Annex C – End User General Terms and Conditions
End User General Terms and Conditions
Whereas
……………………………, with registered office in ……………………………, (hereinafter the "Company") is the licensee (exclusively for the purpose of providing the Service, as defined below) of a program developed by Vitality Plus SA which, through a digital service, allows licensees to improve the corporate wellbeing of their employees and/or collaborators through an APP and Web APP designed to promote physical, mental, spiritual and relational health.
The Company is the controller of all the personal data that the employee and/or collaborator decides to share within it.
The End User – as defined below – declares that they are interested in using the Service to improve their level of corporate wellbeing.
It is agreed and stipulated as follows
Subject matter of the contract
Essential definitions
In this contract, the following terms shall have the meaning specified here:
"Software" (or, generically, the "Platform"): the program developed by Vitality Plus SA which, through a digital service, allows licensees to improve the corporate wellbeing of their employees and/or collaborators through an APP and Web APP named "Vitality+", designed to promote physical, mental, spiritual and relational health.
"Customers" (or, generically, "Users"): all parties who purchase a licence to the Software in order to integrate it into their own business processes.
"End Users": the employees, collaborators or persons associated with the Customer who use the Software licensed by the Licensee.
"Account": the access credentials (e-mail address and one-time code) required for End Users to use the Software.
"Intellectual Property Rights": any right relating to patentable and non-patentable inventions, patent rights, database rights, copyright and related rights including copyright in the Software, in the source code and algorithms, in databases, as well as trade secrets pursuant to Articles 98-99 of the Italian Industrial Property Code (i.e., Legislative Decree no. 30 of 10 February 2005), design rights, rights in drawings and models, trademarks, domain names and any other right relating to any industrial and/or intellectual property, whether registered or not, including all rights to apply for such rights.
"Third-Party Content": materials, videos, texts, audio, articles or other contributions produced by external professionals and made available within the Software.
"Services": the Software, its documentation, maintenance, technical support, updates and agreed optional services.
"Documentation": user manuals, guides, technical specifications and any other information provided by the Licensor relating to the Software.
"AI or Recommendation Algorithm": artificial intelligence systems integrated into the Software which analyse personal and behavioural data in order to provide personalised suggestions or programmes.
"Blood Tests": the reports, images, files or other documents relating to the End User's blood tests, which the End User may voluntarily upload to the Software as a PDF, as an image or via the device camera.
"Connected Third-Party Devices": the wearable devices and third-party applications (by way of example and without limitation: Apple Watch, Whoop) that the End User may optionally connect to the Software through the Google Health Connect and Apple HealthKit integrations.
"Photo Calorie Count": the optional feature that allows the End User to obtain an estimate of the nutritional value of meals through photographic recognition of food, carried out by a third-party provider, or to enter food items and their calorie values manually, without using the camera.
"AI Chatbot": the conversational artificial intelligence system integrated into the Software, accessible (i) by the Company through the corporate dashboard, exclusively on aggregated and statistical data containing no name or identifying reference to individual End Users, and (ii) by the End User, limited to consulting their own personal data.
"Location Service": the optional Software feature which, subject to activation of the device permissions and the End User's consent, allows the collection and processing of the End User's geolocation (GPS) data for personal purposes (e.g. routes and sports activities), without such data being made visible to the Company or to third parties.
Nature of the Service
The Service consists of a program developed by Vitality Plus SA which allows Companies ("Users") that purchase a licence to the software to use it within their own corporate context for the corporate wellbeing of their employees and/or collaborators. Use of the "Vitality+" software is not mandatory for End Users, who may decide not to use it or, subsequently, to delete their account at any time.
End Users shall be entitled to be awarded "fringe benefits" or other individual rewards should they choose to take part in corporate "Challenges" to improve their psycho-physical wellbeing or to actively use the Software.
It is understood that the Company reserves the right to deliver the rewards referred to above up to the thresholds provided for by applicable legislation.
The management of Rewards is quantified on the basis of the Budget set by the Licensee which, in agreement with the Licensor, shall establish the timing and manner of delivery of each Reward. Rewards earned may be redeemed through the application by the expiry date of the current annual contractual period and within the limits of the Budget allocated. Vouchers must be used at partner merchants by the same deadline. Once these deadlines have passed, rewards not redeemed or not used shall definitively lapse without any right to a refund.
The redemption and use of rewards are subject to the licence agreement between the Licensor and the Licensee being in force at the same time and to the continuation of the employment relationship between the employee and the company. If either relationship ends, the employee/collaborator immediately loses all rights to rewards earned but not redeemed and may not use rewards already redeemed.
The Software also allows the End User, always on a voluntary and optional basis that can be deactivated at any time: (i) to upload their Blood Tests; (ii) to connect Third-Party Devices; (iii) to use the Photo Calorie Count; (iv) to interact with the AI Chatbot; (v) to activate the Location Service. The methods, purposes and safeguards relating to each of these features are described in this section and in the End User Privacy Notice (Annex D1/D2), which the End User declares to have read and understood.
Fundamental limitations
The End User acknowledges: (a) (i) that the Service is based on personal data directly provided by the End User which may involve special category data (e.g. state of health); (ii) that the Service uses artificial intelligence recommendation systems capable of analysing the content viewed by the End User and suggesting new content; (iii) that the Software is not a substitute for or an alternative to medical or specialist advice and that all the information provided may not always be accurate, truthful, up to date or otherwise relevant and/or may in any event contain errors of various kinds; and (iv) that no interaction may constitute a binding commitment for the Company; (b) that the Service is not medical advice or a specialist examination; that the Service cannot: (i) prescribe medicines, or issue diagnoses or prognoses; (ii) replace a medical opinion; (iii) be used without having shared the health information and the advice received with one's own doctor; (c) that the Service must not be used to obtain: (i) medical advice; (ii) psychological advice or support; (iii) therapeutic indications.
Disclaimer and limitations relating to the new Software features
Blood Tests. The End User is expressly warned that the files, images or documents uploaded as part of this feature may contain personal data, including health data within the meaning of Article 9 of Regulation (EU) 2016/679 and Article 5(c) of the FADP, relating to themselves and/or third parties (e.g. identifying data on the report). The End User undertakes to remove or redact such identifying data before uploading. Should the End User fail to do so, the upload automatically triggers an anonymisation service based on Google Cloud (Cloud Run and Cloud DLP) which detects and removes personal identifiers from the document. Neither the Company nor the Software Provider is able to identify the person who uploaded the document or to link the uploaded Blood Tests to a specific End User.
Connected Third-Party Devices. Third-Party Devices are connected through the Google Health Connect, Apple HealthKit et similia integrations and the connection is entirely optional. The related indicators (KPIs) are provided by the individual third-party providers and the Company does not guarantee the accuracy, completeness or currency of such data, for which it is not responsible.
Calorie Count. The estimate of nutritional value obtained through a photograph or direct entry of values is produced by a third-party provider on the basis of automatic image recognition or of the nutritional values themselves and is purely indicative. This feature does not constitute nutritional or medical advice and does not replace the opinion of a qualified professional.
AI Chatbot. The AI Chatbot made available to the Company in the corporate dashboard operates exclusively on aggregated and statistical data which cannot be traced, even indirectly, to a specific End User (by way of example: identifying the team with the highest stress level or the best sleep quality, on an aggregated basis). The AI Chatbot does not and cannot provide the Company with answers containing names, identifiers or other information traceable to individual End Users. The End User may also query the AI Chatbot, limited to their own personal data. The outputs of the AI Chatbot may under no circumstances be used by the Company for disciplinary measures, performance evaluations or other decisions concerning individual End Users.
Location Service. The collection of geolocation (GPS) data may be optionally activated by the End User solely for personal purposes related to the use of the App (e.g. routes and sports activities). Such data is not shared with the Company or made visible in the corporate dashboard and is not collected in the background outside the active use of the specific feature.
Registration and access
Registration requirements
Access to the Service is permitted exclusively to persons who:
- are at least 18 years old;
- have full legal capacity;
- provide the personal data required by the Software;
- declare that they have read and expressly accept: these terms; the privacy notice, the usage policies and the licence terms.
Obligations of the End User
The End User undertakes to:
- provide information that is: truthful; accurate, complete and up to date;
- maintain the security of: access credentials; devices used; active sessions; personal data;
- immediately notify: unauthorised access, security breaches; improper use; loss of credentials.
Limitation of liability
General exclusion of liability
The Company assumes no liability for:
- decisions of the User based on the content of the Service; information received; suggestions generated;
- consequences arising from: the interpretation of content; the application of information; the use of the Service; the sharing of content.
Specific limitations for medical, psychological or social content
The Service does NOT provide: medical advice: diagnoses; therapies; prescriptions; treatment indications; recommendations on: medicines, supplements, diets, training, lifestyles, wellbeing practices; psychological advice or support; social support or assistance.
The End User acknowledges that: any reference to medical, psychological or social matters is purely informational; healthcare professionals must be consulted; the Company disclaims all liability for health-related decisions.
Nature of content based on information from smart devices
The End User acknowledges that:
- content provided on the basis of data received from smart devices or other applications is: not necessarily up to date; potentially inaccurate; accuracy is not guaranteed for: technical information; numerical data; measurements; health parameters; etc.;
- the Software relies on smart devices not directly controlled by the Software Provider, which may not always be accurate, truthful, up to date or fully functional.
Intellectual property and licence to use
Ownership of rights
All industrial and intellectual property rights relating to the Service (including, without limitation, trademarks, domain names, inventions, utility models, know-how, copyright and related rights, etc., as well as the software, algorithms, databases, graphical and voice interfaces, the digital avatar and any other element that constitutes or forms part of the Service as provided now or in the future, together with all the Content on which its operation is based, including the outputs generated by interaction with the End User or otherwise made available to the End User through the Service) are the exclusive property of Vitality Plus SA (or its suppliers) and the Company may validly dispose of them towards the End User under these terms and conditions.
Licence to use
Vitality Plus SA has granted the User a licence for consideration (as provided for in the relevant General Terms and Conditions), which is non-exclusive, non-transferable and non-sub-licensable to third parties, for access to and use of the Service for exclusively personal and non-commercial purposes, in compliance with these terms and conditions and with applicable laws and regulations, for the term corresponding to the subscription period chosen by the User. The licence is personal and non-assignable and may not otherwise be shared with third parties (e.g. by sharing the User's access credentials). The End User acknowledges what is expressly provided for the User.
Prohibited uses
The End User is strictly prohibited from:
- copying, reproducing (except within the limits of what is functional to access to and use of the service as permitted by these terms and conditions), displaying, lending, renting, distributing, communicating to the public (including making available to the public), selling or licensing, modifying, adapting, processing, creating derivative works, translating, decompiling, disassembling, reverse engineering, analysing, testing, emulating or altering in any way the Service, the related technology, the software, the algorithms, the databases, the interfaces and any other element or Content thereof (at input or output level), present or future;
- evading, or attempting to evade, breaching, circumventing or removing the protections, security measures, authentication systems or technical limits imposed by the Company for access to and use of the Service;
- manipulating, interfering with, damaging, compromising, overloading, altering or preventing the proper functioning of the Service or the related Content (at input and output level); using software, bots, scripts, crawlers, spiders or other automated or fraudulent means to access, use, monitor, extract, collect or manipulate the Service or its Content (at input and output level) or to generate traffic, requests, interactions or deep fake content or content that is otherwise false, misleading, unlawful or harmful;
- using the Service for unlawful purposes or in breach of applicable laws, including those on intellectual property, the protection of personal data and electronic communications.
Subscription and financial terms
Subscription structure
The Service is available free of charge to the End User because the Company (the "User") to which they belong has taken out a paid subscription with Vitality Plus SA. No further costs are charged to the End User.
Privacy and data protection, security and confidentiality
The processing of personal data is governed by the Privacy Notice available in the dedicated "Privacy" section, which the User declares to have read and understood.
The Privacy Notice forms an integral and substantial part of these Terms and Conditions.
The User acknowledges that use of the Service involves the processing of their personal data as specified in the Privacy Notice.
Governing law and jurisdiction
Governing law
This contract is governed by Italian law. The contract is also subject to the applicable European Union regulations on the protection of personal data and on artificial intelligence (where applicable), on information society services, on consumers and on intellectual property, as well as to sector regulations, the Italian Consumer Code, mandatory rules and the commercial practices in force in Italy.
Jurisdiction
For Companies: in the event of disputes between the Company and the User, where the latter acts in the course of its professional or business activity, the court with exclusive jurisdiction is the Court of Milan.
For consumers: in the event of disputes between the User and the End User, where the latter acts for purposes outside their professional or business activity, the competent court is that of the place of residence or elected domicile of the End User, unless a legal provision assigns jurisdiction to another court.
Final provisions
Partial invalidity
Should one or more clauses of this contract be declared null, invalid, ineffective or unenforceable by a competent judicial or administrative authority, the remaining clauses of the contract shall retain their validity, effectiveness and enforceability, unless the nullity, invalidity, ineffectiveness or unenforceability undermines the purpose or the balance of the contract. Null, invalid, ineffective or unenforceable clauses shall be automatically replaced by the legal provisions in force on the matter or, failing that, by equivalent or similar clauses, interpreted conservatively and in accordance with the purpose and balance of the contract.
The nullity, invalidity, ineffectiveness or unenforceability of one or more clauses of this contract shall not extend to the other clauses of the contract, nor shall it result in the nullity, invalidity, ineffectiveness or unenforceability of the entire contract. Null, invalid, ineffective or unenforceable clauses are replaced by operation of law by the legal provisions in force on the matter or, failing that, by equivalent or similar clauses, interpreted conservatively and in accordance with the purpose and balance of the contract.
