Privacy Policy

Last updated: 24 July 2026

This Privacy Policy explains how ISOdodo collects, uses, shares and protects personal data when you use the platform available at https://isododo.com (the "Platform"). It is provided in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable national data protection law, and it complements the Terms and Conditions.

1. Data controller

ISOdodo, as the operator of the Platform, is the data controller for the processing described in this Privacy Policy, except where stated otherwise in Section 10.

For any question relating to the processing of personal data, or to exercise the rights described in Section 12, you may write to info@isododo.com.

2. Who this policy applies to

The Platform is addressed to companies, professionals and other entities acting in the course of their business or profession. This Privacy Policy therefore applies to:

  • Visitors who browse the public pages of the website;
  • Registered Users who create a Business Account or a Professional Account;
  • Individuals whose data is provided by a User, for example a client for whom a professional activates a certification path, or persons named in the documentation uploaded to the Platform.

Data relating to a company as such (for example a company name or VAT number) is not personal data, but it becomes so where it allows a natural person to be identified, for example in the case of a sole trader.

3. Personal data we process

3.1 Registration and account data

When you create an account we process: email address, password (stored exclusively in hashed form and never in plain text), full name, company name, country, telephone number and international prefix, VAT number or equivalent tax identifier, business classification code (ATECO / NACE / NOGA or equivalent), business sector, number of employees, account type, registration date, date of last access and, where applicable, the referral code used at registration.

3.2 Professional verification data

Where you register as a Professional Account, the information provided at registration is used to carry out the prior verification described in the Terms and Conditions, and is retained for the time necessary to complete the review and to document its outcome.

3.3 Purchase and billing data

Payments are processed exclusively by Stripe. ISOdodo does not receive or store payment card numbers or other payment credentials, which are collected directly by Stripe in its own capacity. On our systems we retain the data required to manage the purchase: the certification path acquired, the pricing tier, the payment mode, the purchase and expiry dates, the transaction and subscription identifiers issued by Stripe and, where a professional purchases on behalf of a client, the email address of the beneficiary.

3.4 Documentation submitted for verification

The documents you upload at the end of a certification path in order to request verification are transmitted to the Certification Body by email, together with your email address and the reference of the path concerned. Such documents are processed for the sole purpose of forwarding them and are not stored on the Platform after transmission. Their content is determined entirely by you: you are asked not to include personal data that is not strictly necessary for the certification process, and never to include special categories of data within the meaning of Article 9 GDPR.

3.5 Data relating to the AI assistant

Where you use the virtual assistant "Isotta", the messages you send and any files you attach are transmitted to OpenAI, which operates the underlying language model, in order to generate a response. The text of attached files is extracted and forwarded as part of the message.

The content of conversations is retained by OpenAI and is associated with a conversation identifier; on ISOdodo's own systems we store only that identifier and the counters for the usage allowance associated with your account. Deleting the conversation history from your profile area causes the corresponding conversation to be deleted at OpenAI as well and a new one to be created.

You are asked not to enter into the assistant any confidential information or personal data that is not necessary for the request you are making.

3.6 Technical and usage data

When you access the Platform, our systems and those of our providers automatically record technical data such as the IP address, browser type and version, operating system, device type, pages visited, date and time of access, referring page and any errors encountered. This data is processed for security, diagnostic and anti-abuse purposes and, in aggregate form, for statistical purposes.

3.7 Communications

We process the content of the communications you send us, for example by email, in order to handle your requests and to keep a record of the assistance provided.

4. Purposes and legal bases

We process personal data only where a legal basis under Article 6 GDPR applies:

