Privacy Policy for the Site

Privacy policy on the processing of personal data.

Effective as of Oct 2, 2025

INTRODUCTION

This information takes into account the provisions of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and of the Privacy Code (Legislative Decree 30 June 2003 n. 196). The document has also been drafted in accordance with the Guidelines of the Privacy Guarantor (especially the Guidelines for combating spam issued by the Privacy Guarantor on July 4, 2013).

Data Controller: PANsoft, Viale Guido Gozzano 36, 21052 Busto Arsizio, Italy – VAT IT03608300129, privacy@panquiz.com

Site to which this privacy policy refers:https://www.panquiz.com (Sito).

The Data Controller has not appointed a DPO. Therefore, you may send any inquiries directly to the Data Controller.

GENERAL INFORMATION

This document describes how the Data Controller processes your personal data.

The following describes the main processing of your personal data. In particular, we explain the legal basis of the processing, whether the provision of personal data is compulsory and the consequences of not providing personal data. To better describe your rights, if necessary, we have specified if and when a certain processing of personal data is not carried out.

Site registration

The information and data requested in case of registration will be used to allow you both to access the private area of the Site and to use the online services offered by the Data Controller to registered users. The legal basis of the processing is the need for the Data Controller to execute pre-contractual measures taken at the request of the data subject. The conferment of data is optional. However, your refusal to provide the data will make it impossible to register on the Site.You can also register on the Site using external services. In this case, your registration data will be shared with the companies of these external services for the sole purpose of enabling registration on the Site. The legal basis for this processing is the legitimate interest of the Data Controller in enabling registration on the Site via external services. The provision of personal data for this purpose is purely optional. However, failure to consent to the processing of data will make it impossible to register through external services.

Purchases on the Site

Your personal data will be processed to allow you to make purchases on the Site. in the case of making an online purchase order, to allow the conclusion of the purchase contract and the proper execution of transactions related to the same (and, if necessary under the legislation, to fulfill tax obligations). This treatment of personal data also includes the possibility of sending communications (e.g. tracking, order information and requests for reviews) via automated tools such as email and/or SMS and/or WhatsApp. The legal basis for the processing is the obligation of the Data Controller to execute the contract with the data subject or to comply with legal obligations. Apart from the above (and therefore your consent), the Data Controller may process your data for the purpose of so-called “soft-spam”, governed by art. 130 of the Privacy Code. This means that limited to the email you provided in the context of a purchase through the Site, the Data Controller will process the email to allow direct offers from similar products/services, unless you object to such processing in the manner provided by this policy. The legal basis for processing is the legitimate interest of the Data Controller to send this type of communication. This legitimate interest can be considered equivalent to the interest of the data subject in receiving “soft-spam” communications.

Answering your requests

Your data will be processed to respond to your requests for information. The conferment is optional, but your refusal will make it impossible for the Data Controller to answer your questions. The legal basis for the processing is the legitimate interest of the Data Controller in fulfilling your requests. This legitimate interest is equivalent to the user’s interest in receiving a response to communications sent to the Data Controller.

Marketing

Subject to your consent, the Data Controller may process the personal data provided by you in order to send you advertising material and/or newsletters relating to its own products or those of third parties. The legal basis of this treatment is your consent. The provision of personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will make it impossible for you to receive advertising material relating to products/services of the Data Controller and/or third parties, as well as making it impossible for the Data Controller to carry out market surveys, also aimed at assessing the degree of user satisfaction, and to send you newsletters.

Profiling

The Data Controller does not carry out “profiling” with your personal data. Therefore, it will not send you advertising material and/or newsletters relating to its own products or third parties of your specific interest.

Data transfer

The Data Controller does not transfer your personal data to third parties.

Web scraping

The use of any automated process or system to access, acquire, copy, or monitor any part of our website, including, but not limited to, web scraping, crawling, or spidering techniques, is expressly prohibited. The Data Controller reserves the right to take all necessary measures, including legal action, to prevent and prosecute any unauthorised scraping activities. By using the Site, the user or any third party agrees not to: (i) use automated systems, such as bots, scrapers, or spiders, to access or interact with the Site; (ii) collect content, data, or other information on the Site without express written permission; (iii) distribute, display, publish, or otherwise use content acquired through scraping techniques without consent. Any breach of this clause will be considered a material breach of the terms of use of the Site and will result in appropriate action being taken, including the possible suspension of access to the Site and the taking of legal action to protect the interests of the Data Controller.

Communication of personal data

As part of its ordinary business, the Data Controller may communicate your personal data to certain categories of subjects. In article 2 you can find the list of subjects to which the Data Controller communicates your personal data. In order to facilitate the protection of your rights, Article 2 may specify in certain cases when your data is not communicated to third parties.

The “communication” of personal data to third parties is different from the “transfer” (governed by the preceding point). In fact, in the communication the third party to whom the data is transmitted can use it only for the specific purposes described in the relationship with the Data Controller. In the transfer, instead, the third party becomes the autonomous Data Controller. Moreover, to transfer your personal data to third parties is always required your consent.

Without prejudice to the foregoing, it is understood that the Data Controller may still use your personal data in order to correctly fulfill the obligations provided for by the laws in force.

PRIVACY POLICY

Art. 1 Method of processing

1.1 The processing of your personal data will be mainly carried out with the help of electronic or automated means, according to the methods and with the tools suitable to ensure their security and confidentiality.

1.2 The information acquired and the methods of treatment will be relevant and not excessive in relation to the type of services rendered. Your data will also be managed and protected in secure computer environments appropriate to the circumstances.

1.3 Through the Site are not processed “special data”. Particular data are those that can reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership of parties, trade unions, associations or organizations of a religious, philosophical, political or trade union, health and sex life.

1.4 No judicial data is processed through the Site.

Art. 2 Communication of personal data

The Data Controller may communicate your personal data to certain categories of subjects. The Data Controller wishes to inform users that, in the context of using the YouTube service (managed and owned by Google LLC), some personal data may be collected and shared. This data collection is essential to provide and enhance the user experience on our Site and to enable viewing of video content integrated through the YouTube API. In detail, when a user views a video content through the YouTube API on our Site, the following information may be collected: IP Address: Used to connect the user’s device to YouTube for video transmission. Behavioral Data: Includes information on how the user interacts with videos, such as which videos are viewed and for how long. Location Information: Used to provide relevant content based on the user’s geographical location. These data are automatically collected by the system and, in some cases, may be stored to improve user experience and for internal analytical purposes at YouTube. It is specified that our Site uses YouTube’s API services and, by viewing content through these APIs, the user accepts YouTube’s Terms of Service available at https://www.youtube.com/t/terms. For further details on data management by Google LLC, users are invited to consult Google LLC’s privacy policy at http://www.google.com/policies/privacy and YouTube’s at https://www.youtube.com/intl/ALL_it/howyoutubeworks/our-commitments/protecting-user-data/. Details on the use of User API Data User API Data: When a user interacts with YouTube videos embedded in our Site, data such as viewing preferences, video viewing history, and interactions with video content (likes, comments, shares) may be collected. These data are made available through the YouTube API and help to understand how users interact with video content. Access to data via the Client API: Our Site may use specific API calls to request and receive data from YouTube. This may occur when a user views a video, with the system automatically recording relevant information. Data Collection: Data are automatically collected by the YouTube system when users interact with YouTube videos on our Site. This process is essential to provide a smooth and personalized user experience. Data Storage: The collected data are securely stored in YouTube’s systems for a period that does not exceed the necessity of use. YouTube adopts all necessary security measures to protect these data from unauthorized access or illicit uses. Use of Data: YouTube uses these data for various purposes, including: Internal Analysis: To better understand user interactions with video content and improve the quality of YouTube services. Content Personalization: To offer users a more personalized experience, based on their preferences and interaction history. User Experience Improvement: To identify and resolve any technical issues and optimize the usability of video content. The subjects to whom the Data Controller reserves the right to communicate your data are indicated below:

  • The Data Controller may communicate your personal data to all those subjects (including Public Authorities) who have access to personal data by virtue of regulatory or administrative measures.
  • Your personal data may also be disclosed to all those public and / or private individuals and / or legal entities (legal, administrative and tax, judicial offices, Chambers of Commerce, Chambers and Offices of Labor, etc..), if the communication is necessary or functional to the proper fulfillment of obligations under the law.
  • The Data Controller does not make use of employees and/or collaborators in any capacity. Therefore, your personal data will not be communicated to this category of subjects.
  • The Data Controller does not use companies, consultants or professionals in charge of the installation, maintenance, updating and, in general, the management of the Data Controller’s hardware and software. Therefore, your data will not be communicated to these categories of subjects.
  • The Data Controller does not use CRM platforms (companies that carry out the activity of sending automated communications to users. Therefore, your personal data are not communicated to these companies.
  • The Data Controller does not use external companies to provide customer care services. Therefore, your personal data will not be processed for this purpose.
  • The Data Controller utilizes banking institutions and companies that manage national and international payment networks for online payments of products and services purchased through the Website.
  • Buyers’ personal data are not communicated to couriers or forwarding agents.

