Who is responsible for your data
PRCN Academy is the education brand of IUVENTA S.R.L., which is the data controller for everything described in this notice — it decides why your data is collected and how it is handled.
- Entity
- IUVENTA S.R.L.
- VAT number
- IT 17740121003
- [email protected]
If you have a question about your data, or want to exercise any of the rights in section 9, write to [email protected]. We answer within one month, as Art. 12(3) GDPR requires.
What this notice covers
This notice covers prcnacademy.com and the registration process for our events. It does not cover other websites we link to — the venue, our partners, the car park, or the Stripe payment page, each of which publishes its own notice and is responsible for its own processing.
We process personal data under the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
The data we collect
Registration details you give us
When you complete the registration form, we collect:
- Identity and contact — first name, surname, email address, telephone number.
- Professional details — your profession or clinical role, and the name of your clinic or organisation.
- Location and billing status — your country and, if you are in Italy, whether you are registering as an individual or as a company.
- Tax identifiers — a codice fiscale if you are an Italian individual, or a VAT number if you register as a company. These are required for the invoice, not for the registration itself.
- Attendance details — your t-shirt size, and any dietary requirement or allergy note you choose to give us.
Payment and billing data
We never see or store your card details. Payment is taken on a page hosted by Stripe; your card number goes to Stripe and never touches our server. What comes back to us afterwards is the outcome: the amount paid, the tax applied, any discount, the payment status, and the billing name, address and VAT number you entered on Stripe's page.
Dietary requirements and allergies
Allergy and dietary information can reveal something about your health, which makes it a special category of data under Art. 9 GDPR. These two fields are optional. We ask for them only so the caterer can feed you safely, we pass only what the caterer needs, and we delete them within 30 days of the event. Leaving them blank does not affect your registration in any way.
How you reached us
If you arrive through a partner link or a campaign link, we record the partner code, the campaign parameters (utm_source, utm_medium, utm_campaign) and the website that referred you. This is how a partner who introduced you gets paid their commission, and how we learn which channels actually work. See section 10 for the cookies that carry it.
Technical data
Our server and our security provider log the usual technical details of a web request — IP address, browser user-agent, the pages requested and when. These logs exist to keep the site available and to stop abuse.
What we deliberately do not collect
There is no analytics, no advertising pixel and no profiling on this website. We do not run Google Analytics, a Meta pixel, a LinkedIn insight tag, or any equivalent. We do not build behavioural profiles, we do not sell data, and we do not share it with advertisers.
Why we use it, and our legal basis
Every use below is tied to one of the legal grounds in Art. 6 GDPR (and Art. 9 for health-related data). We do not process your data for anything not listed here.
| What we do | Data used | Legal basis |
|---|---|---|
| Register you, confirm your place, admit you to the event and get your name badge and t-shirt right | Identity, contact, professional details, t-shirt size | Performance of a contract — Art. 6(1)(b) |
| Take payment and handle refunds or disputes | Contact details, payment outcome, billing address | Performance of a contract — Art. 6(1)(b) |
| Issue your invoice and transmit it to the Italian Revenue Agency through the Sistema di Interscambio, then keep the accounting records | Billing name and address, codice fiscale or VAT number, amounts | Legal obligation — Art. 6(1)(c), with Italian tax and e-invoicing law |
| Cater for your dietary requirement or allergy | Dietary preference, allergy notes | Your explicit consent — Art. 9(2)(a). Given by filling the field in; withdrawable at any time |
| Credit the partner who introduced you and pay their commission; understand which channels bring registrations | Partner code, campaign parameters, referring site | Legitimate interests — Art. 6(1)(f): paying the people who sell for us, and knowing what our marketing achieves |
| Keep the site up, block abuse and rate-limit attacks | IP address, request logs | Legitimate interests — Art. 6(1)(f): the security of our own service |
| Send you practical information about the event you registered for — timings, venue, changes | Email address, name | Performance of a contract — Art. 6(1)(b) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them — largely because the data involved is commercial rather than sensitive, and is not used to make any decision about you. You can object to this processing at any time: see section 9.
Who we share it with
We share your data only with the organisations below, only for the purpose stated, and only with what they need. Each one that processes data on our behalf does so under a written contract required by Art. 28 GDPR. We never sell your data.
