PRIVACY
Privacy notice.
How Grey Wolf / YUN SHOU ASD handles data submitted through the website and the trial-week process.
1. Data controller
The data controller is YUN SHOU ASD, VAT No. 03071660165, for Grey Wolf Jiu Jitsu Bergamo activities. Privacy contact: simo.piazzi@gmail.com. Activity location: Sports Centre, Via Stezzano 33, 24052 Azzano San Paolo (BG), Italy.
2. Data processed
The website may collect identification and contact details, course and trial start date, adult/minor status, campaign-attribution data and, during the document stage, the signed participation declaration, identity document, Italian tax-code document when available/required, optional photo/video consent, the participant’s medical certificate and its expiry date. For minors, the signing parent or guardian’s data are also processed.
The medical certificate contains health-related personal data and is processed only to manage the medical-eligibility requirement for participation and connected obligations. The Association must formally document the specific lawful condition applicable to health data and the related organisational safeguards in accordance with the applicable rules.
3. Purposes and legal bases
Contact data are used to respond to the enquiry, organise the trial and, only after the document stage is completed, send one administrative notification and one transactional confirmation to the participant. Requested documents are used for participation, identification and applicable insurance/administrative requirements. The medical certificate is used only to verify eligibility for participation and its validity period. Essential anti-abuse, security and logging measures protect the website and data. Photo/video use relies on a separate, specific and optional consent that can be withdrawn for future uses.
4. Retention
Trial requests that do not become active participation and their uploaded documents, including the medical certificate, are automatically deleted within 90 days of the last activity, unless retention is demonstrably required by law or to establish or defend a legal claim. If the person becomes a participant/member, data strictly required for association, insurance, administrative or medical-eligibility purposes are transferred to the appropriate operational systems; the temporary web copy must be removed when no longer necessary.
5. Security and recipients
Uploaded documents are transmitted over HTTPS, stored outside the public web directory and encrypted at rest using authenticated encryption. Physical filenames are generated server-side and cannot be reached by a public URL. For operational handling of the request, a copy of the uploaded documents may be sent as attachments only in administrative notifications addressed to authorised recipients, using authenticated SMTP over encrypted TLS transport. These attachments are not sent to the participant and are never exposed through a public URL. Copies held in administrative mailboxes must be managed under the same purposes, access restrictions and applicable retention rules as the request itself. Administrative access is limited to authorised persons and server-side document access should be logged.
6. Minors
Requests for a minor must be managed by a parent or legal guardian. The uploaded medical certificate must refer to the minor participant, while the signing adult’s identification document must refer to the parent/guardian as indicated by the workflow. Photo/video consent remains separate from sporting participation.
7. Analytics and advertising
Funnel analytics events do not include names, email addresses, phone numbers, tax codes, medical-certificate content or filename, or other health data. Non-essential analytics, advertising or profiling tools are enabled only when configured and, where required, after the user’s consent choice.
8. Rights
Data subjects may request access, rectification, erasure, restriction, objection and, where applicable, portability. Consent may be withdrawn at any time without affecting processing lawfully carried out before withdrawal. Requests: simo.piazzi@gmail.com. A complaint may also be lodged with the Italian Data Protection Authority.
Last updated: 19 August 2026. This notice describes the web workflow currently implemented; YUN SHOU ASD must keep the applicable lawful condition, internal authorisations, supplier arrangements and safeguards for health-data processing documented and aligned with applicable law.