The Data Controller reserves the right to modify the above list in accordance with its ordinary operations. Therefore, you are invited to regularly access this information to check to which subjects the Data Controller communicates your personal data.

Art. 3 Personal data retention

3.1 This article describes how long the Data Controller reserves the right to retain your personal data.

  • User data will be kept only for the time necessary to ensure the proper provision of the services offered through the Site.
  • For marketing purposes, personal data will be kept until consent is revoked. For inactive users, personal data will be deleted after one year from the sending of the last email eventually viewed.
  • Through the Website (or by requesting it from the Data Controller), it is possible to delete the user’s account. In this case, all stored personal data will be deleted and will not be retained by the Data Controller for any purpose.

3.2 Without prejudice to the provisions of Article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as amended from time to time.

Art. 4 Transfer of personal data

The Data Controller is established in the European Union, and therefore in a country that ensures an adequate level of protection of personal data from a regulatory standpoint, in accordance with GDPR. The location of the Data Controller within a legal framework compliant with the GDPR guarantees that the processing of personal data is carried out in compliance with the principles of lawfulness, fairness, and transparency, as well as with appropriate technical and organizational measures to ensure data security.

Art. 5. Your rights

The Data Controller informs you that you have the right:

  • to request from the Data Controller access to your personal data and the rectification or erasure of the same or the restriction of the processing thereof or to object to the processing thereof, in addition to the right to data portability
  • revoke consent at any time without affecting the lawfulness of the processing based on the consent given before revocation
  • to lodge a complaint with a supervisory authority (e.g. the Italian Data Protection Authority).

The rights referred to above may be exercised by making a request without formalities to the contacts indicated in the Introduction.

Art. 6. Amendments

The Data Controller reserves the right to make changes to this policy at any time, giving appropriate publicity to users of the Site and ensuring in any case an adequate and similar protection of personal data. In order to view any changes, you are invited to regularly consult this policy. In case of substantial changes to this privacy policy, the Data Controller may give notice of such changes also by email.

Privacy Policy for the Application

Privacy policy on the processing of personal data pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

Effective as of Oct 2, 2025

INTRODUCTION

This information takes into account the provisions of the GDPR and the Privacy Code (Legislative Decree 30 June 2003 n. 196). The document has also been drafted in accordance with the Guidelines of the Privacy Guarantor (especially the Guidelines for combating spam issued by the Privacy Guarantor on July 4, 2013).

Data Controller: PANsoft, Viale Guido Gozzano 36, 21052 Busto Arsizio, Italy – VAT IT03608300129, privacy@panquiz.com

APP to which this privacy policy refers:PanQuiz (APP).

The Data Controller has not appointed a DPO. Therefore, you may send any inquiries directly to the Data Controller.

GENERAL INFORMATION

This document describes how the Data Controller processes your personal data.

The following describes the main processing of your personal data. In particular, we explain the legal basis of the processing, whether the provision of personal data is compulsory and the consequences of not providing personal data. To better describe your rights, if necessary, we have specified if and when a certain processing of personal data is not carried out.

APP registration

The information and data requested in case of registration will be used to allow you both to access the private area of the APP and to use the online services offered by the Data Controller to registered users. The legal basis of the processing is the need for the Data Controller to execute pre-contractual measures taken at the request of the data subject. The conferment of data is optional. However, your refusal to provide the data will make it impossible to register on the APP. You can also register on the APP using external services. In this case, your registration data will be shared with the companies of these external services for the sole purpose of enabling registration on the APP. The legal basis for this processing is the legitimate interest of the Data Controller in enabling registration on the APP via external services. The provision of personal data for this purpose is purely optional. However, failure to consent to the processing of data will make it impossible to register through external services.

Purchases on the APP

It is not possible to make purchases on the APP. Therefore, your personal data will not be processed for this purpose.

Answering your requests

Your data will be processed to respond to your requests for information. The conferment is optional, but your refusal will make it impossible for the Data Controller to answer your questions. The legal basis for the processing is the legitimate interest of the Data Controller in fulfilling your requests. This legitimate interest is equivalent to the user’s interest in receiving a response to communications sent to the Data Controller.

Marketing

Subject to your consent, the Data Controller may process the personal data provided by you in order to send you advertising material and/or newsletters relating to its own products or those of third parties. The legal basis of this treatment is your consent. The provision of personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will make it impossible for you to receive advertising material relating to products/services of the Data Controller and/or third parties, as well as making it impossible for the Data Controller to carry out market surveys, also aimed at assessing the degree of user satisfaction, and to send you newsletters. These communications will be sent to your e-mail.

