation that you are at least 16, the privacy notice version and acknowledgment date, application date and review status.
If the incoming link includes campaign codes, we store utm_source, utm_medium and utm_campaign with the application to identify its campaign of origin. We do not record browsing history. Do not put personal information in campaign codes or sensitive information in the fields.
Required fields are needed to handle your application. The social link and marketing choice are optional. We do not request passwords, identity documents, your full birth date or payment details.
Purposes and legal bases
We use these details to organize and review applications and contact selected applicants. The legal basis is the controller’s legitimate interest in preparing early access groups and responding to requests (Article 6(1)(f) GDPR). You may object under the conditions provided by law.
Only if you tick the optional box will we use your email for updates and communications about Tapper, based on consent (Article 6(1)(a) GDPR). We record your choice and, if positive, its date. You can withdraw consent without affecting earlier lawful processing or losing your application. Acknowledging the privacy notice is separate from marketing consent.
Submitting does not create an account or guarantee access, a TestFlight invitation or selection. We do not make decisions with legal effects based solely on automated processing of applications.
Recipients and anti-abuse protection
Applications are accessible to people authorized to manage them. The infrastructure uses Cloudflare Workers and D1 to receive and store requests separately from the app. We do not sell this data. It may be disclosed to authorities where required by law.
When the form is active, Cloudflare Turnstile checks for abusive submissions. The widget loads when you interact with the form. Cloudflare may process IP addresses and technical browser signals under its Turnstile privacy notice. This protection relies on the legitimate interest in preventing abuse. Our application database does not store Turnstile tokens, full IP addresses or full user agents.
Cloudflare may process data outside the European Economic Area. Transfer safeguards are described in Cloudflare’s Data Processing Addendum, including standard contractual clauses where applicable. The document is available through the link below; you can request a copy from the controller.
Retention
We keep application data for at most 12 months from the request, unless deleted earlier. Data for updates is kept within the same limit or until consent is withdrawn, if earlier. A duplicate request does not extend retention.
Submitting again with the same normalized email does not change the earlier application or recorded consent. Use the contact details below for corrections, withdrawal or deletion.
Your rights and contacts
Where applicable, you can request access, correction, deletion, restriction and portability, object to processing and withdraw consent. You can complain to the Italian data protection authority or another competent supervisory authority.
To exercise your rights, state the email used to apply and what you need. We may request the minimum information needed to verify the request. Do not send passwords or unsolicited identity documents. You can also write to the controller at the registered address above.
Contact details
For information, data requests, exercising your rights or questions about your application:
