Two different roles
In Abra there are two kinds of data, and someone different answers for each. It matters because it changes whom you have to ask for what.
- The organisation running a mission answers for that mission's data. It decides whom it registers, what it keeps about each person, why and for how long, and it is the one who asks for consent when consent is needed. It is the controller. Its name appears in every message you receive and on the page it takes you to.
- We keep that data on its behalf. We are the processor (Article 28 of the GDPR): we store it, show it to whoever the organisation authorises and do nothing else with it. What that obliges us to do is in the data processing agreement.
- We answer for your account. If you sign in to the panel, you do so with a ProfBlu account — email, name, password, sessions —, which is the same for every application on the platform. We are the controller of that data, and it is explained in the platform's privacy policy, at https://profblu.com/en/privacidad.
Who the processor is
- Owner: Germán Ezequiel Laso Andino, libero professionista, trading as ProfBlu.
- Partita IVA: 04702090988. Codice fiscale: LSNGMN88S04Z600M.
- Professional activity not registered in the Registro delle Imprese (no REA number).
- Contact address: Via della Sega 1, 38080 Verdesina, Porte di Rendena (TN), Italia.
- Email for anything about your data: privacidad@profblu.com.
No data protection officer has been appointed: the law does not require one for an activity of this size.
What data Abra keeps
What follows comes from the application's code, not from a generic list. Which specific fields are asked for in each mission is decided by its organisation, because each mission brings its own forms.
About those taking part in a mission
- The name under which you appear in the mission, and whether you take part as a person or as an entity.
- Contact details: email, phone and address, whichever the organisation has. They are stored apart from the rest and do not appear in any listing.
- Your role in the mission, from when and until when, and in which areas.
- Your permission to receive messages by WhatsApp, if you gave it: when, by which means and, if someone on the team noted it, who.
- Your consent, if the mission asks for it: the exact text generated for you with its fingerprint, whether it is signed, when, who recorded the signature, who signed and in what capacity, and the scanned paper.
- What you do: what you offer, what you commit to, what you deliver, the photos or documents you upload as proof of a delivery, and whether someone checked it.
About the person the aid goes to
Abra calls them the "subject" of a request. What is kept about them is whatever the mission's form asks for. Part of that data — the part the organisation marks as protected, which is where the full name, the address or the phone go — is stored in a separate table:
- it is seen only by those who hold a specific permission for it;
- every time someone reads it, a note is made of who it was and when;
- it does not appear in listings, in the summary, or in any email or message.
If the person is a minor
Abra does not ask minors for data and does not open accounts for them. A minor's data is entered by the entity that has them in its care or by whoever the organisation designates, and the consent is signed by an adult on their behalf: their mother, their father, their guardian, or the entity's legal representative. Abra does not allow that signature to be recorded without noting who signed, in what capacity and with what relationship.
About those who receive a handover link
If you receive a link to take charge of a request that another person had to give up, Abra holds your name and your email, and your phone if someone gave it. If the one who proposed you was the person who withdrew, that data was written by them: it does not come from you. The link's page tells you so and explains what you can do.
Of your reply, what is kept is whether you accepted or not, when, and the reason if you write one.
About messages
For each email or message a mission sends, what is kept is whom it was for, the subject, the text, which channel it went out by and whether it was delivered or why not.
About the trail of what is done
Every action that changes something — registering, committing, verifying, correcting a contact — leaves an audit line: what was done, who did it, when and for what reason. That trail cannot be edited or deleted, and for that very reason it carries no contact details and none of the content of what was changed: it says a phone number was corrected, not what it was.
What for, and on what basis
The purpose and the legal basis for a mission's data are set by its organisation, which is the one that answers for them. As far as we are concerned:
- To provide the service to the organisation — storing, showing, sending the notices it configures —: because it is what we agreed with it in the data processing agreement.
- For security and maintenance — error and access logs —: on our legitimate interest in the service working and in being able to investigate an incident.
We do no profiling, we take no automated decisions about anyone, we do not use a mission's data for advertising and we do not sell or transfer it.
Where it is processed, and who else sees it
- Hetzner Online GmbH hosts the server, in Nuremberg (Germany). Within the European Economic Area.
- IONOS SE delivers outgoing email, from its Spanish region. Within the EEA.
- WhatsApp: Abra can send a notice by WhatsApp through Meta Platforms Ireland Ltd., which receives the number and the text of the message. It only happens if the organisation has that channel switched on and the person gave their express permission for that number. Today that channel is switched off: no mission uses it.
There is nobody else. In Abra's code there is no analytics tool, no advertising tool and no other external provider receiving data.
For how long
Abra deletes nothing on its own. A mission's data is kept for as long as its organisation needs it and until it asks for it to be deleted; the specific period for each piece of data is set by the organisation, which states it in its mission's consent.
What is kept in any case is the audit trail and the record of signed consents, with their date and version: they are the proof that things were done as stated, and they carry no contact details.
Your rights
You have the rights the General Data Protection Regulation gives you: access, rectification, erasure, portability, objection, restriction and withdrawing your consent without affecting what was done before.
- Regarding a mission's data, they are exercised before the organisation running it. If your request reaches us, we pass it on to the organisation and help it handle it.
- Regarding your account, write to us at privacidad@profblu.com from your account email. We reply within the legal deadline, one month at most.
- For us to stop writing to you about a mission, reply to the message or write to the organisation; if you get no answer, write to us.
You may complain to the supervisory authority: in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it); in Spain, the Agencia Española de Protección de Datos (www.aepd.es); in Argentina, the Agencia de Acceso a la Información Pública (www.argentina.gob.ar/aaip); or the authority of the country where you live.
Security
Communications are encrypted (TLS). Access to data depends on each person's role within their organisation and their mission, and organisations are isolated from one another. Protected data has its own permission and each reading of it is noted. If we detect a breach affecting a mission's data, we tell its organisation without undue delay.
A warning about the demonstration
Addresses containing demo are a demonstration environment: it is rebuilt, emptied and seeded again. Do not put other people's real data into a demonstration, least of all that of minors.
Changes
If we change what we do with data, we change this text and move the revision date.