Tolerance
The Company's failure to challenge any breach, non-performance, delay, omission, non-compliant conduct or improper use of the Service, of the conversational AI, of the content, of the data or of the contract by the User shall not constitute acquiescence, waiver, novation, settlement or release of the rights or legal actions to which the Company is entitled, nor shall it prevent the Company from exercising its rights or legal actions at any later time.
Acceptance and signature
General acceptance
The undersigned End User expressly declares that they:
- have read this contract in full and understood its content, nature, scope, implications and effects;
- accept all the clauses, conditions (including all limitations of liability), methods, purposes, warranties and responsibilities provided for in this contract, without reservations, exceptions, limitations or conditions;
- have the right and the capacity to be bound by this contract, under applicable law and in light of their personal, professional or business situation;
- have received all the information, communications, notices, warnings and instructions necessary, useful and relevant for the signing and performance of this contract and for the use of the Service;
- have given their explicit, specific, free and informed consent to the processing of their personal data by the Company, for the purposes and in the manner provided for in this contract and in the Company's Privacy Notice.
Acceptance of this contract by clicking the "I accept" button is equivalent to an electronic signature pursuant to Article 21 of Italian Legislative Decree no. 82 of 7 March 2005 (Digital Administration Code).
Annex D1 – Employee Privacy Notice for companies established in Switzerland
Privacy notice
Notice on the processing of personal data pursuant to Article 19 of the Swiss Federal Act on Data Protection of 25/09/2020
Dear Employee,
this notice on the processing of personal data governs the processing of the personal data of Employees of our company who access the Web Application or download the "Vitality+" application available on the Apple Store and Google Play.
1. Data subject
You, i.e. the natural person to whom this notice is addressed, also referred to as the User who uses the services offered by the "Vitality+" Web App.
2. Data Controller
The Controller of your personal data is ……………………… (hereinafter also the "Controller" or "………"), with registered office in ………………………, which can be contacted at the following e-mail address: ………………….
3. Nature of the data processed
We inform you that we will process the following data of yours:
- personal identification data, to allow you to register on the App;
- physical data: Gender, Weight, Height, Meals and food choices, to assess nutritional quality and balance;
- subject to your consent, given directly by ticking the boxes within the App, certain data defined by law as sensitive personal data; this is data from which information on your state of health can be derived, to allow the tool to help you improve your quality of life by offering you personalised plans to increase your levels of corporate wellness;
- subject to your consent, the reports, images or documents relating to your blood tests which you decide to upload voluntarily to the Software and which you undertake to anonymise; such data is also processed by a third-party provider (Google Cloud – Cloud Run and Cloud DLP) which anonymises it if you do not do so yourself before uploading;
- the data from wearable devices and connected third-party applications (by way of example: Apple Watch, Whoop) through the Google Health Connect, Apple HealthKit et similia integrations;
- the photographs of meals and/or the data on food and calorie values that you enter manually, for the calorie count feature, which do not directly constitute personal data;
- geolocation (GPS) data, subject to your consent, for the personal purposes described in the following point;
- the content of your interactions with the AI Chatbot, when you choose to use it to consult your personal data.
4. Purpose of processing, justification, retention period of your personal data
We inform you that your data will not be used to bring disciplinary charges or to monitor your conduct or performance, but will be used solely for the purpose of improving the corporate wellbeing of the employee/collaborator. The main objective of the software is therefore to increase levels of corporate wellness.
Failure to provide the data may prevent you from accessing the welfare benefits or personal rewards provided for those who complete the so-called "challenges" or actively take part in the use of the Software. In addition, failure to give consent could result in lower work performance, with indirect consequences for possible professional growth.
Such data is processed for the following purposes.
4.1.1. Providing the service
To follow up your registration, i.e. to give you access to the App and provide the services. Provision of the data is necessary; without it, it will not be possible to use the application.
Justification: (for Users in Switzerland) Art. 31(2)(a) FADP, overriding interest of the Controller, namely the processing of data relating to the Data Subject in direct connection with pre-contractual measures. Retention period: data will be retained for 12 months after the end of the relationship.
4.1.2. Measuring performance through the processing of sensitive personal data
You can provide data relating to your state of health to allow us to help you improve your quality of life, offering you personalised plans to increase your levels of corporate wellness.
This will allow us to create tailor-made sports plans and optimise your rest by integrating your hours of sleep into your programmes to improve daily recovery and energy, and to suggest personalised activities and habits to adopt, including at work, that take your psycho-physical condition into account.
Provision of the data is optional and consent is given by ticking the relevant box and voluntarily providing the data relating to your state of health.
