Privacy notice

Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679

Last updated:

This notice explains how BIT Automation srl processes the personal data of visitors to agvsimulationstudio.com and of users of the AGV Simulation Studio application (the “Service”), in accordance with Regulation (EU) 2016/679 (“GDPR”) and the Italian Privacy Code (Legislative Decree 196/2003). Information on what is stored in your browser is in the cookie policy, which forms part of this notice.

1. Data controller

The data controller is BIT Automation srl, VAT number IT03806430363 (the “Controller”). For any matter concerning your personal data, including the exercise of the rights described in section 10, write to info@agvsimulationstudio.com.

2. Data we process

Visiting the site and the guide

To show you the pages, the hosting provider's systems process the technical data your browser sends with every request, such as IP address, date and time, requested page and browser type. The public pages contain no forms, profiling tools or third-party content; statistics tools load only with your consent.

Statistics, with your consent

If you accept statistics cookies, Google Analytics collects on the public pages and in the guide the pages viewed, times and interactions, the referring page, device and browser type and approximate location, linked to the random identifiers in the _ga cookies. We use this data in aggregate form only. The app is never measured.

Account

To create and use an account we process your email address, username, password and a unique identifier assigned at registration, together with the dates of creation and last sign-in. Supabase stores the password only in non-reversible encrypted form (hash); when you sign in with your username, our server forwards it to Supabase for verification without storing it.

Sign-in with Google or Microsoft

If you choose to sign in with a Google or Microsoft account, we receive from that provider your email address, the identifier of your account with the provider and, if the provider shares them, your name and profile picture. We do not receive your password or any other data from your account.

Projects and results

We store the content you save in the Service: .sim projects with layouts, scenarios and CAD floor plans, backup copies of earlier versions created at every save, and archived runs with their results. DWG or DXF floor plans sent to the server for conversion are kept there only temporarily. This is normally technical data, and it contains personal data only if you put it there (section 9).

Security data

To protect username sign-in against repeated attempts, the server keeps in memory the IP address the attempts come from for at most 15 minutes. The hosting and authentication providers also record technical request data, such as IP address and time, to keep their systems secure.

Communications

If you write to us, we process your email address, the information you choose to share and the content of your message.

3. Purposes and legal bases

We do not process your data for marketing, we do not sell it; we disclose it to the providers listed in section 5, and we do not use it for profiling or for decisions based solely on automated processing (Article 22 GDPR). We do not process special categories of data (Article 9 GDPR). Processing based on legitimate interest is limited to the data strictly necessary, and you can object to it as described in section 10.

4. Whether you must provide data

Browsing the public pages and the guide requires no data from you. An email address, username and password, or sign-in with Google or Microsoft, are necessary to create an account and use the Service: without them we cannot provide it. What you put in your projects is up to you. Consent to statistics cookies is optional: refusing it has no consequence on your use of the site.

5. Recipients

Data is processed by the Controller's authorised and instructed staff (Article 29 GDPR and Article 2-quaterdecies of the Italian Privacy Code) and by the following providers, acting as processors under Article 28 GDPR:

  • Render Services, Inc.: application hosting and encrypted storage of projects and runs on servers in Frankfurt (Germany);
  • Supabase, Inc.: registration, authentication and account management;
  • Google Ireland Limited: statistics with Google Analytics, only with your consent;
  • the provider of the service that sends confirmation and password recovery emails;
  • the provider of the info@agvsimulationstudio.com mailbox.

Google and Microsoft, if you choose to sign in with their accounts, process data as independent controllers under their own privacy notices. Data may also be disclosed to authorities and other parties where required by law. Data is not published or sold. The current list of processors is available on request.

6. Transfers outside the EEA

Projects and runs are stored in the European Union. Render, Supabase and Google LLC, the parent company of Google Ireland Limited, are based in the United States, as is the Microsoft group: some data, such as account data, may therefore be processed or accessed outside the European Economic Area, for example for technical support or security. In such cases the transfer relies on an adequacy decision of the European Commission, such as the EU-U.S. Data Privacy Framework for certified providers (Article 45 GDPR), or on the standard contractual clauses adopted by the Commission (Article 46 GDPR). You can ask the Controller for information on the safeguards in place.

7. Retention

Automatic backups of the hosting provider's systems are overwritten according to their rotation cycle.

8. Security

The Controller applies technical and organisational measures appropriate to the risk (Article 32 GDPR), including:

  • encrypted HTTPS connections;
  • AES-256-GCM encryption of projects, backup copies, runs and the username index stored on the server;
  • separate storage for each user, accessible only after identity verification with Supabase;
  • hosting provider disks encrypted at rest;
  • limits on sign-in attempts.

Encryption is not end-to-end: the server decrypts projects to return them to the authorised user. The recovery copy kept in your browser and the .sim files you export are not encrypted by the application: keep them safe.

9. Third-party data in projects

The Service is designed for technical plant data. If you put personal data of third parties in your projects, such as names or references in a floor plan, you, or the organisation you work for, determine the purposes and means of that processing: you need an appropriate legal basis and should keep such data to what is strictly necessary. For this data the Controller acts on your behalf solely to provide the Service. Organisations that need a data processing agreement under Article 28 GDPR can request one at info@agvsimulationstudio.com.

10. Your rights

Within the limits and under the conditions set by the GDPR you have the right to:

  • access your data and obtain a copy (Article 15);
  • have it rectified (Article 16);
  • have it erased, including closure of your account (Article 17);
  • obtain restriction of processing (Article 18);
  • receive the data you provided in a structured, commonly used and machine-readable format and transmit it to another controller (Article 20): projects can always be exported as .sim files and results as CSV, JSON and PDF;
  • object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Article 21);
  • withdraw your consent to statistics cookies at any time from “Cookie settings” at the bottom of the pages, without affecting the lawfulness of earlier processing (Article 7(3)).

You can delete your account directly from Project → Manage storage. This removes server data and the Supabase user; the draft and pending runs are removed from the current browser. Copies in other browsers or provider snapshots follow the applicable technical retention. For other requests, write to info@agvsimulationstudio.com, preferably from the address linked to your account. Requests are free of charge; we reply without undue delay and at the latest within one month, extendable by two months for complex requests (Article 12 GDPR). We may ask for information to verify your identity.

If you believe the processing infringes the GDPR, you can lodge a complaint with the Italian Garante per la protezione dei dati personali or with the supervisory authority of the Member State where you live or work, or seek a judicial remedy (Articles 77 and 79 GDPR).

11. Minors

The Service is intended for professional use and is not directed at persons under 18. We do not knowingly collect data from minors: if you believe a minor has given us data, write to us and we will delete it.

12. Changes

We may update this notice to reflect changes to the Service or the law. The version in force is always published on this page with the date of the last update; we will also point out substantial changes in the Service. If the Italian and English versions differ, the Italian version prevails.