Privacy Policy
June 2026
1. Data Controller
The Data Controller for the processing of personal data is:
- Company: gyn.dev Srl
- Registered office: Via Vincenzo Monti, 32 - 20123 Milan, Italy
- VAT Number: 13658260966
- Email: support@theold.farm
- Privacy email: privacy@theold.farm
2. Scope
This privacy policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") and applies to all individuals who interact with the The Old Farm platform ("Service"), accessible through the domains app.theold.farm and www.theold.farm.
This policy covers three categories of data subjects:
- Registered users: farm owners and operators who access the administrative dashboard.
- Public visitors: people who view public content (e.g. product information) via QR tags, web links, or iframes.
- Institutional website visitors: users who browse the
www.theold.farmwebsite.
3. Personal data collected
3.1 Registered users (owners and operators)
At the time of registration and during use of the Service, we collect:
| Data | Required | Purpose |
|---|---|---|
| Yes | Access to the Service, service communications | |
| First and last name | Yes | Identification in the interface |
| Phone number | No | Optional contact |
| Profile photo | No | Interface personalization |
| Preferred language | Yes | Interface personalization |
| Timezone | Yes | Correct display of dates and times |
| Login credentials (password) | Yes | Authentication (managed by a dedicated system, not accessible to the application platform) |
| Last login | Automatic | Account security |
| Navigation data in the admin area | Automatic | Service analysis and improvement |
3.2 Organization data (farms)
Users may enter data related to their farm: name, type, and description; logo and images; address, country, and region; website; VAT number / Tax code of the farm. Such data may constitute personal data in the case of sole proprietorships.
3.3 Public visitors (unregistered users)
When a visitor accesses a public page of the Service (e.g. a product page via QR tag), the following technical data is automatically collected: IP address, User Agent (browser type and operating system), browser language, referring URL (referer), date and time of access. Public visitors are not required to register and do not knowingly provide personal data.
3.4 Institutional website visitors
The website www.theold.farm does not collect personal data and does not use cookies. Anonymous and aggregated browsing data (pages visited, referrer, device type) is collected solely to improve the service. This data cannot be traced back to identifiable individuals and is not used for profiling.
3.5 Payment data
Payment data (credit card number, expiration date, CVV) is collected and managed exclusively by Stripe, Inc., our payment service provider. Such data is never transmitted to or stored on our systems. For information on how Stripe processes data, please refer to its privacy policy.
4. Purposes and legal bases
| Purpose | Legal basis | Data subjects |
|---|---|---|
| Service delivery (registration, account management, platform features) | Performance of a contract (Art. 6.1.b GDPR) | Registered users |
| Payment processing and billing | Performance of a contract (Art. 6.1.b GDPR) and legal obligation (Art. 6.1.c GDPR) | Registered users |
| Service communications (technical notices, contract changes, deadlines) | Performance of a contract (Art. 6.1.b GDPR) | Registered users |
| Analysis of dashboard usage for Service improvement | Legitimate interest of the Controller (Art. 6.1.f GDPR) | Registered users |
| IT security, abuse prevention, and debugging | Legitimate interest of the Controller (Art. 6.1.f GDPR) | Registered users, Public visitors |
| Logging of public page access for aggregate statistics and security | Legitimate interest of the Controller (Art. 6.1.f GDPR) | Public visitors |
| Compliance with legal obligations, responses to authority requests | Legal obligation (Art. 6.1.c GDPR) | All |
With regard to processing based on legitimate interest, the data subject has the right to object at any time as described in section 9.
5. Processing methods
Personal data is processed using electronic tools and is protected by appropriate technical and organizational measures to ensure its security and confidentiality, in accordance with Article 32 of the GDPR. Data in transit and at rest is protected by encryption.
6. Recipients and sub-processors
To provide the Service, the Controller engages the following providers who process personal data as Data Processors (Art. 28 GDPR):
| Provider | Function | Data processed | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Payment data, email, name | European Union / United States (see Stripe DPA) |
| Google Cloud Platform (Google LLC) | Storage of uploaded images and documents | Image files, documents (e.g. invoice PDFs) | European Union |
| Amazon Web Services, Inc. | Transactional email delivery | Email, name | European Union / United States (see AWS DPA) |
| Fatture in Cloud (TeamSystem S.p.A.) | Electronic invoicing | Identity and billing data | Italy / European Union |
Authentication is managed by a dedicated system hosted by the Controller (auth.theold.farm); passwords are not accessible to the application platform. All sub-processors are bound by Data Processing Agreements compliant with Article 28 of the GDPR. Personal data is not disclosed to third parties for purposes other than those indicated above, except where required by law.
7. Data transfers outside the EU
Personal data is stored on servers located within the European Union. Where any of the sub-processors indicated in section 6 processes data in countries outside the European Economic Area (EEA), such transfer is based on adequate safeguards pursuant to Articles 46-49 of the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs).
8. Data retention
The Controller retains personal data for the time strictly necessary to achieve the purposes for which it was collected, in compliance with the principle of data minimization. At the end of the identifiable retention period, data is anonymized and retained in aggregate form for statistical and Service improvement purposes.
| Data category | Identifiable retention | Afterwards |
|---|---|---|
| Registered user profile | For the duration of the contract and up to 10 years after termination | Anonymization |
| Organization (farm) data | For the duration of the contract and up to 10 years after termination | Statistical aggregation |
| Public page access data (IP, User Agent) | 90 days | Anonymization and aggregation |
| Operations log (audit log) | 24 months | Anonymization |
| Uploaded images and documents | Until deletion by the user or contract termination + 30 days | Permanent deletion |
| Login credentials | Until account deletion + 30 days | Permanent deletion |
| Billing data | 10 years from accounting entry (Art. 2220 Italian Civil Code) | Mandatory retention |
Data may be retained for a longer period in the event of litigation or at the request of a competent authority.
9. Data subject rights
Pursuant to Articles 15-22 of the GDPR, the data subject has the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21) to processing based on the legitimate interest of the Controller, and withdrawal of consent where processing is based on consent (without affecting the lawfulness of processing carried out prior to withdrawal).
To exercise these rights, the data subject may contact the Controller at privacy@theold.farm. The Controller undertakes to respond within 30 days of receiving the request.
10. Right to lodge a complaint
The data subject has the right to lodge a complaint with the Italian Data Protection Authority:
- Garante per la protezione dei dati personali
- Piazza Venezia 11, 00187 Rome, Italy
- Web: www.garanteprivacy.it
- Email: protocollo@gpdp.it β PEC: protocollo@pec.gpdp.it
11. Cookies and similar technologies
For details on the cookies and technologies used, please refer to the Cookie Policy. In summary: the dashboard (app.theold.farm) uses strictly necessary technical cookies (authentication, security) and usage analytics (PostHog) to improve the product, based on the legitimate interest of the Controller, with the right to object (by writing to privacy@theold.farm); the institutional website (www.theold.farm) collects by default only anonymous, aggregate statistics (PostHog cookieless) and enables full analytics with cookies only with the consent given via the banner. Public pages only save the language preference in localStorage.
12. Children's privacy
The Service is not intended for users under the age of 16. We do not knowingly collect data from minors.
13. Changes to this policy
The Controller reserves the right to modify this privacy policy at any time. Changes will be published on this page with an updated "last updated" date. In the event of material changes, registered users will be notified by email.