Last updated: 18 September 2026
( Contents )
Made in Evolve S.r.l. provides this notice pursuant to Articles 13 and 88 of Regulation (EU) 2016/679 (GDPR), Article 114 of Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (Italian Privacy Code) and Article 4 of Law 300/1970 (Workers’ Statute) as amended by Article 23 of Legislative Decree 151/2015. This document replaces the previous notice for employees and contractors published on this website and supplements the internal rules on the use of company tools.
The Controller is Made in Evolve S.r.l., with registered office at Via Rosalba Carriera 26, 41126 San Damaso, Modena (MO), Italy, tax code and VAT no. 03497200364, REA MO-392876, certified email madeinevolve@pec.it, tel. +39 059 788 0854. No data protection officer has been appointed, as the legal requirements for such appointment are not met; for any matter the dedicated mailbox privacy@madeinevolve.com is available.
This notice is addressed to three categories of Data Subjects:
Employees and Contractors are referred to together as Staff. For processing relating to website visitors and clients, please see the Privacy policy.
The Controller processes special categories of data under Article 9 GDPR only where necessary to comply with legal or collective agreement obligations: health data (sick notes, accidents at work, fitness-for-work assessments, membership of protected categories under Law 68/1999), pregnancy and parental leave, trade union membership for the purpose of payroll deductions. Candidates are advised not to include such data in their curriculum vitae, except for membership of protected categories where relevant to the selection.
Data under Article 10 GDPR are processed only where a law or regulation so requires, within the limits of Article 2-octies of the Italian Privacy Code, for example for access to specific assignments.
Work is carried out through tools provided or authorised by the Controller: Google Workspace (email, calendar, Drive, Meet), Slack, GitHub, Asana, Notion, Figma, Fireflies.ai, Nucleo Platform, accounts on clients’ platforms (in particular Shopify and Klaviyo) and company devices. Their use generates account identifiers, access logs, IP addresses, date and time of activities, metadata of messages and files, code change history and device security status.
| Purpose | Data processed | Legal basis |
|---|---|---|
| Recruitment and selection, management of interviews | Identification data, curriculum vitae, interview outcomes | Art. 6(1)(b) GDPR (pre-contractual measures); Art. 9(2)(b) GDPR for protected categories |
| Establishment, management and performance of the relationship: payroll, contributions, mandatory notifications, attendance and absences | Identification, contractual, pay and attendance data, special categories where necessary | Art. 6(1)(b) and (c) GDPR; Art. 9(2)(b) GDPR; Art. 88 GDPR |
| Occupational health and safety, health surveillance, accidents at work | Identification and health data | Art. 6(1)(c) GDPR; Art. 9(2)(b) and (h) GDPR; Legislative Decree 81/2008 |
| Management of accounts and devices, system security, protection of client data, business continuity | Usage data of company tools | Art. 6(1)(b) and (f) GDPR (system security, aligned with the principles of ISO/IEC 27001); Art. 4 Workers’ Statute |
| Establishment, exercise or defence of legal claims, internal investigations into unlawful conduct | All categories, where necessary | Art. 6(1)(f) GDPR; Art. 9(2)(f) GDPR |
| Publication of Staff photographs and videos on the website and social channels | Images, name and role | Art. 6(1)(a) GDPR (consent, freely revocable) |
| Handling of reports of wrongdoing | Data contained in the report | Art. 6(1)(c) GDPR; Legislative Decree 24/2023 |
The tools listed in section 3.4 are work tools within the meaning of Article 4, paragraph 2, of the Workers’ Statute: they serve to perform the work and to record access, not to monitor. The data they generate may be used for all purposes connected with the employment relationship (Article 4, paragraph 3) provided that Staff are adequately informed of the methods of use and of controls, as is done through this notice and the internal rules.
The Controller does not use activity monitoring software, keyloggers, screen capture, continuous geolocation or systems allowing the systematic reconstruction of individual activity. The administration functions of Google Workspace, Slack and GitHub are used for configuration, security and recovery, not to monitor performance. Access to the contents of individual mailboxes, chats or files is permitted only in exceptional and documented cases (security incidents, legal obligation or order of an authority, business continuity during a prolonged absence, well-founded suspicion of unlawful conduct), proceeding in stages and limiting access to what is strictly necessary.