  • Providing the Service — creating and managing the account, giving access to certification paths, training content and document templates, tracking progress, forwarding documentation to the Certification Body, providing the AI assistant, managing purchases and renewals, and providing support. Legal basis: performance of a contract, Art. 6(1)(b).
  • Verifying Professional Accounts — assessing requests to register as a professional. Legal basis: performance of a contract and pre-contractual measures, Art. 6(1)(b).
  • Service communications — messages relating to registration, email verification, password reset, purchases, renewals and the status of paths. Legal basis: performance of a contract, Art. 6(1)(b).
  • Accounting and tax obligations — issuing and retaining accounting records, VAT compliance, responding to requests from the competent authorities. Legal basis: legal obligation, Art. 6(1)(c).
  • Platform security — preventing fraud, abuse and unauthorised access, including through automated protection systems and technical logs. Legal basis: legitimate interest in protecting the Platform and its users, Art. 6(1)(f).
  • Improving the Service — analysing the use of the Platform in order to improve its features and stability. Legal basis: legitimate interest, Art. 6(1)(f), or consent where carried out by means of analytics cookies.
  • Analytics cookies — measuring traffic and the use of the website. Legal basis: consent, Art. 6(1)(a).
  • Promotional communications — sending information about services, updates and offers. Legal basis: consent, Art. 6(1)(a), which may be withdrawn at any time.
  • Establishing or defending legal claims — where necessary to protect our rights. Legal basis: legitimate interest, Art. 6(1)(f).

Providing the data marked as mandatory at registration and at purchase is necessary in order to enter into and perform the contract; without it, the Service cannot be provided. Providing the remaining data is optional.

5. Cookies and similar technologies

The Platform uses the following categories of cookies and similar technologies:

  • Technical and essential cookies — required for the Platform to operate and always active. They include the authentication cookies actoken (duration 15 minutes) and reftoken (duration 7 days), which are set as httpOnly and are therefore not accessible to scripts running in the browser, and the cookie cookie_consent (duration 12 months), which records your choice regarding cookies.
  • Functional cookies and local storage — used to remember preferences such as the interface language (i18n_redirected) and the light or dark theme.
  • Analytics cookies — Google Analytics 4, activated only after you give consent through the banner. Where consent is not given, the Google Analytics script is not loaded at all. Where consent is given and you are logged in, the identifier of your account is also transmitted to Google Analytics so that visits by the same user can be correlated.
  • Anti-abuse protection — Google reCAPTCHA is used on the registration, login, password reset and account deletion forms in order to distinguish legitimate use from automated use. This technology may store technical information on your device and transmit interaction data to Google.
  • Embedded video — training videos are embedded from YouTube in privacy-enhanced mode (youtube-nocookie.com), which prevents the setting of profiling cookies unless the video is played.

You may accept or refuse non-essential cookies through the banner displayed on first access. You may also configure your browser to block or delete cookies, bearing in mind that disabling technical cookies prevents you from logging in and using the Platform.

6. Recipients of the data

Personal data may be made known to personnel authorised by ISOdodo and communicated to the following categories of recipients, appointed as processors under Article 28 GDPR where they act on our behalf:

  • Payment provider — Stripe, for the processing of payments, subscriptions and renewals. Stripe acts as an independent controller in respect of payment data collected directly by it.
  • Artificial intelligence provider — OpenAI, for the operation of the AI assistant.
  • Hosting, database and content delivery providers — including Amazon Web Services (Amazon CloudFront) for the delivery of training materials and document templates through time-limited signed links.
  • Email provider — for sending service communications and for transmitting documentation to the Certification Body.
  • Google — for the analytics, anti-abuse and embedded video services described in Section 5.
  • Certification Bodies and auditors — who receive the documentation you submit for verification. They act as independent controllers in respect of their own audit and certification activities.
  • Professional advisers and public authorities — accountants, lawyers, tax authorities and other bodies, where required in order to comply with a legal obligation or to establish or defend a legal claim.

Personal data is not sold, rented or transferred to third parties for their own marketing purposes. In the event of a merger, transfer of business or corporate reorganisation, data may be transferred to the acquiring entity, with prior notice to the persons concerned and without any reduction in the level of protection afforded.

7. Transfers outside the European Economic Area

Some of the providers referred to in Section 6 are established in the United States or process data in countries outside the European Economic Area. In such cases, transfers are carried out on the basis of the adequacy decisions adopted by the European Commission, of the Standard Contractual Clauses referred to in Article 46(2)(c) GDPR, or of another appropriate safeguard provided for in Chapter V GDPR, together with supplementary measures where necessary.

You may request further information about the safeguards applied by writing to the address given in Section 1.

