Always Friday Privacy Policy
Last updated: July 24, 2026
Data Controller
Always Friday S.r.l. - Via del casello, 5 - Latina (LT) - 04100, Italy
Owner contact email: info@alwaysfriday.it
Types of Data collected
Among the types of Personal Data that Always Friday collects, by itself or through third parties, there are: registration and account data (first name, last name, email address, password, phone number, company and role); data relating to the events organized through the Platform (event brief, location, dates, number of attendees and — where provided by the User — attendee data, preferences and requests); content uploaded or sent by the User (documents, images, messages exchanged on the Platform or by email with Always Friday and with suppliers); Usage Data and Trackers (see the Cookie Policy for details).
Providing the data marked as mandatory during registration or ordering is necessary for the provision of the Service: failure to provide it may make it impossible to register, fulfil orders or deliver the related features. Providing any other data is optional.
Users who communicate third-party Personal Data to Always Friday (for example, the data of Event attendees) warrant that they have the right to do so, that they have provided those third parties with the information required by law, and assume all related responsibility.
Legal basis of processing
The Owner processes Personal Data on one or more of the following legal bases: performance of a contract to which the User is party or pre-contractual measures taken at the User’s request (Art. 6(1)(b) GDPR — registration, account management, Event organization, invoicing); compliance with legal obligations (Art. 6(1)(c) GDPR — accounting and tax obligations); the Owner’s legitimate interest (Art. 6(1)(f) GDPR — Platform security, prevention of abuse and fraud, Service improvement, defense of its rights); the User’s consent (Art. 6(1)(a) GDPR — Trackers in the Experience and Measurement categories, as described in the Cookie Policy).
Where processing is based on consent, the User may withdraw it at any time without affecting the lawfulness of the processing carried out before the withdrawal.
Methods and place of processing of the Data collected
The Owner takes appropriate technical and organizational security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data. Processing is carried out using computers and/or IT-enabled tools, following organizational procedures and modes strictly related to the purposes indicated.
In addition to the Owner, the Data may be accessible to internal parties involved in the organization of the Service (administration, sales, technical staff) or to external parties (such as third-party technical service providers, hosting providers, communication service providers) appointed, where necessary, as Data Processors pursuant to Art. 28 GDPR. The updated list of Processors may be requested from the Owner.
The Data is processed at the Owner’s operating offices and at the data centers of its service providers, located mainly in the European Union. Some providers (listed in the purposes section and in the Cookie Policy) are based in the United States: in such cases, the transfer takes place on the basis of an adequacy decision (including the EU-US Data Privacy Framework, where the provider adheres to it) or of appropriate safeguards under Art. 46 GDPR, such as the standard contractual clauses approved by the European Commission.
Retention period
Data is processed and stored for as long as required by the purposes for which it was collected: account and Event data for the entire duration of the contractual relationship and, after its termination, for the time needed to settle any pending matter; data needed to comply with accounting and tax obligations for 10 years; data processed on the basis of consent until the consent is withdrawn; consent records (consent logs) for the time needed to demonstrate compliance with legal obligations.
At the end of the retention period the Data is deleted or anonymized, unless further storage is necessary to establish, exercise or defend a legal claim or to comply with legal obligations.
Purposes of processing and services used
The User’s Data is collected to allow the Owner to provide the Service and in particular to: register and authenticate the User (managed directly by the Platform); plan, organize and manage Events, including contacts with suppliers; send operational and transactional email communications; handle invoicing and administrative obligations; provide User support; ensure security and prevent abuse; perform analytics and measurement (subject to consent); optimize and improve the Service.
To deliver the Service, the Owner relies on third-party providers, which process Data on behalf of the Owner or as independent controllers, including: Amazon Web Services EMEA SARL (infrastructure hosting and transactional email delivery via Amazon SES); Google LLC (Google Analytics 4, Google Tag Manager and Google Maps — see the Cookie Policy); Amplitude Inc., Hotjar Ltd., Claydar and Meticulous (analytics, behavior analysis and session recording, active only upon consent — see the Cookie Policy); Calendly, LLC (appointment scheduling); Microsoft (Azure services, including text processing via the Azure OpenAI Service in support of Event organization); Functional Software, Inc. dba Sentry (application error monitoring); Stream.io, Inc. (in-Platform chat features); Aircall (telephony and support); Cloudflare, Inc. (SPAM protection and security).
AI-based assistance features process the content provided by the User (for example, the event brief and messages) solely to support the organization of Events, in accordance with the contractual terms applicable to the providers of those services.
The rights of Users
Users may exercise certain rights regarding the Data processed by the Owner. In particular, to the extent permitted by law, the User has the right to: withdraw consent at any time; object to the processing of their Data (Art. 21 GDPR); access their Data (Art. 15 GDPR); verify its accuracy and ask for rectification (Art. 16 GDPR); restrict the processing (Art. 18 GDPR); have their Personal Data deleted or otherwise removed (Art. 17 GDPR); receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller (portability, Art. 20 GDPR); lodge a complaint with the competent supervisory authority (for Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it) or take legal action.
Requests may be addressed to the Owner at info@alwaysfriday.it. The Owner replies within one month of receiving the request, unless extended in the cases provided for by law. Preferences regarding Trackers can be managed independently via the panel accessible from the Cookie Policy.
Additional information about Data processing
Legal action: the User’s Personal Data may be used for legal purposes by the Owner in court or in the stages leading to possible legal action arising from improper use of the Service by the User or third parties.
System logs and maintenance: for operation and maintenance purposes, the Platform and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User’s IP address.
Minors: the Service is addressed to Users acting in the exercise of a business or professional activity (B2B) and is not intended for persons under the age of 18.
Automated decision-making: the Owner does not take decisions based solely on automated processing which produce legal effects concerning the User or similarly significantly affect them.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, in the event of substantial changes, via the Platform or by email. Please check this page frequently, referring to the date of the last modification listed at the top.
Should the changes affect processing activities based on consent, the Owner shall collect new consent from the User, where required.