Justification: (for Users in Switzerland) Art. 31(1) FADP. Consent of the User. Retention period: until withdrawal.
4.2. Health APIs
If you choose to authorise the account to access accounts created with other app providers such as SDKs and APIs, Apple Health, Google Fit and other platforms, Vitality+ will obtain information about you from those accounts and sometimes also information about your health.
Such data is processed for the following purpose.
4.2.1. Personalising the App. Through integration with other platforms. Configuration is optional, because our App is able to work even without such synchronisation, so the provision of this data is based on your consent.
Justification: (for Users in Switzerland) Art. 31(1) FADP, consent of the Data Subject. Retention period: data will be retained until synchronisation is deactivated.
4.3. Synchronising the App with your devices
Our application allows you to synchronise your devices with the Vitality App. When you synchronise your device with the App, transmission data will be collected (for example: IP address, date and time of synchronisation, geographical location of the device).
Such data is processed for the following purposes.
4.3.1. Personalising the App. To allow you to personalise your profile by synchronising it with your devices to make the app easier to use. Device configuration is optional, because our App is able to work even without such synchronisation, so the provision of this data is based on your consent.
Justification: (for Users in Switzerland) Art. 31(1) FADP, consent of the Data Subject. Retention period: data will be retained until synchronisation is deactivated.
4.3.2. Processing of sensitive personal data. When synchronising your devices you are free to also provide us with data relating to your state of health, to allow us to help you improve your quality of life by offering you personalised plans to increase your levels of corporate wellness. This will allow us to create tailor-made sports plans and optimise your rest by integrating your hours of sleep into your programmes to improve daily recovery and energy, and to suggest personalised activities and habits to adopt, including at work, that take your psycho-physical condition into account.
Provision of the data is optional and consent is given by ticking the relevant box and voluntarily providing the data relating to your state of health.
Justification: (for Users in Switzerland) Art. 31(1) FADP. Consent of the User. Retention period: until withdrawal.
4.4. Uploading Blood Tests
If you choose to upload your blood tests as a PDF, as an image or via the device camera, such documents may contain your data or third-party data, including identifying data and data relating to your state of health. By uploading them, you undertake to anonymise the personal data before sharing them in the application.
In any event, we inform you that neither the Controller nor the Software Provider is able to identify the person who uploaded the document or to link the uploaded document to a specific End User. Furthermore, should you fail to remove or redact your identifying data before uploading, we have implemented an automatic anonymisation service based on Google Cloud (Cloud Run and Cloud DLP) which removes the personal identifiers contained in the document.
Such data is processed for the following purpose.
4.4.1. Providing you with informational support on your state of wellbeing. Provision of the data is optional and the upload takes place through a voluntary action by the User.
Justification: (for Users in Switzerland) Art. 31(1) FADP. Consent of the User. Retention period: until consent is withdrawn or the Account is deleted.
4.5. Photo Calorie Count
If you choose to use the calorie count feature via the camera, the photographs of food are processed by a third-party provider which provides an estimate of the nutritional value of the product. Alternatively, you can enter the food items and their calorie values manually, without using the camera.
Such data is processed for the following purpose.
4.5.1. Personalising the App. To provide you with information on the nutritional value of meals. Provision of the data is optional, since you can alternatively enter the data manually or not use the feature.
Justification: (for Users in Switzerland) Art. 31(1) FADP. Consent of the User. Retention period: until withdrawal.
4.6. AI Chatbot
You can query the AI Chatbot integrated into the Software, limited to your own personal data. Interactions with the AI Chatbot by the Company, through the corporate dashboard, take place exclusively on aggregated and statistical data containing no name or identifying reference to individual End Users.
Such data is processed for the following purpose.
4.6.1. Providing you with information on your personal data. Provision of the data is optional.
Justification: (for Users in Switzerland) Art. 31(1) FADP. Consent of the User. Retention period: for the duration of the conversation, unless you consent otherwise to the retention of the history.
4.7. Location Service (GPS)
If you activate the Location Service, we collect your geolocation (GPS) data solely for personal purposes related to the use of the App (e.g. routes and sports activities). Such data is not disclosed to the Company or made visible in the corporate dashboard and is not collected when the App is not actively in use for that specific feature.
Such data is processed for the following purpose.
4.7.1. Personalising the App. To provide you with personal features based on your geographical location. Provision of the data is optional and can be withdrawn at any time through the device permissions.
Justification: (for Users in Switzerland) Art. 31(1) FADP. Consent of the User. Retention period: until withdrawal.
