Privacy Policy

Last updated: 17 July 2026

This notice describes processing carried out through stayopen.it, contact forms, applications and event registrations.

Controllers and joint controllers

OPEN S.r.l., Piazzale Luigi Sturzo 15, 00144 Rome, VAT 16423471008, info@stayopen.it, is controller for the website, contacts and applications.

For some event registrations, OPEN S.r.l. acts as joint controller under Article 26 GDPR with the relevant organiser. The identity and contact details of that joint controller are shown in the event-specific notice inside the form before data is collected. The essential terms of the arrangements may be requested from OPEN S.r.l.

Data processed

  • Contact details, request type and messages.
  • Application, professional profile, availability and CV data relevant to the role.
  • Event registration, organisation, role, interests, organisational requests and consent records.
  • Voluntarily supplied dietary, travel or accessibility needs, which may reveal special-category data.
  • IP address, technical logs, device, viewed pages and online identifiers as described in the Cookie Policy.

Purposes and legal bases

  • Enquiries and quotations: pre-contractual steps or contract (Art. 6(1)(b)).
  • Recruitment: pre-contractual steps and legal obligations (Art. 6(1)(b) and (c)).
  • Event registration, accreditation, safety and organisation: contract/pre-contractual steps and legitimate organisational interests (Art. 6(1)(b) and (f)).
  • Dietary or accessibility needs: explicit consent (Art. 6(1)(a) and 9(2)(a)).
  • Marketing, identifiable promotional imagery, Analytics and external media: separate consent where required.
  • Security and abuse prevention: legitimate interest.

Provision of data

Required fields are necessary to handle the relevant request. Marketing, external media and promotional image use are optional. Special requirements are optional, but without them the relevant assistance may not be arranged.

Recipients and suppliers

Authorised personnel, joint controllers, Google Cloud/Firebase, Google Forms, the Helios event project, Resend or email providers, IT and event suppliers, venues and advisers may receive data only where necessary. Data is not shared for third-party independent marketing without specific consent.

International transfers

Some suppliers may process data outside the EEA. Transfers rely, as applicable, on an adequacy decision including the EU-US Data Privacy Framework, or Standard Contractual Clauses and supplementary measures. Details may be requested from the controller.

Retention

  • Unsuccessful contacts: up to 24 months.
  • Applications: up to 12 months unless renewed or a relationship begins.
  • Event registrations: up to 24 months after the event.
  • Marketing: until withdrawal and no longer than 24 months after the last interaction or consent review.
  • Administrative records: statutory terms, normally 10 years; security logs: up to 12 months.

Automated decisions

No solely automated decision produces legal or similarly significant effects. Applications receive human review.

Rights

You may request access, correction, deletion, restriction, portability, objection and withdrawal of consent by emailing info@stayopen.it. You may complain to the competent supervisory authority.