Data protection

Privacy policy

Information for website visitors, prospective members, members, association activities and social channels. The complete Italian notice remains the reference version.

La discrezione è il primo lusso. Discretion is the first luxury

Data controller

Associazione Ricreativa Culturale VELVET, C.F. 91067320464, registered office Piazza Sacro Cuore 5, 55041 Camaiore (LU). Privacy contact: info@velvetclub.it.

Main data processing areas

Pre-registration flow and retention

Pre-registration data are stored in the Aruba website database, used to create a CSV copy sent to the VELVET mailbox and imported into the local VELVET Manager. Temporary database, email and CSV copies are deleted under an internal procedure: within 30 days after a successful import and in any case within 90 days if the application is not completed. The complete Italian notice sets out the separate retention periods for logs, backups, consents, former members and administrative records.

Data sources, suppliers and security

Data may be received directly from the data subject, from instructed promoters or PRs, by authorised CSV import, from external channels or from technical logs. Aruba currently provides the domain, hosting, database and email services. Newsletter and payment providers will be identified before activation. VELVET applies proportionate access controls, staff instructions, logging, updates, backups, restore checks and incident procedures without publishing security-sensitive technical details.

Members Area, PWA, Digital Pass and synchronisation

Admitted members may use a password-protected Members Area which can be installed as a Progressive Web App (PWA). Depending on the active functions it may display membership status, CAPIT information, Digital Pass, attendance records, communications, events, assemblies and association documents. The Digital Pass uses a technical identifier and QR code and does not display personal data in clear text inside the QR.

VELVET Manager is the office system used for membership applications, the membership register, CAPIT data and attendance. Only data required for the online service are synchronised with the website through authenticated HTTPS connections; identity-document copies and internal notes are not routinely transferred to the online area.

Push notifications and preferences

Push notifications are optional and require permission on the user’s device. Technical subscription endpoints, cryptographic keys and device tokens are processed to deliver them. Browser or operating-system push services, including Apple or Google services where applicable, may be involved. Members can manage separate preferences for association communications and events / parties. Push notifications do not replace any formal notice method required by the Statute, internal rules or law.

Online retention

Members Area accounts are retained for the membership relationship and the period needed to manage its termination. Push subscriptions are retained while active and are disabled after withdrawal or when the push provider reports that the endpoint is no longer valid. Technical security logs are retained only for the time needed for security and diagnostics.

No profiling or automated decisions

VELVET does not carry out profiling and does not make decisions based solely on automated processing. Formal checks performed by the website or Manager do not replace the human and association decisions on membership, reservations or access.

Rights

Data subjects may request access, rectification, erasure, restriction, objection, portability where applicable and withdrawal of consent by writing to info@velvetclub.it.