AIPIA Europe

Legal

Privacy notice

Last updated 5 May 2026 — extends the aipia.it privacy notice (last updated 20 May 2025) to aipia.eu.

1. Data controller

The data controller for personal data processed on aipia.eu is the same entity that operates aipia.it:

AIPIA — Associazione Italiana Professionisti dell'Intelligenza Artificiale
Via Ostiense, 92 — 00154 Roma — Italy
Fiscal Code 96628540583
Email privacy@aipia.it · Telephone +39 06 5654 7987

AIPIA has not designated a Data Protection Officer under Article 37 GDPR; the controller may be reached for data-protection matters at the address above.

2. Personal data we process

  • Navigation data: IP addresses, technical logs, cookies (see the cookie notice).
  • Information you provide voluntarily: name, email, telephone and professional details when you write to us.
  • Newsletter subscription details: where you have opted in on aipia.it.
  • Event and course participation data: where applicable on aipia.it.
  • Member-area credentials: where you hold an aipia.it account.

3. Purposes of processing

  • Managing the membership relationship under the AIPIA statutes.
  • Organising events, courses and the issuance of the European AI Credential.
  • Sending newsletters with explicit consent.
  • Fulfilling legal and fiscal obligations under Italian and Union law.
  • Site security, fraud prevention and abuse mitigation.

4. Legal bases (Article 6 GDPR)

Processing relies on:

  • Performance of the membership contract (Art. 6(1)(b)).
  • Legal obligations to which the controller is subject (Art. 6(1)(c)).
  • The data subject's consent for marketing communications (Art. 6(1)(a)).
  • The legitimate interest of the controller in maintaining a secure and functional service (Art. 6(1)(f)).

5. Retention

  • Membership data: for the duration of the membership relationship plus 10 years.
  • Newsletter subscription: until consent is revoked.
  • System logs: maximum 12 months.
  • Accounting records: 10 years, per Italian fiscal law.

6. Your rights (Articles 15–22 GDPR)

You may at any time:

  • Withdraw any consent you have given.
  • Request access to your personal data, and correction of inaccurate data.
  • Request erasure of your data, where the conditions of Article 17 are met.
  • Restrict or object to processing, in the cases provided by Articles 18 and 21.
  • Receive your data in a portable format under Article 20.
  • Lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali (gpdp.it) — or with the supervisory authority of your habitual residence.

To exercise these rights, write to privacy@aipia.it. AIPIA responds within thirty days.

7. Recipients and transfers

Personal data may be processed by qualified service providers acting as data processors on AIPIA's behalf, contracted under Article 28 GDPR. AIPIA does not transfer personal data outside the European Economic Area unless adequate safeguards under Articles 44 ff. GDPR apply.

8. Changes to this notice

AIPIA may update this notice. The date of the last update is shown at the top of the document. Material changes are signalled via the website and, where appropriate, by direct communication to members.