8. Retention periods

  • Account data — for as long as the account remains active, and subsequently for the time necessary to fulfil residual legal obligations.
  • Certification path data — for the duration of the path and thereafter for the period required to manage renewals, disputes and legal obligations.
  • Accounting and tax data — for the period required by applicable tax legislation, which in Italy is generally ten years.
  • Documentation submitted for verification — not stored on the Platform after transmission to the Certification Body, which retains it according to its own policies.
  • AI conversations — until you delete the conversation history or your account, subject to the retention periods applied by the provider of the model.
  • Technical logs — for a limited period, proportionate to security and diagnostic requirements.
  • Data processed on the basis of consent — until consent is withdrawn.

When you delete your account from your profile area, the data associated with it — including the account record, conversations with the assistant, usage allowances, verification tokens and any professional review request — is deleted. Paths purchased for you by a professional are returned to the management of the purchaser, and paths you purchased for others remain active for their beneficiaries with the purchaser reference removed, so that the service already paid for is not interrupted.

9. Security

ISOdodo adopts appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. These include encryption of communications in transit, storage of passwords using cryptographic hashing algorithms, authentication based on short-lived tokens contained in httpOnly cookies, access control on the basis of least privilege, protection of forms against automated use, and time-limited signed links for access to materials.

No method of transmission or storage is entirely secure. Should a personal data breach occur that is likely to result in a high risk to the rights and freedoms of the persons concerned, we will notify the competent supervisory authority and the persons concerned in accordance with Articles 33 and 34 GDPR.

10. Data of third parties uploaded by the User

Where a User uploads to the Platform, or enters into the AI assistant, personal data relating to third parties — such as employees, collaborators or its own clients — that User acts as data controller in respect of such data, while ISOdodo acts as processor and processes it solely on the User's instructions and for the purpose of providing the Service.

In such cases the User warrants that it has a valid legal basis for the processing and for the communication of the data to ISOdodo and, where applicable, to the Certification Body, and that it has provided the persons concerned with the information required under Articles 13 and 14 GDPR.

Where a professional activates a certification path on behalf of a client, the client's email address is processed in order to grant access to the path and to send the related service communications.

11. Automated decision-making

ISOdodo does not carry out automated decision-making producing legal effects, or similarly significant effects, in relation to individuals. The AI features of the Platform are support tools: the content they generate is a preliminary draft which must be reviewed by the User and does not in itself determine any decision concerning individuals.

12. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • obtain confirmation as to whether your personal data is being processed and access that data;
  • obtain the rectification of inaccurate data and the completion of incomplete data;
  • obtain the erasure of your data where one of the grounds set out in Article 17 GDPR applies;
  • obtain the restriction of processing in the cases provided for in Article 18 GDPR;
  • receive the data you have provided in a structured, commonly used and machine-readable format and transmit it to another controller;
  • object at any time, on grounds relating to your particular situation, to processing based on legitimate interest;
  • withdraw the consent you have given at any time, without affecting the lawfulness of processing carried out before its withdrawal.

You may exercise your rights directly from the profile area of the Platform, where you can update your information, delete the history of conversations with the assistant and delete your account, or by writing to info@isododo.com. We will respond within one month of receipt of the request, which may be extended by two further months where the request is complex.

You also have the right to lodge a complaint with the supervisory authority of the Member State in which you are habitually resident or in which the alleged infringement occurred. In Italy, this is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

13. Minors

The Service is not addressed to persons under 18 years of age and we do not knowingly collect their personal data. Should we become aware that we have collected data relating to a minor without a valid legal basis, we will delete it without undue delay.

14. Links to third-party websites

The Platform may contain links to websites operated by third parties. This Privacy Policy does not apply to such websites: we recommend that you read the privacy policy of each site you visit. ISOdodo exercises no control over, and assumes no responsibility for, their content or practices.

15. Changes to this Privacy Policy

We may update this Privacy Policy in order to reflect changes to the Service, to the providers used or to applicable law. The updated version is published on this page together with the date of the last update. Material changes are notified to registered Users by email or by notice within the Platform. Where the change concerns processing based on consent, we will request new consent.

16. Contact

For any request relating to the protection of personal data you may contact us at info@isododo.com or through the profile area of the Platform.

Last updated: 24 July 2026