5. Categories of recipients of personal data, disclosure and dissemination
Your data will not be disseminated to unspecified parties by being made available or consultable. We disclose your data to the following categories of recipients:
5.1. Collaborators or other staff authorised to process data (by way of example: administrative, sales and accounting staff, system administrators), within the limits necessary to carry out their duties for the Controller, subject to a letter of appointment imposing the duty of confidentiality and security.
5.2. Consultants or suppliers acting as data processors (by way of example: IT companies developing the Software, or other parties carrying out outsourced activities on behalf of the Controller), within the limits necessary to carry out their duties for the Controller, subject to the signing of a contract imposing the duty of confidentiality and security.
5.3. Bodies and, in general, any public or private party to which we are obliged (or entitled under primary, secondary or EU legislation) or need to disclose data, within their respective and specific areas of competence, such as, for example: i) the cantonal and federal authorities (e.g. for accounting or tax reasons) where a legal notification obligation applies; ii) other recipients (e.g. banks); iii) third-party providers which, on your behalf and in your interest, anonymise the documents relating to your blood tests (Google Cloud – Cloud Run and Cloud DLP), if you do not do so yourself; iv) third-party providers which process the photographs of food to provide the estimate of nutritional value as part of the Photo Calorie Count.
The Controller uses exclusively certified and secure service providers which:
- (i) are established in Switzerland;
- (ii) are established in the EEA, in particular ………………………;
- (iii) are established outside the EEA, in particular in ………………………
Disclosure of personal data to providers that do not adequately protect data under Swiss law is therefore excluded.
Data Subjects may request further information by writing to the following e-mail address: ………………………
6. Processing methods
Data is processed by means of technical and organisational measures suitable to ensure that the security of personal data is appropriate to the risk. Processing may be carried out both on paper and with the aid of automated IT tools capable of storing, managing and transmitting the data.
Data transmission between the app, the APIs and our servers takes place in encrypted form via the HTTPS protocol.
7. Rights of Data Subjects
Articles 25 to 32 of the FADP grant you the following rights and claims, within the limits of the prescribed legal framework:
- the right of access, to request information on the processing of your personal data;
- the right to request the updating and rectification of your personal data;
- the right to request the restriction of processing and of disclosure to third parties;
- the right to request erasure or destruction;
- the right to request a ban on processing or on disclosure to third parties;
- the right to request that the disputed nature of the data or the court decision be noted.
If you have a complaint about how we handle your data, we would like to hear from you, but you also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner.
8. How to exercise your rights
To exercise your rights and claims, in the manner and within the time limits prescribed by the FADP or the GDPR, you may proceed as follows: by writing to the following e-mail address ………………………
We kindly ask you to promptly inform the Controller of any change to your personal data so that we can comply with Article 6 of the FADP, which requires that the data collected be accurate and, therefore, up to date.
Pursuant to the Federal Act on Data Protection (FADP), I have read and understood every point of the above notice on the processing of my personal data.
Annex D2 – Employee Privacy Notice for companies established in Europe
Privacy notice
Notice on the processing of personal data pursuant to Article 13 of Regulation (EU) 2016/679
Dear Employee,
this notice on the processing of personal data governs the processing of the personal data of Employees of our company who access the Web Application or download the "Vitality+" application available on the Apple Store and Google Play.
1. Data subject
You, i.e. the natural person to whom this notice is addressed, also referred to as the User who uses the services offered by the "Vitality+" Web App.
2. Data Controller
The Controller of your personal data is ……………………… (hereinafter also the "Controller" or "………"), with registered office in ………………………, which can be contacted at the following e-mail address: ………………….
3. Nature of the data processed
We inform you that we will process the following data of yours:
- personal identification data, to allow you to register on the App;
- physical data: Gender, Weight, Height, Meals and food choices, to assess nutritional quality and balance;
- subject to your consent, given directly by ticking the boxes within the App, certain data defined by law as sensitive personal data; this is data from which information on your state of health can be derived, to allow the tool to help you improve your quality of life by offering you personalised plans to increase your levels of corporate wellness;
- subject to your consent, the reports, images or documents relating to your blood tests which you decide to upload voluntarily to the Software; such data is also processed by a third-party provider (Google Cloud – Cloud Run and Cloud DLP) which anonymises it if you do not do so yourself before uploading;
- the data from wearable devices and connected third-party applications (by way of example: Apple Watch, Whoop) through the Google Health Connect and Apple HealthKit integrations;
- the photographs of meals and/or the data on food and calorie values that you enter manually, for the calorie count feature;
- geolocation (GPS) data, subject to your consent, for the personal purposes described in the following point;
- the content of your interactions with the AI Chatbot, when you choose to use it to consult your personal data.
