Privacy Policy
Last updated: 19 July 2026 (version 2.2)
This is an English translation provided for convenience. In case of any discrepancy or conflict, the Italian version shall prevail as the legally binding text.
1. Data Controller
The controller of personal-data processing is:
BOSIO GROUP SRL
Via Carlo Bossi 20, 26020 San Bassano (CR), Italy
VAT ID: 01818540195
Certified email (PEC): bosiogroupsrl@pec.it
Email: info@cantiericloud.com
2. Roles: When We Act as Controller and When as Processor
CantieriCloud is management software used by businesses. BOSIO GROUP SRL therefore operates in two distinct roles:
- Data controller for the data of its direct customers: account registration data, billing and subscription data, platform usage data and communications.
- Data processor (Art. 28 GDPR) for the data that the customer company enters into the platform in the course of its business: data about its own employees and collaborators (workers), its end clients, suppliers, time-clock records and attendance data. For this data the controller is the customer company; BOSIO GROUP SRL processes it exclusively on the customer's behalf, under the Data Processing Agreement (DPA) that forms an integral part of the General Terms.
3. Data We Collect
CantieriCloud collects the following categories of personal data:
- Registration data: first name, last name, email, password (encrypted), business name, VAT number, tax code
- Contact data: address, phone number, certified email (PEC), SDI code (Italian e-invoicing identifier)
- Usage data: access logs, actions performed within the platform, user preferences
- Payment data: handled directly by Stripe (we do not store credit-card details)
- Construction-site data: information about job sites, clients, workers, quotes, photos and uploaded documents
- Geolocation data (on-site clock-in): if the customer company enables clock-in with presence verification, the GPS position of the worker's device is captured only at the moment of clocking in/out and during site-perimeter verification events — never continuously and never outside working hours. Coordinates are retained for 90 days and then automatically deleted (attendance times are kept, without location).
- Audio recordings (voice site reports): if a worker records a voice report, the audio file is automatically transcribed and retained for a maximum of 30 days, then deleted. The report text remains and can be edited by the user.
- AI assistant conversations: messages exchanged with the assistant are retained to allow conversation continuity, for a maximum of 24 months.
4. Purposes of Processing
Personal data is processed for the following purposes:
- Service delivery: account management, access to the platform, management-software features
- Service communications: technical notifications, updates, customer support
- Billing: management of subscriptions and payments
- Service improvement: anonymous analytics to optimise the user experience
- Legal compliance: tax and regulatory obligations
5. Legal Basis for Processing
Data processing is based on:
- Performance of a contract: Art. 6(1)(b) GDPR — to deliver the service requested
- Consent: Art. 6(1)(a) GDPR — for marketing communications (optional)
- Legitimate interest: Art. 6(1)(f) GDPR — for analytics and service improvement
- Legal obligation: Art. 6(1)(c) GDPR — for tax and regulatory compliance
For data processed on behalf of customer companies (e.g. worker data), the legal basis is determined by the customer company acting as controller.
6. Data Retention
Personal data is retained as follows:
- Account data: for the entire duration of the contractual relationship; billing data for the following 10 years (tax obligations)
- Construction-site data: for the entire duration of the subscription; deleted upon account deletion (backup copies are overwritten within 30 days)
- Clock-in GPS coordinates: 90 days, then automatically deleted
- Voice-report audio recordings: 30 days, then automatically deleted
- AI assistant conversations: 24 months
- Access logs and activity records: 12 months
- Billing data: 10 years, as required by Italian tax law
7. Recipients and Sub-processors
To deliver the service we rely on the following providers (sub-processors under Art. 28 GDPR for data processed on behalf of customer companies):
- Supabase: database, file storage and authentication — data hosted in Zurich (Switzerland, a country covered by an EU adequacy decision)
- Vercel: web application hosting (USA)
- Stripe: payment processing (USA)
- Resend: transactional email delivery (USA)
- Anthropic: conversational AI assistant and supporting features (USA). Requests may include data from the management system (e.g. client and site names) needed to answer; under the provider's commercial terms, data submitted via API is not used to train models
- Google: automatic document reading (delivery notes, bills of quantities) via Gemini models; Google Calendar sync if enabled by the user; Google Analytics 4 on the website, subject to cookie consent (USA)
- OpenAI: voice-report transcription and text structuring (USA). Here too, data submitted via API is not used for model training
- FAL.ai: photorealistic render generation from user-uploaded photos (USA)
- FiscoAPI: electronic invoice processing (Italy)
- TeamSystem — Fatture in Cloud: e-invoicing integration, if connected by the user (Italy)
- Brevo: contact management and communications (EU)
- Cal.com: booking of demo appointments via the calendar embedded in the website — European instance, with data hosted in the EU. It processes name, email, the chosen date and time, and time zone, on the basis of pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR)
- Sentry: technical error monitoring — data region Germany, with content masking
- OpenStreetMap (Nominatim): address search and site geocoding (EU)
- Meta Platforms: Meta Pixel and Meta Conversions API on the website, to measure advertising campaign effectiveness (only with explicit consent via the cookie banner). In addition to the browser pixel (cookies
_fbpand_fbc), we also send conversion events to Meta from our servers: in that case, any email address and phone number provided in forms are transmitted exclusively in pseudonymised form (SHA-256 hash), together with IP address and user agent, for the sole purpose of conversion measurement and with event deduplication
An up-to-date list of sub-processors is available on request at privacy@cantiericloud.com. We do not sell or transfer your personal data to third parties for marketing purposes.
