Privacy Policy
This policy explains how personal data collected through the SABIA LABS website, accounts, quote requests, prototypes and app rescue service is processed.
1. Data controller and contact details
The data controller is Sky Flora di Sabia Olga, a sole proprietorship under Italy’s flat-rate tax regime, owned by Sabia Olga, with registered office at Viale Panoramica R. Meccadinardo SNC, 85020 Filiano (PZ), Italy, Italian VAT no. 01978450763, REA PZ-148595. For privacy requests, the exercise of data protection rights and assistance: info@sabialabs.it · +39 342 068 3216.
SABIA LABS is the name of the service. Giambattista Sabia is identified separately as the author and software developer, as well as the technical contact.
2. Scope of the service
The service is intended for adults, including consumers, professionals and companies in Italy and in the countries available in the billing profile. Checkout availability may vary depending on the country, tax requirements and payment-provider checks.
3. Data processed
- account and authentication: first and last name, email address, Firebase identifier, sign-in provider and email verification status;
- request and project: brief, requested features, industry, budget, timeframe, demo or repository URL, colour palette, reference images, messages, customer documents, previews and delivery files;
- billing for individuals: first name, surname, full address, country and billing email address; an Italian tax code is also required for an Italian billing address;
- billing for professionals and companies: personal details or company name, full address, country, VAT or Tax ID and billing email address; Italian customers must also provide the applicable Italian tax code, VAT number, SDI recipient code and optional certified email address (PEC);
- orders and payments: product or service purchased, amounts, order status, Stripe transaction identifiers, receipts and refunds. SABIA LABS does not store full card details;
- optional showcase: version of the copy, optional customer name, links and images proposed for the projects page, the customer’s decision and evidence of consent;
- security: IP address, technical logs, device information, tokens and anti-fraud assessments produced by Firebase App Check and reCAPTCHA Enterprise.
Passwords, tokens, API keys, .env files, health data or other special categories of personal data that are not necessary for the assessment must not be submitted through public forms.
4. Purposes and legal bases
- to create and protect the account, verify the email address, manage the brief, prepare a quote and perform the engagement: steps taken at the user’s request before entering into a contract and performance of the contract;
- to issue and retain invoices and comply with tax, accounting or authority requirements: compliance with a legal obligation;
- to prevent fraud and abuse, protect systems and credentials, and establish or defend legal rights: the controller’s legitimate interests;
- to publish a delivered project in the showcase, together with any approved data and materials: the customer’s separate, specific and revocable consent;
- to send non-essential promotional communications: only with separate, revocable consent. This feature is not active in the current version.
5. Requirement to provide data
Data marked as required is necessary to create an account, assess the project, prepare a quote or place an order. The relevant operation cannot be completed without it. Billing details are requested only before a purchase; budget and timeframe remain optional where stated.
6. Third-party data and development engagements
Anyone submitting materials containing third-party data must have the right and a valid legal basis to do so and must limit the data to what is strictly necessary. When an engagement requires the provider to process personal data on behalf of the customer, the parties’ roles, instructions, security measures and deletion arrangements will be set out in the quote or in a data processing agreement, where required.
7. Recipients and service providers
Data may be processed by authorised personnel and by technical providers appointed as processors where required: Google Firebase and Google Cloud for authentication, hosting, database, server functions, private file storage and anti-fraud protection; Gmail/Google for operational email notifications; Stripe for checkout, payment processing, fraud prevention and receipts; Fatture in Cloud, a TeamSystem S.p.A. product, for preparing and managing electronic invoices; and tax advisers, legal advisers or public authorities where required by law. Data is not sold.
Stripe checkout is available in live mode to the authenticated owner of the request, after verification of the email address, billing details and acceptance of the current legal documents. Stripe processes payment details directly; SABIA LABS retains only the identifiers and statuses needed to manage the order, receipt and any refund.
8. International transfers
The Cloud Firestore database, Cloud Functions and the operational Cloud Storage bucket used for attachments, documents and deliveries are configured in the europe-west1 region in Belgium. The previous US bucket is not used by the application and contains no customer content.
This configuration does not mean that all processing by service providers takes place exclusively within the European Economic Area: Firebase Authentication operates from the United States, and some Firebase services, technical data or service metadata may be processed on the global infrastructure of Google or its subprocessors. Any transfers to third countries take place under the provider’s applicable terms and on the basis of adequacy decisions or safeguards provided for by the GDPR, including standard contractual clauses where applicable. Further information is available in the Firebase Privacy and Security documentation and the Cloud Data Processing Addendum.
9. Retention
- accounts: until deletion, except for data that must be retained separately;
- requests that do not result in a contract: generally for up to 24 months from the last contact;
- briefs, orders and contractual communications: for the duration of the relationship and the subsequent period required to protect legal rights;
- accounting and tax data and evidence of acceptance: for the period required by law, normally ten years;
- delivery ZIP files associated with paid orders: together with the contractual records, for the period needed to document performance and protect legal rights, generally no longer than ten years unless a different period is required by law or a dispute;
- showcase materials: until consent is withdrawn or the project is removed; evidence of the customer’s decision may be retained for as long as necessary to document the processing;
- security logs: for a period proportionate to the prevention and management of abuse.
10. Data subject rights
Where applicable, individuals may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent without affecting processing already carried out. Requests should be sent to info@sabialabs.it. Individuals may also lodge a complaint with the Italian Data Protection Authority.
11. Account deletion
A self-service process for deleting the account and associated data is available in the authenticated area. A request may also be submitted by email. Deletion removes credentials, conversations, their attachments and files not linked to paid orders. For paid orders, tax and contractual data, evidence of acceptance and delivery ZIP files needed to document performance and protect legal rights remain stored separately with restricted access for the periods stated above.
12. Cookies, App Check and Analytics
The website uses technologies strictly necessary for sign-in, security and abuse prevention, including reCAPTCHA Enterprise through Firebase App Check. Google Ads is loaded only after an optional positive choice, in order to link an ad click to a successfully submitted request. Advertising and campaign identifiers, the visited page, technical context information and the request’s unique identifier are sent to Google; the customer’s name, email address, phone number and request text are not sent. The choice may be rejected or changed at any time through “Privacy choices”. Google Analytics is not active.
13. Security and automated decisions
Email verification, Google or password sign-in, per-user authorisations, App Check and server-side controls are in place. Estimates produced by the configurator do not automatically determine acceptance of an engagement: complex features are subject to human assessment.
14. Children and updates
The service is not intended for anyone under 18. This policy may be updated when features, obligations or providers change; material changes will be communicated and, where necessary, submitted to the user for acceptance again.