4. Purpose of processing, legal basis, retention period of your personal data
We inform you that your data will not be used to bring disciplinary charges or to monitor your conduct or performance, but will be used solely for the purpose of improving the corporate wellbeing of the employee/collaborator. The main objective of the software is therefore to increase levels of corporate wellness.
Failure to provide the data may prevent you from accessing the welfare benefits or personal rewards provided for those who complete the so-called "challenges" or actively take part in the use of the Software. In addition, failure to give consent could result in lower work performance, with indirect consequences for possible professional growth.
Such data is processed for the following purposes.
4.1.1. Providing the service
To follow up your registration, i.e. to give you access to the App and provide the services. Provision of the data is necessary; without it, it will not be possible to use the application.
Legal basis: Art. 6(1)(b) GDPR, performance of pre-contractual measures taken at the Data Subject's request. Retention period: data will be retained for 12 months after the end of the relationship.
4.1.2. Measuring performance through the processing of sensitive personal data
You can provide data relating to your state of health to allow us to help you improve your quality of life, offering you personalised plans to increase your levels of corporate wellness.
This will allow us to create tailor-made sports plans and optimise your rest by integrating your hours of sleep into your programmes to improve daily recovery and energy, and to suggest personalised activities and habits to adopt, including at work, that take your psycho-physical condition into account.
Provision of the data is optional and consent is given by ticking the relevant box and voluntarily providing the data relating to your state of health.
Legal basis: Art. 6(1)(a) GDPR, Consent of the User. Retention period: until withdrawal.
4.2. Health APIs
If you choose to authorise the account to access accounts created with other app providers such as SDKs and APIs, Apple Health, Google Fit and other platforms, Vitality+ will obtain information about you from those accounts and sometimes also information about your health.
Such data is processed for the following purpose.
4.2.1. Personalising the App. Through integration with other platforms. Configuration is optional, because our App is able to work even without such synchronisation, so the provision of this data is based on your consent.
Legal basis: Art. 6(1)(a) GDPR, consent of the Data Subject. Retention period: data will be retained until synchronisation is deactivated.
4.3. Synchronising the App with your devices
Our application allows you to synchronise your devices with the Vitality App. When you synchronise your device with the App, transmission data will be collected (for example: IP address, date and time of synchronisation, geographical location of the device).
Such data is processed for the following purposes.
4.3.1. Personalising the App. To allow you to personalise your profile by synchronising it with your devices to make the app easier to use. Device configuration is optional, because our App is able to work even without such synchronisation, so the provision of this data is based on your consent.
Legal basis: Art. 6(1)(a) GDPR, consent of the Data Subject. Retention period: data will be retained until synchronisation is deactivated.
4.3.2. Processing of sensitive personal data. When synchronising your devices you are free to also provide us with data relating to your state of health, to allow us to help you improve your quality of life by offering you personalised plans to increase your levels of corporate wellness. This will allow us to create tailor-made sports plans and optimise your rest by integrating your hours of sleep into your programmes to improve daily recovery and energy, and to suggest personalised activities and habits to adopt, including at work, that take your psycho-physical condition into account.
Provision of the data is optional and consent is given by ticking the relevant box and voluntarily providing the data relating to your state of health.
Legal basis: Art. 6(1)(a) GDPR, Consent of the User. Retention period: until withdrawal.
4.4. Uploading Blood Tests
If you choose to upload your blood tests as a PDF, as an image or via the device camera, such documents may contain your data or third-party data, including identifying data and data relating to your state of health. By uploading them, you undertake to anonymise the personal data before sharing them in the application.
In any event, we inform you that neither the Controller nor the Software Provider is able to identify the person who uploaded the document or to link the uploaded document to a specific End User. Furthermore, should you fail to remove or redact your identifying data before uploading, we have implemented an automatic anonymisation service based on Google Cloud (Cloud Run and Cloud DLP) which removes the personal identifiers contained in the document.
Such data is processed for the following purpose.
4.4.1. Providing you with informational support on your state of wellbeing. Provision of the data is optional and the upload takes place through a voluntary action by the User.
Legal basis: Art. 9(2)(a) of Regulation (EU) 2016/679, explicit consent of the Data Subject. Retention period: until consent is withdrawn or the Account is deleted.
4.5. Calorie Count
If you choose to use the calorie count feature via the camera, the photographs of food are processed by a third-party provider which provides an estimate of the nutritional value of the product. Alternatively, you can enter the food items and their calorie values manually, without using the camera.
Such data is processed for the following purpose.
4.5.1. Personalising the App. To provide you with information on the nutritional value of meals. Provision of the data is optional, since you can alternatively enter the data manually or not use the feature.
Legal basis: Art. 6(1)(a) GDPR, consent of the Data Subject. Retention period: until withdrawal.