Moderate personal use of company tools is tolerated, but accounts, devices and contents remain company property; Staff are invited to use their own tools for private communications. Meetings may be transcribed with Fireflies.ai only with prior notice to participants, who may object. Upon termination of the relationship, accounts are deactivated and the mailbox is closed or kept for a limited period with an automatic reply pointing to an alternative contact.
Publication of photographs, videos and name with role of Staff on the madeinevolve.com website and on company social channels takes place only with the express consent of the person concerned, collected in writing. Consent is optional, does not affect the relationship and may be withdrawn at any time by writing to privacy@madeinevolve.com (Article 7(3) GDPR). Upon withdrawal the Controller removes the content from the channels under its control within the necessary technical time; withdrawal does not affect prior publication or copies already disseminated by third parties.
| Category of recipients | Role | Purpose |
|---|---|---|
| Labour consultant and payroll firm | Data processor | Payslips, contribution and tax obligations, mandatory notifications |
| INPS, INAIL, Italian Revenue Agency, employment centres and other public administrations | Independent controllers | Social security, insurance, tax and administrative obligations |
| Insurance companies, supplementary pension and healthcare funds | Independent controllers | Coverage and benefits provided by contract or law |
| Occupational physician and head of the prevention and protection service | Depending on the role | Health surveillance and occupational safety |
| IT providers: Google (Workspace), Microsoft (365, GitHub), Slack Technologies (Salesforce), Asana, Notion Labs, Figma, Fireflies.ai, DigitalOcean (hosting of Nucleo Platform) | Data processors (Article 28 GDPR) | Work tools and data storage |
| Clients of the Controller | Independent controllers | Name, role and professional contact details for project delivery, including creation of accounts on their platforms |
Data are not disseminated, except for photographs and videos published with consent, and internally are accessible only to persons authorised under Article 29 GDPR and Article 2-quaterdecies of the Italian Privacy Code.
Some providers listed in section 7 are based or have servers in the United States. Transfers rely on the Standard Contractual Clauses of Decision 2021/914 and, for participating providers, on the EU-US Data Privacy Framework (adequacy decision of 10 July 2023). A copy of the safeguards may be requested from privacy@madeinevolve.com.
| Category | Retention period |
|---|---|
| Unsuccessful candidates | 12 months from receipt of the application or from the last relevant contact |
| Employment or contractor relationship data (personnel file, contracts, payslips, attendance) | 10 years from termination of the relationship, in line with Article 2220 of the Italian Civil Code and limitation periods |
| Access and security logs of company tools | Maximum 12 months, except for incident investigations or litigation |
| Published photographs and videos | Until withdrawal of consent or termination of the relationship, unless otherwise agreed in writing |
| Whistleblowing reports | No longer than 5 years from notification of the outcome (Article 14 Legislative Decree 24/2023) |
Once these periods have elapsed, data are deleted or anonymised.
Provision of the data required for selection and for management of the relationship is necessary: refusal prevents evaluation of the application or the establishment and continuation of the relationship. Consent to publication of photographs and videos is optional and refusal has no consequences.
The Controller does not take decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect Data Subjects (Article 22 GDPR): selection, evaluation and disciplinary decisions are always taken by people. Artificial intelligence tools are used to support tasks in accordance with the AI policy, not to evaluate Staff.
| Right | Reference |
|---|---|
| Access to data and to information on processing | Art. 15 GDPR |
| Rectification of inaccurate or incomplete data | Art. 16 GDPR |
| Erasure, within the limits of retention obligations | Art. 17 GDPR |
| Restriction of processing | Art. 18 GDPR |
| Portability of data provided on the basis of contract or consent | Art. 20 GDPR |
| Objection to processing based on legitimate interest | Art. 21 GDPR |
| Withdrawal of consent, without affecting prior processing | Art. 7(3) GDPR |
| Complaint to the supervisory authority | Art. 77 GDPR |
Requests may be sent to privacy@madeinevolve.com, by post to the registered office or through the Privacy requests page. The Controller replies within one month, extendable by two months in the cases set out in Article 12(3) GDPR; data whose retention is required by law cannot be erased. The supervisory authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it.
Staff and Candidates, including after termination of the relationship, may report breaches of law or unlawful conduct learned of in the work context through the confidential internal channel described in the Whistleblowing policy, adopted pursuant to Legislative Decree 24/2023 and managed by a designated, autonomous and trained person, with protection of the reporting person’s identity and prohibition of retaliation.
This English version is provided for convenience; in case of discrepancy the Italian version prevails.