Privacy Policy
This notice describes processing through repairos.it and the RepairOS cloud platform. It distinguishes data processed by RepairOS as controller from repair-shop customer data processed on behalf of subscribers.
1. Data controller
MasterTech di Petrongolo Luigi, sole proprietorship of Luigi Petrongolo
Viale Abruzzo 150, 66100 Chieti (CH)
VAT no.: 02707090698
Email: info@mastertechchieti.it · Tel. 320 950 4829
https://www.repairos.it
No Data Protection Officer (DPO) has been appointed, as the applicable conditions are not currently met. Privacy requests may be sent to the address above.
2. Privacy roles within the platform
RepairOS is controller for visitor data, subscriber registration, billing, support, security and contract administration. The subscribing repair shop is controller for data it enters about its customers, devices, repairs, sales and staff; for such data RepairOS acts as processor under Article 28 GDPR, in accordance with documented instructions and the data-processing terms included in the Terms.
Each repair shop must provide its customers with its own privacy notice and ensure it has a legal basis for recording and communicating data through RepairOS.
3. Personal data processed
- Technical data: IP address, date and time, browser, operating system, session identifiers, security logs and HTTP requests.
- Account and organisation: name, surname, email, phone, encrypted credentials, role, business name, VAT number, address, logo and locations.
- Contract and payments: plan, subscription status, expiry dates, coupons, Stripe identifiers and billing data; RepairOS does not receive full card numbers.
- Support and contact data: message content, quote requests, reports and communications.
- Repair-shop data: customer details, contact data, devices, IMEI/serials, reported faults, photos, signatures, quotes, payments, parts, sales and operational history.
- Optional public data: shop profile, address, contact details, opening hours, coordinates and reviews published by the subscriber.
RepairOS is not designed for special-category data under Article 9 GDPR. Do not enter health data, biometric identification data or other sensitive data unnecessary for the repair.
4. Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Registration, authentication and service delivery | Contract and pre-contractual steps, Art. 6(1)(b) | Account term and up to 90 days after termination, subject to backups and legal duties |
| Subscriptions, payments and billing | Contract and legal obligation, Arts. 6(1)(b)-(c) | 10 years for accounting and tax records |
| Support, enquiries and complaints | Contract or legitimate interest, Arts. 6(1)(b)-(f) | 24 months after closure, subject to disputes |
| Security, abuse prevention and legal claims | Legitimate interest and legal duties, Arts. 6(1)(c)-(f) | Logs normally 180 days; longer for incidents or disputes |
| Repair-shop customer data | Instructions of the repair shop as controller; Art. 28 | According to the shop’s settings/instructions and no later than 90 days after termination, subject to backups |
| Optional cookies, if activated in future | Consent, Art. 6(1)(a) and Section 122 Italian Privacy Code | According to the Cookie Policy and until withdrawal |
At expiry, data is deleted or anonymised unless needed for legal duties, pending requests or legal claims. Backup copies are overwritten according to the technical retention cycle.
5. Requirement to provide data
Mandatory data is required to register, enter into or perform the contract. Failure to provide it prevents use of the relevant feature. Optional data may be omitted without affecting essential functions.
6. Recipients and service providers
- VPS infrastructure and self-hosted Supabase components for application, database and authentication;
- Stripe for checkout, fraud prevention and subscription management;
- Aruba/email provider for transactional and support communications;
- Meta Platforms/WhatsApp, only when the shop enables or initiates messages;
- MobileSentrix, only for the restricted parts integration and at the direction of an authorised user;
- OpenStreetMap, CARTO and Nominatim for maps and geocoding;
- Google Fonts for website font delivery;
- tax, legal or technical advisers and authorities where required by law.
Providers receive only data necessary for their service and are governed, where required, by Article 28 GDPR agreements.
7. International transfers
Some providers, particularly Stripe, Google and Meta, may process data outside the EEA. Such transfers rely on an adequacy decision, including the EU-US Data Privacy Framework for certified organisations, or Standard Contractual Clauses and supplementary measures where required. Information about safeguards may be requested from the privacy contact.
8. Security and data breaches
Proportionate safeguards include HTTPS/TLS, role- and tenant-based access control, authentication, event logging, updates, backups and logical data segregation. No system is risk-free; users must protect credentials and devices and promptly report suspicious access.
Breaches are handled under Articles 33-34 GDPR; when acting as processor, RepairOS informs the controller repair shop without undue delay.
9. Automated decision-making
RepairOS does not make solely automated decisions producing legal or similarly significant effects under Article 22 GDPR and does not commercially profile users.
10. Data-subject rights
Data subjects may request access, rectification, erasure, restriction, portability, objection and consent withdrawal under Articles 15-22 GDPR. Withdrawal does not affect prior processing. Requests should be sent to info@mastertechchieti.it. Reasonable identity verification may be requested. If the request concerns data entered by a repair shop, it should normally be addressed first to that shop as controller.
11. Complaint
A complaint may be lodged with the Italian Data Protection Authority, Piazza Venezia 11, 00187 Rome, through www.garanteprivacy.it, or with the supervisory authority of the EEA state of residence, work or alleged infringement.
12. Children
The professional service is not intended for children. Accounts may only be created by adults with legal capacity or authority to represent an organisation.
13. Cookies and similar technologies
For the current list, retention periods and available choices, see the Cookie Policy.
14. Updates
This notice may be updated for legal or technical changes. Material changes will be communicated by appropriate means and the date above identifies the current version.