4.6. AI Chatbot
You can query the AI Chatbot integrated into the Software, limited to your own personal data. Interactions with the AI Chatbot by the Company, through the corporate dashboard, take place exclusively on aggregated and statistical data containing no name or identifying reference to individual End Users.
Such data is processed for the following purpose.
4.6.1. Providing you with information on your personal data. Provision of the data is optional.
Legal basis: Art. 6(1)(a) GDPR, consent of the Data Subject. Retention period: for the duration of the conversation, unless you consent otherwise to the retention of the history.
4.7. Location Service (GPS)
If you activate the Location Service, we collect your geolocation (GPS) data solely for personal purposes related to the use of the App (e.g. routes and sports activities). Such data is not disclosed to the Company or made visible in the corporate dashboard and is not collected when the App is not actively in use for that specific feature.
Such data is processed for the following purpose.
4.7.1. Personalising the App. To provide you with personal features based on your geographical location. Provision of the data is optional and can be withdrawn at any time through the device permissions.
Legal basis: Art. 6(1)(a) GDPR, consent of the Data Subject. Retention period: until withdrawal.
5. Categories of recipients of personal data, disclosure and dissemination
Your data will not be disseminated to unspecified parties by being made available or consultable. We disclose your data to the following categories of recipients:
5.1. Collaborators or other staff authorised to process data (by way of example: administrative, sales and accounting staff, system administrators), within the limits necessary to carry out their duties for the Controller, subject to a letter of appointment imposing the duty of confidentiality and security.
5.2. Consultants or suppliers acting as data processors (by way of example: IT companies developing the Software, or other parties carrying out outsourced activities on behalf of the Controller), within the limits necessary to carry out their duties for the Controller, subject to the signing of a contract imposing the duty of confidentiality and security.
5.3. Bodies and, in general, any public or private party to which we are obliged (or entitled under primary, secondary or EU legislation) or need to disclose data, within their respective and specific areas of competence, such as, for example: i) the cantonal and federal authorities (e.g. for accounting or tax reasons) where a legal notification obligation applies; ii) other recipients (e.g. banks); iii) third-party providers which, on your behalf and in your interest, anonymise the documents relating to your blood tests (Google Cloud – Cloud Run and Cloud DLP), if you do not do so yourself; iv) third-party providers which process the photographs of food to provide the estimate of nutritional value as part of the Photo Calorie Count.
The Controller uses exclusively certified and secure service providers which:
- (i) are established in the EEA;
- (ii) are established outside the EEA, in particular in Switzerland through the company Vitality Plus, which developed the App and provides support for the tool.
The transfer is therefore authorised since Switzerland has been recognised by the European Commission as an adequate country.
Data Subjects may request further information by writing to the following e-mail address: ………………………
6. Processing methods
Data is processed by means of technical and organisational measures suitable to ensure that the security of personal data is appropriate to the risk. Processing may be carried out both on paper and with the aid of automated IT tools capable of storing, managing and transmitting the data.
Data transmission between the app, the APIs and our servers takes place in encrypted form via the HTTPS protocol.
7. Rights of Data Subjects
Articles 15 to 21 of the GDPR grant you the following rights, within the limits of the prescribed legal framework:
- the right of access under Article 15 GDPR and the right to rectification (to amend your data) under Article 16 GDPR;
- the right to erasure under Article 17 GDPR and the right to restriction of processing (i.e. that such data is not subject to further processing and can no longer be modified) under Article 18 GDPR;
- the right to data portability (i.e. to receive the personal data concerning you, which is processed by automated means, in a structured, commonly used and machine-readable format, and to transmit it to another controller, or to have it transmitted directly) under Article 20 GDPR;
- the right to object to processing (i.e. to object to the processing of data concerning you and to the sending of advertising material, direct sales and market research) under Article 21 GDPR.
If you have a complaint about how we handle your data, we would like to hear from you, but you also have the right to lodge a complaint with the supervisory authority competent for the country in which you habitually reside, without prejudice to any other administrative or judicial remedy.
8. How to exercise your rights
To exercise your rights and claims, in the manner and within the time limits prescribed by the FADP or the GDPR, you may proceed as follows: by writing to the following e-mail address ………………………
We kindly ask you to promptly inform the Controller of any change to your personal data so that we can comply with Article 16 of the GDPR, which requires that the data collected be accurate and, therefore, up to date.
Pursuant to the General Data Protection Regulation (GDPR), I have read and understood every point of the above notice on the processing of my personal data.
Prevailing language version
These terms of use are available in several languages. Translations are provided for ease of understanding only: in the event of any divergence, doubt of interpretation or conflict between versions, only the Italian version prevails and is legally binding.