Profiling

The Data Controller does not carry out “profiling” with your personal data. Therefore, it will not send you advertising material and/or newsletters relating to its own products or third parties of your specific interest.

Data transfer

The Data Controller does not transfer your personal data to third parties.

Communication of personal data

As part of its ordinary business, the Data Controller may communicate your personal data to certain categories of subjects. In article 2 you can find the list of subjects to which the Data Controller communicates your personal data. In order to facilitate the protection of your rights, Article 2 may specify in certain cases when your data is not communicated to third parties.

The “communication” of personal data to third parties is different from the “transfer” (governed by the preceding point). In fact, in the communication the third party to whom the data is transmitted can use it only for the specific purposes described in the relationship with the Data Controller. In the transfer, instead, the third party becomes the autonomous Data Controller. Moreover, to transfer your personal data to third parties is always required your consent.

Without prejudice to the foregoing, it is understood that the Data Controller may still use your personal data in order to correctly fulfill the obligations provided for by the laws in force.

PRIVACY POLICY

Art. 1 Method of processing

1.1 The processing of your personal data will be mainly carried out with the help of electronic or automated means, according to the methods and with the tools suitable to ensure their security and confidentiality in accordance with the GDPR.

1.2 The information acquired and the methods of treatment will be relevant and not excessive in relation to the type of services rendered. Your data will also be managed and protected in secure computer environments appropriate to the circumstances.

1.3 Through the APP are not processed “special data”. Particular data are those that can reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership of parties, trade unions, associations or organizations of a religious, philosophical, political or trade union, health and sex life.

1.4 No judicial data is processed through the APP.

Art. 2 Communication of personal data

The Data Controller may communicate your personal data to certain categories of subjects. The subjects to whom the Data Controller reserves the right to communicate your data are indicated below:

  • The Data Controller may communicate your personal data to all those subjects (including Public Authorities) who have access to personal data by virtue of regulatory or administrative measures.
  • Your personal data may also be disclosed to all those public and / or private individuals and / or legal entities (legal, administrative and tax, judicial offices, Chambers of Commerce, Chambers and Offices of Labor, etc..), if the communication is necessary or functional to the proper fulfillment of obligations under the law.
  • The Data Controller does not make use of employees and/or collaborators in any capacity. Therefore, your personal data will not be communicated to this category of subjects.
  • The Data Controller does not use companies, consultants or professionals in charge of the installation, maintenance, updating and, in general, the management of the Data Controller’s hardware and software. Therefore, your data will not be communicated to these categories of subjects.
  • The Data Controller does not use CRM platforms (companies that carry out the activity of sending automated communications to users. Therefore, your personal data are not communicated to these companies.
  • The Data Controller does not use external companies to provide customer care services. Therefore, your personal data will not be processed for this purpose.

The Data Controller reserves the right to modify the above list in accordance with its ordinary operations. Therefore, you are invited to regularly access this information to check to which subjects the Data Controller communicates your personal data.

Art. 3 Personal data retention

3.1 This article describes how long the Data Controller reserves the right to retain your personal data.

  • User data will be kept only for the time necessary to ensure the proper provision of the services offered through the APP.
  • For marketing purposes, personal data will be kept until consent is revoked. For inactive users, personal data will be deleted after one year from the sending of the last email eventually viewed.

3.2 Without prejudice to the provisions of Article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as amended from time to time.

Art. 4 Transfer of personal data

The Data Controller is established in the European Union, and therefore in a country that ensures an adequate level of protection of personal data from a regulatory standpoint, in accordance with GDPR. The location of the Data Controller within a legal framework compliant with the GDPR guarantees that the processing of personal data is carried out in compliance with the principles of lawfulness, fairness, and transparency, as well as with appropriate technical and organizational measures to ensure data security.

Art. 5. Your rights under the GDPR

Pursuant to art. 13 of the Privacy Regulations, the Data Controller informs you that you have the right:

  • to request from the Data Controller access to your personal data and the rectification or erasure of the same or the restriction of the processing thereof or to object to the processing thereof, in addition to the right to data portability
  • revoke consent at any time without affecting the lawfulness of the processing based on the consent given before revocation
  • to lodge a complaint with a supervisory authority (e.g. the Italian Data Protection Authority).

The rights referred to above may be exercised by making a request without formalities to the contacts indicated in the Introduction.

Art. 6. Amendments

The Data Controller reserves the right to make changes to this policy at any time. Therefore, you are invited to regularly consult this policy. In case of substantial changes to this privacy policy, the Data Controller may give notice of such changes also by email.