| Recipient | What for | Where |
|---|---|---|
| Stripe Stripe Payments Europe Ltd. and Stripe, Inc. | Taking payment, calculating tax, collecting your billing address and VAT number | Ireland, with transfers to the United States |
| Fatture in Cloud TeamSystem group | Issuing and storing your invoice | Italy |
| Agenzia delle Entrate Sistema di Interscambio (SdI) | Mandatory transmission of the electronic invoice. A legal requirement, not a choice | Italy |
| Zapier Zapier, Inc. | Passing the confirmed registration into our internal ledger | United States |
| Google Google Ireland Ltd. | The spreadsheet our team uses to manage the delegate list | Ireland, with transfers to the United States |
| Cloudflare Cloudflare, Inc. | Serving the site, TLS encryption, blocking attacks. Also serves the JavaScript libraries the page uses | United States, served from EU edge locations |
| Hetzner Hetzner Online GmbH | The server this website and its database run on | Germany |
| Google Fonts Google Ireland Ltd. | Serving the typefaces the page is set in. Your browser requests these directly, so Google receives your IP address | Ireland / United States |
| The event caterer | Only your first name and your dietary or allergy note, and only if you gave one | Italy |
| Our accountants and, if ever needed, our lawyers | Filing our accounts; establishing or defending a legal claim | Italy |
Partners do not receive your details. A partner who introduced you sees that a registration was credited to their code and what commission it earned. They do not see your name, your email, your telephone number or anything else about you.
Data sent outside the EU
Stripe, Zapier, Google and Cloudflare are US-headquartered, so some data reaches the United States. Those transfers are covered by the Standard Contractual Clauses adopted by the European Commission, and — where the provider is certified — by the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to any particular transfer by writing to [email protected].
Everything else — the web server, the database, the invoicing system and the tax transmission — stays inside the EU.
How long we keep it
| Data | Kept for | Why |
|---|---|---|
| Invoices and accounting records | 10 years | Art. 2220 of the Italian Civil Code and tax law require it. This period is not something we can shorten on request |
| Your registration record | 10 years where it underlies an invoice; otherwise until the event, plus the limitation period for any claim arising from it | Accounting, and the ability to defend a legal claim |
| Dietary requirements and allergy notes | 30 days after the event, then deleted | They are only needed to feed you at the event |
| Partner attribution and campaign data | For as long as commission may be owed, then with the accounting records | Paying partners correctly, and being able to show why |
| Attribution cookies on your device | 90 days | Long enough to credit a partner for a registration that took a while to decide on |
| Server and security logs | Short-term, on a rolling basis | Diagnosing faults and investigating abuse |
| Registrations that never resulted in a payment | 24 months, then deleted | So we can help if your payment failed, without keeping the record indefinitely |
How we protect it
The site is served only over encrypted HTTPS connections. The server sits behind a security proxy that filters malicious traffic and rate-limits abuse. Administrative access is restricted to named people who need it, file editing through the browser is disabled, and the database is backed up daily to encrypted storage with a fixed retention period.
Card data never reaches our systems at all — it goes straight to Stripe, which is certified to PCI DSS Level 1. That is a deliberate design decision: the safest way to hold card numbers is not to hold them.
No system is perfectly secure. If a breach ever put your rights at risk, we will notify the Garante within 72 hours and tell you directly where the law requires it.
Your rights
Under Articles 15 to 22 GDPR you can ask us to:
- Give you a copy of the data we hold about you, and tell you what we do with it.
- Correct anything inaccurate or incomplete — a misspelled name, a wrong VAT number.
- Delete your data, where we have no overriding obligation to keep it. Note that invoices are the main exception: tax law fixes those at ten years.
- Restrict how we use it while a dispute about accuracy or legitimate interests is resolved.
- Receive it in a portable format, machine-readable, for data you gave us under a contract or with consent.
- Object to any processing we base on legitimate interests, including partner attribution.
- Withdraw consent for your dietary or allergy note at any time, without affecting anything done before you withdrew it.
Write to [email protected]. These rights are free to exercise and we will respond within one month. We may need to confirm who you are before acting, so that nobody else can obtain your data by asking for it.
There is no automated decision-making here. Nothing about your registration is decided by an algorithm, and we do not profile you.
Cookies
This site sets two cookies, both first-party, and neither of them tracks you across other websites.
| Cookie | What it holds | Life |
|---|---|---|
prcn_partner | The partner code from the link you arrived through, so the right partner is credited when you register | 90 days |
prcn_source | The campaign parameters and referring site from that same visit, kept together so a registration is never credited to a partner but sourced from nowhere | 90 days |
There are no analytics cookies and no advertising cookies on this site. Stripe sets its own cookies on its own payment pages, which are governed by Stripe's privacy policy, and Cloudflare may set a security cookie to distinguish real visitors from bots.
You can delete or block cookies in your browser settings at any time. Blocking the two above does not stop you registering — it only means a partner who introduced you may not be credited.
Children
X DAYS is professional medical education intended for clinicians and healthcare practitioners. The site is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has registered, tell us at [email protected] and we will delete the record.
Changes to this notice
If we change how we handle your data — a new processor, a new purpose — we will update this page and change the date at the top. Where a change materially affects your rights, we will tell registrants by email rather than relying on you to re-read the page.
Contact and complaints
For anything in this notice, write to [email protected]. We would always rather hear a complaint directly and fix it.
You also have the right to complain to the Italian supervisory authority, whether or not you contact us first:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
garanteprivacy.it
If you live in another EU country, you may complain to your own national supervisory authority instead.