8. Data Transfers Outside the EU
The database and files are hosted in Zurich (Switzerland), a country recognised as adequate by the European Commission. Some providers (Stripe, Vercel, Resend, Anthropic, Google, OpenAI, FAL.ai) are based in the United States: transfers take place in accordance with the EU–US Data Privacy Framework and/or the Standard Contractual Clauses adopted by the European Commission.
9. Artificial Intelligence Features
CantieriCloud includes AI-powered features: a conversational assistant, quote-drafting support, automatic document reading (delivery notes, invoices, bills of quantities), voice-report transcription and render generation. AI-generated or AI-extracted content is always presented as such and remains subject to user review and confirmation: no decision is taken in a fully automated way. CantieriCloud does not use AI systems to evaluate, monitor or classify workers. Further details on which features use AI, which providers are involved and which data is submitted are available on the AI Transparency page (in Italian).
10. Workers of Customer Companies
If you are a worker of a company that uses CantieriCloud, the controller of your data (personal details, attendance, clock-ins, site reports) is your employer; BOSIO GROUP SRL processes it on the employer's behalf as processor. In particular, for GPS presence-verification clock-ins:
- location is captured only at clock-in/out and during site-perimeter verification events, never continuously;
- coordinates are automatically deleted after 90 days;
- enabling the feature and complying with Art. 4 of the Italian Workers' Statute (informing workers and, where required, obtaining a union agreement or Labour Inspectorate authorisation) is the employer's responsibility.
To exercise your rights over this data, contact your employer; you may also contact us at privacy@cantiericloud.com and we will forward the request to the controller.
11. Cookies and Tracking
The website uses three categories of cookies:
- Strictly necessary cookies: essential for the website to function (authentication, preferences, security). No consent required.
- Analytics cookies: Google Analytics 4, for aggregated traffic analytics with anonymised IP. Loaded only with explicit consent via the cookie banner.
- Marketing cookies: Meta Pixel (cookies
_fbp,_fbc), to measure the effectiveness of advertising campaigns, including server-side delivery (Conversions API). Loaded only with explicit consent via the cookie banner.
On your first visit a banner allows you to accept, refuse, or customise the cookie categories. You can change your preferences at any time by clicking the button below, or the Cookie preferences link in the website footer.
12. Your Rights
Under the GDPR, you have the right to:
- Access: obtain confirmation of processing and a copy of your data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data (the "right to be forgotten")
- Restriction: limit processing in specific circumstances
- Portability: receive your data in a structured format
- Objection: object to processing on legitimate grounds
- Withdrawal of consent: withdraw consent at any time
Two of these rights can be exercised directly within the platform: under Settings → Security you will find "Download my data" (full export in JSON format) and "Delete account" (permanent deletion of all data). For the other rights, contact us at: privacy@cantiericloud.com
13. Security
We adopt appropriate technical and organisational measures to protect your data:
- SSL/TLS encryption for all communications
- Passwords hashed using secure algorithms
- Two-factor authentication available
- Regular, encrypted backups
- Data access restricted to authorised, logged personnel only
- Row Level Security (RLS) to isolate data between organisations
14. Complaints
If you believe the processing of your data violates the GDPR, you have the right to lodge a complaint with
the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali):
www.garanteprivacy.it
15. Changes to this Privacy Policy
We reserve the right to amend this notice. Any changes will be published on this page, with an indication of the update date. For material changes we will send a notification by email.
Contact
For questions about this notice or the processing of your data:
BOSIO GROUP SRL
Email: privacy@cantiericloud.com
Certified email (PEC): bosiogroupsrl@pec.it
Address: Via Carlo Bossi 20, 26020 San Bassano (CR), Italy